Privacy Policy

Last updated: August 8, 2026

This Privacy Policy explains how personal information is handled when you use Mewdicate (the "App") and its related support pages. Mewdicate is developed and operated by Pham Quang Trung, an independent developer based in Vietnam and identified in the App Store or Google Play listing from which you obtained the App ("we", "us", or "our"). For privacy questions, contact phamcham.dev@gmail.com.

Privacy at a Glance

1. Information Handled by the App

Information stored locally

Depending on the features you use, the App may store the following on your device:

This information may reveal sensitive health information. It remains on your device unless you choose a feature that transmits it, such as cloud backup, an export or share action, or a support request.

Account and cloud backup information

If you sign in and use cloud backup, we process your account identifier, email address and sign-in provider information, together with encrypted backup files and limited backup metadata such as timestamps, versions, and file integrity information. Backup content may include the local information listed above. After you configure encrypted cloud backup, weekly automatic backup is enabled by default for your convenience. You can turn it off at any time in the App's backup settings. Automatic backup runs only while this setting remains enabled and the feature requirements are met.

Diagnostics, security, and purchase information

The App and its service providers may automatically process limited technical information, including app and operating-system version, device model, language or locale, screen characteristics, IP address, identifiers generated by a service provider, crash traces, error logs, and security or integrity signals. Where analytics is enabled in a distributed build, limited app interaction and performance events may also be processed. We do not intentionally include medication names, diary text, or health measurements in crash-report custom fields.

If you make a purchase, the relevant app store and RevenueCat process transaction, product, subscription status, entitlement, country, and related device or attribution information. We do not receive your full payment-card details.

Support communications

If you contact us, we receive your email address, message, and any files or diagnostic details you choose to send. Please avoid sending health information that is not necessary to resolve your request.

2. Device Permissions

The App may request notification, alarm, camera, photo-library, storage, or related device permissions only when needed for a feature. You can change permissions in your device settings, but some features may then stop working. The App does not require access to your contacts or precise location for its core reminder features.

3. Why We Process Information

We process information only as needed to:

Depending on your location and the feature involved, our legal basis is performance of our agreement with you, your consent, our legitimate interests in security and service reliability, or compliance with law. Where applicable law requires explicit consent to process sensitive health information in an optional cloud feature, you may choose whether to enable that feature and may withdraw consent by disabling it and deleting the related cloud data. Withdrawal does not affect processing that was lawful before withdrawal.

4. Local Exports, Backup Password, and Encryption

Current cloud backups are encrypted on your device using AES-256-GCM. A key is derived from your backup password using PBKDF2-HMAC-SHA256. The backup password is not uploaded to our server and cannot be recovered by us. To support automatic backup and restore, the password may be cached locally in the App's private preferences on your device. Anyone who can access an unlocked or compromised device may be able to access locally stored information, so use a device passcode and keep your operating system current.

Older backups may use a legacy format to support migration. Future backups use the current encrypted format after you configure a backup password. Files you explicitly export or share may be unencrypted and become subject to the security and privacy practices of the destination you select. You are responsible for protecting exported files and your backup password.

5. Service Providers and Disclosures

We use the following categories of service providers:

These providers process information under their own terms and privacy notices and may act as our processor, our service provider, or an independent controller depending on the activity. You can review Firebase privacy information, Google's Privacy Policy, Apple's Privacy Policy, and RevenueCat's Privacy Policy.

We may also disclose the minimum information necessary to comply with a valid legal request, protect users or the public, investigate abuse, or defend legal rights. If control of the App is transferred, affected information may transfer with it subject to this Policy, and we will provide notice where required. We do not disclose personal information to affiliates, business partners, or other users for their own marketing.

6. Retention

Deletion from active systems may not immediately remove residual copies from a service provider's disaster-recovery backups. Any such copies are handled under that provider's retention, security, and deletion procedures and may remain for a limited period. De-identified data that can no longer reasonably identify you may be retained for service reliability and statistical purposes.

7. Account and Data Deletion

You may delete individual local records within the App. To delete an account, use the account-deletion option in the App or follow the account-deletion instructions to submit a request by email. Account deletion triggers a server-side process that deletes account-linked cloud backup files and removes the authentication account. We may ask for limited information to verify an email request, but we will not ask for your password or health records.

Uninstalling the App deletes its active local data from the device but does not by itself delete an account or cloud backup. Account deletion does not remove purchase records controlled by Apple, Google, or other records that must be retained by law. Once encrypted backup data and its account are deleted, they cannot be restored by us.

8. International Processing

Firebase, RevenueCat, Apple, and Google may process information in countries other than your own, including the United States. These providers describe the safeguards they use for international transfers in their applicable terms and privacy notices. Where required, those safeguards may include adequacy decisions, standard contractual clauses, or another lawful transfer mechanism. The privacy laws in those countries may differ from those in your place of residence.

9. Security

We use measures appropriate to the nature of the information, including platform access controls, transport encryption, app-integrity checks, access restrictions, and client-side encryption for current cloud backups. No method of storage or transmission is completely secure. If we become aware of a personal-data incident, we will investigate, mitigate it, and notify affected users and authorities when required by law.

10. Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; withdraw consent; receive a portable copy; or complain to a data-protection authority. You may also have the right not to be discriminated against for exercising a privacy right. Contact us to make a request. We may verify your identity and may decline or limit a request only where permitted by law.

11. Children

The App is not directed to children under 13. A minor should use the App only with permission and supervision from a parent or legal guardian. Where local law requires parental consent for an account, cloud backup, or processing sensitive information, the parent or guardian must provide that consent. If you believe a child provided account-linked personal information without required consent, contact us so we can delete it.

12. Changes to this Policy

We may update this Policy when the App, our providers, or applicable law changes. We will post the updated Policy on this website and revise the date above. Changes take effect when posted unless a later date is stated or applicable law requires otherwise. Please review this page periodically.

13. Contact

For privacy questions or requests, contact phamcham.dev@gmail.com. Please include "Mewdicate Privacy" in the subject line and identify the country in which you reside if your request concerns a jurisdiction-specific right.