Privacy Policy
MediScript Privacy Policy
MediScript is a mobile application that lets licensed doctors create digital prescriptions, share them as PDF files, maintain a local record of the prescriptions they have issued, and keep free-form clinical notes.
How to Delete Your Account and Data
MediScript stores all information directly on your device and operates no servers, so you can delete your account and your records at any time from within the App itself. No request to us is required, and deletion takes effect immediately.
To delete your account and all associated data, open the App and go to Profile > Data Management > Delete profile, then confirm using your medical registration number.
To delete your records while keeping your account, go to Profile > Data Management > Clear all data, then confirm using your medical registration number.
Full step-by-step instructions, the exact categories of data removed or retained in each case, and our retention periods are set out in Section 6: Data Retention and Deletion.
1. Who We Are
MediScript ("the App", "we", "us", "our") is a mobile application for licensed doctors.
- App developer / publisher: Khush Desai
- Contact email: khush.desai.kol@gmail.com
If you are a patient: MediScript is used by your doctor. Your doctor (not the App developer) decides what information about you is entered into the App and is the party responsible (the "data controller") for that information. Please direct questions about your records to the treating doctor.
2. Our Privacy-First Design: Data Stays on Your Device
MediScript is designed to keep your data on your device. We do NOT operate a backend server, and we do NOT transmit your account information, patient records, or clinical notes to us or to any server operated by us.
- All data you enter is stored locally on your device using the device's on-device storage (AsyncStorage).
- We (the developer) cannot see, access, collect, or retrieve your data.
- There is no account on our servers, no cloud sync, no remote backup, and no login to any service operated by us.
- Data leaves your device in only one situation: when you explicitly choose to share or print a file (see Section 5).
No patient records, clinical notes, passwords, or images are ever transmitted off the device by the App.
3. Information Processed by the App
Everything below is processed and stored locally. We do not receive it.
(a) Doctor account information (entered by the doctor at registration or in the profile):
- Full name, qualification, registration number, state medical council, year of registration.
- Email address and phone number.
- Password (stored only as a salted, one-way SHA-256 hash — the plaintext password is never stored).
- Optional profile photo and signature image.
- Optional clinic details: clinic name, address, phone, email and other free-text notes (shown in the prescription footer).
(b) Patient and clinical information (entered by the doctor for each prescription):
- Patient name, age, sex, phone number, email, blood group.
- Weight, height and the calculated BMI.
- Visit type, chief complaint, history, examination findings, diagnosis, tests, medications, advice and remarks.
(c) Clinical notes (entered by the doctor):
- Title, body text, a category tag, and pin state.
- Optionally, a linked patient name and phone number (only when the doctor chooses to link one; notes do not require a patient).
(d) Device permissions and access used (only when you trigger the relevant feature):
- Camera — to take a profile photo or capture a signature.
- Photo library — to choose a profile photo or signature image.
- Haptics/vibration — for tactile feedback.
The App does NOT record audio, and it does NOT collect device identifiers, location data, advertising IDs, usage analytics, crash analytics, or contacts.
4. How the Information Is Used
The information is used solely to provide the App's core features on your device:
- Authenticating the doctor's local login.
- Generating prescription and note PDF documents.
- Maintaining and displaying the doctor's own prescription history, grouped by patient phone number, and the doctor's own notes.
- Pre-filling the form for returning patients.
- Exporting and printing records at the doctor's request.
We do not use the information for advertising, profiling, or any secondary purpose, and we never sell it.
Note: the registration details a doctor enters at sign-up are self-declared. The App does not verify medical credentials; anyone relying on a prescription should confirm the prescriber's registration status independently (for example, on the National Medical Commission's public register).
5. Sharing and Printing of Information
The App shares or prints data only at your explicit instruction, using your device's native share sheet or print dialog:
- Prescription PDFs — when the doctor taps "Share PDF" or "Print".
- Note PDFs — when the doctor shares or prints a note.
- A CSV export of prescriptions — "Export data".
- An RTF export of notes (opens in Word/Docs) — "Export notes".
- A combined export of both — "Export all data".
When you share or print a file, it is handed to the app, contact, or printer you select (for example WhatsApp, email, a printer, or cloud storage). Once shared, the data is governed by the privacy practices of that destination app or service, which are outside our control. Doctors are responsible for sharing patient information only through channels and with recipients permitted by applicable medical-confidentiality and data-protection laws.
Apart from this, we do not disclose your information to any third party. We have no servers from which information could be disclosed.
6. Data Retention and Deletion
Because MediScript operates entirely on your device and we run no backend server, you retain full and direct control over your information. Data remains on your device until you choose to delete it or uninstall the App. We do not retain any of your data, because we never receive it in the first place.
The App offers two distinct deletion options, allowing you to choose whether to remove your clinical records only, or to remove your account in its entirety. Both are performed within the App, require no request to us, and take effect immediately.
6.1 Deleting Your Account and All Associated Data
To permanently remove your doctor profile together with every record stored by the App, follow these steps:
- Open the MediScript App and sign in.
- Tap Profile in the main navigation.
- Select Data Management.
- Tap Delete profile.
- Confirm by entering your medical registration number when prompted.
Navigation path: Profile > Data Management > Delete profile
Once confirmed, your profile and all records are erased from the device immediately and the App returns to its initial state. You will need to register again in order to continue using the App.
6.2 Deleting Your Records While Keeping Your Account
If you wish to erase your clinical records but retain your registration details, follow these steps:
- Open the MediScript App and sign in.
- Tap Profile in the main navigation.
- Select Data Management.
- Tap Clear all data.
- Confirm by entering your medical registration number when prompted.
Navigation path: Profile > Data Management > Clear all data
All prescriptions and clinical notes are erased immediately, while your doctor profile is preserved so that you may continue using the App without registering again.
You may also delete individual prescriptions or individual notes at any time from their respective screens, without affecting any other record.
6.3 Data Deleted and Data Retained
The table below sets out precisely which categories of data are removed and which are kept under each option.
| Category of data | Delete profile | Clear all data |
|---|---|---|
| Doctor account details (name, qualification, registration number, state medical council, year of registration, email, phone) | Deleted | Retained |
| Password (stored only as a salted, one-way SHA-256 hash) | Deleted | Retained |
| Profile photo and signature image | Deleted | Retained |
| Clinic details (name, address, phone, email, footer notes) | Deleted | Retained |
| Prescriptions and all patient information they contain (name, age, sex, phone, email, blood group, weight, height, BMI, complaint, history, examination findings, diagnosis, tests, medications, advice, remarks) | Deleted | Deleted |
| Clinical notes (title, body text, category tag, pin state, and any linked patient name or phone number) | Deleted | Deleted |
Files you previously exported, shared, or printed — such as prescription PDFs saved to your device or sent through another application — are not affected by either option, as they reside outside the App. You will need to remove those separately from wherever they were saved or sent.
6.4 Retention Period
- Data held by us: none. MediScript has no backend server and transmits no records to us, so there is no server-side copy of your information and no associated retention period.
- Data held on your device: retained until you delete it using one of the options above, or until you uninstall the App. There is no automatic expiry.
- Following deletion: no additional retention period applies. Deletion is immediate and permanent, with no grace period, archive, or backup copy from which data could be recovered.
- Uninstalling the App removes all locally stored MediScript data from the device.
Please note: all deletion actions are irreversible. As data is stored solely on your device and we hold no copy, we are unable to restore deleted records. If you wish to keep a copy of your information, please use the export options described in Section 5 before deleting.
7. Security
- Passwords are never stored in plaintext; they are protected with a per-account random salt and a one-way SHA-256 hash.
- Patient records, clinical notes, and account data are stored in the App's private, sandboxed on-device storage, which is isolated from other apps by the operating system.
- No patient records, notes, or credentials are transmitted off the device, removing the risks associated with server-side breaches.
No method of electronic storage is 100% secure. You are responsible for securing the device itself (screen lock, device encryption, OS updates) and for who you grant physical access to it. Because data is device-local, loss, theft, or damage of the device may result in permanent loss of the data.
8. Children
MediScript is a professional tool intended for use by licensed doctors and is not directed to children. Patient information about minors may be entered by a doctor in the course of care; such information is handled the same way as all other on-device data and remains the responsibility of the treating doctor.
9. Your Rights
Because all data is stored locally and under the doctor's direct control, doctors can access, correct, export, and delete the data at any time from within the App. Patients wishing to exercise rights over their health information should contact their treating doctor, who controls those records. Depending on your jurisdiction (e.g. India's DPDP Act, the EU/UK GDPR), you may have additional statutory rights; please consult the treating doctor and applicable law.
10. Third-Party Services
The App is built with the Expo / React Native framework and uses open-source libraries that run on-device. It does not embed advertising SDKs or analytics SDKs, and it does not contact any third-party service. No data is sent to the developer or to Expo during normal use.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect the latest revision. Material changes will be communicated through an App update. Continued use of the App after an update constitutes acceptance of the revised policy.
12. Contact Us
For any questions about this Privacy Policy, your data, or the deletion options described in Section 6, please get in touch:
- Khush Desai
- Email: khush.desai.kol@gmail.com
- Contact form: khushdesai.com/#contact
You may also reach out through the contact section of my portfolio website, where you will find alternative ways to get in touch.