App Privacy Policy
Assign Mobile Application
Last Updated: August 26, 2026
Version History
| Version | Date | Description |
| 1.0 | August 25, 2026 | Initial publication for App Store / Google Play submission. |
| 1.1 | August 26, 2026 | Updated for data retention / Company full name |
1. Scope
This Privacy Policy applies only to the Assign mobile application (the “App”) published on the Apple App Store and Google Play Store. It describes what limited information the App itself collects and how it is used. It does not describe the data practices of the medaptus.com website, or of the separate Charge Pro application, each of which is covered by its own privacy policy.
2. The App Does Not Support Account Creation
The App does not allow a user to create a new account, register, or sign up from within the App. Instead, the App authenticates against an existing account that was already provisioned for you by your employer — typically a hospital, health system, or medical group — within the underlying Assign line-of-business system.
Your username and password are issued and managed by your employer’s system administrator as part of your work access, in the same way they would be if you logged into that system from a desktop browser. The App is a client that lets you use those existing, employer-issued credentials from a mobile device.
3. Information the App Collects
The App collects and processes only the following:
- Username and password — entered by you to authenticate against your employer’s existing Assign system. These credentials are not created by the App; they already exist in the backend system before you ever open the App.
- A locally cached copy of your login credential — stored using the platform-native secure storage API (Apple’s Keychain on iOS; Android Keystore on Android) so you don’t have to re-enter your username and password every time you open the App.
- Biometric authorization — if you enable it, biometric unlock is implemented using the operating system’s native biometric API (Apple’s LocalAuthentication framework on iOS; Android’s BiometricPrompt on Android). Your actual biometric data (fingerprint or face scan) is captured, matched, and stored entirely by your device’s operating system and secure hardware; the App only receives a yes/no authorization result. Medaptus never collects, transmits, or stores your biometric data.
The App does not automatically collect device or diagnostic data — it does not use analytics SDKs, crash reporting, or push notification tokens. The App does not independently collect your name, email address, phone number, location, contacts, photos, or any other personal information beyond the login credential described above.
4. How This Information Is Used
Your username and password are used solely to authenticate you to the Assign backend system operated by Medaptus on behalf of your employer, so that you can access the functionality your employer has granted you within that system.
Once you are logged in, the App displays protected health information (PHI) and other clinical data drawn from that backend system, and transmits any entries you make back to it over an encrypted connection. The App functions as a secure window into the system your employer already uses: it does not copy this information to any other Medaptus system, and it does not retain it on your device after you log out or close the App. Medaptus processes this information as a Business Associate of your employer, under HIPAA and the Business Associate Agreement (BAA) between Medaptus and your employer, which govern how it may be used, disclosed, retained, and safeguarded.
5. Account & Credential Management
Because the App does not create or own your account — it only authenticates against a credential that already exists in your employer’s system — account creation, password resets, and account deletion are managed by your employer’s IT department or system administrator, not by the App or by Medaptus directly.
To remove your access
- Contact your employer’s IT department or system administrator. They can disable or delete your login credential directly in the underlying system — this immediately removes your ability to authenticate through the App as well.
To remove the App and any locally stored data from your device
- Use the App’s “Log Out” option to clear your cached credential and revoke the biometric unlock binding for this device.
- Uninstalling the App also removes any locally cached credential and the biometric-unlock association for the App, since that data is stored in the App’s private, sandboxed storage and is deleted by the operating system when the App is removed.
6. Why This App Does Not Include Full In-App “Delete Account”
Both Apple and Google require in-app (or, for Google, web-based) account deletion for apps that support account creation within the app. Because this App does not support account creation — accounts are provisioned entirely outside the App by the employer/health system — the App is not the owner of the account and cannot delete it. This mirrors guidance Apple has given to other apps that authenticate against third-party or employer-managed systems rather than creating accounts themselves.
7. Data Sharing
Medaptus Solutions, Inc., does not sell your username or password, and does not share them with third parties except as necessary to operate the authentication and hosting infrastructure that supports the App (for example, AWS, our cloud infrastructure provider), under appropriate confidentiality and security obligations.
8. Data Security
Credentials are transmitted using TLS 1.2 or higher. The locally cached credential is stored using your device’s secure, encrypted, sandboxed storage as described in Section 3, and is inaccessible to other apps. Where you enable biometric unlock, your device’s operating system — not Medaptus — handles the biometric matching, and the App only receives an authorization result.
The App enforces the same password policy as the web application. The App also enforces an automatic logout / re-authentication timeout on the cached session, consistent with our web application’s session security policies.
9. Children’s Privacy
The App is intended for use by credentialed healthcare and administrative employees of our health system customers and is not directed to, and does not knowingly collect information from, children.
10. Changes to This Policy
We may update this App Privacy Policy from time to time. Material changes will be reflected by an updated “Last Updated” date at the top of this page and logged in the Version History table above.
11. Contact
Reach out to us here and a member of our security team will be in touch with you shortly.









