Application privacy

Vexel Health Passport Privacy Policy

How Vexel Health Passport handles locally stored personal and health information.

Effective date: 9 August 2026

Last updated: 9 August 2026

Vexel Health Passport is provided by Vexel Consultants (Private) Limited ("we", "us", or "the developer"). This Privacy Policy explains how Vexel Health Passport (com.vexel.passport) accesses, uses, stores, exports, shares, retains, and deletes information.

1. App purpose

Vexel Health Passport is an offline-first personal health-record organizer. It lets a user record and organize profile information, symptoms, medications, reminders, appointments, private documents, reports, exports, and encrypted backups on the user's Android device.

The app does not require an account and does not provide cloud synchronization, advertising, analytics, or developer-operated health-data processing.

2. Information the app can access and store

The app stores only information entered, selected, imported, or generated by the user, which may include:

  • Name, date of birth, profile details, and other personal identifiers entered by the user.
  • Symptoms, severity, timing, notes, allergies, diagnoses, procedures, and other user-recorded health information.
  • Medication names, doses, schedules, changes, notes, and reminders.
  • Appointment and follow-up details created by the user.
  • Imported PDF, JPEG, and PNG documents and images chosen through Android's system file picker.
  • Reports, readable exports, structured exports, and encrypted backups generated at the user's request.
  • App preferences and security settings, including a protected PIN verifier and Android Keystore-protected PIN material. The app does not store the user's raw PIN.

This information is personal and may be sensitive health data. It is used only to provide the app functions requested by the user.

3. Local storage and use

Health and profile information is stored locally in the app's private storage on the user's device. Imported documents are copied into app-private storage under generated identifiers. Core app features work without an internet connection.

The app uses the information to display the user's records, organize the timeline, schedule user-created reminders, generate user-selected reports and exports, create encrypted backups, restore backups, and support deletion.

4. Data collection by the developer

The current release does not transmit personal information, health data, device data, app activity, or identifiers to the developer or a developer-operated server. It contains no analytics SDK, advertising SDK, account service, cloud synchronization service, or crash-reporting SDK.

Because the developer does not receive this information from the app, the developer does not sell it, use it for advertising, or share it with data brokers or other companies.

5. User-directed export and sharing

The user can intentionally create an export, report, or encrypted backup and choose a destination using Android system interfaces. The user can also explicitly share a document or generated report with another app.

These actions occur only after the user chooses them. Once a file is saved outside Vexel Health Passport or shared with another app or person, that destination's privacy and security practices apply. The developer does not receive a copy.

Users should share health information only with trusted recipients and store backup passwords securely. The developer cannot recover a forgotten backup password.

6. Permissions and device capabilities

Vexel Health Passport requests notification permission on supported Android versions so it can display reminders created by the user. Denying this permission prevents reminder notifications but does not prevent local record keeping.

File selection uses Android's system picker, so the user chooses each imported or exported file. Scoped temporary access is used when the user opens or shares a private document. Optional device authentication is handled by Android's biometric or device-credential interface when available.

The app does not request location, contacts, microphone, camera, body sensors, Health Connect, phone, SMS, or broad storage permissions in the current release.

7. Security

The app uses Android app-private storage, optional PIN or device authentication, Android Keystore protection, opaque document identifiers, integrity hashes for imported files, and password-derived AES-GCM encryption for backups. Backup passwords are not stored by the app.

No storage or security method can guarantee absolute protection. Device security, operating-system updates, chosen PIN strength, backup password strength, and the security of export destinations also affect protection.

8. Retention and deletion

Information remains on the device until the user edits it, deletes individual records, uses Delete all app data, clears the app's storage through Android settings, or uninstalls the app. Delete all app data removes the local profile, health events, medications, private documents, reminders, preferences, and app-lock material managed by the app.

Files previously exported, shared, or backed up outside the app are not controlled by Vexel Health Passport and must be deleted separately from their destination.

Because the app has no account or developer server, there is no remote account record to delete and no server-side health-data retention period.

9. Children

The app is not specifically designed or marketed for children. The developer does not knowingly collect children's information because the app does not transmit user information to the developer. A parent or guardian is responsible for deciding whether local use is appropriate under applicable law.

10. Medical disclaimer

Vexel Health Passport is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. It does not provide medical advice, diagnosis, treatment recommendations, or emergency assessment. Users should consult a qualified healthcare professional for medical advice, diagnosis, or treatment and contact local emergency services in an emergency.

11. Changes to this policy

We may update this Privacy Policy when app behavior, legal obligations, or store requirements change. The updated policy will show a revised effective or last-updated date. Material changes to data handling will also require corresponding app and Google Play disclosures.

12. Contact

Developer: Vexel Consultants (Private) Limited

Privacy and support email: contact@vexel.pk

Support website: https://vexel.pk/apps/vexel-health-passport/support/

Address or country, if required: Faisalabad, Pakistan