MediFamily Logo MAS Labs / MediFamily
  • Home Hub
  • Features
  • Privacy Policy
  • Terms of Use
  • Contact Us
Legal & Compliance

MediFamily Privacy Policy

Last Updated: September 7, 2026 • Version: 2.1 (Store-Ready Compliance)

đź”’ Our Core Privacy Guarantee: MediFamily is architected as an offline-first, zero-knowledge health tracking hub. Your medical records, prescription logs, attached photos, and vital readings are stored locally on your device in an encrypted vault and are NEVER transmitted to or stored unencrypted on any central cloud server.

1. Information We DO NOT Collect

Unlike traditional cloud medical applications, MediFamily operates on a strict minimization and decentralized architecture. We do NOT collect, access, monetize, or harvest:

  • Personal Health & Routine Data: Your medication names, dosages, vital signs, blood glucose readings, blood pressure logs, and personal notes remain exclusively on your device.
  • Health Document Attachments: Lab report photos, prescription packaging scans, and doctor note PDFs are stored in your device's private sandboxed file system.
  • Precise Location Data: We do not request, access, or track GPS coordinates or Wi-Fi location beacons.
  • Biometric Data: FaceID or Fingerprint authentication is processed entirely on-device by your operating system’s secure enclave.
  • No Commercial Advertising Trackers: We do not sell your personal health records or embed third-party advertising networks (such as Google AdMob or Meta Ad Pixel) to track you across apps. We may utilize privacy-preserving, aggregated diagnostics (such as Firebase Analytics & Crashlytics) to monitor application stability and performance, without linking analytics metrics to your personal medical records.

2. Information We Process for Security & Account Identity

To provide verified cryptographic backups and subscriber communications, we process only the minimal necessary data:

  • Verified Email Address: Used solely to dispatch 6-digit One-Time Password (OTP) verification codes and to anchor client-side zero-knowledge cryptographic backups.
  • Device Platform & General Region: Coarse device language format (e.g. en_AE) and operating platform (iOS / Android) for local time and language formatting.
  • Marketing Opt-In (Optional): If you explicitly check the opt-in box during verification, we may send you occasional product updates from MAS Labs. You can unsubscribe at any time.

3. Zero-Knowledge Cryptographic Backup Architecture

When you create an encrypted backup package (.medifamily) or single profile transfer package (.medifamilyprofile):

  • Data is encrypted client-side using industry-standard AES-256-CBC envelope encryption.
  • Encryption keys are mathematically derived using PBKDF2 with SHA-256 hashing bound to your chosen secret password or 16-character Emergency Recovery Key. Backup headers securely embed cryptographic salt anchors, enabling seamless restoration across any device.
  • MAS Labs does NOT hold, escrow, or store your passwords or recovery keys. We cannot decrypt your backups under any circumstances.

4. Device Hardware Permissions & Justifications

In accordance with Google Play Health Apps, User Data, and Permissions policies, MediFamily requests only the minimal hardware permissions strictly necessary for user-initiated health tracking, document archival, and medication adherence features:

  • Camera (android.permission.CAMERA / NSCameraUsageDescription): Accessed solely to allow users to photograph printed paper medical records, prescription packaging, or doctor notes for encrypted on-device archival. The camera is NOT used as an optical physiological sensor (such as for heart rate or pulse oximetry measurements).
  • Photo Library & Storage (READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE / NSPhotoLibraryUsageDescription): Accessed solely to allow users to import existing document images or PDF clinical summaries from device storage into their private, local-only encrypted vault.
  • Exact Alarms (SCHEDULE_EXACT_ALARM / USE_EXACT_ALARM): Schedules exact-minute alarms solely to deliver timely, user-configured reminders for daily medication adherence and household wellness routines, preventing delays during operating system battery-saver modes.
  • Post Notifications (POST_NOTIFICATIONS): Requested solely to deliver user-scheduled medication dose reminders, refill warnings, and doctor appointment alerts. MediFamily never uses push notifications for marketing, advertising, or promotional tracking.
  • Restore Alarms on Device Restart (RECEIVE_BOOT_COMPLETED): Because mobile operating systems clear pending alarm timers upon power-off or reboot, this permission allows MediFamily to automatically re-register your active medication reminder schedules when your phone turns back on, ensuring continuous adherence.
  • Keep Device Awake (android.permission.WAKE_LOCK / iOS Idle Timer): Invoked strictly during active, user-initiated cryptographic operations (such as creating or restoring AES-256 encrypted health vaults and exporting or importing encrypted family profile packages) to prevent the device from entering sleep mode mid-process, guaranteeing zero archive corruption. It is immediately released upon completion and is never active in the background or during normal app usage.

5. Data Retention, Portability & Deletion

Because your medical data resides exclusively on your local device:

  • Complete Control: You can delete any family profile, medication, or medical record at any time from within the app.
  • App Deletion: Uninstalling the application permanently deletes the local on-device database and all cached attachments from your device.
  • Portable Exports: You can export your health summaries as printable PDF documents or encrypted archives whenever you choose.

6. Children’s Privacy (COPPA & GDPR-K Compliance)

MediFamily allows parents and legal guardians to manage pediatric family profiles (e.g., child vaccinations, growth measurements). This data is entered solely by the parent, stored locally on the parent's device, and is never shared, marketed to, or harvested.

7. Compliance with Store Guidelines & Regulations

This policy complies fully with the Apple App Store Review Guidelines (Guideline 5.1 Privacy), Google Play Developer Program Policies (User Data & Health Content), the General Data Protection Regulation (GDPR), and international health data privacy standards.

8. Contact Our Data Protection Officer

If you have any questions, security inquiries, or feedback regarding this Privacy Policy, please contact our dedicated security team:

  • Publisher: MAS Labs Health Informatics
  • Security & Privacy Desk: security@maslabs.app
  • Customer Support: support@maslabs.app
  • General Inquiries: info@maslabs.app
© 2026 MAS Labs. All rights reserved. MediFamily™ Privacy Center.
Terms of Service • Home Hub