Proteneo is a local-first app. Information you enter โ treatment items and administration records, completed lab draws, supply ledgers, schedules, reminder records, workouts, nutrition, weight, and wellness check-ins โ stays in encrypted storage on your phone. There is no Proteneo account or sign-in, and no Proteneo/MFS-managed health-data server or sync. Android cloud Auto Backup is disabled. Some Android 12+ manufacturer device-to-device flows may still move app files despite that setting; Proteneo does not support or promise that as recovery. iOS backup or device transfer may separately preserve app data according to platform behavior and your settings, but Proteneo does not promise that it will restore a readable record.
Clinic Link also lets you deliberately choose one clinician-authored Clinic Plan text file from your device or paste its complete text. Proteneo parses it locally, shows the stated clinic and every proposed local change. Only facts you explicitly adopt are applied to your active records. If you save any change, Proteneo separately retains the complete exact plan, including content you did not adopt, plus its receipt, mapping, revision, and adoption evidence in encrypted local storage. It does not contact a clinic, EHR, lab, pharmacy, portal, or MFS server. The plan checksum detects accidental changes and exact duplicates only; it does not authenticate the clinic or patient, prove medical correctness, provide confidentiality, or prove delivery or review.
We do not sell your data or use advertising trackers. The routine app path makes no network call carrying Clinic Plan or wellness content. This does not cover a separate email or attachment someone deliberately sends to a published support/privacy address. Subscriptions are billed by the Apple App Store or Google Play and managed for us by RevenueCat, Inc. As applicable to the platform and configuration, RevenueCat may process an anonymous App User ID; purchase, subscription, product, entitlement, transaction-history, and status information; an Apple receipt file or Google purchase token; last-seen or activity timing; device type and operating system; locale and currency; and network/IP metadata. RevenueCat uses this billing information to operate purchases and entitlements and for its provider dashboard and analytics. The identified candidate billing seam sends no Clinic Plan or wellness-record payload and uses no custom RevenueCat login or customer-attribute API. No outbound RevenueCat analytics integration is identified in the current candidate/configuration; that console fact must be reverified before release. See revenuecat.com/privacy.
When you visit proteneo.com, the browser and hosting provider process ordinary request information such as IP address, browser or user-agent details, requested pages, timestamps, referring page, and security or diagnostic logs to deliver and protect the site. We do not use the site for advertising tracking. The report reader reads a report you deliberately select inside your browser and does not upload the report contents to us, although loading the reader is still an ordinary website request. Hosting provider, exact log fields, and retention remain counsel and operations verification items before this draft becomes final.
If you email support@multifactorsolutions.net or privacy@multifactorsolutions.net, the email systems used by you and us process the sender name and address, message, ordinary email-routing headers, and any attachment or other information you choose to include. We use that communication to respond, route the request, investigate the reported issue, and keep the operational record needed to handle it. Do not email a Clinic Plan, report, backup, screenshot, or other health or wellness content unless it is necessary and you intend to send it. The email provider, authorized access, retention, and deletion procedure remain operations and counsel verification items before this draft becomes final.
Proteneo is a consumer wellness tracker, not a clinical tool. It is not operated through the app by a healthcare provider. A Clinic Plan may be clinician-authored, but the patient carries it locally and the routine in-app path sends no plan payload to MultiFactor Solutions. A separate support/privacy email or attachment you deliberately send is handled as described above. We do not operate Proteneo as a HIPAA Covered Entity or Business Associate. Your data remains protected by this policy and applicable consumer-privacy laws.
What the app handles locally: treatment items and administration records; completed lab draws; supply profiles, balances, and dated received, used, or adjustment entries; schedules and reminder records; fitness, nutrition, weight, and wellness records; a Weight calculation profile with sex, age, height, and activity level if you choose to use calculated targets; the exact Clinic Plan source you choose or paste; clinic identity/contact; treatment, lab, follow-up, and education facts; import receipts; adopted revision history; treatment mappings and evidence; preferences like theme and units; and the billing metadata described above. After any saved change, the exact source retains unselected content as provenance, not as facts applied to your active record. Choosing a Clinic Plan file can create a temporary plaintext app-cache working copy. Clinic Link retains no Clinic Plan record when you leave without a completed save; verified cleanup of that working copy is a release requirement. In this release candidate the app requests no account, camera, location, contacts, microphone, notification, HealthKit, Health Connect, or Google Fit permission and provides no dedicated government-ID or financial-account field. Free text can still contain what a user or source author writes.
How it's stored: entered and adopted data is held in an encrypted local store. A random app-storage key in your phone's secure keychain protects against off-device file copying, not someone using an unlocked phone, so use a passcode or biometric lock. Before opening an existing MMKV data or CRC artifact, Proteneo requires a valid secure key and encryption marker plus a non-secret SHA-256 identifier beside the MMKV files that matches that exact key. A missing, malformed, pre-identifier, or mismatched state stops before the native store opens; Proteneo does not wipe, replace, or re-key the preserved store. On a fresh install, Proteneo verifies by readback that the key, marker, and file-side identifier were stored before opening the new store. Android cloud Auto Backup is disabled. Some Android 12+ manufacturer device-to-device flows may still move app files despite that setting; Proteneo does not support or promise that as recovery. iOS backup/transfer behavior is platform-controlled and not a promised recovery method.
File custody: an incoming Clinic Plan is readable plaintext in your custody, and file selection can create the temporary app-cache working copy described above. Generated PDF and interactive HTML reports are plaintext files outside the encrypted record store. Proteneo keeps them in app-owned document storage so you can reopen or delete them in Past exports. Each completed generation uses a collision-safe unique filename, including for multiple reports in the same format on the same day, and does not overwrite an existing retained report while creating the new one. Proteneo verifies the exact PDF or HTML contents before sharing and before cleaning up its source or temporary copy. It attempts to keep the 10 most recent report files, but cleanup, migration, or filesystem failures can leave more; 10 is a target, not a guarantee. A materialization failure never overwrites or deletes an earlier retained report. Cap pruning can remove calculated oldest excess reports before a later failure; unverified pruning or cleanup is reported rather than presented as complete. A report may include selected adopted plan facts and provenance.
A JSON backup is also plaintext outside the encrypted record store. It is a portable subset, not a copy of every app or device record. It includes portable local records and preferences, including portable Clinic Plan source, receipt, mapping, revision, and adoption history. It excludes per-install legal acceptance and guided-setup state, device-bound cache/connection and recovery state, stored report files, and App Store, Google Play, or RevenueCat records. The on-device encryption does not follow report or backup files.
Your choices: prepare and share a PDF or interactive HTML report; create or restore a portable backup; use the available add, edit, replace, and delete controls for local records; clear local data; or uninstall. A settings-, filter-, view-, navigation-, or display-only file cannot authorize record replacement; at least one valid record-bearing section is required. A successfully completed restore is a full replacement of the portable record subset, not a merge. It does not replace per-install/provider state or delete retained Past exports, an original plan, a backup, or a recipient copy. Clear all data first performs the bounded Proteneo-owned temporary-file and app-retained report cleanup. If a cleanup step reports a problem, app records remain in place; a file removed before that failure remains removed. Only after those cleanup steps report success does the app start its journaled clear of the clearable Proteneo record. Files or recipient copies stored elsewhere remain outside that action. Uninstall is controlled by the platform and does not run Proteneo's in-app cleanup. Its exact effect on app storage is not promised. Neither action cancels a store subscription or itself deletes store or RevenueCat billing records. Contact privacy@multifactorsolutions.net for a request concerning billing-provider customer information. When store billing is configured, Settings shows the exact anonymous Billing support ID RevenueCat uses to locate the record; include it with the request. Deleting a RevenueCat record does not itself cancel an Apple/Google subscription. Later app, receipt, or Restore activity may create or reassociate a RevenueCat record; the exact request process and access effects remain subject to operational testing and counsel approval.
Planned, not live: we may later add optional cloud sync for a newly specified and consented subset of eligible data. The current proposal excludes Clinic Plan source, receipts, mappings, and adopted clinic-origin evidence. We will update this policy, re-engage counsel, and ask for fresh consent before enabling any cloud feature.
Questions or data requests: privacy@multifactorsolutions.net
MultiFactor Solutions, LLC ยท 7310 Menchaca Rd, #150091, Austin, TX 78715