Privacy Policy
Chinese Medicine Last updated: 9 September 2026
This Privacy Policy applies to the Chinese Medicine mobile application (the "Application"), published on the stores as Traditional Chinese Medicine and provided by Lanchas Dev (the "Service Provider"). Contact: lanchasdev@gmail.com
This is the only one of our applications with accounts, cloud sync and a subscription, so it is the longest of these policies. Two things are worth reading before the rest:
- The Application is local-first. It works fully without an account, offline, with everything stored on your device. Signing in is optional and adds sync; it is not a condition of using the Application.
- The Application is educational. It is not a medical device and does not diagnose, treat, cure or prevent disease. Its simulations are study exercises, not clinical acts, and they do not replace care from a qualified health professional.
1. Without an account
Used without signing in, the Application keeps your preferences, progress, favourites, notes, flashcards, exam and practice history, reminders and study sessions in its own private storage on your device. That data is not transmitted, and there is no copy of it anywhere else.
2. With an account
You can sign in with Sign in with Apple or Google. There is no password to create and we never see one. When you do, the following is stored on our behalf by Supabase, our database provider:
- Your identity as the provider gives it to us — an account identifier and the email address associated with your sign-in. If you use Sign in with Apple and choose to hide your address, we receive Apple's relay address and never your real one.
- A profile: the display name and profile picture your provider supplied, and your language.
- A device record for each device you sign in on: platform, application version, and when it was last seen. This exists to make sync work.
- The study data you sync, described in section 3.
Access is enforced per user at the database level: a signed-in account can read and write its own rows and no one else's.
3. What syncs, and what does not
Sync has two tiers, and the second is off by default. This is the most important paragraph in this policy.
3.1 Study data — syncs by default
Learning progress, stage checkpoints, exam history, favourites, flashcards, the Journey, notes, practice history, progression, reminders, and wellness history and rituals.
3.2 Private data — only if you turn it on
The history of your educational simulations and your treatment plans sync only if you separately enable Sync private data. They are separated from everything else precisely because they are the two places where you may have written something clinical — about yourself or about someone else.
Please read this before turning it on. Notes about health are, under European law, a special category of personal data. We do not read them, we do not analyse them, and they never reach analytics — but if you enable this tier, a copy leaves your device and rests in the database. If you write about another person, you are the one deciding to store their information, and you should have their agreement. Leaving the switch off keeps all of it on your device and nowhere else.
Separately, saving study history at all is off by default. When you do enable it, what is stored are identifiers of answers and educational results, the algorithm version and the date; the text of a question is not duplicated, and none of it is ever sent to analytics.
4. Purchases and subscriptions
If you buy Premium, Apple or Google handles the payment end to end. We never see and never store a card number, a billing address or any payment detail.
To know whether a purchase is still active we use RevenueCat, which receives from the store the product you bought and its start, renewal or cancellation dates. Signed out, RevenueCat identifies you by an anonymous device identifier it generates itself. Signed in, it uses your account identifier instead — which is what lets a subscription work across your devices and survive a purchase made before you registered. RevenueCat never receives your name, your email or anything you study.
Cancelling or requesting a refund is done in your App Store or Google Play account settings. Deleting your account here does not cancel a subscription, because the store is what charges you.
5. Usage analytics and crash reports
Analytics goes to PostHog, on servers in the European Union, and it is anonymous by design:
- No person profile is ever created. The Application is configured so PostHog does not build one — not from our events, not from the SDK's own.
- Events are grouped under a random identifier generated on the device. It is not your account identifier, not your device identifier and not an advertising identifier.
- There is no autocapture and no session replay. Nothing is recorded because you happened to touch it; only the events we listed deliberately are sent.
- Nothing is contacted before you have had the chance to decide. Remote configuration, feature flags and surveys are switched off in the Application, so the analytics SDK does not call out on its own the moment it starts.
What is sent: aggregate events such as a module being opened or a lesson completed, with basic technical metadata — platform, application version, language. From the initial walkthrough we also send which screen you are on, how long you have been there, and what you choose in its multiple-choice questions (modules, goal, what you struggle with, pace). From the calibration questions we send only whether you were right, never which option you picked.
What is never sent: your searches, your symptoms, the answers to your exercises, your simulations and exams, the titles you save, your history, your notes, your treatment plans, your name and your email.
Crash reports are governed by the same switch. When the Application breaks we send the error type, its message, the call stack and the component path of the screen. An error message is written by whichever library failed, not by us, so before it leaves the device it passes through a filter that redacts email addresses, the variable part of web addresses, long identifiers, system paths and any quoted text longer than a property name. Source lines and the values of local variables at the moment of the crash are never sent, and the same error stops being sent after a few repetitions.
Turning it off: Profile → Help improve the app. Sending stops immediately and the random identifier is discarded. Turning off analytics turns off crash reports too.
6. Notifications
Study reminders are scheduled on your device. The Application obtains no push token, there is no notification server, and we cannot send you anything. Declining the permission costs you the reminders and nothing else.
7. External connections
Besides the services above, the Application reaches the network for content and upkeep. None of these requests carries your account, your notes or your study data; as with any request over the internet, the provider sees the IP address it came from.
- Editorial images from Unsplash and Wikimedia Commons.
- Meditation ambience, which may stream from Orange Free Sounds.
- Voice packs, downloaded from our own public file storage at Supabase.
- Bibliography links you tap, which open the source's own site — PubMed, the WHO, publishers — under their policies, not ours.
- Over-the-air updates: on start-up the Application asks Expo's update service whether newer code is available. That request carries the platform, the runtime version, the installed version and an installation identifier — never your account or what you study.
8. Third-party data sharing
We do not sell data and we do not use it for advertising — there is no advertising in the Application. Data reaches only the providers named above, each for the single purpose described: Supabase to store your account, RevenueCat to know whether a purchase is active, PostHog to count anonymous usage, and the content hosts to serve files. PostHog and Supabase act on our behalf and under our instructions, not for their own purposes.
9. Data retention
- Account and synced data is kept for as long as your account exists. Deleting the account deletes it.
- Analytics and crash events are retained by PostHog under our project's retention settings and are anonymous throughout.
- Purchase records are kept by RevenueCat and the stores for as long as they need them to honour a subscription.
- Local data stays on your device until you delete it or uninstall.
- Support emails are kept for at most 6 months, unless a legal obligation requires longer.
10. Your controls, and how to delete your account
- Export your account data — Profile.
- Sign out, which stops syncing and leaves the local copy alone — Profile.
- Delete your account permanently — Profile. This deletes your profile, your devices and your synced documents, and it also revokes the Sign in with Apple credential, so the Application stops appearing in Settings → Apple ID → Sign in with Apple on your device.
- Turn off analytics and crash reports — Profile → Help improve the app.
- Turn off study history, or leave Sync private data off — Privacy settings.
- Delete all local data — Delete all data inside the Application. Uninstalling removes local storage; whether a copy survives in an operating-system backup depends on your device settings, not on us.
If you no longer have the Application installed, or the in-app control does not work for you, write to lanchasdev@gmail.com from the address associated with your account and ask for deletion. We will delete the account, the profile, the device records and every synced document, and confirm it, within 30 days. There is nothing to pay and no reason to give.
11. Your rights
If you are in the European Economic Area or the United Kingdom, you have the right to access, rectify, erase, restrict and object to the processing of your personal data, to data portability, and to withdraw consent at any time.
Unlike our other applications, here those rights are real and actionable: if you have an account, we hold data that is identifiably yours, and the export and deletion controls in section 10 exercise access, portability and erasure directly. For anything the Application cannot do by itself, write to lanchasdev@gmail.com from the address associated with your account and we will respond within 30 days.
The exception is the anonymous analytics of section 5: it carries no account identifier, so we cannot locate your events among everyone else's, and the law does not require us to collect more about you in order to be able to. The switch in Profile is the effective control there.
You also have the right to lodge a complaint with your data protection authority. In Spain, that is the Agencia Española de Protección de Datos (www.aepd.es).
12. International data transfers
Analytics data is processed within the European Union. Account and sync data is stored in a database hosted by Supabase; purchase status is processed by RevenueCat. Where any of these involves a transfer outside the European Economic Area, it relies on the safeguards set out in that provider's privacy policy, including the European Commission's standard contractual clauses.
13. Children's privacy
The Application is intended for users aged 13 and over. We do not knowingly collect personal data from children under 13. If a parent or guardian believes a child under 13 has an account here, write to lanchasdev@gmail.com and we will delete it.
14. Changes to this policy
We may update this policy. Changes take effect when the revised version is posted, with a new "Last updated" date. The Application also carries a copy of this policy inside it, under Profile.
15. Contact
Controller: Lanchas Dev — lanchasdev@gmail.com