MedERP
Coming to the App Store

MedERP · Version 1.0

Privacy policy

How your business records, backups, and support information are handled.

Last updatedSeptember 24, 2026

Accounts and company records

MedERP is inventory and commerce software for iPhone, iPad, and Mac, operated by Medembark LLC. Users sign in with Apple or a verified email/password account. Supabase provides authentication, database storage, and realtime synchronization for the hosted app.

The service processes account identifiers, email addresses, profile names, authentication/session information, company membership, invitations, and audit records. Company records can include products, barcodes, prices, inventory activity, customer and supplier contact details, sales, purchases, returns, payments, credits, wallet transactions, VAT calculations, and notes. Uploaded supplier invoices/supporting files, attachment metadata, and advisory editing-presence information are also processed. These records are linked to the company and its authorized accounts and used to provide the app's functionality.

The app does not implement advertising, developer analytics, or cross-app tracking. We do not sell personal information. Medembark operates the app's Supabase project, which stores shared records in Frankfurt, Germany. Supabase and its infrastructure providers process service data to provide authentication, storage, synchronization, and security. Apple handles Sign in with Apple under its own privacy practices. Service providers may process operational information in other locations under their applicable policies.

Explore Demo uses fictional records in an isolated, temporary, read-only workspace on your device. It does not create a MedERP account or upload those demonstration records to the hosted service.

Supabase Privacy Policy · Apple Privacy Policy

Access and device copies

Each company has an owner, administrators, staff, and viewers. Roles control operational writes, team management, complete backups, and destructive actions. Invited users access the company with their own verified accounts. Invitations are bound to the recipient email, manually shared, single use, and expire after seven days.

Each device keeps a local copy of companies it has opened. Previously received records remain readable offline; a connection is required to save changes. The server rejects access after membership or session revocation, and the app hides the workspace when it learns of revoked access. Removing membership cannot recall exported files or guarantee removal from an offline device. Protect devices and exported copies appropriately.

Camera and files

With permission, the camera recognizes product barcodes on-device. Camera frames are not saved or uploaded by the app. Manual barcode entry is available.

MedERP accesses files chosen for CSV import/export and backup/recovery. On Mac, a user can authorize a folder or mounted network folder for automatic backups. Those destinations and their administrators have their own storage practices.

Uploaded document attachments are stored in a private company-scoped bucket. Authorized members can download them; operational roles can add, remove and restore them. Previews and explicitly shared/exported downloads create device copies. The app accepts PDFs and supported images up to 20 MB and does not claim to scan files for malware.

Backups, retention, and deletion

Ordinary exports follow company access. Owners and administrators can export .mederpbackup packages containing business records. Attachment bytes are stored separately and are not included; users must save required originals independently. Exported files are not encrypted by MedERP and may contain sensitive business data. Integrity checks detect corruption rather than conceal contents.

An owner can restore a validated backup into the selected company. Restore replaces its records for all members, preserves company identity and membership, and retains one prior generation for rollback. Other companies are unaffected. Older recovery generations are removed by subsequent replacement transactions. Hosting-provider backups and operational logs are separate copies subject to the provider's retention and recovery controls; deletion from active service does not immediately erase those copies.

Company records remain while the company is active unless changed, deleted, or replaced by an authorized user. Removed attachments retain their bytes for recovery until an authorized manual purge; there is no automatic expiry. Company deletion removes app access and attachment metadata, while physical file deletion requires operator action. Contact us for a permanent-deletion request; we will assess remaining recovery copies and any applicable legal recordkeeping requirements. We do not promise immediate erasure from provider backups.

Settings → Account provides account deletion, and account management is also available from the company chooser without opening a company. An account must transfer or delete its owned companies before it can be deleted. Deleting an account removes its authentication profile and memberships; it does not delete companies owned by other users. Business records and audit history in remaining companies can retain the originating account identifier. Uninstalling the app does not delete hosted companies or exported copies.

For accounts linked to Apple, deletion offers fresh Apple verification so the server can revoke the Apple authorization. Authorization codes and exchanged tokens are used only for that request. If verification is unavailable, you can still delete the MedERP account and follow the displayed instructions to disconnect MedERP in your Apple Account settings.

Local caches and exported backups are separate copies. Their removal is controlled by the device or destination owner. For access, correction, or deletion requests that cannot be completed in the app, contact support.

Security and support

The hosted app uses HTTPS, authenticated commands, company-scoped row-level access policies, role checks and TOTP authentication. Owner/admin company access, accounts with an enrolled authenticator, and account deletion require a verified second factor. The device copy uses the app container and operating-system protections. No storage method is completely secure. Keep account credentials and verification codes private.

If you email support, Medembark LLC and its email provider receive the address, message, and attachments you send to respond and investigate the request. We retain correspondence as needed to resolve requests and meet applicable recordkeeping obligations. Contact us to request access, correction, or deletion. Do not send business records or backup packages until a suitable transfer method has been agreed.

The public website has no advertising, analytics scripts, account registration, or submission forms. Email links open your email application. Its hosting and network providers process ordinary request information, such as IP address, requested page, browser details, and access time, to deliver and protect the website.

MedERP is business operations software and is not directed to children. It does not provide medical advice, diagnosis, treatment, patient records, or clinical decision support.

Contact Medembark LLC

For privacy questions or requests, email info@medembark.com. We will respond to requests for access, correction, or deletion and explain any applicable retention restrictions.