Privacy policy
What Clinilog knows about you.
Last updated 13 August 2026
Applies to the Clinilog apps for Android
(com.mishtik.health_tracker) and iOS
(com.mishtik.clinilog)
Clinilog is a symptom diary. What you put in it is medical information about you, and the whole app is built on the assumption that it should never be seen by anyone you have not personally invited. This page describes exactly what is stored, where it goes, and who can reach it.
What Clinilog stores
Your account
You sign in with Google, or on iPhone with Apple. Clinilog never sees or handles your password — the provider authenticates you and hands the app a user ID. Against that ID the app stores your display name, your email address and, where the provider supplies one, the URL of your profile picture, so that a profile has a name to show in the switcher when it is shared with someone.
If you use Sign in with Apple and choose to hide your
address, what Clinilog receives and stores is the
@privaterelay.appleid.com address Apple generates — your
real one is never sent to the app. Apple also supplies your name only
on the very first sign-in, so a name you decline there stays absent.
Your check-ins
Each check-in is one record holding the date and which of your daily slots it belongs to, the time that slot was due, the time you actually saved it, and whether it was filled in late. Alongside that are your answers: whether you had a fever and the temperature you entered, whether you had pain and the 1–10 score for each area, which body areas had a rash and whether each itched or hurt, and your fatigue score. A free-text note is stored if you write one — whatever you type there is stored exactly as typed.
A "no" answer is stored as a no, rather than left out, so a question that was asked and answered can be told apart from one that was never asked. Missed check-ins are not stored at all — a missed slot is simply the absence of a record.
Photos
If you attach a photo to a check-in, the image itself is compressed and stored with the check-in it belongs to, along with its size, a category and its creation date. Photos are deleted automatically 60 days after they are taken. Deletion runs within about a day of expiry, and the app filters expired photos when reading, so one is never shown past its date.
Sharing
If you invite someone to view your records, an invitation is stored containing your name and email and the email address you typed. When they accept, that becomes a share record holding both parties' names, emails and user IDs. This is what lets each of you see the share in your own app and revoke it.
Kept only on your phone
Your reminder times, the symptoms you have chosen to track and your medicine list are stored on the device — the phone that shows the notification owns the schedule. A copy of them is mirrored to your own account so that someone you share with can read your check-ins against your questions and your times rather than theirs; it is covered by the same access rules as everything else, and goes when your account goes. Reminders themselves are local alarms: nothing is pushed from a server, and no notification content leaves your device.
If you support the app
Clinilog is free, and the optional supporter purchases unlock nothing. They are handled entirely by the App Store or Google Play — Clinilog never sees or stores your card, your billing address or your store account. The only trace inside the app is a yes/no flag on the device that shows a thank-you note. Nothing about a purchase is written to your health records.
What Clinilog does not do
- No advertising. There are no ads and no advertising SDKs in the app.
- No analytics or tracking. The app contains no analytics, crash-reporting or attribution SDK. Your behaviour in the app is not measured, profiled or reported anywhere.
- Nothing is sold or shared for marketing. Your data is never sold, rented, brokered, or handed to anyone for advertising or any other commercial purpose.
- No public access. There is no link, ID or URL that exposes your records publicly. There is no public read path to any record in the system.
- No password. Sign-in is Google's or Apple's, so the app never receives, stores or transmits a password.
Where the data lives
Records are stored in Google Cloud Firestore in the asia-south1 region (Mumbai, India), inside a Firebase project controlled solely by Clinilog's developer. Google acts as the infrastructure provider — it processes and stores the data on Clinilog's behalf under its own security and privacy terms, and Google's operation of that infrastructure involves its own operational logging, which is outside Clinilog's control.
Data in transit is encrypted with TLS, and encrypted at rest by Google Cloud.
Who can see your records
Access is enforced on the server, not in the app, so a modified or malicious client cannot talk its way past it. The rules allow exactly two things:
- You — the signed-in owner of a record — can read and write it.
- Someone you have invited and who has accepted can read it, and only for as long as that share exists. They can never edit, add or delete anything, and viewing your records does not put your reminders on their phone.
Removing someone cuts off their access immediately and drops your profile from their app. Sign-in additionally requires a verified email address, so access can never be gained by claiming an address you do not control.
The doctor's report
The PDF report is generated on your phone and shared through the normal share sheet. Clinilog does not upload it anywhere and keeps no copy of it. Once you send it — over WhatsApp, email, print or anything else — it is outside Clinilog's control, and the privacy policy of whatever app or service you chose applies to it from that point on.
How long things are kept
- Photos: deleted automatically 60 days after capture. No action needed from you.
- Check-ins, profile and shares: kept until they are deleted. Symptom history is only useful over months, so nothing is removed on a timer.
You can delete everything yourself, from inside the app: menu → Settings → Delete account. Nothing is queued for review and no email is involved — the app asks you to confirm, asks your sign-in provider to prove it is really you, and then erases your check-ins, photos, medicines, schedule, profile, invitations and shares along with the login itself. It is immediate and cannot be undone. The account deletion page lists exactly what goes and what cannot, and is the route to take if you can no longer sign in.
On iPhone, deleting the account also tells Apple to revoke Clinilog's Sign in with Apple token, so the app stops appearing under Apps Using Apple ID. You can revoke access yourself at any time — Google account permissions, or Settings → your name → Sign in with Apple on an iPhone — which stops further sign-in but does not delete anything already recorded.
Your choices
- Revoke any share, at any time, from within the app.
- Decline or cancel an invitation before it is accepted.
- Leave the note field, the temperature field and photos empty — every one of them is optional.
- Delete your account and everything in it from Settings inside the app, at any time, without asking anyone.
- Request a copy of your data, or delete your account by email if you can no longer sign in.
Children
Clinilog is not directed at children and is not intended for use by anyone under 13. It does not knowingly collect data from them. If a child's records have been entered, email the address below and they will be removed.
Changes to this policy
If what the app stores or who can reach it changes, this page changes with it and the date at the top is updated. Material changes — anything that widens who can see your records or what is collected — will be called out in the app's release notes, not only here.
Contact
Questions about this policy, or a request about your data: support@mishtik.com. Clinilog is built and operated by Prateek Grover, who is the data controller for the records described above.