Privacy Policy — Medtaker
Last updated: 2026-05-04
Summary
Medtaker runs 100% offline. Your medical data (medications, schedules, adherence, events) never leaves your device. The only data we send out is what is strictly necessary to manage your premium subscription — if you activate it — through RevenueCat and Google Play Billing.
1. Data controller
Torhen is the data controller for the data described in this policy. To exercise your rights or ask any privacy question, write to contacto@torhen.com.
2. Data we do NOT collect
- We do not collect medical or health data.
- We do not operate our own server that receives your data.
- We do not use analytics, crash reporters or advertising.
- We do not share data with third parties for commercial purposes.
- We do not access your contacts, location, microphone or camera unless you explicitly enable the features that require them (and even then, that data stays on the device).
3. Data that IS processed (only if you activate the premium subscription)
To manage the premium subscription, the following data is processed through RevenueCat and Google Play Billing:
- Anonymous App User ID: a pseudonymous identifier generated by the app, not tied to your real identity.
- Google Play Billing purchase tokens.
- Subscription status: active, expired, in trial.
- Device info: model, OS version, language, country.
Legal basis (GDPR Art. 6.1.b): performance of the subscription contract. Because this is necessary to deliver the service you contracted, no consent banner is required.
If you never activate the subscription, none of this data leaves your device.
4. Subprocessors
The only third parties that receive subscription-related data are:
- RevenueCat, Inc. (United States) — subscription management. Privacy policy.
- Google LLC (Google Play Billing, global) — payment processing. Privacy policy.
5. Data retention
- Local medical data: stays on your device until you delete it or uninstall the app. Uninstalling fully removes it from the device.
- Subscription data at RevenueCat: kept while the subscription is active plus the legally required billing retention period (typically 5 years under applicable tax law).
6. Your rights
Under the GDPR (EU), LGPD (Brazil), Argentine Law 25.326 and equivalent regulations, you have the following rights:
- Access: the app itself shows everything it has (your data lives on your device).
- Rectification: you can edit everything from inside the app.
- Erasure: use the "Delete my data" button in Settings → Privacy, or uninstall the app.
- Portability: the app lets you export your data from Settings.
- Complaint to a supervisory authority: you may file a complaint with AEPD (Spain), AAIP (Argentina), ANPD (Brazil) or the data protection authority in your jurisdiction.
To exercise any right related to subscription data, write to contacto@torhen.com.
7. International transfers
RevenueCat operates from the United States. The international transfer is covered by the Standard Contractual Clauses (SCCs) included in RevenueCat's Data Processing Agreement.
8. Children
Medtaker is not directed to children under 16. We do not knowingly collect data from minors. If you are a parent or guardian and believe a minor in your care is using the app, contact us and we will delete any related data.
9. Changes to this policy
We may update this policy to reflect legal, technical or subprocessor changes. The "Last updated" date at the top of this document indicates the current version. We will notify material changes the next time you open the app.
10. Contact
For any privacy inquiry, write to contacto@torhen.com.