Jump to section
HealthSync handles health information, which is sensitive personal information. This policy explains what we collect, why, who can see it, where it is kept and how you can have it removed. It applies to the HealthSync Android app and its supporting services.
1. Who we are
Link to this sectionThe HealthSync Team, a BSIT capstone team at National Teachers College, decides how and why your information is used. On Google Play, HealthSync is published under the developer name seymoneym on behalf of the HealthSync Team. Contact: support.healthsync@gmail.com.
2. What we collect
Link to this section| Who it is about | Information | Where it comes from |
|---|---|---|
| Care partner | First and last name, email address, phone number, password (stored and protected by Firebase Authentication, not readable by us) | You, when you register |
| Care partner | Alert settings (missed dose, low stock, daily), notification token | You, and your phone |
| Managed patient | First and last name, optional phone number | The care partner, when adding the patient |
| Managed patient | Medical conditions, allergies, emergency contact name and phone number | The care partner, when adding the patient, if entered |
| Medicines | Medicine name, form (tablet, capsule, liquid and so on), purpose, colour label, amount per dose, dose times and days, pill count, low-stock level, medicine box compartment | The care partner |
| Dose history | Scheduled time, status (pending, taken, snoozed, skipped, missed), whether logged on time or late, the time confirmed, snooze count, optional reason | The patient's actions and our servers |
| Alerts | Records of alerts sent to the care partner and patient (for example dose taken, running late, missed, low stock) | Our servers |
| Phone | A Firebase Cloud Messaging token, used to deliver push notifications to that phone | Your phone |
| Medicine box (optional) | Box serial number, pairing status, which compartments are in use | The care partner or patient, when pairing a box |
A managed patient has no email address or password. They sign in with a one-time code that the care partner gives them. The code can be used once and expires after 48 hours.
3. What we do not collect
Link to this sectionHealthSync does not collect your location, contacts, photos, camera or microphone data, or an advertising ID. It has no ads and no analytics or crash-reporting service. We do not sell your information.
4. How we use it
Link to this section- To create and run accounts and link a care partner to a patient.
- To store medicines and schedules, create dose records, and send reminders.
- To record whether a dose was taken, late or missed, and to show history and adherence summaries.
- To alert the care partner when a dose is running late or missed, or stock is low.
- To work with the optional medicine box.
- To keep the service secure and fix problems.
We use health information only for these purposes. We do not use it for advertising, profiling or marketing.
Your consent. Medical conditions, allergies and medicine information are sensitive personal information. By registering, or by using a one-time code to open an account a care partner created for you, you agree to us handling this information for the purposes above. A care partner who enters a patient's information confirms they are authorised to do so (see the Terms of Service, section 6). You can withdraw consent by deleting your account, though HealthSync cannot work without the information it needs.
5. Who can see your information
Link to this section- The patient sees their own medicines, schedule and dose history.
- The linked care partner sees the patient's medicines, schedule, dose history, adherence summaries and alerts, and can add, change or retire medicines. A patient has one linked care partner.
- Our servers process dose records and send alerts automatically. Team members may access stored data only when needed to keep the service running, fix a problem or handle a request from you.
- Nobody else. We do not share health information with advertisers, data brokers or other apps, and we do not publish it. We may disclose information if a law, court order or government authority requires it.
6. Service providers and where data is kept
Link to this sectionWe use these services to run HealthSync. They process data for us. Your information is stored on Google servers in Singapore (Google Cloud region asia-southeast1), which is outside the Philippines. HealthSync is intended for use in the Philippines.
- Google Firebase (Authentication, Cloud Firestore, Cloud Messaging): accounts, stored data and push notifications.
- Cloudflare (Workers): the service that creates dose records, detects late and missed doses and sends alerts. It keeps a short-lived access token in a cache; it does not keep a database of your health data.
These providers have their own privacy practices. Data in transit between the app and these services is encrypted.
7. Notifications and the medicine box
Link to this sectionDose reminders are scheduled on the phone itself, using notification and alarm permissions that you can turn off in Android settings. Turning them off may stop reminders. Push alerts to care partners use the notification token described above. The optional medicine box connects through our server using its serial number and is used only to show which compartment is due.
8. Security
Link to this sectionWe protect information with sign-in requirements, access rules that limit each user to their own records and their linked patient, and encrypted connections. No system is completely secure, and we cannot guarantee it. Keep your password and one-time codes private, and tell us at support.healthsync@gmail.com if you think your account was accessed by someone else.
9. How long we keep it, and deleting it
Link to this section- We keep your information while your account exists.
- In the app: a care partner can open Profile and tap Delete account. A managed patient can request deletion in the app, and their care partner is asked to confirm it.
- Without the app: follow the steps on the account deletion page, or email support.healthsync@gmail.com from the address on your account.
- Once your request is confirmed, we delete your account and the information linked to it within 30 days. Copies in backups are removed within that period or when the backups expire.
- If a care partner deletes their account, the accounts of the managed patients they created are deleted too, together with those patients' medicines, schedules, dose history and alerts. The app lists these patients and asks for confirmation before anything is deleted. A managed patient account cannot be used without a care partner.
- We may keep a minimal record of the request itself, and information we are legally required to keep.
10. Your rights
Link to this sectionUnder the Data Privacy Act of 2012 (Republic Act No. 10173) you have the right to be informed about how your data is used, to access it, to correct it, to object to its use, to have it erased or blocked in the cases the law provides, to data portability, and to be compensated for damages from unlawful use. Email support.healthsync@gmail.com to use any of these. Care partners can also correct a patient's details in the app. You may file a complaint with the National Privacy Commission (privacy.gov.ph).
11. Age
Link to this sectionHealthSync is for adults. We do not knowingly collect information from children as account holders. A care partner may enter information about a person in their care only if authorised to do so.
12. Changes to this policy
Link to this sectionIf we change this policy in a material way, we will update the effective date and tell you in the app or by email before the change takes effect, where the law requires.
13. Contact
Link to this sectionHealthSync Team, BSIT, National Teachers College ยท support.healthsync@gmail.com