HealthTracker
Privacy Policy
Last updated: August 2026
Your records
You decide what information to enter, export, or share.
Protected storage
Records are encrypted in transit and at rest using supported service protections.
Named providers
Firebase, RevenueCat, Apple, Google, and other listed providers support the service.
Sharing by choice
HealthTracker does not send a report until you review and send it through an Apple system interface.
Who this policy covers
This policy explains how Nexus Technology Consulting handles information for the HealthTracker iPhone, iPad, and web experiences. HealthTracker is a personal record-keeping service. It is not a healthcare provider, health plan, medical device, or substitute for professional medical advice.
Information we handle
Depending on the features you use, information may include:
- Account details such as your name, email address, account identifier, and authentication provider.
- Patient profile details, medications, appointments, allergies, test results, trackers, notes, journals, and other health records you enter.
- Files and images you choose to upload, including prescriptions, test reports, profile images, and supporting documents.
- Care-team contact details you save, including names, email addresses, and phone numbers.
- Subscription and transaction status supplied by Apple and RevenueCat.
- Device, app-version, usage, performance, and crash information used to operate and improve the service. We do not use health-record content for advertising.
How we use information
- Provide, synchronize, secure, troubleshoot, and improve HealthTracker.
- Authenticate accounts and enforce subscription patient limits.
- Deliver reminders, imports, reports, exports, and other features you request.
- Respond to support requests and meet legal, security, and fraud-prevention obligations.
HealthTracker has no advertising and does not sell personal data.
Service providers
HealthTracker relies on service providers to operate. They process limited information for the purposes described below and under their own contractual and security obligations.
Google Firebase and Google Cloud
Authentication, database storage, file storage, analytics, crash reporting, and infrastructure.
RevenueCat
Subscription status, purchase management, and entitlement delivery.
Apple and Google
Sign-in services when you choose those account options.
Apple system services
Mail, Messages, calendar, notifications, Siri, Shortcuts, and sharing actions you initiate.
Vercel
Hosting and basic performance analytics for this website.
Reports, email, and Messages
HealthTracker can generate a PDF and hand it to Apple's share sheet, Mail, or Messages. You choose the destination, review the system composer, and decide whether to send. Email can include several care-team addresses. Messages is limited to one care-team mobile number at a time so a group conversation does not reveal recipients' phone numbers to one another.
Once you send or save a report, the recipient, delivery provider, and destination service handle that copy under their own privacy and security terms. HealthTracker cannot recall a sent message or control a file after it leaves the app.
Security and encryption
HealthTracker uses Firebase and Google Cloud protections for data in transit and at rest, together with account-scoped access rules and optional device controls such as Face ID or Touch ID and inactivity locking. These safeguards reduce risk but no internet-connected service can guarantee absolute security. HealthTracker does not claim that its full data path is end-to-end encrypted.
Retention, deletion, and backups
Account and health records remain in the live service while your account is active or as needed to provide the features you use. You can update records, export your data, delete patients, or request account deletion from the app.
Automated encrypted database backups are created daily and retained for up to seven days for disaster recovery. Information deleted from the live service may remain in those backups until the retention period expires. Backups are not used for advertising or routine account access.
International use and your rights
Information may be processed in countries where our providers operate. Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information. We will assess requests under the laws that apply to the request and our operations.
HealthTracker is offered directly to individuals and does not represent that it is a HIPAA-covered service or that a Business Associate Agreement is available. Organizations with contractual or regulatory requirements should contact us before using HealthTracker in an organizational workflow.
Children's information
HealthTracker is intended for adults managing their own information or records for people in their care. A parent, guardian, or authorized caregiver is responsible for entering and sharing a child's information appropriately.
Contact us
Questions or privacy requests can be sent to healthtrackersupport@ntc.com.au.