one2family Privacy Policy

Last updated: August 3, 2026

This policy describes how one2family ("we", "our", "the app") handles information when you use our mobile application and related services.

What we collect

We process information you enter, including family profiles, health records, documents, appointments, insurance details, and sharing preferences. We also process account and security information needed to sign you in and protect your account.

How information is stored

Depending on the feature and configuration, information may be stored on your device and transmitted to the one2family backend or configured Firebase services. Authentication tokens are stored using secure platform storage.

How information is used

Information is used to provide family health organization, search, reminders, reports, sharing, and AI-assisted features that you request. one2family does not intentionally sell personal health information.

AI-assisted features and service providers

A. one2AI (OpenAI API services)

When you use one2AI features, relevant context is sent from the one2family backend to OpenAI API services to generate explanations and summaries from health information you have saved or confirmed in the app.

What may be sent for one2AI features you request: your question or instruction; minimum necessary confirmed health-record context for authorized family member(s); capability and safety metadata; a hashed abuse-prevention identifier (not your raw account id).

What is not intended for ordinary one2AI use: your entire family vault by default, or raw document files when confirmed structured records are sufficient.

B. Cloud document recovery (Google Cloud / Vertex AI — MedGemma)

When you upload a health document, one2family first uses on-device or local processing (including OCR). If local extraction is insufficient, you may be offered optional cloud document recovery after an in-app disclosure. If you continue, document text or page images may be sent to Google Cloud / Vertex AI (MedGemma). Recovery produces proposed fields only — nothing is saved until you review and confirm.

Third-party processing: OpenAI and Google Cloud may process data on our behalf when you invoke these features. Whether a provider qualifies as a "service provider" under Google Play Data Safety definitions must be confirmed before Play Console submission.

We apply automated scrubbing intended to remove common identifiers before AI calls where feasible. Clinical content may still be included when required to answer your request or suggest extraction fields for your review.

Analytics, crash reporting, and AI telemetry

Analytics and AI telemetry are designed to record metadata (feature, tokens, latency, hashed identifiers), not full documents or full chat transcripts. Short-lived backend caches of AI responses may exist for reliability and are subject to retention limits.

Retention and deletion

Health records follow in-app delete/restore and account support paths where available. OpenAI processes prompts under its API terms and our project retention settings (including requesting that responses not be stored for training where supported). Contact support for account help.

Sharing and consent

Records are shared only through an action you initiate or a permission you grant. Family role and permission checks apply before AI context is assembled for another member's records.

Your choices

You may review permissions, export or delete data where the feature is available, and contact support for account help.

Contact

For privacy questions, contact privacy@familyos.app or one2ai.ideations@gmail.com.