Privacy Policy
Last updated: 2 August 2026
MedCabinet helps households track medicines on their Android device. This policy explains what we store, what syncs to the cloud when you sign in, and how optional analytics and notifications work.
1. Who we are
MedCabinet is operated for the product at medcabinetapp.com. Questions: support@medcabinetapp.com.
2. Data we process
- Account: email, password (hashed), display name, optional country, language preference.
- Cabinet inventory: medicine names, barcodes, stock counts, expiry dates, notes, photos you capture, and related AI draft fields.
- Reminders: local dose schedules on your device; schedules may sync so other signed-in devices stay aligned.
- Family sharing: invitation emails, cabinet membership, and care-profile labels you create.
- Device signals: push token (if Firebase is configured), app language, and basic diagnostics needed to keep sync reliable.
- Optional analytics: product events you allow in Settings (for example scan started or medicine saved). No advertising ID sale.
3. Where data lives
- On device: inventory and photos are stored in an encrypted local database / app storage.
- In the cloud (when signed in): your private cabinet syncs to MedCabinet’s Azure-hosted API, SQL database, and blob storage for photos and avatars.
- Processors: email delivery (Azure Communication Services or SMTP), AI pack analysis (Azure OpenAI) when you upload photos for analysis, and Firebase Cloud Messaging when push is configured.
4. Why we use the data
- Provide the cabinet, reminders, family sharing, and care-profile features you request.
- Authenticate your account and protect against abuse (rate limits, audit of admin actions).
- Improve recognition quality when you submit pack photos for analysis.
- Send optional alerts (family updates, security notices) if notifications are enabled.
- Understand product usage only when analytics are opted in.
5. Sharing
We do not sell your personal data. Cabinet contents are shared only with people you invite to that cabinet, or with service providers that process data solely to run MedCabinet (hosting, email, AI analysis, push). Admin operators may access limited records under role controls for support, safety review, or abuse response, with auditing.
6. Retention & account deletion
Account and cabinet data remain while your account is active. You can delete medicines in the app. To close your account and request deletion of associated cloud data, use: medcabinetapp.com/delete-account.html (or email support@medcabinetapp.com). Backups and audit logs may persist for a limited operational period.
7. Security
We use HTTPS for API traffic, hashed passwords, encrypted local storage on Android, and role-based access for the admin console. No method of transmission or storage is perfectly secure; keep your device unlocked only for trusted people and use a strong password.
8. Children
MedCabinet is intended for adults managing a household cabinet. It is not directed at children. Care profiles are labels you create; do not store sensitive clinical records for minors beyond what you need for household organization.
9. Your choices
- Use the app without cloud features until you create an account.
- Skip AI analysis or edit any AI draft before saving.
- Turn analytics off or on in Settings.
- Revoke notification permission in system settings.
- Leave shared cabinets or remove members you invited.
- Request account and data deletion at Delete account.
10. Changes
We may update this policy as the product evolves. The “Last updated” date above will change when we do. Continued use after an update means you accept the revised policy.
11. Contact
Privacy questions: support@medcabinetapp.com
Account deletion: Request deletion
Product site: medcabinetapp.com