Privacy Policy for Lab Results Tracker

Lab Results Tracker

Effective Date: September 30, 2026
Last Updated: September 30, 2026


Overview & Application Details

FieldDetail
Application NameLab Results Tracker
Store SubtitleFree, Offline & Private
Package Name (Android)com.labresultstracker.lab_results_tracker
Bundle Identifier (iOS)com.labresultstracker.lab_results_tracker
Application Version1.0.0
Primary CategoryMedical / Health & Fitness
Developer Contactinfo@gcaninfo.com

Lab Results Tracker (“the Application”, “we”, “us”, or “our”) is an independent, client-first mobile application designed to help individuals and families track recurring laboratory and blood test measurements (such as cholesterol, HbA1c, glucose, blood pressure, CBC, etc.) and view trends over time.

We believe that personal health data is among the most sensitive information a person owns. Lab Results Tracker is engineered with a strict privacy-by-design, local-only architecture:

  • No User Accounts: You never register, log in, or provide an email address, password, or phone number.
  • No Developer Cloud Servers: We do not operate remote databases, synchronization servers, or backend analytics systems.
  • No Advertising or Monetization of Health Data: We do not host ads, embed advertising SDKs, track user behaviour, or sell, broker, or share your data with insurance companies, pharmaceutical entities, or data brokers.
  • 100% On-Device Processing: Optical character recognition (OCR) and PDF parsing run entirely on your physical device.

1. Information Handling & Local Storage

All medical and personal information entered into or processed by Lab Results Tracker resides solely on your device.

A. Health & Medical Data

  • Data Recorded:
    • Laboratory test names and categories (e.g., Lipid Panel, Metabolic, Vitals, Vitamins).
    • Numeric measurement values and units (e.g., mg/dL, mmol/L, %).
    • Date the laboratory test was collected/taken.
    • Laboratory reference ranges (e.g., normal guidelines, per-entry range overrides, custom profile targets).
    • Laboratory names and optional user notes.
  • Storage Mechanism: Stored locally in a relational SQLite database managed via Drift (lab_results_tracker.sqlite) within the application’s isolated sandboxed storage.
  • Multi-Profile Data: If you use the app to track family members, profile labels (e.g., nickname, display colour) are stored strictly inside the same local SQLite database file.

B. Imported Laboratory Documents & Source Files

  • Document Types: Digital PDF documents and captured photographic images of paper laboratory reports.
  • Storage Location: When you choose to save a report, a copy is retained in the application’s local sandbox storage (report_sources/ folder) so that you can inspect, verify, and compare your historical readings against original documents at any future time.
  • Protection: Stored documents are never transmitted to developer servers or external third-party cloud hosts.

C. OS-Level Device Backups

Because data is saved in standard platform document directories, your local database and saved documents may be included in your personal device backups (such as Apple iCloud Backup on iOS or Google Drive Device Backup on Android), if you have enabled those operating system features on your phone. These backups are governed by your personal relationship and settings with Apple or Google; we have no access to your backup archives.


2. Device Permissions & How They Are Used

Lab Results Tracker requests only device permissions essential for user-initiated core features. Each permission is requested dynamically at runtime:

Platform PermissionName / KeyPurpose & Usage Scope
CameraiOS: NSCameraUsageDescription
Android: CAMERA
Capture Paper Reports: Used only when you tap “Import from Photo” to photograph a printed lab report. Images are processed on-device and never transmitted over the internet.
Photo Library (Read)iOS: NSPhotoLibraryUsageDescription
Android: READ_MEDIA_IMAGES
Import Lab Report Images: Used only when you select an existing laboratory document image from your photo album for on-device recognition.
Photo Library (Save)iOS: NSPhotoLibraryAddUsageDescriptionExport Charts & Reports: Used when you explicitly choose to save an exported report image or chart to your device photo library.
Storage / FilesiOS: File Picker
Android: System Document Picker
Import PDF Reports: Used when you tap “Import PDF” to select an electronic lab document from your device downloads or local file storage.

Permissions We NEVER Request

  • ❌ Location Data (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, ACCESS_BACKGROUND_LOCATION)
  • ❌ Contacts & Address Book (READ_CONTACTS)
  • ❌ Microphone / Audio Recording (RECORD_AUDIO)
  • ❌ Advertising Identifier / Tracking (IDFA, GAID, AD_ID)
  • ❌ Network State Inspection (ACCESS_NETWORK_STATE is explicitly stripped from production manifests)

3. On-Device Document Parsing & OCR Pipeline

When you import a laboratory report, the document is processed entirely using on-device engines:

  1. Digitally Generated PDFs: For standard vector/text PDFs from Quest, Labcorp, Epic, or hospital portals, the embedded text layer is read directly on the device using native parsers (syncfusion_flutter_pdf). No optical scanning or external network requests occur.
  2. Scanned Documents & Photographs: When you import a paper photograph or scanned PDF image, optical character recognition runs entirely on the device using Google ML Kit (google_mlkit_text_recognition) or Apple Vision frameworks.
  3. Mandatory User Confirmation: Parsed rows are always displayed on an interactive review screen before saving. No medical numbers are committed to the database without your explicit inspection and approval.

4. Optional Network Feature: AI Lab Test Explanations

The core application operates completely offline without network capabilities. There is a single, optional feature that interacts with the internet: AI Plain-Language Test Explanations.

How It Works:

  • Strict Opt-In: This feature is disabled by default. It requires the user to manually provide their own Google Gemini API key in Settings.
  • On-Demand Only: Requests are dispatched only when you tap the “Explain” button on a specific test detail screen.
  • Strict Data Minimization: To ensure complete medical privacy, the request body contains only general educational metadata:
    • Test Name (e.g., "Total Cholesterol")
    • Measurement Unit (e.g., "mg/dL")
    • Typical Reference Range (e.g., "< 200 mg/dL")
  • What is NEVER Sent to the AI:
    • 🚫 Your measured numeric lab value
    • 🚫 Your test date or time
    • 🚫 Your name, nickname, or profile identifier
    • 🚫 Your doctor, clinic, or facility name
    • 🚫 Any personal notes or clinical history
    • 🚫 Your lab report document or image
  • Endpoint & Protocol: Requests are transmitted via encrypted HTTPS directly from your device to Google Generative Language API (generativelanguage.googleapis.com).
  • API Key Security: Your API key is stored only on your physical device using local preferences (SharedPreferences). It is never uploaded to developer servers. You can clear or remove the key at any time in Settings.

5. Third-Party Frameworks & Analytics

  • No Analytics SDKs: The application does not contain Google Analytics, Firebase, Mixpanel, Segment, Flurry, or any behavioral telemetry frameworks.
  • No Crash Reporting Trackers: The application does not integrate third-party remote crash trackers (such as Sentry or Crashlytics) that harvest system or memory dumps.
  • No Advertising Networks: The application is ad-free and contains no advertising SDKs.
  • No Social Logins or Trackers: No Facebook SDK, Google Sign-In, or tracking pixels are incorporated.

6. Data Portability, Export, & Deletion

You own your data completely. Lab Results Tracker provides unhindered data access and deletion capabilities:

Data Export (No Vendor Lock-In)

At any time, you can export your records directly from the application’s Settings or Share menu:

  • CSV Spreadsheet: Exports a complete comma-separated file of all readings, dates, units, reference limits, and notes.
  • Printable PDF: Generates a structured clinical summary report suitable for printing or sharing with your physician.
  • Native System Share: Exported files are handled via the native platform share sheet (share_plus). The app transmits data only to the destination you choose (e.g., email to your doctor, save to Files, AirDrop, or local printing).

Data Deletion

  • Individual Entries & Reports: You can delete individual readings, reports, or full person profiles directly from the app interface. Deleting a report permanently deletes the associated local copy of the document and its parsed values.
  • Complete Erasure: You can clear all data instantly by clearing application storage in your device settings or by uninstalling the application. Because there is no remote cloud server, uninstalling the app permanently purges all local data from your device.

7. App Store & Google Play Declarations

Google Play Data Safety Disclosures

For transparency during Google Play review and store listing inspection:

Data CategorySpecific Data TypeCollected?Shared?Processing ModePurpose
Health and FitnessHealth info / Lab test valuesYes (On-device only)NoStored locally in on-device SQLite database. Never sent to developer.App functionality (Tracking personal lab trends).
Photos and VideosPhotos of lab reportsYes (On-device only)NoProcessed on-device via ML Kit OCR; stored locally if saved.App functionality (Document import).
Files and DocsPDF lab reportsYes (On-device only)NoProcessed on-device; stored locally in app sandbox.App functionality (Document import).
Personal InfoName / NicknameYes (On-device only)NoOptional profile labels stored in local SQLite database.App functionality (Multi-person organization).
Financial InfoPayment info, purchasesNoNoN/A — Free app, no in-app purchases.None.
LocationPrecise / ApproximateNoNoN/A — No location permissions requested.None.
Device or other IDsAdvertising ID / Device IDNoNoN/A — No identifiers collected or accessed.None.
  • Security Practices:
    • Data is encrypted at rest by the operating system file encryption (iOS Data Protection / Android File-Based Encryption).
    • Optional AI queries use standard HTTPS encryption (TLS 1.2/1.3).
    • Users can delete their data at any time via the in-app deletion tools or by uninstalling.

Apple App Store Privacy Nutrition Labels

  • Data Not Collected: Lab Results Tracker does not collect any data from your device.
  • No Tracking: The app does not track you across apps and websites owned by other companies.

8. Children’s Privacy

Lab Results Tracker does not knowingly collect, solicit, or store personal information from children under the age of 13 (or under 16 in the European Union). The application is intended for adult users and parents/guardians managing household lab records locally on their personal devices.


9. Medical Disclaimer

Lab Results Tracker is an informational and organizational utility for personal recordkeeping.

  • Not a Medical Device: The application is not certified as a medical device and is not intended for diagnostic purposes.
  • No Medical Advice: The app does not provide medical advice, clinical diagnosis, or treatment recommendations.
  • Reference Ranges: Reference ranges provided in the application are general population guidelines (derived from public clinical reference sources such as the NIH, AHA, and ADA) and may not apply to your specific health status.
  • Consultation Required: Always consult a licensed physician or qualified healthcare provider regarding the interpretation of laboratory results, diagnoses, or treatment decisions. Never disregard professional medical advice or delay seeking it because of information tracked in this application.

10. Regulatory Compliance & HIPAA Notice

  • HIPAA Notice: Lab Results Tracker is not a “covered entity” or “business associate” under the Health Insurance Portability and Accountability Act (HIPAA), as it operates strictly on the consumer’s local personal device and does not transmit Protected Health Information (PHI) to remote healthcare systems or insurers.
  • GDPR & CCPA/CPRA: Because all personal and health information remains entirely on your physical device under your exclusive control, you possess complete sovereignty over your data, including the right to access, rectify, export, and delete your data at any time without third-party involvement.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements, operating system capabilities, or app enhancements. Any changes will be published in the application repository with a revised “Last Updated” date. Continued use of the Application after revisions constitutes your acceptance of the updated policy.


12. Contact Information

If you have questions, feedback, or privacy-related inquiries regarding Lab Results Tracker, please contact:

  • Email: info@gcaninfo.com