HealthDecoder ("the app," "we," "our") is built around one rule: your medical records are yours, and they stay on your device. This page explains exactly what data the app touches, why, and what you control.
This app is provided by an independent developer, not a hospital, clinic, or certified medical device manufacturer. See the in-app Medical Disclaimer for details on that.
Every medical record you scan or enter — reports, lab values, medicines, doctor notes, reminders, appointments — is stored in an encrypted local database (SQLCipher) on your phone. This data is never uploaded to, or stored on, any server we operate. If you uninstall the app without exporting first, this data is gone; we have no copy to recover it from, because we never had one.
To extract structured information (medicines, lab values, dates) from a scanned report or answer a question you ask, the relevant page images or text are sent to:
This happens through our backend, which relays the request but does not store the report content — it only resolves which API key to use and enforces a daily usage limit. Neither Gemini nor Sarvam is instructed to retain your data for training or any purpose beyond processing that single request. The structured result they return is saved only in your device's local, encrypted database.
You must accept this in the in-app disclaimer before the app can be used, since scanning and AI chat don't work without it.
Our backend uses a Postgres database for exactly three things: accounts (if you sign in), anonymous usage/quota counters, and UI translation strings. It does not contain your medical reports, scanned images, lab values, or AI chat history — those never leave your device except transiently, in-transit, to the AI services described in Section 2.
In Account settings, there's an opt-in toggle asking whether you'd be willing to have only your age and sex — never your name, reports, exact location, or any other detail — used in aggregate for medical research, to help fund keeping this app free.
This program has not launched. Turning the toggle on today only records your preference on your device; no data is transmitted to us or anyone else because the collection pipeline doesn't exist yet. If this ever becomes active, this policy will be updated first, and only users who separately opted in at that time would be included.
| Permission | Why |
|---|---|
| Camera | To photograph reports/prescriptions and scan QR codes from lab reports |
| Notifications, exact alarms | To deliver medication and appointment reminders on time |
| Full-screen intent | So a medication reminder can show as a full-screen alert with large text |
| Biometric | Only if you enable fingerprint login |
| Internet / network state | To reach the AI proxy and, if signed in, sync your account |
Google Gemini, Sarvam AI, and (if you sign in with Google or link Gmail) Google's own account/OAuth systems. We do not sell data to advertisers or data brokers, and the app does not run any analytics or advertising SDK.
If what the app collects or how it's used changes materially, this page will be updated and the date at the top revised. Continued use of the app after an update means you accept the revised policy.
Questions about this policy or a request to delete your account data can be sent via GitHub or through the app's own feedback channel.