HEALTH LIBRARY

Privacy policy

Last updated: 5 October 2026

This policy explains how Aqsa LogicByte ("we", "us") handles your information when you use the Health Library mobile app and website (together, the "Service"). Health Library helps you keep your own and your family's health information organised in one place.

Health information is sensitive. We collect only what the Service needs, we never sell it, and you can ask us to delete it at any time.

1. Information we collect

Information you give us:

  • Account details — your name, email address and password. The password is stored only as a secure one-way hash; we can never see it.
  • Health profile — date of birth, sex at birth, blood group, allergies, long-term conditions, height and weight, if you choose to enter them.
  • Emergency contacts — the name, relation and phone number of the people you add.
  • Family members — the profiles you add for relatives: their name, relationship to you and the same health details as your own profile, if you choose to enter them.
  • Family member email addresses — if you enter one, we use it only to send that person an invitation to join your family.
  • Profile photos — if you choose to add one for yourself or a family member.
  • Account deletion requests — the optional reason you give us.
  • Later features (uploaded records, medications) will be described here before they launch.

Information collected automatically:

  • Sign-in data — secure session tokens kept in the app’s memory while it is open. Closing the app, or leaving it in the background for 15 minutes, signs you out.
  • Fingerprint unlock (optional) — your phone checks your fingerprint; Health Library never receives or stores it. We keep only a random key for that phone, deleted when you turn the feature off, reset your password or delete your account, or after 180 days unused.
  • Technical data — IP address, device or browser type and request times, used for security, abuse prevention (for example limiting repeated sign-in attempts) and fixing problems.
  • Preferences — your light or dark theme choice, stored only on your device.

We do not use advertising trackers, and we do not collect your location, contacts or photos unless a feature asks you to share them.

2. How we use your information

  • To create and secure your account, including emailing you verification and password-reset codes.
  • To store and show your health profile back to you, and to calculate things like profile completion and BMI.
  • To process account deletion requests and email you about them.
  • To protect the Service against misuse and to fix problems.

We never sell your information, never use it for advertising, and never use your health information to make decisions about you.

4. Who we share it with

We share information only with service providers who run parts of the Service for us, under their own security and confidentiality commitments:

  • Hosting (Vercel) — runs the website and the app's server.
  • Database hosting (MongoDB Atlas) — stores your account and health profile.
  • Email delivery — sends verification codes and account emails.
  • File storage (Amazon Web Services S3, Sydney region) — stores the profile photos and records you add; files are private and only reachable through short-lived signed links.
  • AI summaries (Groq, Inc., United States) — reads a record when you ask for its AI summary (see below).
  • Push notifications (Expo and Google Firebase Cloud Messaging) — tell your phone when a summary is ready; the message says only that it is ready, with no health details.

AI summaries: nothing is sent to an AI service unless you tap "Get AI summary" on a record. Then its pages (or the text of a digital PDF) are sent to Groq so an AI model can explain the record in plain language — what it is, its key points, what it suggests about your health and questions to ask your doctor. Only the record itself is sent — we add no names, emails or profile details, and we ask the model to leave out names and ID numbers printed on it. Groq does not use it to train AI models and does not keep it after answering.

We may disclose information if the law requires it. We will never share it with advertisers or data brokers.

5. Family sharing

When you join a family, its creator can view and edit your profile, the other people in that family can view it, and you can view that family’s profiles. Either of you can end this at any time; when it ends, the family no longer sees your profile and you keep it.

6. How long we keep it

We keep your information for as long as you have an account.

When your account is deleted, we permanently delete your account, health profiles (yours and your family members’), profile photos, emergency contacts, family links and invitations, sessions, fingerprint-unlock keys and verification codes. We keep one small record that the deletion happened — your name, email address, the request and decision dates and who approved it — so we can prove the deletion was carried out. Short-lived security counters (for example sign-in attempt limits) expire on their own within an hour.

7. How we protect it

  • All traffic between the app, the website and our servers is encrypted (HTTPS).
  • Passwords and verification codes are stored only as secure hashes.
  • Sign-in sessions expire and can be revoked; repeated sign-in attempts are rate limited.
  • Only a small number of administrators can access account records, and only to run the Service (for example to process deletion requests).

No system is perfectly secure, but we work to protect your information and will tell you promptly if a breach affects you.

8. Your choices and rights

  • See and correct your information at any time in the app.
  • Remove optional health details by clearing them in the app.
  • Delete your account and all of its data — in the app (Profile → Delete account) or on our website at /delete-account.
  • Ask us a question or make a request by emailing aqsahamzadev@gmail.com.

9. Deleting your account

You can request deletion in the app or at /delete-account on our website. An administrator reviews every request, usually within 7 days, and we email you when we receive it and when it is done. Until then your account keeps working and you can cancel the request in the app. Once approved, deletion is permanent and cannot be undone.

10. Children

You must be at least 18 to create an account. Parents and guardians may keep health information about their children in their own account (once family members launch); that information is treated with the same care as their own.

11. Changes to this policy

If we make significant changes we will update the date above and tell you in the app or by email before they take effect.

12. Contact us

Aqsa LogicByte — aqsahamzadev@gmail.com