1. Scope and Acceptance
This Privacy Policy explains how ObiCalc collects, uses, stores, discloses and protects information when you use the ObiCalc mobile application, web application, website and related services (together, the App).
- ObiCalc is intended for qualified healthcare professionals and clinical teams. It is not intended for direct use by patients or children as end users.
- The App provides obstetric calculations, clinical tools, saved patient workflows, account features and optional PDF exports.
- By creating an account or using the App, you confirm that you have read this Policy and agree to the processing described here.
- If you use ObiCalc on behalf of a hospital, clinic or other organisation, you are responsible for ensuring that your use is permitted by that organisation and by applicable law.
2. Who Operates ObiCalc
ObiCalc is operated by the developer or legal operator identified in the applicable Apple App Store, Google Play and website listings (the Operator, we, us or our).
- Privacy requests: support@obicalc.com
- General support: support@obicalc.com
- Website: www.obicalc.com
- If a local law requires a specific legal address, registered entity, data representative or Data Protection Officer, those details will be provided through the official store listing, website or direct response to a lawful request.
3. Controller and Processor Roles
Because ObiCalc can store clinical information entered by healthcare professionals, different privacy roles may apply to different data.
- For account, authentication, support and app-operation data, ObiCalc acts as the data controller or business responsible for that processing.
- For patient or clinical information that you choose to enter, you or your healthcare organisation are normally the data controller. ObiCalc processes that data only to provide the App features you request.
- You are responsible for having a lawful basis, patient notice, consent or professional authority to enter and store patient information in the App.
- United States HIPAA notice: ObiCalc is not your Business Associate and does not accept Protected Health Information under HIPAA unless a separate written Business Associate Agreement has been signed. Do not store PHI in ObiCalc unless your organisation permits it and the required agreement is in place.
4. Information We Collect
We collect only the information needed to provide the App, secure accounts, save your chosen records and support the service.
- Account data: email address, Firebase user identifier, sign-in provider, email verification status and password reset state. Firebase Authentication handles passwords; we do not see or store your raw password.
- Professional profile data: first name, last name, specialty, hospital or clinic name, country, city, mobile number and optional profile photo if you add one.
- Saved patient data: patient name or initials, medical record number, mobile number, short history, selected avatar, LMP, EDD, gestational age, dating method, saved dates and calculation results that you choose to save.
- Local app data: dark mode, Hijri/date-format preferences, date-picker preference, font size, haptic setting, hospital name for PDF headers and local calculation history.
- Generated content: PDF reports that you create. PDFs are generated on your device and shared only when you choose a share or print action.
- Technical and security data: app version, device/operating system information, authentication tokens, service logs and similar operational data processed by Firebase or platform services to keep the App secure and working.
5. Sensitive Health and Clinical Data
Patient information entered into ObiCalc may be health data or special-category data under laws such as the GDPR, UK GDPR, Saudi PDPL and other healthcare privacy laws.
- We use patient and clinical data only to display, calculate, save, retrieve, export or delete the records you choose to manage in the App.
- We do not sell patient data, use it for advertising, use it for marketing, train AI models on it, or create behavioural profiles from it.
- You should enter the minimum identifying information needed for your workflow. When possible, use initials, MRN or limited identifiers instead of full patient details.
- The App does not connect to Apple HealthKit, Google Health Connect, electronic medical record systems or wearable health data sources.
6. How We Use Information
- Create, verify, authenticate and secure your account.
- Provide clinical calculators, date conversion, saved patients, local history and PDF export features.
- Sync saved patient records to your authenticated account when you choose to save them.
- Store app preferences and improve usability on your device.
- Send account-related emails such as verification and password reset messages.
- Respond to support, privacy or account-deletion requests.
- Detect, prevent and investigate abuse, security incidents, fraud or unauthorised access.
- Comply with legal obligations and enforce our rights where necessary.
7. What We Do Not Do
- We do not sell personal data or patient data.
- We do not share data with advertisers or data brokers.
- We do not use third-party advertising SDKs.
- We do not collect precise location, contacts, microphone audio, calendars or advertising identifiers.
- We do not use patient data for marketing, profiling, research, model training or unrelated analytics.
- We do not access your photo library or camera unless you choose to add or update a profile photo.
8. App Permissions
- Internet access is used for sign-in, email verification, password reset, cloud-saved patient records, profile photos and support links.
- Camera permission is requested only if you choose to take a profile photo.
- Photo/media permission is requested only if you choose a profile photo from your device gallery.
- You may deny camera or photo access; core calculation features remain available, but profile photo upload will not work.
- PDF sharing uses your device sharing/printing system. Once you share a PDF to another app, that receiving app controls its own copy under its own privacy practices.
9. Local Storage and Cloud Storage
- Local-only data includes app settings and calculation history stored on your device using platform storage. Local history is limited to recent calculation entries and can be cleared in the App.
- Cloud data includes account profile details, optional profile photo and saved patient records stored under your authenticated user account using Firebase services.
- PDFs are generated on your device. Depending on your device and share action, a temporary copy may remain in app cache, print history or the destination app until removed by the operating system or by you.
- If you uninstall the App, local data is normally removed by the operating system. Cloud account data remains until you delete it or request deletion.
10. Service Providers and Sharing
We disclose data only as needed to operate the App, comply with law, protect safety or complete actions you request.
- Google Firebase Authentication is used for account creation, sign-in, email verification and password reset.
- Google Cloud Firestore stores account profiles and saved patient records under access-controlled user paths.
- Firebase Storage stores optional profile photos if you upload one.
- Google Sign-In is used only if you choose to sign in with Google.
- Platform services from Apple, Google, Android, iOS and your device may process data necessary to run the App, send system email links, provide app distribution and support device-level permissions.
- We may disclose information if required by law, court order, regulatory request, to protect rights or safety, or in connection with a merger, acquisition or transfer of the App, subject to this Policy and applicable law.
11. International Processing
- Your information may be processed in countries other than the country where you live or practise medicine, including countries where Google, Firebase and platform providers operate infrastructure.
- Where international transfer safeguards are required, we rely on provider data-processing terms, contractual protections, Standard Contractual Clauses or other lawful transfer mechanisms as applicable.
12. Security Safeguards
- Data is transmitted over encrypted connections using TLS where supported by the platform and service provider.
- Firebase services provide encryption at rest and managed infrastructure security controls.
- Saved patient records are stored under authenticated user paths and are intended to be accessible only to the signed-in account that created them.
- Passwords are handled by Firebase Authentication and are not stored by ObiCalc in readable form.
- You are responsible for keeping your device, email account, App account and device lock secure. Do not share your credentials.
- No electronic system is completely secure. We cannot guarantee absolute security, but we take reasonable technical and organisational measures to protect the data we process.
13. Retention and Deletion
- Account and profile data are retained while your account remains active, unless deletion is required earlier by law or requested by you.
- Saved patient records remain until you delete them, delete your account, or they are removed by app logic after the pregnancy record becomes expired based on the stored LMP timeline.
- Local calculation history is limited to a maximum number of recent entries and remains on your device until cleared, overwritten, or removed by uninstalling the App.
- When you delete your account in the App, ObiCalc attempts to delete your user profile, saved patient records, profile photo and Firebase Authentication account. Some deletion may require recent sign-in for security.
- Backups, logs and residual copies may persist for a limited period according to provider backup and security-retention cycles before being overwritten or deleted.
- We may retain limited records where necessary to comply with law, resolve disputes, prevent abuse, enforce agreements or protect legal rights.
14. Your Rights and Choices
Depending on your location, you may have legal rights over your personal data. These rights may include:
- Access: request a copy of personal data we control about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Deletion: delete records in the App, delete your account, or request deletion by contacting us.
- Restriction or objection: ask us to restrict or stop certain processing where the law allows.
- Portability: request a portable copy of data we control, where technically feasible and legally required.
- Withdraw consent: withdraw consent where processing is based on consent. Withdrawal does not affect processing already completed before withdrawal.
- California rights: residents may have rights to know, delete, correct and opt out of sale or sharing. ObiCalc does not sell or share personal information for cross-context behavioural advertising.
- Saudi PDPL and other local rights: you may have rights to know, access, correct, complete, update, delete or withdraw consent subject to applicable law.
- To exercise rights, contact support@obicalc.com. We may need to verify your identity before responding.
15. Account Deletion
ObiCalc provides a public account deletion page at Delete Your ObiCalc Account. This page is intended for users and app-store reviewers and explains how to request deletion, what data is deleted, what data may be retained, and the retention period.
- You can request deletion inside the App from My Account by choosing Delete account.
- You may also request account deletion by emailing support@obicalc.com from the email address linked to your account.
- Deletion is permanent and may remove saved patient records, profile information and profile photo. Export anything you are legally allowed and required to keep before deleting.
- If deletion fails because your authentication session is stale, sign out, sign in again and repeat the deletion request, or contact support.
16. Professional Responsibilities
- You must comply with professional confidentiality duties, hospital policies and applicable laws before entering patient information into ObiCalc.
- You must not enter information you are not authorised to process.
- You must not use ObiCalc as the sole medical record, legal medical chart or emergency communication system.
- You must review all calculations, dates and exported PDFs before relying on them clinically or sharing them.
- If your organisation prohibits third-party cloud storage of patient data, do not save patient records in ObiCalc.
17. Children and Minors
- ObiCalc is not directed to children as users and is intended for professional users only.
- Clinical users may enter patient data relating to fetuses, newborns, adolescents or other minors only where they have legal and professional authority to do so.
- If we learn that a child has created an account as an end user without proper authority, we will take reasonable steps to delete that account.
18. Store Privacy Disclosures
Apple App Privacy and Google Play Data Safety disclosures must match this Policy and the App behaviour. Based on the current App design, the following categories may need to be disclosed in store forms:
- Personal information linked to the user: name, email address, phone number, hospital/clinic details, country, city, specialty and profile photo if provided.
- Health or medical information linked to the user account when a clinician chooses to save patient records or clinical calculation results.
- User content: PDF reports and saved clinical notes/history that the user creates or enters.
- App activity or app information: local settings, calculation history and app interactions needed to provide features.
- Diagnostics or technical data processed by Firebase or platform services for security, authentication, crash prevention or service operation.
- Data is not used for third-party advertising and is not sold. Store submissions should not claim that no health data is collected if saved patient features are enabled.
19. Legal Bases Where Required
Where GDPR, UK GDPR or similar laws apply, our legal bases may include:
- Contract: to provide the App and account features you request.
- Legitimate interests: to secure, maintain, troubleshoot and improve the App, prevent misuse and respond to support requests.
- Consent: where you choose optional features such as profile photo upload or where consent is otherwise required.
- Legal obligation: where we must comply with applicable law.
- For patient health data, the lawful basis is primarily determined by you or your healthcare organisation as controller, such as healthcare provision, professional obligation, patient consent or another permitted basis under local law.
20. Breach and Incident Response
- We maintain procedures to assess suspected security incidents involving personal data under our control.
- Where a personal data breach is likely to create a legally notifiable risk, we will notify affected users and/or regulators as required by applicable law.
- If you believe your account or device has been compromised, contact us promptly and change your account credentials where applicable.
21. Changes to This Policy
- We may update this Policy when the App, law, service providers or store requirements change.
- Material changes will be communicated through the App, website, email or store listing where appropriate.
- The effective date shows when this Policy was last updated. Continued use of the App after an update means you accept the updated Policy.
22. Contact
- Privacy requests: support@obicalc.com
- Support: support@obicalc.com
- Website: www.obicalc.com
- If email delivery is unavailable, use the support contact listed in the official app store listing or website.
Privacy disclosure, not legal or medical advice
This Policy is a privacy disclosure, not legal or medical advice. ObiCalc supports professional clinical judgement; it does not replace clinical assessment, local protocols or legal compliance obligations.