Privacy Policy
This policy explains what information the e-PT app handles, why, and what control you have over it. It covers the app itself. It does not cover the proficiency testing server your organisation runs, which is a separate system with its own operator.
1. Who is responsible
The app is developed and published by the Deforay Developers Team, reachable at hello@deforay.com.
e-PT is a client application. When you sign in you supply the address of a proficiency testing server, and the app communicates only with that server. That server is operated by your proficiency testing programme, national reference laboratory, or the organisation that issued your account — not by us, unless we separately host your instance under a written agreement. The operator of that server is the controller of the data you submit through the app. For questions about how your submitted results are used or retained, contact your programme administrator.
2. Who the app is for
e-PT is intended for laboratory and testing-site staff enrolled in a proficiency testing or external quality assessment scheme. It is not a consumer app and is not directed at children.
Not for patient data. e-PT is designed for proficiency testing panels and control samples. Do not enter patient names, patient identifiers, or any other personally identifiable patient information into the app.
3. Information you provide
- Server address — the host name of the proficiency testing server you connect to.
- Sign-in credentials — the username and password issued to you by your programme. These are sent to your server for authentication; the app does not store your password after sign-in.
- Profile information held on your account, such as first and last name, primary and secondary email addresses, and mobile or telephone number. This is retrieved from and updated on your server.
- Proficiency testing responses — the shipment, panel and result data you enter for each scheme, which is submitted to your server.
4. Information stored on your device
The following is kept locally on your phone or tablet so the app can work offline and stay signed in:
- An authentication token for your session, and your server address.
- Cached shipment, scheme and result data, so you can enter results without a network connection and sync later.
- Reports you choose to download, saved as files in an
EPT REPORTSfolder in your device storage. These remain on your device until you delete them, and are not removed automatically when you uninstall the app. - Your app-lock preference, if you enable one.
Signing out clears your session. Uninstalling the app removes the app's local data, but not files already saved to your device storage.
5. Biometric and app-lock
You may optionally protect the app with a passcode or your device biometrics (fingerprint or face unlock). Biometric verification is performed entirely by the Android operating system. The app never receives, sees, or stores your fingerprint or face data — it is told only whether the device verified you successfully.
6. Push notifications
The app includes Firebase Cloud Messaging. On sign-in it asks Google for a device registration token and sends that token to your proficiency testing server. The token identifies the app installation, not you personally.
Push notifications are not in operation. Delivering them would require each programme to run its own Firebase project, which is not possible without building a separate copy of the app for every country. No notifications are sent, and the server does not act on the tokens it receives. The component is left in place for a future release. If that changes, this policy is updated first. You can turn off notifications for the app in your device settings at any time.
7. Diagnostics and analytics
The app links Google Firebase Analytics, Crashlytics (crash reporting) and Performance Monitoring, and all three are enabled in the published build. They start collecting when the app opens, without any action by you or by us. The information they collect is technical and usage information such as:
- crash reports, error traces and the state of the app at the time of a crash;
- device model, operating system version, language, and app version;
- app screen views, session length, and performance timings;
- a pseudonymous app-instance identifier generated by Google.
This information is processed by Google as our service provider. In practice we do not consult it. It is retained by Google under its own retention periods, and we intend to remove these components in the next release of the app. It is not used for advertising, and the app contains no advertising SDKs. Google's handling of this data is described in the Firebase privacy documentation and the Google Privacy Policy.
Because the app is open source, you can inspect exactly what is collected, or build a version with these components removed, from the source repository.
8. Permissions the app requests
| Permission | Why |
|---|---|
| Internet and network state | To reach your proficiency testing server and to detect whether you are online before syncing. |
| File storage | To save downloaded reports to the EPT REPORTS folder and open them. |
| Biometrics | Only if you enable biometric unlock for the app. |
| Notifications | To display shipment and result alerts sent by your programme. |
The app does not request access to your location, camera, microphone, contacts, call logs or SMS messages.
9. What we do not do
- We do not sell or rent your information.
- We do not show advertising or use advertising identifiers.
- We do not share your proficiency testing data with third parties. It goes only to the server you sign in to.
- We do not track you across other apps or websites.
10. Data security
Traffic between the app and your server uses HTTPS where your server provides it; the app defaults to https:// when you enter a server address. Because the server is chosen and operated by your organisation, the security of data at rest, and its retention, are governed by that organisation's policies.
11. Your choices and rights
- Access, correction or deletion of your account and submitted results — contact your proficiency testing programme administrator, who operates the server holding that data. We cannot access it on your behalf.
- Local data — sign out to clear your session, or uninstall the app to remove its local data. Delete the
EPT REPORTSfolder to remove downloaded reports. - Notifications — disable them in your device settings.
- Diagnostics — you can build and install the app from source without the analytics and crash reporting components.
12. Changes to this policy
If this policy changes, the updated version will be published at this address with a new effective date. Material changes will also be noted in the app's release notes on Google Play.
13. Contact
Questions about this policy or about the app: hello@deforay.com.
Questions about your account, your results, or data held by your programme: contact your proficiency testing programme administrator.