← Policies
MedliLog -- offline health-record vault

Privacy Policy

Effective Date: July 23, 2026
Health Data Storage 100% On-Device
User Accounts None Required
Ads / Analytics Zero, None
Cloud Servers None Operated by Us

1. Executive Summary

MedliLog is a personal health-record vault built with a strict offline-first architecture. Your vitals, lab reports, medications, and insurance policies are deeply personal and stay under your control. We do not require accounts, we operate no servers that store your health data, and we collect no analytics. By default, nothing leaves your device.

There is exactly one optional feature that can send data off your device, and only when you deliberately turn it on: the online AI assistant (Section 4). Everything else is fully local.

2. Data You Store in MedliLog

All records you enter are stored directly in a sandboxed database (IndexedDB) on your device. This includes:

  • Vitals: readings such as blood pressure, glucose, weight, and heart rate, with their history.
  • Lab reports and prescriptions: images you capture and the text extracted from them.
  • Medications: the medicines, dosages, and schedules you track.
  • Insurance and mediclaim policies: policy details you choose to record.
  • Emergency profile: information such as name, blood type, allergies, and emergency contacts.

We cannot access, read, edit, or delete any of this data. It never leaves your phone unless you choose to export a backup or enable the optional online AI assistant.

3. On-Device Text Recognition (OCR)

MedliLog can scan paper lab panels and prescriptions and convert them into text. This text recognition runs entirely on your device. The images you scan and the text extracted from them are stored locally and are not uploaded to us or any third party.

4. Optional Online AI Assistant (Google Gemini)

The AI Health Guide works fully offline using an on-device medical databank -- no account, no network, no model download. You may optionally enable higher-quality online answers by entering your own Google Gemini API key.

  • Opt-in and off by default: if you leave the API key blank, MedliLog stays entirely on-device and this feature is inactive.
  • What is sent, and when: when -- and only when -- you enable this feature and ask a question, the text of your question is sent over an encrypted (HTTPS) connection to Google's Gemini API so it can be answered. The app strips obvious personal identifiers where practical, but you should avoid entering directly identifying details in questions.
  • Whose terms apply: because the request uses your own API key, that data is handled by Google under the terms of your Google / Gemini API account. MedliLog does not operate a server in between and does not retain your questions.
  • You are in control: remove the key at any time to return the app to fully offline operation.

5. Device Permissions

To deliver its features, the app may request these permissions:

  • Camera and Photos/Media: used only when you scan or import a lab report or prescription for on-device OCR. Images stay on your device.
  • Internet: used only for the optional online AI assistant (Section 4) and for Google Play licensing/purchases. The core app works with no network connection.
  • Set wallpaper: used only when you choose to set your emergency medical ID card as your device's lock-screen wallpaper, so first responders can see critical information without unlocking your phone. This is user-initiated.

6. Backups, Portability, and Deletion

Because your data is on-device, backing it up and deleting it are entirely under your control:

  • Exports: you can export a backup file from within the app and save it to storage you choose (for example, your device, or your own Google Drive).
  • Deletion: you can clear your data inside the app, or uninstall the app, to remove it from the device. Backups you exported are managed by you.

7. Third-Party Services and Tracking

MedliLog contains no third-party advertisements, no advertising-network SDKs, and no analytics software (such as Firebase Analytics or Mixpanel). Aside from the optional Gemini assistant you may enable yourself, the app talks to no external services. Your usage remains anonymous to us.

8. Children

MedliLog is a personal health-record tool intended for general audiences and is not directed at children.

9. Medical Disclaimer

MedliLog is a personal record-keeping and reference tool. It does not diagnose, treat, or prescribe, and it is not a medical device or a substitute for professional medical advice. Always consult a qualified clinician for medical decisions.

10. Changes and Contact

If this policy changes, the updated version will be posted at this URL with a revised effective date. For privacy questions, feedback, or concerns, please open an issue in the project's GitHub repository.