Privacy Policy

Last Updated: August 26, 2026

PathLab Pro ("we", "us", or "our") operates the PathLab Pro mobile application (the "App"). We are committed to protecting the privacy and security of clinical, patient, and user data. This Privacy Policy details how we collect, use, process, and secure user information in compliance with Google Play Developer Policies and applicable data protection regulations.

1. Information We Collect and Process

To provide laboratory ERP, diagnostic record-keeping, and report generation services, the App collects and processes the following categories of data:

A. Authentication & Account Data

  • Google & Firebase Account Info: When logging in via Google Sign-In or Firebase Auth, we collect your email address, display name, and unique Firebase UID to identify your user account and associate you with your specific Laboratory/Institute.

B. Laboratory Operational Data

  • Patient Records: Full name, age, gender, contact number, email address, pregnancy status, blood group, and diagnostic sample numbers.
  • Report Details: Observation values, referral doctor details, laboratory technician signatures, and clinical notes/interpretations.
  • Referring Physicians: Doctor names, qualifications, genders, and commission percentages.

C. Device Identifiers

  • Device UUID: The App generates a persistent, installation-specific unique identifier (stored locally on the device) used to construct conflict-free prefixes. This prefix prevents sequence overlaps and duplicate report numbers when multiple devices operate offline. We do not track location or capture hardware serial numbers.

2. How We Use Your Information

We process collected data solely for the following purposes:

  • To authenticate and authorize laboratory technicians and administrators.
  • To generate, format, and export patient diagnostics and PDF laboratory reports.
  • To sync records between the device's local Room SQLite database and Cloud Firestore.
  • To maintain sequence tracking, sample codes, and prevent invoice number collisions across devices.
  • To auto-calculate laboratory billing, discounts, payments, and referring doctor commission details.

3. Permissions We Request

The App requests the following system permissions to perform its core functionalities:

  • Internet Access: Required to synchronize database records with Cloud Firestore.
  • Read/Write Storage: Required to generate and save patient PDF reports to the device's local storage and to select laboratory logos for PDF branding.

4. Data Storage, Synchronization, and Security

We apply high-security standards to safeguard sensitive diagnostic and patient data:

  • Local Storage Encryption: The App stores local user preferences and sync cursors inside EncryptedSharedPreferences using AES256-GCM encryption, and offline laboratory records inside a SQLCipher AES-256 encrypted SQLite database.
  • Offline Database: Offline records are managed in an encrypted Room SQLite database. If a database is found to be corrupted or undecryptable, the App safely resets it and triggers a fresh synchronization from Firestore to protect data integrity.
  • Firestore Transit: All communication between the App and Firebase servers is encrypted in transit using Secure Sockets Layer (SSL/TLS 1.3) protocols and Play Integrity verification.
  • Backup & Export: Users can manually export database files and PDFs to their personal Google Drive or local directories. We do not upload backups to third-party servers.

5. Data Sharing, Advertising & Mediation Networks

We do not sell, trade, or rent patient diagnostic details or technician identities to third parties. All clinical laboratory data remains strictly within your laboratory's private Firebase instance and local device storage.

To support free features or serve relevant advertising, the App integrates Google Mobile Ads (AdMob) along with mediation partner networks. These third-party networks may collect non-sensitive device identifiers (such as Advertising ID) strictly for ad delivery and fraud prevention:

6. Compliance with India's DPDP Act 2023 & EU GDPR

PathLab Pro strictly adheres to India's Digital Personal Data Protection (DPDP) Act 2023, the General Data Protection Regulation (EU GDPR), and global data privacy standards. As a Data Principal / User, you enjoy the following statutory rights:

  • Right to Access & Summary: Users can view all stored personal records, lab settings, and diagnostic data directly within the App at any time.
  • Right to Correction & Erasure: Laboratory administrators can edit or permanently delete patient profiles, test entries, and account data from local storage and Cloud Firestore.
  • Right to Withdraw Consent: Explicit consent provided upon app launch/login can be managed or withdrawn by requesting complete account termination.
  • Right of Grievance Redressal: Data Principals have the statutory right to seek redressal for any data processing concerns through our designated Grievance Officer.

7. Data Deletion and Retention Rights

In compliance with Google Play Console policies and DPDP 2023 regarding user control over their data:

  • Retention: We retain patient records and laboratory reports as long as your Laboratory account remains active or as required by clinical retention laws.
  • Deletions: Account administrators can delete individual patient records, referring doctors, and diagnostic reports directly from the App dashboard, which immediately propagates deletions to Cloud Firestore.
  • Account Terminations: If you wish to permanently delete your Laboratory account, Firebase Auth profile, and all associated Firestore data, you can request a complete data wipe by contacting our support team at [email protected].

8. Children's Privacy

PathLab Pro is designed for medical laboratories and adult practitioners. We do not knowingly collect personal information directly from children under 18 years of age. Patient records of minors may only be entered into the App by authorized clinical professionals with parent or guardian consent.

9. Cookies and Website Storage

This section covers this website (including the report page a patient reaches by scanning the QR code printed on a report), not the Android app. It is written to satisfy the EU ePrivacy Directive and GDPR Articles 6 and 7, which require your consent before any storage that is not strictly necessary, and require that a refusal be as easy as an agreement.

We set no advertising, profiling, or cross-site tracking cookies on this website. The categories below are the complete list.

  • Strictly necessary (no consent required, cannot be switched off):
    • One entry in your browser's local storage, plp_cookie_consent_v1, holding your cookie choice and the date you made it. Without it we would have to ask you again on every page.
    • On the report page only: a Google reCAPTCHA check, used by Firebase App Check to confirm the request comes from this page in a real browser. It is what prevents a leaked report link from being harvested by a script, so a report cannot be displayed without it. reCAPTCHA may set its own storage in your browser and sends technical signals to Google.
    • On the report page only: a short-lived anonymous Firebase sign-in, held in memory and discarded when you close the tab. It is never written to your browser's storage, and it grants access to nothing by itself — only the token in the link does.
  • Analytics (optional, off unless you turn it on): we do not currently run any analytics or measurement script on this website. The option is offered so that if we ever add one, it stays inactive until you have agreed.

The report page. Your report is fetched directly from Google Firestore over TLS and displayed from your device's memory. The link's access token travels in the part of the URL after the #, which browsers never transmit to a web server, so the server hosting this site never receives it and cannot log it. No report file passes through this website's host, and nothing about the report is stored by your browser. Because every one of those steps is strictly necessary to put the report in front of you, that page shows a plain notice rather than a choice — there is nothing optional there to refuse.

Third-party fonts. The pages on this site load the Outfit and Plus Jakarta Sans typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). That request reveals your IP address and browser details to Google. It places no cookie and is therefore outside the choice described above, but we disclose it here because it is a transfer to a third party.

Changing or withdrawing your choice. Select Cookie settings in the footer of any page at any time; the banner reopens with your current selection and a new decision replaces the old one immediately. Clearing your browser's site data for this domain also erases the stored choice, after which you will simply be asked again.

Cookies and identifiers used by the Android app, including the Advertising ID used for ads, are described in Sections 1 and 5 above and are governed by your choices inside the app, not by this website's banner.

10. Policy Updates

We may modify this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy periodically to stay informed about our data protection practices.

11. Data Protection & Grievance Officer

In accordance with Section 13 of India's DPDP Act 2023 and EU GDPR Article 37, if you have any questions, concerns, or grievance requests regarding your personal data or this Privacy Policy, please reach out to our designated Data Protection & Grievance Officer:

Grievance / Data Protection Officer: PathLab Pro Privacy Desk
Email: [email protected]
Response Time: All grievances are acknowledged within 24 hours and addressed within 30 days as mandated by law.