Privacy
Privacy policy
This policy explains how MediFile handles personal and health information when you use the MediFile mobile app and its record-sharing features.
Last updated: 28 July 20261. Who we are
MediFile is developed by HOST SL in Sierra Leone. In this policy, “MediFile”, “we”, “us” and “our” refer to the MediFile service and its operator. Questions or deletion requests can be sent to hello@medifile.sl.
2. Information you provide
Depending on the features you use, MediFile may process:
- Account information: email address, phone number, Google sign-in details and authentication identifiers.
- Profile information: name, date of birth, gender, blood type, emergency contact details and an optional profile photo.
- Health records: prescriptions, medication schedules, dose responses, doctor visits, diagnoses, treatment notes, lab results, medical history, allergies, conditions, surgeries, family history, current medicines and immunisations.
- Patient-entered measurements: values you choose to record, such as temperature, blood pressure, pulse, oxygen saturation, blood glucose, weight and accompanying notes.
- Files and images: prescription photographs, profile photographs, lab-result images or PDFs that you select or capture.
- Support communications: information included when you contact us.
3. Information processed automatically
MediFile and its service providers may process limited technical information required to provide authentication, secure cloud access, file delivery and service reliability. This can include device and operating-system information, IP address, request timestamps, security events and diagnostic information.
MediFile does not include advertising SDKs and does not use your health information for advertising.
4. How we use information
We process information to:
- Create and secure your MediFile account.
- Store, organise, display and synchronise the records you add.
- Provide offline access and resume supported uploads.
- Schedule medication reminders and record your responses.
- Create PDFs and temporary read-only record shares you request.
- Prevent misuse, troubleshoot problems and protect the service.
- Respond to support, privacy and account-deletion requests.
5. Device permissions
MediFile may request access to:
- Camera and selected photos/files when you choose to add a profile image, prescription image or lab attachment.
- Notifications, alarms and lock-screen presentation to deliver medication reminders you configure.
- Internet and network status to synchronise cloud records and show when the app is operating offline.
These permissions are used for the features described above. MediFile does not request your location, contacts or microphone.
6. Storage and offline use
Account records are stored using Google Firebase services, including Firebase Authentication, Cloud Firestore and Cloud Storage. Some records and preferences are cached on your device so MediFile can continue to work during poor connectivity. Medication reminders are scheduled locally on your device.
Cloud service providers may process or store information in countries outside Sierra Leone, subject to their security controls and applicable data-protection requirements.
7. Sharing your records
Sharing is initiated by you. When you create a share link or QR code, MediFile creates a read-only snapshot of the profile and health records included by the sharing feature. Anyone who receives the link may view that snapshot, so only give it to people you trust.
Share links expire automatically after 24 hours and can be revoked from the app. Expiry or revocation prevents further access through the link; it cannot remove copies or screenshots already made by a recipient.
8. When information is disclosed
We may disclose information:
- To a person you authorise through a share link or exported PDF.
- To service providers, such as Google Firebase and Google Sign-In, where necessary to operate the app.
- When required by applicable law, legal process or to protect users, the public or the security of the service.
- In connection with a business reorganisation, subject to appropriate confidentiality and notice requirements.
We do not sell personal or health information and do not share it for cross-context behavioural advertising.
9. Retention and deletion
Records remain associated with your account until you delete them or request account deletion, except where limited retention is required for security, legal compliance, dispute resolution or backup integrity. Deleting a supported record also removes its associated uploaded attachment from active storage.
You can edit or delete individual records in the app. To request deletion of your account and associated cloud data, follow the steps on our MediFile account-deletion page. We may need to verify your identity before completing the request.
10. Security
MediFile uses account authentication, encrypted network connections, access-control rules and owner-scoped cloud storage. No system is completely secure, so you should protect your device and sign-in credentials and share records only with trusted recipients.
11. Your choices
You may:
- Choose which optional profile and health details to add.
- Decline camera or notification permissions in device settings.
- Edit or delete records in the app.
- Revoke active share links.
- Request access, correction or deletion by contacting us.
Declining a permission may prevent the related feature from working but does not prevent use of unrelated features.
12. Children’s privacy
MediFile is not directed to children who are legally unable to consent to the processing of their own information. Where a parent or guardian manages a minor’s information, they should do so only when authorised and in accordance with applicable law.
13. Changes to this policy
We may update this policy when MediFile’s features, service providers or legal obligations change. The “Last updated” date will show when the current version took effect. Material changes may also be communicated through the app or other appropriate channels.