Privacy Policy
1. Data controller
AppChemylabs (owner of appchemylabs.es), developer of the My Health mobile application (Android, package com.myhealth.emergency_profile).
Privacy contact: soporte@appchemylabs.es
2. Scope
This policy applies to the processing of personal data, including special category (health) data, when you use the My Health app, related services (backup, caregiver mode, AI features), and, where applicable, the legal pages on appchemylabs.es.
3. Data we collect
3.1 Profile and clinical data (provided by you)
- Identity: name, nickname, age, biological sex, blood type, allergies, chronic conditions.
- Medication and Pharma Hub: medicines, supplements, treatments, doses, schedules, adherence, history.
- Symptoms, vital signs, blood tests, biomarkers, blood pressure, glucose, SpO₂.
- Medical appointments, documents, healthcare expenses, vaccines, dental health.
- Women's health: menstrual cycle, pregnancy, lactation, menopause and related symptoms.
- Lifestyle: nutrition, habits, sleep, mood journal, health goals.
- Emergency contacts, emergency profile (SOS), accessibility settings.
3.2 Health Connect (Google) data
If you authorize it, the app may read Health Connect data such as: steps, heart rate, sleep (stages and sessions), blood oxygen, blood pressure, body temperature, heart rate variability (HRV), active energy, distance and workouts. We do not sell this data. You can revoke permission in Android Settings / Health Connect.
3.3 Account and cloud data (optional)
- Firebase Authentication: email, user ID, or local guest mode without an account.
- Firestore / cloud backup: clinically encrypted data (AES-256-GCM) before transmission, if you enable backup or care groups.
- Firebase Cloud Messaging: device token for caregiver alerts (where applicable).
- Caregiver mode / care groups: caregiver–patient relationship, section permissions, group IDs and invitations.
3.4 Data sent to AI services (with consent)
If you accept wellness AI recommendations, portions of your health context (e.g. active medication, allergies, recent symptoms, aggregated biometrics, limited journal excerpts) may be sent over HTTPS to artificial intelligence services (Google Gemini), directly or via a proxy on Google Cloud Functions protected with Firebase App Check. AI does not replace a healthcare professional. You can disable this in Settings → Privacy.
3.5 Premium subscriptions
If you subscribe to Premium, payments are processed by Google Play and RevenueCat. We do not store full card numbers.
3.6 Technical data and analytics (optional)
- Firebase Crashlytics: anonymized crash reports in production builds.
- Firebase Analytics: only if you explicitly accept anonymous analytics during onboarding.
- Technical device identifiers, app version, language.
3.7 Images and OCR
Photos you capture (lab results, documents, meals, drug packaging, gums, vaccine labels) may be processed on-device (ML Kit) and/or sent to AI only with your action and consent. We do not use them for advertising.
4. Purposes and legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Health tracking and recording features | Contract / consent |
| Medication and appointment reminders | Contract / consent |
| PDF reports and export | Contract |
| Caregiver mode and alerts | Consent / vital interests |
| Encrypted cloud backup | Consent |
| Wellness AI features | Explicit consent (withdrawable) |
| Health Connect | Consent (system permission) |
| Crashlytics / anonymous analytics | Legitimate interest / consent (analytics) |
| Legal compliance | Legal obligation |
5. Storage, security and retention
- Local: SQLCipher-encrypted SQLite database on your device (offline-first).
- Sensitive preferences: Flutter Secure Storage (Android EncryptedSharedPreferences).
- Cloud: AES-256-GCM encryption of clinical data before it leaves the device; TLS in transit.
- Android system backup: disabled for the app (security policy).
- Retention: while you keep the account or data on the device; deletion upon your request or app removal per the deletion procedure.
6. Recipients and international transfers
We may use processors outside the EEA with appropriate safeguards:
- Google LLC (Firebase, Gemini, Play Store, Health Connect) — USA; Standard Contractual Clauses / adequacy framework where applicable.
- RevenueCat — subscription processing.
We do not sell or share your health data with advertisers or data brokers.
7. Your rights
You may exercise access, rectification, erasure, restriction, objection, portability and withdrawal of consent:
- In the app: Profile, Settings → Privacy, export and local deletion.
- Web procedure: Account and data deletion.
- Email: soporte@appchemylabs.es (subject line: «Privacy»).
You may lodge a complaint with your supervisory authority. In Spain: AEPD — www.aepd.es.
8. Children
The app is not directed at children under 13. You must confirm minimum age during onboarding. We do not knowingly collect data from minors without verifiable parental consent.
9. Automated decisions and AI
AI features produce guidance (chat, reports, habit plans, scans). They do not provide binding medical diagnoses. Local predictive alerts use rules on your data without necessarily sending it to third parties. See the medical disclaimer.
10. Cookies and web technologies
This legal website may use minimal technical cookies. See our Cookie Policy. The mobile app does not use cookies; it uses on-device storage.
11. Changes
We may update this policy. The revision date appears at the top. Material changes will be communicated in the app when reasonable.