Privacy Policy
At Upkit, we prioritize your privacy through a “Privacy by Design” approach. Our core principle is straightforward: “Your health information” belongs to you and remains on your device, and we maintain a strict policy of non-interference—meaning we do not transmit, retrieve, or monitor your personal health records. “Your health information” includes your Health Profile — the medications, health conditions, healthcare providers, and healthcare facilities you record (your personal health information, or “PHI”). The limited exceptions to on-device-only processing are described under “Third-Party Services” — principally the optional place search and map display, where text you enter and the map area you are viewing are sent to a third-party map provider.
No AI Training on Your Health Data
We do not, and will not, use your health information (PHI) — your medications, health conditions, healthcare providers, healthcare facilities, or any other Health Profile content — to train, fine-tune, or develop artificial-intelligence or machine-learning models. We also do not sell, share, or transfer your health information to any third party for them to do so. This commitment holds even if the data were aggregated or de-identified. Because your health data is stored only on your device and is never transmitted to us, we do not have it available for any such purpose in the first place.
Local Personal Health Information
Upkit is built “Local-First”: your sensitive health information stays on your device, under your exclusive control.
- On-Device Encryption: Your Health Profile — your medications, health conditions, healthcare providers, and healthcare facilities — is structured using the industry-standard FHIR data model and stored in an encrypted local database on your device. The encryption key is held in your device’s secure keystore, and photographs you attach are encrypted separately, file by file, with AES-256. This protects your data against unauthorized access by other applications on your device.
- Data Access Policy: As the developer of Upkit, we maintain a Strict Non-Interference Policy. While we technically manage the application’s architecture, we do not transmit your health records to our servers. We do not monitor, retrieve, or “peek” at the personal health information stored in your local app database.
- No Backups or Remote Recovery: Because we never store a copy of your records on our servers, we cannot recover them if your device is lost, stolen, damaged, or the app is deleted. Your data exists only where you control it — on your device — so you are responsible for keeping any external records of your medication history that you may need.
- Zero-Knowledge in Practice: We operate no server that holds your health information, and the app has no facility to send it to us. We therefore cannot read your health records — not as a policy choice, but because the data never reaches us. If we ever introduce cloud backup or cross-device syncing, it will use end-to-end encryption so that this stays true in transit and at rest.
- Future Syncing Features: If we introduce cloud backup or cross-device syncing features in the future, these will be strictly opt-in. Your health data will only be uploaded if you provide explicit consent and activate the service manually.
Exporting Your Data
Upkit lets you export two kinds of reports: a History Report — the recorded history of one medication as a PDF or CSV file — and a Medication Report — a PDF listing the medications you choose to include, with their schedules, instruction notes, the pause reason if currently paused, and the latest photo attached. This is the one point at which health information deliberately leaves the protection described above, and it happens only when you choose it.
- On-Device Generation: The file is created entirely on your device. No part of the export is sent to Synctronic or to any third party while it is generated, and we never receive, see, or store a copy.
- Not Saved by Default: We do not save the report into your device's storage. It is held temporarily while you decide what to do with it, and cleaned up automatically. If you want to keep a copy, you save it yourself — from the viewer you open it in, or from the share sheet.
- Not Encrypted: The health information held inside Upkit is encrypted on your device and inaccessible to us. An exported report is an ordinary document: once you save or send it, it can be read by anything with access to it. Upkit's encryption does not extend to it.
- Photos: If you attach a photo to a medication, it is stored encrypted on your device. When you include that medication in a Medication Report, the photo is decrypted, reduced in size, and embedded in the report file. This is the only way a photo leaves the encrypted store, and it happens only when you export.
- You Control Who Sees It: If you share an exported report — by messaging app, email, cloud storage, or by handing it to a healthcare provider — you are the one disclosing that health information. Synctronic is neither the controller nor a processor of the copy you share, and we cannot recall, restrict, or delete it. The privacy terms of whatever service you use, and the practices of whoever receives the file, apply from that point on.
- Limiting What You Export: You can narrow what a report contains before you create it, by shortening the date range, deselecting record types, and turning off notes and details for a History Report, or by choosing which medications to include in a Medication Report, and you can delete any copy you save once you no longer need it. A full explanation of what an exported report is, and how it should be read, is published at upkit.app/reports.
Data Collection & Usage
We aim to minimize the information we collect and process. Outside your on-device Health Profile, the only data involved is the limited information below.
Information You Provide to Us via Support Channels
When you contact us for support or otherwise communicate with us, you may provide information such as:
- Account Information: Your name and email address if you contact us for support.
- Communication Data: The content of your messages and any attachments if you contact us via email.
Information Collected Automatically (Identifiers)
To ensure app stability and improve your experience, our third-party services (Firebase Analytics and Crashlytics) collect specific technical identifiers:
- Device Identifiers: Firebase assigns a random installation identifier to your copy of the app so that our diagnostic and analytics services can tell installations apart. Collection of the IDFV (Identifier for Vendors on iOS) and the Android advertising identifier is disabled.
- Advertising Identifiers: We do not collect them. Collection of the IDFA (Apple) and the AAID (Google) is disabled in the app on both platforms, and advertising personalisation is switched off in all regions.
- Device State: (e.g., battery optimization status), granted permissions, reminder telemetry (timestamps, and internal IDs), time zone.
- Technical Data: This includes your IP address (pseudonymized), device model, and operating system version.
What We Do NOT Collect
Unless you explicitly opt-in to a cloud-sync feature, the following data is stored strictly on your device and is never transmitted to our servers:
- Health & Medication Data: we do not transmit, retrieve, or monitor your personal health records, including your stock counts, refill records, and refill reminder settings.
- Approximate Birth Date (Optional): if you add general information to your Health Profile, your approximate birth date (month and year only) is stored locally and used only on-device — for example, to work out a date from your age when you record when a health condition began.
- Biometric Data: While we utilize Fingerprint or FaceID authentication for security, we do not see or store your biometric templates.
- Default Location (Optional): if you save a default location in your Health Profile, the place name and its coordinates are stored locally on your device and used to centre map searches. Searching for that location sends your search text to a map provider, as described under “Maps, Places and Address Lookup”; the saved result itself stays on your device.
- Parental Consent Record (Optional): if you are under 18 and save a birth date, the app records on your device that a parent or guardian has confirmed their consent. This confirmation stays with your other General Information on your device and is never sent to us.
How We Use This Data
We use the collected information solely for:
- Legal Basis (GDPR): We ask your permission before collecting any usage data, and we rely on your consent for it (Art. 6(1)(a)). We do not claim a legitimate interest in analytics, and we do not collect usage data on the basis that you have not objected. Diagnostic data — crash and performance reports — is processed under our legitimate interest in keeping the app stable and safe (Art. 6(1)(f)); see “Data Rights” for how to object. Synctronic does not process your health information as a controller: it stays on your device and never reaches us, so there is no special-category processing by us for Article 9 to apply to. The explicit consent you give during onboarding authorises the application on your device to process your health information there.
- App Optimization: Analyzing how users navigate the app to improve the user interface.
- Bug Fixing: Using crash reports to identify and resolve technical issues.
- Support: Responding to your inquiries or technical support requests.
- Turning Analytics Off: usage analytics is off unless you turn it on, and you can turn it off again at any time in Settings. When it is off, collection is switched off at the source rather than filtered afterwards. A small number of technical start-up events are recorded before your saved choice is applied on each launch.
Device Permissions
To provide its core features—particularly reliable reminder alerts—Upkit requires access to specific functions on your mobile device. These permissions are only active when necessary, and you can manage them at any time through your device’s system settings.
- Local Notifications: Allows the app to send you timely reminders for your medications and health tasks.
- Alarms & Reminders: Permits the app to schedule precise alarms. This is critical for ensuring that time-sensitive medication alerts are triggered even when the device is in “Do Not Disturb” or “Sleep” modes.
- Full-Screen Intent: Allows the app to display a high-priority, full-screen alert when a medication is due, ensuring you do not miss a critical reminder.
- Background Execution: Permission to run in the background without battery restrictions. This ensures that our internal scheduling engine remains active and that your reminders are delivered accurately and on time, even if the app hasn’t been opened recently.
- Camera & Photo Library Access: If you choose to add a photo to a medication record (for example, a photo of the pill or its packaging), you can take a new photo or pick an existing one. Your device’s operating system handles this selection and will ask for any camera or photo-library permission it requires; Upkit only receives the specific photo you choose, and it is stored locally on your device.
On-Device Features
The following features work entirely on your device and do not require you to grant a system permission:
- Biometric Authentication: Used to secure the app via Fingerprint, FaceID, or TouchID. Upkit never has access to your actual biometric data; we simply receive a secure confirmation from your operating system that the authentication was successful.
- Vibration & Sound: Used to provide tactile and audible feedback for your alerts, ensuring you are notified of your schedule even if you are not looking at your screen.
Third-Party Services & Data Processors
To provide a reliable and secure experience, Upkit utilizes several third-party service providers. These services help us monitor app performance, facilitate communication, and provide essential functionality.
Analytics & Performance Monitoring
These services fall into two groups, and the difference matters. Usage analytics runs only with your permission. Diagnostics — crash and performance reporting — runs on every installation under our legitimate interest in keeping the app working, because a reminder that fails to fire is a safety problem rather than an inconvenience. Neither group receives your Health Profile:
- Google Analytics for Firebase: We collect pseudonymized usage data (such as screen views and button interactions) to help us improve the user experience. This runs only if you agree to it — see “Turning Analytics Off”.
- Firebase Crashlytics: When the app crashes or hits an unexpected error, we receive a technical diagnostic report describing what failed — device model, operating system version, and the internal state at the point of failure. These reports are used only to fix faults, and may in rare cases include fragments of application data. If you have turned analytics on, a report may also carry a short trail of recent activity, such as which screens were open; screen names never identify a particular medication or condition. Crash reporting is not covered by the analytics permission.
- Firebase Performance Monitoring: measures how quickly the app starts, draws its screens, and completes internal operations, so we can find and fix slowdowns. It records timings, a small number of technical counts, and aggregated patterns of the network addresses the app contacts — never individual addresses, places, or health information. Like crash reporting, it runs on every installation and is not covered by the analytics permission.
- Firebase Installations: issues the random installation identifier that the Firebase services above use to tell installations apart. It is not linked to you personally and is reset if you reinstall the app.
- Firebase Remote Config: This service allows us to update the app’s behavior and appearance (such as UI adjustments) without requiring a manual update from the App Store or Play Store.
Maps, Places and Address Lookup
When you add a healthcare provider or facility, or save a default location in your Health Profile, Upkit can search for a place, show it on a map, and let you open it in your maps app. Upkit does not request access to your device’s location, and does not track where you are. Four things can happen here:
- Address Lookup (Geocoding) When you search for an address, the address text you type is sent to a third-party map and geocoding provider (such as Google Maps Platform) to convert it into map coordinates. This is one of the few features where information leaves your device. That processing is governed by the provider’s own privacy policy, and we do not control how the provider handles it. We send only the address text you choose to search — never your medications, conditions, or other health records.
- Map Display: if you open the map picker to place or check a pin, the map itself is provided by Google. Displaying it sends Google the technical information needed to serve map images, including your IP address and the area of the map you are viewing. We never send your medications, conditions, or other health records.
- Turning a Pin into an Address: if you drop a pin rather than search, the coordinates are turned into a street address by your device’s own operating system, not by us and not by any service we have engaged.
- Opening in Your Maps App: If a saved facility has coordinates, you can tap to open them in your device’s default maps application (for example, Google Maps or Apple Maps). This simply hands the coordinates to that app; Upkit does not access your location to do this.
App Marketplaces & Platform Data
When you download, update, or interact with Upkit through official app stores, those platforms collect and process data according to their own privacy policies.
- Platform Collection: The Apple App Store and Google Play Store may collect information such as your account ID, device hardware information, and download history.
- Payments & Subscriptions: We use RevenueCat to manage purchases and to tell the app which features you are entitled to. RevenueCat starts on every installation, not only when you buy something: on first launch the app registers a random identifier with RevenueCat and asks what you are entitled to — for most people the answer is “nothing”. If you do make a purchase, the transaction itself is processed by the relevant app store’s payment system, and RevenueCat receives a store-provided purchase identifier and related subscription status. RevenueCat also serves the images and fonts used on our purchase screens from its own content network. All of this is handled under RevenueCat’s own privacy policy, and none of it involves your health information. Synctronic LTD never receives or stores your credit card numbers, bank details, or other financial information — only confirmation that a purchase was successful.
Advertising
We advertise Upkit to help people find the app. We do not advertise inside Upkit, and Upkit contains no advertising software.
- Install Attribution (Android): if you install Upkit after clicking one of our advertisements, the advertising platform receives an advertisement click identifier and confirmation from the app store that an install occurred. This is how we know an advertisement worked.
- Install Attribution (Apple devices): on Apple devices the app asks Apple’s attribution service whether the installation came from an advertisement. This happens on installation regardless of whether we are running a campaign at the time.
- What We Do Not Do: we do not use your health information for advertising, and we do not build advertising audiences from your data. Advertising personalisation is disabled in all regions, and no advertising identifiers are collected by the app.
Communication & External Links
Our app facilitates communication through established third-party platforms. When you use these features, your data is handled according to their respective privacy policies:
- Support & Messaging: If you choose to contact us via the support channels we offer (such as email), those providers will process your contact information (such as your email address) and the content of your message.
- External Links: Our app may contain links to external websites or services. Once you leave the Upkit app, we are no longer responsible for the privacy practices of those third parties.
Security & Data Integrity
Security is a shared responsibility between Upkit and you.
- Local Database Security: We protect your data using the encrypted storage environments provided by your device’s operating system. While we use commercially acceptable means to protect your information, no method of electronic storage is 100% secure. Note also that your device’s own backup service — such as iCloud or Google backup — may include app data in a device backup. Any such backup is held by Apple or Google under their terms, not by us, and we cannot read or restore it.
- Rooted or Jailbroken Devices: We strongly advise against using Upkit on rooted or jailbroken devices. Modifying your device’s operating system compromises the built-in security protections (such as sandboxing and hardware-backed encryption) provided by Android and iOS.
- User Responsibility: By using Upkit on a compromised device, you acknowledge that the security of your local database and any personal health information stored within the app may be at significantly higher risk of unauthorized access.
Data Rights
- Selling Data: We do not sell your data. Because we do not collect your health records, we have no such data to sell. Upkit contains no advertising software and displays no advertisements. We do not share your health information with advertisers, data brokers, insurers, or employers.
- Data Portability: Your data is stored locally on your device, so there is nothing for us to download on your behalf — you control and manage it directly within the app. Where a feature offers an export, such as the reports described under “Exporting Your Data,” the file is generated on your device; the CSV format of the History Report gives you your data in a structured, commonly used, machine-readable form that you can take elsewhere.
- Your Rights: you have the right to ask us for a copy of the personal data we hold about you, to have it corrected or deleted, to restrict how we use it, to receive it in a portable form, and to object to processing we carry out under our legitimate interests. You can withdraw your consent to usage analytics at any time in Settings, without giving a reason and without affecting anything done before you withdrew it. To object to crash and performance diagnostics, write to us. See “Right to Erasure” below for the practical limits on these rights — those limits apply to an objection in the same way as to a request for deletion.
- Complaints: if you believe we have handled your personal data improperly, you may complain to a data protection supervisory authority. In the United Kingdom this is the Information Commissioner’s Office. In the European Union it is the authority in the country where you live or work; our EU Representative is listed below.
- Where Your Data Is Processed: our service providers process the limited data described in this policy at facilities outside the United Kingdom and the European Economic Area, including in the United States. Where that happens, the transfer is covered by safeguards in our agreements with them — the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for transfers subject to UK law, and, where a provider is certified under it, the EU–US Data Privacy Framework. You can ask us for details of the safeguards that apply by contacting us using the details below.
Data Retention & Deletion
Because Upkit stores your information locally, how long most data is retained is determined by your own use of the app.
Data Retention
We retain different types of data for different periods depending on their purpose:
- Local Data: Your medication logs, schedules, and health records (including your health conditions, healthcare providers, and healthcare facilities) remain on your device as long as the app is installed. We do not have a mechanism to remotely delete this data as we do not host it on our servers.
- Service Performance Logs: Raw technical logs used for immediate troubleshooting and security monitoring are typically retained for 30 to 90 days, after which they are deleted or aggregated into anonymized statistics.
- Analytics and Diagnostics: Usage and diagnostic records held by our service providers are retained for 14 months, after which they are deleted automatically. Because we cannot identify you from these records, that automatic expiry — rather than a request from you — is how they are deleted. Aggregated statistics derived from them, which cannot be traced back to an individual installation, are kept for longer.
- Support Correspondence: If you contact us for support via email or messaging apps, we remove any health information from the correspondence once your request is resolved. We retain the remaining message for up to six years, because we may need it to comply with legal and accounting obligations or to establish, exercise, or defend a legal claim. During that period we cannot delete it on request.
How to Delete Your Data
You can delete your data at any time through the following methods:
- In-App Deletion: You can manually delete specific records (like a medication or a log entry) within the app interface.
- Clearing App Data: On Android, you can go to Settings > Apps > Upkit > Storage and select “Clear Data” to wipe the local database entirely.
- Uninstalling the App: Deleting the Upkit app from your device will typically remove all locally stored databases and settings associated with the app. Note: We recommend manually backing up any data you wish to keep before uninstalling.
Right to Erasure (GDPR)
You have the right to request erasure of personal data we hold about you, subject to important practical limits in how Upkit works. Because your health data is stored only on your device and never reaches our servers, there is nothing for us to erase on your behalf — you delete it yourself at any time using the methods above (in-app deletion, clearing app data, or uninstalling). For the limited personal data you may have sent us directly, such as support correspondence, please note that we may be unable to delete it where we are required to retain it to comply with a legal obligation or to establish, exercise, or defend a legal claim (as permitted under Article 17(3) of the GDPR). Where no such requirement applies, we will honour valid erasure requests. There is one further limit, and it is worth explaining plainly. We do not operate a server that stores your information, and we do not hold an account for you. The limited usage and diagnostic records our service providers hold are not stored under your name or email address; they are linked only to a random identifier generated on your device, and we have no way to connect that identifier to you or to any message you send us. Where a controller genuinely cannot identify an individual from the data it holds, it is not required to obtain additional information about that individual solely in order to respond to a request (Article 11 of the GDPR). We therefore cannot locate, export, or delete usage or diagnostic records on request; they are deleted automatically when their retention period expires, as described above. To make a request, contact us at the email address in the “Contact Us” section.
Children’s Privacy
Upkit is not intended for, or directed to, children under the age of 13 (or the age of digital consent in your jurisdiction). Where the applicable minimum age in your jurisdiction is higher than 13 (for example, the age of digital consent under local data-protection law), that higher age applies, and anyone below it may not use the app. This matches the User Eligibility terms in our Terms of Service.
- No Collection from Minors: We do not knowingly collect personal information directly from children. If you are under 13, please do not use the app or provide any personal information through its features.
- Parental Use: If you are a parent or guardian using Upkit to manage the health or medication of a minor, you are responsible for the protection of that data on your device. Any information entered by a parent regarding a child is treated with the same security measures as all other personal data. Where a user aged under 18 records a birth date, the app asks them to confirm that a parent or guardian has consented, and records that confirmation on the device. As described in our Terms of Service, you confirm that you are the minor’s parent or legal guardian, or otherwise have lawful authority and any necessary consent to manage their health information, and you must stop managing and delete their data if that authority or consent ends.
- Correction & Deletion: We do not knowingly hold any data about children on our servers; a minor’s health information stays on the device and is deleted by the parent or guardian directly. The deletion and erasure terms in “Data Retention & Deletion” above apply equally here. If you believe a child has sent us personal data directly, please contact us at the email address in the “Contact Us” section.
EU Representative (GDPR)
As Synctronic LTD is established in the United Kingdom, we have appointed a representative within the European Union to act as a point of contact for any questions regarding our processing of personal data and to liaise with EU Supervisory Authorities.
In accordance with Article 27 of the GDPR, our designated EU Representative is:
- Representative: Maziar M.Danialy
- Location: Netherlands
- Contact Email: hi@upkit.app
- Purpose: This representative is authorized to be addressed on all issues related to the processing of personal data for the purpose of ensuring compliance with the General Data Protection Regulation.
Contact Us
- For questions regarding this policy, contact us at hi@upkit.app.
- Synctronic LTD is the controller of the limited personal data described in this policy.
Ready to take control of your health?
Free to download. No account needed. Reminders work offline.