DigiPlugLabs

Privacy Policy

Last updated: 22 August 2026 · Applies to ChronCare version 1.0

Who we are

ChronCare is developed by DigiPlugLabs LLC, Winter Garden, Florida, USA.

For any privacy question or request, contact us at support@digipluglabs.com or through our support page. That address is our privacy point of contact and we aim to respond within two business days.

The short version

Your health information stays on your device.

ChronCare stores everything you log — symptoms, medications, vitals, wellness entries, appointments, your Emergency ID — in an encrypted database on your own phone or tablet.

Cloud backup is not enabled in this release. Nothing you enter is transmitted to us, because the app has no server to transmit it to. You can confirm this in the app: Profile shows that your data stays on this device, and offers no backup control. If your copy of ChronCare shows no Cloud backup option in Profile, every sentence below about backup describes a feature you do not have.

The rest of this section describes how backup behaves in a release that offers it, so that the terms are on the record before it is switched on rather than after.

When offered, cloud backup is off unless you turn it on. If you do turn it on, your data is encrypted on your device before it is sent, using a key derived from a passphrase you choose. We receive only the encrypted result. We hold no key that can open it, so we cannot read your health data, cannot hand it to anyone else in readable form, and cannot recover it for you if you lose your passphrase and your recovery code.

That is a statement about what is technically possible for us, not only a promise about what we choose to do.

There is no advertising, and no analytics or tracking of how you use the app.

Information you enter, which stays on your device

All of the following is created by you and stored in the encrypted database on your device. Cloud backup is not enabled in this release, so none of it is ever transmitted to us. Where a release offers backup and you turn it on, it is encrypted on your device and the encrypted result is stored on our backend, where it cannot be read:

  • Profile details — display name, sex, date of birth, blood type, height and weight, emergency contact, preferred hospital, and insurance details (provider, member ID, group number, member services phone).

  • Health and symptom data — symptom logs (body region, pain level, mood, notes), medication names, schedules and dose history, vitals readings (heart rate, blood pressure, SpO2, glucose, temperature, weight), lab results you type in, exercise and food journal entries, and menstrual cycle logs.

  • Wellness data — hydration, sleep, activity and stress entries.

  • Appointments — visit dates, times and notes.

  • Emergency ID — the allergies, conditions, medications and emergency contact you choose to make visible on the reduced-access emergency screen.

  • Photos you attach — an optional picture of a meal, optional photos in the symptom log for documenting things like a rash, swelling or bruising, and an optional profile photo if you choose to set one.

  • App settings — theme preference, notification preferences.

Some of this is sensitive health information. That is precisely why this version keeps it on your device.

About photos specifically

Photos are only ever captured when you choose to attach one, and they stay on your device like everything else. This covers all three places ChronCare accepts a picture: a meal, a symptom entry, and your profile photo. When you attach one, ChronCare copies it into its own private storage so it can't be reclaimed by the operating system later.

We do not analyse them. ChronCare does not attempt to identify food in a meal photo or a condition in a symptom photo, and no image is uploaded, transmitted, or shown to any third-party service. A photo is a memory aid attached to something you recorded.

Your profile photo is decorative and nothing more. It replaces the initials on your own screen. It is not facial recognition, not an identifier, not shared with anyone, and not sent anywhere — it is the same private file storage as any other photo in the app, and removing it deletes the file.

One limitation worth stating plainly: image files are stored inside the app's private storage, which is not inside the AES-256 encrypted database. Your logged text is encrypted at rest; the image files are protected by the operating system's app sandbox and your device passcode. Deleting a photo in the app deletes the file, and uninstalling ChronCare removes them all.

Apple Health and Health Connect (optional)

ChronCare can import a few figures from your phone's own health store — Apple Health on iOS, Health Connect on Android — so your wellness score reflects what your watch already recorded instead of asking you to type it twice.

This is off until you connect it in Profile, and the operating system asks for your permission separately. Nothing is read before then.

  • What is read: today's step count, hours slept, and resting heart rate. Nothing else.

  • Read-only. ChronCare requests no permission to write, and never writes anything back into Apple Health or Health Connect.

  • Where it goes: into the same wellness entry for that day that you would otherwise fill in by hand, in the same encrypted database on your device. It is not sent anywhere, not used for advertising, and not shared with anyone.

  • It never overwrites what you entered. If you have already recorded last night's sleep, an import that disagrees leaves your figure alone and fills only what is empty.

  • Turning it off: disconnect in Profile, or revoke ChronCare's access in Apple Health or Health Connect at any time. Figures already imported stay in your ChronCare entries, and you can edit or delete them like anything else you logged.

Information we do not collect

To be explicit, ChronCare does not:

  • collect, receive, or transmit your health data;

  • contain any advertising, ad network, or advertising identifier;

  • contain any analytics, telemetry, attribution, or crash-reporting service;

  • use your camera or photo library for anything other than a photo you explicitly attach to a meal or symptom entry, or choose as your profile photo — and it never uploads or analyses those;

  • write anything back into Apple Health or Health Connect, or read anything from them beyond steps, sleep and resting heart rate after you connect;

  • read the rest of your calendar. If you turn on calendar sync, ChronCare adds and updates only the events it creates for your own ChronCare appointments, and deletes them when you delete the appointment. Granting calendar access does technically permit reading your other events, so this is a commitment about what we do, not a claim about what is possible. Calendar sync is off until you turn it on, and no calendar permission is requested before that;

  • use your microphone for anything other than dictating an entry, and only while you are actively dictating — speech is turned into text by your device's own speech service, and no audio is recorded, stored, or sent to us;

  • request or use your location;

  • read your contacts, calendar, call logs, messages, or files;

  • track you across other apps or websites;

  • sell or share personal information for advertising or cross-context behavioural advertising.

How your data is secured on the device

  • The local database is encrypted at rest with AES-256 (SQLCipher).

  • The encryption key is generated on your device by a cryptographically secure random number generator on first launch, and is stored in the operating system's keychain (iOS) or keystore (Android) — never in the database itself, never in plain application storage.

  • The key is marked so that it is only readable while the device is unlocked and is not included in device backups, including iCloud and Google backups.

  • Access to the app is protected by your device's own security — your passcode, Face ID, Touch ID, or fingerprint.

  • You can additionally turn on "Require unlock to open ChronCare" in Profile. It asks for a passcode you set inside ChronCare — deliberately separate from the one that unlocks your phone, so the app is protected even from someone who knows your phone's PIN. Fingerprint or face can be enabled as a shortcut on top of it. It asks when you open the app, and again after a minute in the background. Your Emergency ID stays reachable from that lock screen, so it can still be shown to a first responder.We store only a salted Argon2id hash of that passcode, in your device's secure keystore. It is never sent anywhere and cannot be reset or recovered — if you forget it you will need to reinstall the app, and anything not backed up is lost.This is a screen lock, not a second layer of encryption. It stops someone holding your unlocked phone from browsing your records; it does not change how the data is encrypted, and your fingerprint is not part of the key. We would rather say that plainly than let a security feature sound stronger than it is.

Because the key never leaves your device's secure storage, if the key becomes unrecoverable the encrypted data is unrecoverable too. That is a deliberate security property, not a defect.

No method of electronic storage is perfectly secure, and we cannot guarantee absolute security.

The limited cases where information leaves your device

Cloud backup is not enabled in this release, so the following are the only cases, and none of them involve your health data. Where a release offers backup and you turn it on, your encrypted records are also sent to our backend — see "Cloud backup and sync" below for exactly what that does and does not expose.

1. If you buy a ChronCare Premium subscription

Payment is processed by Apple or Google, not by us. We never see your card details.

We use RevenueCat to check whether your subscription is active. When you make or restore a purchase, RevenueCat receives the store's purchase receipt and transaction details, an anonymous app-generated identifier, and basic technical information such as platform, app version and country. It does not receive your name, email, or any health data.

RevenueCat acts as our service provider for this purpose. Apple and Google act as the sellers of record. Their handling of your purchase is governed by their own privacy policies.

If you never subscribe, no purchase information is created or shared.

2. If you tap "Find care nearby"

This opens Google Maps in your browser or the Maps app with a generic search for urgent care near you. ChronCare does not send your location, your identity, or any health data — it simply hands off a standard search. Once you are in Google Maps, Google's own privacy policy applies.

3. If you use the provider health-summary share

This uses your device's standard share sheet to let you send a plain-text summary to a recipient you choose. The content goes only where you send it. We are not involved and receive no copy.

Medication reminders

Reminders are local notifications scheduled on your device by its operating system. No reminder content is sent to us or to any server, and ChronCare does not use push notifications, so there is no push token and no notification service involved.

Data retention and deletion

We retain nothing, because we receive nothing. There is no server-side copy of your health data to retain or delete.

  • Your data is retained on your device for as long as you keep ChronCare installed.

  • Deleting the app deletes the data. Uninstalling ChronCare removes its encrypted database and its key from your device's secure storage. This is permanent and cannot be undone by us or by you.

  • You can also clear your data from within the app at any time.

  • Purchase records held by RevenueCat, Apple or Google are retained under their respective policies, as they are needed to honour and audit an active subscription. Deleting the app does not cancel a subscription — cancel that in your Apple Account or Google Play settings.

  • If you have emailed us, we keep that correspondence only as long as needed to handle your enquiry, and will delete it on request.

To make a privacy request, email support@digipluglabs.com. Since we hold no health data about you, most requests are satisfied by the fact that your data is under your own control on your own device — but we will always explain your position clearly and help where we can.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict processing, and not to be discriminated against for exercising those rights.

In this version, your health information is entirely within your control on your own device, which means access, correction, export and deletion are all things you perform directly in the app. For anything we do hold — essentially, email correspondence and subscription status — contact us and we will act on your request as required by applicable law.

Children's privacy

ChronCare is not directed to children under 13 and we do not knowingly collect information from them. If you believe a child has provided information to us, contact us and we will delete it.

Third parties

  • Supabase — authentication and encrypted storage, only if you turn on cloud backup. Supabase acts as our processor. It holds your email address and your encrypted records, and no key capable of decrypting them.

  • RevenueCat — subscription entitlement validation (only if you subscribe).

  • Apple / Google — app distribution and payment processing.

  • Google Maps — only if you tap "Find care nearby".

We do not share personal information with anyone else, and we do not sell personal information.

Not medical advice. ChronCare is a wellness and self-tracking tool. It is not a medical device and does not provide medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider with questions about a medical condition. In an emergency, call your local emergency number. See our Terms of Use.

Changes to this policy

If we change this policy we will update the "Last updated" date above and, for material changes — in particular any change that causes health data to leave your device — we will give notice in the app before the change takes effect.

Cloud backup and sync (optional)

Cloud backup is not enabled in this release. This section is published in advance so that the terms are on the record before the feature is switched on, not after. If Profile offers you no Cloud backup control, nothing in this section applies to you and nothing described here is happening.

Where a release does offer it, cloud backup is off by default, and nothing in this section applies unless you turn it on.

What we receive

  • Account information. An email address and an authentication credential, handled by Supabase Auth acting as our processor. We never see or store a plaintext password.

  • Your encrypted records. Each entry is encrypted on your device before it is sent. What reaches our backend is ciphertext.

What we can see, stated precisely

We think a privacy policy should be specific about what a design leaks rather than only about what it protects. With backup on, our backend can see:

  • that a record exists, and what kind it is — that a row is a symptom log rather than a medication, and therefore how many of each you have;

  • when it was created or changed, which reveals when you tend to log things;

  • the total number and size of your records;

  • your email address, as your account identifier.

It cannot see the contents of any record: no pain levels, no medication names, no allergies, no notes. Those are inside the encrypted payload.

The key, and what it means if you lose it

Your data is encrypted with a key that is generated on your device and stored only in encrypted form — wrapped under a passphrase you choose, and again under a one-time recovery code shown to you during setup. Either one opens it. We hold neither.

If you lose both your passphrase and your recovery code, your backed-up data cannot be recovered — by you, by us, or by anyone else. There is no reset, no support route, and no master key. This is deliberate: a key we could use to restore your data would also be a key we could be compelled to use. Your data on the device you are already using is unaffected.

Photos are not backed up

Photos attached to meal and symptom entries, and your profile photo, stay on your device and are not part of cloud backup.

Turning it off, and deleting your account

You can turn cloud backup off at any time in Profile. Deleting your account — Profile → Delete account — permanently removes your account and all stored encrypted records. This is immediate and irreversible.

Not "end-to-end encrypted"

We describe this as encrypted on your device under a key we do not hold, rather than as "end-to-end encrypted". End-to-end normally describes data moving between two people; this is your own data moving between your own devices. The protection is equivalent, but we would rather use accurate words than a familiar phrase that does not quite fit.

Contact

DigiPlugLabs LLC
Winter Garden, Florida, USA
support@digipluglabs.com

DigiPlugLabs · Winter Garden, Florida, USA
Support · Terms of Use