Back to CardioTrack

Privacy Notice

Draft last updated August 30, 2026. This is not legal advice.

Who is the data controller

The data controller for CardioTrack is Dawood Togoo (sole operator), based in Doha, Qatar. Privacy questions, individuals' rights requests, and data breach reports should be sent to contact@cardiotrack.org (also the contact for the designated Privacy Officer, Dawood Togoo).

What data the app may store on this device

Profile information you enter (name, age, sex, country, optional ethnicity), height, weight, blood pressure, heart rate, SpO₂, sleep, steps, medications and dose history, symptoms, documents you upload, lab results, source labels, risk-score inputs and snapshots, family-history entries, alerts, and a privacy audit log.

Health and special-category data

Health data and ethnicity are special-category personal data under Qatar Law No. 13 of 2016 (PDPPL Article 16) and equivalent provisions in GDPR Article 9. The app processes these only on the basis of your explicit consent, captured at onboarding and revocable in Settings → Privacy choices.

How data is used

Data is used to provide the in-app tracking, charts with source labels, risk calculations, medication safety rules, your own exports, and the audit log. If you turn on account backup it is also used to restore your records when you reinstall or sign in on another device, and if you opt in to research the ticked categories are used in pseudonymised form for cardiovascular research. The app does not sell data, does not use data for advertising or marketing, does not use it to train models, and does not perform automated decision-making with legal effect. The cardiovascular risk calculators (e.g. AHA PREVENT 2024, SCORE2, QRISK3) are deterministic published equations, not AI/ML systems, and are presented for educational use only.

Where data is stored

By default every CardioTrack record stays on this device: browser localStorage on the web, the app sandbox on iOS and Android. Clearing browser data, uninstalling the app, or using another device removes or hides those records. Three optional features, each off until you turn it on, place data outside this device. First, 'Account backup and multi-device sync' in Settings → Privacy choices writes a copy of your records to a single private row in our Supabase Postgres database, keyed to your user ID and readable only by your own account under row-level security. Second, research contribution uploads pseudonymised numeric values for the categories you tick. Third, 'Try cloud OCR' sends one lab-report PDF for text extraction, and only when you ask for it on that specific report. Your authentication tokens and your research pseudonym are never included in the backup copy. Turning a setting off stops the corresponding processing immediately.

Processors and any data sharing

CardioTrack does not sell your data, does not share it with advertisers or data brokers, and does not use it for advertising, marketing, or model training. There is no third-party analytics or advertising SDK in the app. The processors that may handle data on our behalf are: our hosting provider, which serves the web app and the static bundle; Supabase, which provides authentication for all accounts and, only if you turn on account backup or opt in to research, stores that data; Microsoft Azure Document Intelligence, which performs one-shot text extraction for a specific lab report you explicitly choose to send; and Apple's App Store / TestFlight and Google Play, which distribute the app binary. Text recognition on a document you import runs on your own device using a bundled open-source engine (tesseract), so the image and the text read from it never leave the device on that path. Your operating system platform (Apple Health on iOS, Health Connect on Android) keeps its data on the device. Apple and Google never receive your tracked health data.

Cross-border data transfers

If you keep everything local, no cross-border transfer of your tracked health data occurs. Signing in transfers your account identity (email address and a stable user identifier) to Supabase, whose servers are outside Qatar; the 'Online account' consent covers exactly that and nothing more. Turning on account backup, opting in to a research category, or using cloud OCR transfers the corresponding health data outside Qatar, and each of those has its own separate consent under PDPPL Articles 16 and 17. Hosting and app-distribution providers may also operate outside Qatar and receive only network metadata (IP, user-agent).

Retention

On-device data is retained until you delete it; there are no automatic-deletion timers, because that data is under your direct control. If account backup is on, the server copy is retained until you turn the setting off, delete the records, or delete your account. Settings → Account → Delete account permanently removes your account and its stored row and erases the on-device data; you are asked to type DELETE to confirm. The encrypted cross-device transfer payload expires automatically after 24 hours. Pseudonymised research rows carry no link back to your account, so they cannot be individually withdrawn once uploaded; revoking a research consent stops any further upload.

Your rights

You can: (1) access - every record is visible in the app and exportable as JSON or CSV via Settings → Export my data; (2) rectify - edit medications and onboarding details directly; (3) erase - Settings → Delete all my data clears every entry, or use clearAll-equivalent per-entity controls; (4) object / withdraw consent - Settings → Privacy choices toggles each consent and offers a 'Withdraw all' action; (5) portability - the JSON / CSV export is machine-readable; (6) lodge a complaint with the Qatar National Data Privacy Office (NDPO).

Security

On iOS, app data is sandboxed and protected by the platform's Data Protection class when the device is locked. On Android, app data sits in the per-app sandbox protected by Health Connect / OS controls. On web, browser localStorage is not encrypted at rest - for highly sensitive use, prefer the iOS or Android app. The app uses HTTPS for all network requests. Where a server copy exists, because you turned on account backup or opted in to research, it is encrypted in transit and at rest, and access is restricted by Postgres row-level security so that a signed-in user can read and write only the row matching their own user ID. The cross-device transfer feature encrypts its payload on your device with AES-GCM under a key derived from a passphrase you choose, so that blob is not readable by the server at all.

Children

CardioTrack is intended for adults 18 and over. Onboarding asks you to confirm you are 18+. The app does not knowingly process data from minors. If you become aware that a minor has used the app, contact the privacy officer to have data erased.

Changes to this notice

This notice is reviewed at least annually and on any material change to the app's data handling. The current version date is shown above. When the consent-statement version changes, you will be asked to re-confirm consent on next launch.

Legal review status

This notice is maintained by the operator and is kept in step with what the app actually does; it was last reconciled against the shipping build on the date shown above. It has not yet been reviewed by a Qatar-qualified privacy lawyer, and such a review remains outstanding for both this notice and the Terms of Service.