e-PT

Privacy Policy

For the e-PT Android application (com.deforay.ept), published by the Deforay Developers Team.
Effective 27 August 2026.

This policy explains what information the e-PT app handles, why, and what control you have over it. It covers the app itself. It does not cover the proficiency testing server your organisation runs, which is a separate system with its own operator.

1. Who is responsible

The app is developed and published by the Deforay Developers Team, reachable at hello@deforay.com.

e-PT is a client application. When you sign in you supply the address of a proficiency testing server, and the app communicates only with that server. That server is operated by your proficiency testing programme, national reference laboratory, or the organisation that issued your account — not by us, unless we separately host your instance under a written agreement. The operator of that server is the controller of the data you submit through the app. For questions about how your submitted results are used or retained, contact your programme administrator.

2. Who the app is for

e-PT is intended for laboratory and testing-site staff enrolled in a proficiency testing or external quality assessment scheme. It is not a consumer app and is not directed at children.

Not for patient data. e-PT is designed for proficiency testing panels and control samples. Do not enter patient names, patient identifiers, or any other personally identifiable patient information into the app.

3. Information you provide

4. Information stored on your device

The following is kept locally on your phone or tablet so the app can work offline and stay signed in:

Signing out clears your session. Uninstalling the app removes the app's local data, but not files already saved to your device storage.

5. Biometric and app-lock

You may optionally protect the app with a passcode or your device biometrics (fingerprint or face unlock). Biometric verification is performed entirely by the Android operating system. The app never receives, sees, or stores your fingerprint or face data — it is told only whether the device verified you successfully.

6. Push notifications

The app includes Firebase Cloud Messaging. On sign-in it asks Google for a device registration token and sends that token to your proficiency testing server. The token identifies the app installation, not you personally.

Push notifications are not in operation. Delivering them would require each programme to run its own Firebase project, which is not possible without building a separate copy of the app for every country. No notifications are sent, and the server does not act on the tokens it receives. The component is left in place for a future release. If that changes, this policy is updated first. You can turn off notifications for the app in your device settings at any time.

7. Diagnostics and analytics

The app links Google Firebase Analytics, Crashlytics (crash reporting) and Performance Monitoring, and all three are enabled in the published build. They start collecting when the app opens, without any action by you or by us. The information they collect is technical and usage information such as:

This information is processed by Google as our service provider. In practice we do not consult it. It is retained by Google under its own retention periods, and we intend to remove these components in the next release of the app. It is not used for advertising, and the app contains no advertising SDKs. Google's handling of this data is described in the Firebase privacy documentation and the Google Privacy Policy.

Because the app is open source, you can inspect exactly what is collected, or build a version with these components removed, from the source repository.

8. Permissions the app requests

PermissionWhy
Internet and network stateTo reach your proficiency testing server and to detect whether you are online before syncing.
File storageTo save downloaded reports to the EPT REPORTS folder and open them.
BiometricsOnly if you enable biometric unlock for the app.
NotificationsTo display shipment and result alerts sent by your programme.

The app does not request access to your location, camera, microphone, contacts, call logs or SMS messages.

9. What we do not do

10. Data security

Traffic between the app and your server uses HTTPS where your server provides it; the app defaults to https:// when you enter a server address. Because the server is chosen and operated by your organisation, the security of data at rest, and its retention, are governed by that organisation's policies.

11. Your choices and rights

12. Changes to this policy

If this policy changes, the updated version will be published at this address with a new effective date. Material changes will also be noted in the app's release notes on Google Play.

13. Contact

Questions about this policy or about the app: hello@deforay.com.

Questions about your account, your results, or data held by your programme: contact your proficiency testing programme administrator.