Legal
Privacy Policy
Effective 14 July 2026
Privacy is a core product rule: private record contents are available only to the adult they concern, an adult managing a login-free dependent, or another adult who received the required permission. A person can see records they create for themselves; caregiver access still ends when permission is revoked.
Scope and release transition
This policy describes Turnki’s Family Care service for Android, its website, and its supporting API. The version currently available before the Family Care update keeps its planning data locally on the device. When the new sign-in and family-sharing features become available, the collection and sharing described below will begin only after the user completes the new onboarding.
Information Turnki processes
- Account identity from Google and Firebase Authentication, such as name, email address, and account identifier.
- Profile and family-care relationship information that an adult chooses to create.
- Medicine schedules, dose actions, stock and refill information.
- BP readings and optional notes. Turnki records these values but does not interpret them.
- Appointments, fees, meals, groceries, household tasks, and custom reminders.
- Device notification token, app version, sync timestamps, security events, and limited operational diagnostics that exclude private record contents.
Why information is used
Turnki uses information to authenticate adults, sync their records, deliver reminders, support explicitly permitted family care, prevent abuse, maintain security, provide export and deletion, and operate the service. Turnki does not use health data for advertising, profiling, credit, employment, or insurance decisions.
Encryption and access controls
Connections to Turnki’s service use HTTPS/TLS. Private record payloads are encrypted before storage in the service database, and the Android app protects its local database using device-backed encryption. Authentication identifiers and the limited metadata needed to route reminders or enforce access may be hashed, pseudonymized, or stored separately from encrypted record contents.
Turnki is not marketed as end-to-end encrypted: the service must be able to decrypt an authorized record to sync it to an authorized device. Server-side authorization is checked on every protected request. Access is limited to the concerned adult, an adult managing a login-free dependent, and adults with explicit, active permissions. Revoking a shared permission blocks future caregiver access, including access to records that caregiver previously entered for the adult.
Sharing
Turnki shares private information only when an adult deliberately accepts or grants access. Separate controls cover medicine management, adherence visibility, BP management, BP visibility, appointments, daily reminders, and groceries. Grocery lists are private by default; their creator may instead share a list with selected linked adults or everyone authorized in the family home. Private lists are not returned to other household members. Turnki may use service providers such as Firebase, Hostinger, and their infrastructure partners to operate authentication, notifications, hosting, security, and backups under contractual and technical safeguards. Turnki does not sell personal or health data and is ad-free.
Retention, export, and deletion
Active information is retained while the account is used. Deleting an account immediately revokes its sessions and removes active account data, subject to records another adult must retain as their own record or where legal obligations apply. Encrypted backups expire within 30 days. A user can request deletion in the app or through the web deletion page.
Adult use and security
Turnki accounts are for adults. Adults may create login-free profiles for children or other dependents. Turnki applies rate limits, hashed invitation tokens, short invitation expiry, audit records without health values, and conflict protection. No internet service is risk-free; suspected unauthorized access should be reported promptly.
Contact
Privacy and deletion enquiries can be submitted through the account deletion page. This policy will be updated if Turnki’s data practices materially change.