1. Overview
Rx101 (the "App") is developed and operated by an individual developer based in India ("we", "us", "the developer"). This Policy explains what information Rx101 collects, why, and what happens to it — for the App and for this website, rx101direct.com ("the Site").
The short version: Rx101 is built local-first. Your medicines, diagnoses, symptoms, vitals, mood logs, lab results, allergies, emergency contacts and family profiles are stored in an encrypted database on your own device. We do not run a server that holds your health records. The only things that ever leave your device are described in Section 3 below, and only when you take an action that requires them (signing in, backing up, scanning with AI, sharing an Rx, or opting in to anonymous usage stats).
2. What stays on your device, always
The following categories of data are stored only in Rx101's local, at-rest-encrypted database on your phone. They are never transmitted to us, and we have no way to read them, unless you explicitly export or back them up yourself (Section 9):
- Medicines, doses, schedules, and dose history (taken/skipped)
- Diagnoses and the diagnosis timeline
- Symptom episodes and check-ins
- Mood log entries
- Vitals (blood pressure, sugar, custom measures) and intake/output logs
- Lab test results and values
- Allergies, foods to avoid, and possible side effects notes
- Emergency contacts and the provider directory (doctors, hospitals, labs, pharmacies) you add
- Family member profiles you create under your account
- Steps, sleep, heart rate and other readings imported from Apple Health or Health Connect, where you connect them (Section 6)
The on-device database is encrypted at rest, with its encryption key held in your device's secure Keychain (iOS) or Keystore (Android) — hardware-guarded and never transmitted anywhere, including to us.
3. What we collect
3.1 Account information
If you sign in with Google or Apple, we receive the basic profile information those providers share (name, email address, profile photo) to create and identify your account. You can instead use Rx101 as a Guest, with no account and nothing shared with us.
3.2 Preferences
We sync a small set of app preferences (such as theme and notification settings) to your account, so a new device feels the way you left it. This does not include any health data.
3.3 Opt-in usage analytics & crash reports
If you turn on usage sharing (off by default, toggle in Profile), we collect anonymized, usage-only analytics events (e.g. which screens are used) and crash diagnostics through Firebase Analytics and Firebase Crashlytics. These events pass through a sanitizer built to exclude medicine names, diagnoses, vitals, or any other health content — only app-usage and stability signals are sent.
3.4 Push notification token
To deliver reminder and re-engagement notifications, your device registers a push token with our notification provider, OneSignal. Reminder notifications about your medicines are generated and scheduled entirely on your device; the notifications we send from our side carry no health content.
3.5 Support communications
If you email us, we receive whatever you choose to include in that email (e.g. your email address and message) to respond to you.
3.6 Location-adjacent data (feature-specific, opt-in)
Fly Mode detects your current country from your device's SIM/network carrier and locale settings — not GPS — to show country-aware medicine restrictions and emergency numbers. If you use address autocomplete when adding a provider or address, your search text is sent to our maps provider to return suggestions; this feature is only available to signed-in users and is not active for all users.
3.7 Payment information (optional purchases)
If you choose to buy scan credits or make a voluntary donation, you do so on our website through our payment processor, Razorpay. We receive a record of the transaction — the amount, a payment/order reference, and, for credit purchases, the account the credits belong to — so we can add your credits and keep a basic accounting record. Your card or bank details are entered directly with Razorpay and handled by them under their own privacy policy; Rx101 never sees or stores your full card number. These purchases are entirely optional — the app is fully usable without them.
3.8 Survey responses (optional, may include health questions)
From time to time Rx101 may show a short, optional in-app survey or poll. Some of these ask health-related questions — for example, how you've been feeling, whether you've had a recent symptom such as a fever, or whether you've had a fall — to understand how people are doing and improve the app. Where a survey asks about your health, we tell you before you start, and taking part is always your choice: you can dismiss any survey and never have to answer to keep using Rx101.
Survey answers are collected anonymously. We do not attach your account, name, email, or date of birth to a response — even if you are signed in. So that we can read answers by rough age group, a response may include your age (in whole years) and your birth month only — never the day, the year, or your full date of birth, which on their own cannot identify you. Apart from that, we store just the answers you give and a random per-install identifier, used purely so the same survey isn't shown to you again and a single device isn't counted twice. Because responses carry no account link, they cannot be traced back to you and are not connected to the health records on your device. Responses are stored with our infrastructure provider (Supabase), used in aggregate to understand feedback and guide the product, and are never used to advertise to you or sold to anyone.
3.9 Referral program
If you invite a friend, or join Rx101 using someone's invite, we store the information needed to run the program and keep it fair: your referral code, and the link recording which account referred which — so we can grant the right scan credits to each side. Unlike survey responses, this is tied to the accounts involved (it's the whole point of a referral); it contains no health data — only that account A invited account B. We also use the same random per-install identifier described above, purely to stop a single device from claiming multiple referral rewards. This data is stored with our infrastructure provider (Supabase), is never used to advertise to you or sold, and referrals require a signed-in account — Guest users are not part of the program.
4. What we never collect
- No server-side database of your medicines, diagnoses, symptoms, vitals, or mood logs
- No GPS or precise location tracking
- No use of health-app data for advertising or marketing, and no sharing of it with anyone
- No advertising identifiers, and no data sold or shared for advertising
- No selling of personal information to any third party, ever
The one nuance to the first point: if you choose to answer an optional survey that asks a health-related question (Section 3.8), that answer does reach our servers — but anonymously, with no link to your account, name, or on-device records. We never build a server-side profile of your health that is tied to you.
Rx101 may occasionally show a “sponsor” card inside the app. These slots are sold directly by us to health-adjacent brands and are the same for everyone — they are not behavioural or personalised ads. We use no advertising SDK, we do not profile you, and we share no personal or health data with sponsors. A sponsor only knows that its card ran because it paid for a time slot — never who saw it.
5. Third parties we use
We rely on a small number of infrastructure providers to run specific features. Each only receives the data necessary for the feature it powers, and none receive your on-device health records as a matter of course.
| Provider | Purpose | What it may receive |
|---|---|---|
| Google / Apple Sign-In | Account authentication | Name, email, profile photo (from the provider, per your consent) |
| Google Drive / Apple iCloud | Optional backup, to your own cloud | An end-to-end encrypted backup file only you can decrypt |
| Google Gemini / Anthropic Claude | AI-assisted prescription & lab report reading (opt-in per scan) | The photo you scan, for that single request only |
| Supabase | AI-scan quota proxy, Rx Direct relay, shared reference caches, anonymous survey responses, referral records & purchase records | Scan images in transit (free-tier proxy only), Rx Direct payloads in transit; at rest: your scan-usage count, credit/purchase records, referral records (which account referred which, plus a per-install id for abuse prevention — no health data), and any survey answers you submit — the latter stored anonymously (no account link), even when a survey asks a health question; never your identifiable health records |
| Firebase (Google) | Crash reporting & anonymized usage analytics (opt-in) | Sanitized, health-content-free usage/crash events |
| OneSignal | Push notification delivery | Device push token; no notification content describing your health |
| Ola Maps | Address autocomplete (signed-in users, where enabled) | Address search text you type |
| Razorpay | Payments for optional scan credits & donations (website only) | Payment and order details when you pay; full card details go directly to Razorpay, not to us |
Apple Health and Health Connect are not in this table because nothing is sent to them. They are system frameworks on your own phone that Rx101 reads from, with your permission and never in the other direction — see Section 6.
6. Health app data, specifically
Rx101 can optionally connect to your phone's health platform — Apple Health (HealthKit) on iOS, Health Connect on Android — so the activity your phone or watch already records can sit alongside the vitals you log by hand. This connection is off until you turn it on in the Health tab and grant permission, and each type of data is granted separately by you.
Where you allow it, Rx101 reads: steps, distance walked or run, active energy burned, heart rate, blood oxygen (SpO₂), sleep, blood pressure, and blood glucose.
Rx101 only reads. It never writes anything back to Apple Health or Health Connect, and it never modifies or deletes what is already there. You can revoke access at any time in iOS Settings → Health, or in the Health Connect app on Android; revoking stops all further syncing immediately.
Imported readings never reach our servers. They are stored on your device, in the same at-rest-encrypted database as everything listed in Section 2, and are treated exactly like a reading you typed in yourself. We hold no copy of your step count, your sleep, your heart rate, or any other imported measurement. If you have turned on backup, these readings are included in the end-to-end encrypted backup file described in Section 9 — encrypted on your device, uploaded only to the cloud account you chose, and unreadable by us.
We do not use health-platform data for advertising or marketing, we do not sell it, and we do not share it with any third party — including our analytics provider. The opt-in usage analytics described in Section 3.3 carry no health content of any kind, and imported readings are never among the events sent.
Readings already imported remain in your on-device record until you remove them; you can delete them in the app, and uninstalling Rx101 removes them along with the rest of the local database.
7. Calendar & contacts, specifically
Two features ask for a device permission and use it only at the moment you ask them to. Neither sends anything to us, and both are optional.
Calendar (write only). When you choose to add an appointment or follow-up to your calendar, Rx101 writes that one event to your device's calendar. It does not read your existing events, and nothing about your calendar reaches our servers.
Contacts (read). When you add an emergency contact, you can pick someone from your device's contacts instead of typing their details. Rx101 reads your contact list only while that picker is open, copies just the person you choose into your local emergency-contact record, and keeps nothing else.
Decline either permission and the rest of the app is unaffected — appointments and emergency contacts can always be added by hand.
8. AI scanning, specifically
When you scan a prescription or lab report, the photo of that document is sent to a third-party AI model (Google Gemini or Anthropic Claude) to extract medicines, doses, timings, or lab values. This happens either through our quota-limited free proxy or through your own API key, which you may optionally add and which is stored only in your device's Keychain/Keystore — never on our servers. The image is used only for that one read and is not retained by Rx101.
That image is used only to service your one request. Rx101 does not store the image or the AI's raw response after the extraction is shown to you for confirmation. The AI provider's own privacy policy governs how they handle that single request on their infrastructure; we choose providers with no-training-on-API-data commitments where available, but you should review their policies if you have specific concerns.
9. Backups, specifically
If you turn on backup, Rx101 encrypts your data on your device before it ever leaves — using a key derived from your own credentials — and uploads only that encrypted file to the cloud storage you chose (your Google Drive or your iCloud, never ours). We cannot open that file. If you lose access to both your device and your account credentials, we cannot recover your backup for you.
10. Rx Direct, specifically
Rx Direct lets a prescriber send a signed prescription to your device by QR code or link. The signed, encoded payload passes through our relay service only to connect the sender's and recipient's devices; we do not read or retain it beyond the short window needed to complete that handoff, after which it is deleted.
11. Retention & deletion
On-device health data is retained for as long as it's on your device — you control it directly, including exporting or deleting any record inside the App. Uninstalling the App removes the local database, including any readings imported from Apple Health or Health Connect. Account records (email, preferences) are retained until you delete your account or ask us to remove them. Backup files persist in your own Drive/iCloud until you delete them there. Analytics events, where opted in, are retained per Firebase's standard retention windows and are not linked back to your health data.
12. Your rights
Because most of your data lives on your device, many rights are exercised directly in the App: view, edit, export, or delete any record at any time; turn off analytics sharing in Profile; delete a cloud backup from your own Drive/iCloud account. For anything we hold ourselves — your account record, preferences, or support correspondence — you can request access, correction, or deletion by emailing us at the address in Section 18. We'll respond within a reasonable time, generally within 30 days.
13. Children's privacy
Rx101 accounts require a minimum age of 14 (Terms, Section 2); we do not knowingly collect account information from anyone younger. For a younger child, or any minor who isn't creating their own account, a parent or guardian can instead add a family profile under their own adult account — that data is stored locally under the adult's device and account exactly as any other profile, and the adult is responsible for it. Users between 14 and the age of legal majority in their jurisdiction should have a parent or guardian aware of their use of Rx101.
14. International data transfers
The developer is based in India. Some third-party providers we use (Section 5) process data on servers outside India. Where that happens, it is limited to the specific, minimal data described above (e.g. a scan image for one AI request, an authentication token) and is governed by that provider's own security and privacy commitments.
15. Security
Rx101's on-device database is encrypted at rest with a key held in your platform's secure Keychain/Keystore. Backups are end-to-end encrypted before upload. API keys you add yourself (for BYO AI scanning) are stored the same way. No method of storage or transmission is 100% secure, but we've designed Rx101 so that even a compromise of our own infrastructure would not expose your health records, because we don't hold them.
16. Changes to this Policy
We may update this Policy as Rx101 evolves. Material changes will be reflected by updating the "Effective" date above, and where appropriate, an in-app notice. Continued use of Rx101 after a change means you accept the updated Policy.
17. Grievance Officer (India IT Rules, 2021)
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Grievance Officer for Rx101 is:
Email: hello@rx101direct.com — please start your subject line with "Privacy" so it reaches the right place.
You may contact the Grievance Officer with any complaint about how your information is handled. We aim to acknowledge complaints within 3 days and resolve them within a month.
18. Contact
Questions about this Policy, or requests to access, correct, or delete your data, can be sent to hello@rx101direct.com — start the subject with "Privacy".