HealthTracker

Security practices

A plain-language overview of the safeguards used to protect accounts and health records. This page describes current practices, not a security certification or guarantee of absolute protection.

Account access

Firebase Authentication supports email, Apple, and Google sign-in. Account and patient identifiers are used to scope access to records.

Data protection

Firebase and Google Cloud provide encryption in transit and at rest for supported database and file-storage services.

Device controls

The iOS app can use Face ID or Touch ID and an optional inactivity lock. Sensitive content is obscured in supported capture and app-switching situations.

Recovery backups

Encrypted database backups are created daily and retained for up to seven days for disaster recovery.

User-controlled sharing

Reports are handed to Apple system interfaces. You select recipients, review the composer, and decide whether to send.

No advertising

HealthTracker has no ads and does not sell personal data. Service providers are used to operate the app, subscriptions, and support.

Service boundaries

HealthTracker relies on Firebase and Google Cloud for account, database, file, analytics, and crash-reporting services, and RevenueCat for subscription management.

Apple and Google process sign-in requests when those options are used. Apple system services process reports, messages, email, calendar events, notifications, Siri, and Shortcuts actions that you initiate.

Once you send or save an exported report, the destination service and recipient control that copy.

Claims we do not make

  • HealthTracker does not claim that its complete data path is end-to-end encrypted.
  • HealthTracker is not presented as HIPAA, GDPR, or SOC 2 certified.
  • No internet-connected service can promise zero vulnerabilities, uninterrupted availability, or absolute security.
  • We do not advertise an independent audit or security rating unless a current report can be provided.

Report a security concern

Send enough detail for us to investigate, but do not include passwords or unnecessary health information. We will assess reports and notify affected people or authorities when required by applicable law.

healthtrackersupport@ntc.com.au