OutFlow Privacy Policy

Publisher: TheCriners
Effective: October 8, 2026 · Policy version 4

Purpose and testing status

This policy describes OutFlow 0.5.0 (Android version code 10). Earlier builds retain the privacy policy bundled with that version; their features may differ.

OutFlow is a patient-controlled output, fluid-intake and optional symptom logging application from TheCriners. This Early Access / Development build is under active development and may change significantly. Testers may use OutFlow normally at their own discretion. Encrypted backup and replace restore are available in this development build. Keep verified backups and their passphrases safe; information you need should also be retained independently.

OutFlow is not a medical device and does not diagnose, treat, cure or prevent medical conditions. Consult a healthcare professional for medical advice, diagnosis or treatment. Do not rely on OutFlow for diagnosis, emergency decisions or medical treatment decisions.

Information you choose to record

OutFlow stores the information you enter: an optional nickname, familiar source labels, structured route/site/side information, output and fluid-intake amounts, original units, occurrence and entry times with zone/offset information, and whether output was estimated or unmeasured. Optional How I Feel check-ins store symptom type, an optional 0–10 severity with its named scale, optional notes, and the same occurrence and entry time information. It also stores your reporting-zone, unit, decimal-format and text-size preferences.

OutFlow reads the device time and configured time zone to suggest routine entry times. It does not request location, contacts, camera, microphone, sensor or Health Connect access. No OutFlow account is required.

Local use and network behavior

Your entries are processed locally to save and display History, corrections and recorded per-source totals. Recorded intake is shown separately. Recorded symptoms appear in History and corrections and never change amount totals. The app does not calculate hydration, diagnose conditions or recommend treatment.

This release has no Internet permission, advertising, analytics, crash-upload service, cloud account or automatic synchronization. OutFlow does not automatically transmit your health records to TheCriners or another service. Installing or updating through Google Play or downloading an APK uses those services outside OutFlow.

Storage and protection

Health records are encrypted in the application-private database on your Android device. The database key is protected through Android secure key storage. The non-health text-size preference is stored separately in the same private, backup-excluded area.

Android automatic backup and device-transfer backup are excluded for OutFlow data. Readable PDF reports and CSV exports can be shared or saved by you. Portable backups are encrypted with a passphrase you choose. Keep your device protected with its screen lock; encryption cannot protect records from someone using your unlocked app or a compromised device.

Sharing under your control

Reports are generated completely on your device from your selected period, output sources, optional intake and optional recorded symptoms. Your profile nickname is excluded unless you explicitly choose to include it. Source labels, dates and recorded health information can still identify you; a report without the nickname is not guaranteed anonymous. Generating a report does not automatically transmit it or save it outside OutFlow. No recipient address, contact list or report passes through an OutFlow or TheCriners server.

After reviewing the report, Share Report shows a private-information warning and your selected scope. Only your explicit confirmation opens Android’s system share mechanism. Android presents available receiving applications; you choose the application and any recipient there. OutFlow does not send email, select recipients or confirm delivery. The chosen application or service controls its copy under its own privacy practices and may upload or forward it. Save PDF similarly opens Android’s document picker only after your confirmation; you choose the local or provider-backed destination. Copies sent or saved outside OutFlow cannot be recalled or deleted by OutFlow.

Generated PDF bytes remain in memory until you share or save. The readable temporary PDF is then written only to an application-private report cache. Access is granted narrowly for the selected report. Shared files remain available after chooser cancellation or return so receiving applications can read them. OutFlow checks every ten minutes while running for cached files older than 24 hours and removes all remaining temporary report files and access grants at the next fresh application launch. Cleanup is best effort while the app is backgrounded; after force-stop or a crash a cached file can remain until the next launch. Complete the receiving application’s attachment step before reopening OutFlow. A cancelled document save removes its temporary file when it was not already shared. Generated reports are not retained as health records, and cache deletion does not delete copies held elsewhere.

Intentional foreground screenshots are allowed. You can copy text or use Android text-selection actions and share screenshots or messages yourself. Your keyboard, operating system and other apps handle those actions under their own privacy practices. Copies you share are outside OutFlow’s control. This is why we do not promise that information can never leave your device.

Your backups, restore and CSV exports

Back Up OutFlow creates an authenticated encrypted .outflowbackup file on your device. It includes your profile, record preferences, text size, all existing records including recorded symptoms, original amounts and units, times, relationships, archived sources and source history. It excludes device database encryption keys, signing credentials and temporary reports/exports. OutFlow uses Argon2id to derive a key from your passphrase and AES-256-GCM for authenticated encryption. No readable temporary backup file is written. Before Save is offered, OutFlow decrypts and validates the backup locally. OutFlow and TheCriners cannot recover a forgotten backup passphrase.

You explicitly choose the backup destination through Android’s document picker. A selected provider may store or upload the encrypted file under its own practices. Keep a separate safe record of the passphrase. OutFlow has no server copy of either.

Restore OutFlow Backup reads only the document you select. OutFlow decrypts and validates it in separate encrypted private storage, shows a preview and requires explicit confirmation before replacing local data. Records are not merged. A fresh device database key protects the restored database. The most recent previous encrypted database generation and key are retained privately as rollback/recovery protection; replacement does not promise forensic deletion of old bytes. Wrong passphrase or rejected data does not replace the current records. Interrupted or failed work can leave encrypted staging files until local app data is removed.

Export My Data creates a ZIP of readable UTF-8 CSV files and a format guide for spreadsheets or personal analysis. It contains your profile, source history and all existing records, including recorded symptoms and notes/context already supported by the database. CSV is not encrypted and cannot restore OutFlow. Formula-like cell text receives a visible apostrophe guard; exact original text remains in encrypted backups. OutFlow generates CSV locally and writes a readable temporary export file only after you confirm Save or Share.

CSV sharing and backup/CSV saving use Android’s system mechanisms only after your explicit confirmation. You choose the receiving app, recipient or storage provider. The receiving party controls its copy and may upload or forward it. OutFlow does not send email, access contacts, automatically upload, confirm delivery, recall or delete external copies. Temporary backup/CSV files use a separate application-private export cache with narrowly granted read access. Unshared document-save files are removed after success or cancellation. Shared CSV files remain available so the receiving app can read them, and are removed at the next fresh OutFlow launch or when older than 24 hours during the next export action. Cleanup is best effort; force-stop/crash may leave private cache files until the next launch. Complete an attachment before reopening OutFlow.

Retention and deletion

Local records remain until you delete them or remove the application’s data. In History, open an entry and choose Delete; the immediate Undo action can restore that entry. Archiving a source preserves its historical context and is not deletion of past entries.

Android Settings → Apps → OutFlow → Storage → Clear storage, or uninstalling OutFlow, removes its local data. OutFlow has no server copy of your records. Recovery requires a previously saved encrypted backup and its passphrase. Ordinary updates should not require clearing data. We do not promise forensic erasure from flash storage.

Website, Play and voluntary support

Opening TheCriners in a browser, using Google Play or emailing support is separate from this app’s local recording. Those services receive the requests or messages you send and can process technical data such as account details, IP address and browser information under their own privacy practices. They do not automatically receive your OutFlow entries.

If you volunteer for a closed test, provide only the Google account/email needed for Play access. Do not send diagnoses or medical records merely to participate. If you email support, we receive your email address and message to answer the request. Avoid sending health information, raw databases or keys. Support correspondence is retained only as needed to handle the request and applicable obligations; contact us to request its deletion.

Policy updates

Changes that affect access, use or sharing of information will be described in an updated policy before the changed features are used. The app includes a local policy copy so you can read it offline. Review the policy supplied with future updates.

Contact

For OutFlow support or privacy questions, contact TheCriners at support@thecriners.com. Include the application version and a description of the issue, using synthetic examples. Do not include signing keys, raw databases or unnecessary health information.