PayungMed Privacy Policy
If the service closes
If we ever do shut down, you get 90 days' notice and export keeps working for the whole period.
Export is not a courtesy that depends on your account being in good standing. It does not require a subscription, it does not stop working when a subscription lapses, and it does not need a connection to our servers: the appointments and the card photographs on your phone are the copy that matters, and the export is assembled from them. That is what makes the 90 days above a fact rather than a promise about our future intentions.
One limit, stated here rather than discovered at the worst moment. An export carries the people you manage. Appointments that someone else shared with you are theirs, and they are not in your file — the person who owns them can export them, and you cannot.
What the service can read
Reading the card happens on your phone. The text recognition runs on the device, offline — on Android using a model that ships inside the app, and on iPhone using the text recognition built into iOS itself. The photograph is not sent anywhere to be read, and this works with no signal at the hospital.
What we hold on our servers is the appointment — the date and time, the facility, the department, the purpose if the card gave one, whether fasting is needed, and which family member is taking her — the photograph of the card, and the name you gave her. Alongside those we hold the shape of your care circle: who has been invited, who accepted, who has been removed and when. And the technical rows that make the app work on more than one phone: the delivery address for notifications on each device, and a pointer to your subscription.
All of it is encrypted at rest on our servers, and encrypted in transit. It is not end-to-end encrypted, and we are not going to let the word "encrypted" do work it isn't doing. We looked at building it that way and decided against it. So an engineer with production access could, in principle, open your mother's card photograph.
On the connection itself we will give you the floor rather than the best case: nothing weaker than TLS 1.2 is accepted, and most connections negotiate higher. We are not going to print a bigger number than we can hold ourselves to.
What limits that in practice is not a promise. Every read of personal data held on our servers goes through a single path that writes a record of the access — who, what, when — before the data is returned. If that record cannot be written, the read fails and the data is discarded rather than handed over. Looking at your mother's card is an accountable act, not a routine one.
That covers data held on our servers, and we would rather be exact about the edge. When you export, the app assembles the file from the copy already on your phone; it does not ask our servers for anything, so there is no access to record.
And three internal lookups are not recorded, which we would rather name than let you discover. Checking whether an invitation code is valid, matching a store receipt to an account, and checking whether a care-circle member is still allowed to see a profile. None of them returns an appointment or a photograph — but the first one does reveal which profile a code belongs to and who owns it, and it is not written to the access log. We are telling you because "every access is recorded" would be the easier sentence and it would not be true.
We hold the name you give each person you track. When you type your mother's name into the app, it is stored with her appointments on our servers in Malaysia, and protected the same way as everything above. That is how the name reaches your other phones, and how the people you share her with come to see it — the section on sharing says more. Deleting your account deletes it, as the last section sets out.
The names you type for other people using the app stay on your phone. The name you put on an invitation, and the name you give someone who shared a schedule with you, never reach us.
The note you write for yourself
The note attached to an appointment is different from everything above, and it is worth saying twice.
It never reaches us. It is not merely excluded by policy — the format our app uses to send an appointment has no place to put it, so a copy of the app that tried to send one would be refused. There is no note in our database, none in our logs, and none in any diagnostic record. It is the one thing about your mother's care that we could not produce if we were asked for it.
The other side of that is the limitation, and it is a real one. Because the note never leaves the phone, we cannot put it back. If the phone is lost, replaced or wiped, the appointments and the photographs return when you sign in on the new one, for the people your plan covers — and the notes do not. They are gone. The names of the people you track come back with their appointments, but the names you typed for other people using the app stay on the old phone: you type those in again.
One more place your data could have gone. Your phone's own backup is not ours.
We keep this app out of your phone's automatic backup, on both iPhone and Android. The app's database and the card photographs are left out of it, so a note does not reach Apple or Google. You do not have to switch this on. On Android the rule is built into the app itself; on iPhone the app applies it again every time it starts.
The flip side is the limitation above, arriving from the other direction. Replacing a phone does not bring your notes back — not from us, because we never had them, and not from your backup, because we keep them out of it. The appointments and the card photographs do come back when you sign in on the new phone, for the people your plan covers, because those are on our servers. The notes are not, anywhere.
Where your data is held
Malaysia. Specifically AWS's Kuala Lumpur region, ap-southeast-5 — the database, the card
photographs, the sign-in directory and the access records all live there and are not copied to a
server anywhere else.
There are six exceptions, they are the only six, and each one is here because the product cannot work without it. Anything beyond these would be a defect rather than a policy.
1. Notifications. To tell your sister that something changed, we hand a message to Apple or Google, who deliver it to her phone. That means the delivery token for her device leaves the country, and so does the text of the notification. So the notification says almost nothing: a short line like "Someone updated an appointment escort", with no name, no clinic, no department and no date. The detail arrives only after her app fetches it from our servers in Malaysia.
Your appointment reminders are a different thing, and they are not this. They are prepared by the app on your own phone and never pass through us or through Apple and Google — which is why they still arrive with no signal. But they are also the ones that say something: the person's name, what the visit is for, the time, and the photograph of the card. That appears on your lock screen, where whoever is holding your phone can read it. You can turn reminders off, and if the phone is shared that is worth thinking about.
2. Checking a subscription is real. When you subscribe, we ask Apple or Google whether the purchase is genuine. We send them the identifier their own store issued and nothing else — no email address, no name, no appointment. At the moment of purchase your device also gives the store a scrambled, one-way version of your account identifier, so a refund or a renewal can be matched back to the right account.
3. Crash reports. If we add crash reporting, what may leave is the type of error and the lines of program code it happened in, with the error text itself removed — because an error's text can quote the data that caused it. Today the app sends no crash reports at all. This is written here as a permission with a boundary rather than a description of something happening, so that adding it later does not quietly widen what we told you.
4. Adding an appointment to your own calendar. If you turn on calendar integration and choose an appointment, the app writes it into the calendar on your phone: the person's name, what the visit is for, the time and the clinic. The app adds it to a calendar that syncs to a Google or iCloud account whenever your phone has one, so the appointment goes there too. This is the exception that carries the most, it happens only when you ask for it one appointment at a time, and it is yours rather than ours: our servers send nothing and never see your calendar. Turning it off stops new appointments being added; the ones already there stay.
And one thing about the calendar permission itself. When you turn calendar integration on, the phone asks you for calendar access, and the prompt you see grants read as well as write. An iPhone can offer a write-only version of that prompt; we do not use it, because the way this app finds the calendar to add an appointment to only works with full access — asking for less would mean the feature simply does not work. The app never reads your calendar: the only calendar operation it has is "add this appointment", and there is no code anywhere in it that can list or open an event. But the permission you are granting is wider than what we use, and you should hear that from us rather than from the prompt.
5. The email that sends you a code. When you create an account, or ask to reset your password, the app sends a code to your email address for you to enter. Our sign-in directory is in Malaysia, but Amazon's email service is not offered in that region, so the message is delivered through Amazon's email service in Sydney, Australia. What passes through is your email address and the code, in both languages. Nothing else: no name, no appointment, no photograph.
6. Ending Sign in with Apple when you delete your account. Apple expects every app that offers Sign in with Apple to end that link when an account is deleted. So when you delete your account on an iPhone you signed in on with Apple, the app asks you to confirm with Apple, which gives it a one-time code. Our servers send that code to Apple, and then the sign-in token Apple gives back for it, so that Apple can end PayungMed's link to your Apple ID. Nothing else about you goes with them: no name, no email address, no appointment, no photograph. If the link is not ended this way — for example because you deleted your account on another phone — the app tells you how to end it yourself in your iPhone's settings.
Two smaller things, for completeness. The web address our sign-in page uses is registered outside Malaysia, as that kind of registration has to be — it holds no personal data, only the address itself and its certificate. And our servers keep short-lived technical logs of requests: the network address your phone connected from, alongside the identifier of the signed-in account, which means those two are linked in the log. Those are separate from the access records above, and are discarded on a fixed schedule, set out in the last section.
And one you choose. If you sign in with Google or Apple, that company learns that you use PayungMed and which email address you use for it. That is between you and them, it carries no appointment, and signing in with an email address instead avoids it.
And one more you choose: writing to us. Email sent to support@payungmed.my is passed on by Cloudflare, which handles email for our web address, to a Gmail mailbox, where we read it and reply. Neither company is part of our service in Malaysia, and we cannot promise that your email stays in Malaysia while it is with them. So leave out an appointment's details, card photographs and passwords. How long we keep your email is set out in the last section.
Sharing with a care circle, and taking it back
When you add someone to a care circle, they see the appointments and card photographs for the person you shared, on their own phone, in their own copy of the app.
They also see the name you gave that person. That includes people you shared with before we began keeping names. If one of them had typed their own name for that person, the name you give replaces it. The name they type for you, on the other hand, stays on their phone.
The app only points out that two people have appointments on the same day when it can see both of them. It compares only what is on your phone. So if a person you cannot see has an appointment on the same day, the app has nothing to compare it with, and you will not be told.
You can remove someone at any time. From that moment they stop receiving anything new — no new appointments, no new photographs, no new reminders. It is not quite instant: for a short window after you remove them, a request already in flight may still be answered, and we would rather say so than claim a sharpness we do not have.
What we cannot do is reach into their phone. Appointments and photographs that already reached it stay there. We have no way to remove them, and we are not going to pretend otherwise — that would be true of any app that lets you see something while you are offline, and it is true here. Their own copy of the app tidies up what it can when it next runs, but that is their phone doing it, not us, and you should not count on it.
Removing someone is recorded in the same access log as everything else.
We will not tell you that access can be withdrawn at any time. It is the sentence everyone writes and it is not true. What is true is the paragraph above: future delivery stops, and what has already arrived has arrived. Families fall out, and you should know that before you need to know it.
How long things are kept
We keep your appointments and your card photographs for as long as your account exists. There is no expiry date on them.
We keep your card photographs for as long as your account exists. Moving to the free plan does not delete them, and nothing is removed because of its age.
Stopping paying does not delete anything. If you were on the Family Plan and you stop — because the person you were caring for died, or because you no longer need it — your appointments and their photographs stay where they are. You keep reading them. You keep exporting them. We are saying this plainly because the opposite is common enough that you were right to wonder.
Nothing is deleted for being old. We do not run a clock on your mother's appointment card.
What does remove a photograph, and it is only these two things: deleting the appointment it belongs to, and deleting your account. Either way the photograph is deleted from our storage, and the phone you do it on removes its copy. Your other phones, and the phones of anyone you share that person with, remove theirs when their app next catches up with our servers. That is those phones doing it, not us reaching into them, and we cannot promise it: a phone that never connects again keeps what it has.
Deleting an appointment does not remove every trace of it. The photograph goes, and so do the details — the date and time, the facility, the department, the purpose, whether fasting was needed and who was taking them. What stays is a record that an appointment was deleted, and when, because that is how your other phones and your care circle learn to stop showing it. Nothing in the app shows that record. Our backups keep the older version for up to 35 days before they age out, so the details are not gone from everywhere the moment you delete.
About stray files, and what we are not yet doing. If a photograph ever ends up in our storage with no appointment pointing at it, it is a stray file rather than something you are keeping. A job runs every day and finds those. Today it reports them and does not delete them. We would rather write that down than claim a tidying-up we are not actually doing. It removes nothing you can see, and nothing that any appointment of yours still points at.
Deleting your account. You can delete your account in the app: open Settings, then Account, then Delete account. If you no longer have the app, or cannot sign in, you can ask by email at support@payungmed.my; how to do that is set out at https://payungmed.my/delete-account. Nothing can be brought back afterwards, so export first if you want to keep a copy.
What deleting your account removes. Your account, and every person you track with it, together with their appointments, the names you gave them and their card photographs. The addresses we use to send notifications to your phones. And your place in care circles, in both directions: the people you shared with stop seeing what you shared, and you leave every circle you joined. If you signed in with Apple, we also ask Apple to end PayungMed's link to your Apple ID, as the section on where your data is held describes. The phone you delete from is cleared of everything on it, including anything someone else using that phone had saved there. The app on your other phones clears itself and signs out if it reaches our servers while its sign-in is still valid, which is at most an hour after the deletion. A phone that does not is signed out when it is next opened, but keeps what it already holds until the app is removed from it. Appointments you had added to your phone's own calendar stay there, and what other people's phones already show is covered in the section on sharing.
Deleting your account does not cancel a subscription. The store that sold you the Family Plan keeps charging until you cancel it there, and the app cannot cancel it for you. A subscription cannot move to a new account either.
What we keep after an account is deleted, and for how long.
- Access records, permanently. These are the records of who looked at what, and when, described earlier. They hold identifiers, the kind of access and the time — never a name, an email address, an appointment's details or a photograph.
- A record that the account was deleted, permanently. It holds the account's identifier and when the deletion was asked for and finished. It is what stops a phone still signed in to the old account from putting anything back.
- A record that each person you tracked was removed, permanently. It holds the identifier we gave that person's schedule and when it was removed — never a name. It is what stops a phone that still holds the old schedule from putting it back, under any account.
- Our database backups, for up to 35 days. They exist so the service can be recovered after a failure, and until they age out they hold what the database held, including names and appointments.
- The logs of our photograph storage, for 90 days. Each line names a stored file, and a file's name includes the account's identifier. They hold no photograph.
- Our servers' request logs, for up to 30 days. They link the account's identifier to the network address a phone connected from, as described earlier.
- Our cloud provider's own records of the requests we make to it, for up to 90 days. Amazon Web Services keeps them, and some carry the account's identifier.
- Your identifier in someone else's records, for as long as they keep them. If you were in another person's care circle and they removed you, or you were chosen as the family member taking someone to one of their appointments, their records keep your account's identifier. Never your name or your email address.
- What Apple and Google keep about a purchase, under their own policies rather than ours.
Emails to support. If you write to support@payungmed.my, including to ask for your account to be deleted, we delete your email and our reply within 30 days of dealing with your request. Our support page is at https://payungmed.my/support.
If we ever start removing anything you have not asked us to remove, you will be told before it happens, and with enough time to export first. Export is in Settings, it includes every photograph on your phone, and it has never been locked behind a plan. We would not start removing things and mention it afterwards.