HealthTracker

Privacy Policy

Last updated: August 2026

Your records

You decide what information to enter, export, or share.

Protected storage

Records are encrypted in transit and at rest using supported service protections.

Named providers

Firebase, RevenueCat, Apple, Google, and other listed providers support the service.

Sharing by choice

HealthTracker does not send a report until you review and send it through an Apple system interface.

Who this policy covers

This policy explains how Nexus Technology Consulting handles information for the HealthTracker iPhone, iPad, and web experiences. HealthTracker is a personal record-keeping service. It is not a healthcare provider, health plan, medical device, or substitute for professional medical advice.

Information we handle

Depending on the features you use, information may include:

  • Account details such as your name, email address, account identifier, and authentication provider.
  • Patient profile details, medications, appointments, allergies, test results, trackers, notes, journals, and other health records you enter.
  • Files and images you choose to upload, including prescriptions, test reports, profile images, and supporting documents.
  • Care-team contact details you save, including names, email addresses, and phone numbers.
  • Subscription and transaction status supplied by Apple and RevenueCat.
  • Device, app-version, usage, performance, and crash information used to operate and improve the service. We do not use health-record content for advertising.

How we use information

  • Provide, synchronize, secure, troubleshoot, and improve HealthTracker.
  • Authenticate accounts and enforce subscription patient limits.
  • Deliver reminders, imports, reports, exports, and other features you request.
  • Respond to support requests and meet legal, security, and fraud-prevention obligations.

HealthTracker has no advertising and does not sell personal data.

Service providers

HealthTracker relies on service providers to operate. They process limited information for the purposes described below and under their own contractual and security obligations.

Google Firebase and Google Cloud

Authentication, database storage, file storage, analytics, crash reporting, and infrastructure.

RevenueCat

Subscription status, purchase management, and entitlement delivery.

Apple and Google

Sign-in services when you choose those account options.

Apple system services

Mail, Messages, calendar, notifications, Siri, Shortcuts, and sharing actions you initiate.

Vercel

Hosting and basic performance analytics for this website.

Reports, email, and Messages

HealthTracker can generate a PDF and hand it to Apple's share sheet, Mail, or Messages. You choose the destination, review the system composer, and decide whether to send. Email can include several care-team addresses. Messages is limited to one care-team mobile number at a time so a group conversation does not reveal recipients' phone numbers to one another.

Once you send or save a report, the recipient, delivery provider, and destination service handle that copy under their own privacy and security terms. HealthTracker cannot recall a sent message or control a file after it leaves the app.

Security and encryption

HealthTracker uses Firebase and Google Cloud protections for data in transit and at rest, together with account-scoped access rules and optional device controls such as Face ID or Touch ID and inactivity locking. These safeguards reduce risk but no internet-connected service can guarantee absolute security. HealthTracker does not claim that its full data path is end-to-end encrypted.

Retention, deletion, and backups

Account and health records remain in the live service while your account is active or as needed to provide the features you use. You can update records, export your data, delete patients, or request account deletion from the app.

Automated encrypted database backups are created daily and retained for up to seven days for disaster recovery. Information deleted from the live service may remain in those backups until the retention period expires. Backups are not used for advertising or routine account access.

International use and your rights

Information may be processed in countries where our providers operate. Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information. We will assess requests under the laws that apply to the request and our operations.

HealthTracker is offered directly to individuals and does not represent that it is a HIPAA-covered service or that a Business Associate Agreement is available. Organizations with contractual or regulatory requirements should contact us before using HealthTracker in an organizational workflow.

Children's information

HealthTracker is intended for adults managing their own information or records for people in their care. A parent, guardian, or authorized caregiver is responsible for entering and sharing a child's information appropriately.

Contact us

Questions or privacy requests can be sent to healthtrackersupport@ntc.com.au.