User guide

Account privacy

Account-deletion requests, private receipts and published terms.

Availability

The new mobile and web flows are prepared for testing. New deletion requests and mandatory general terms acceptance are not enabled until MedBuk's legal and operational reviews are complete. This guide does not announce a store release. Use the availability shown in your current app; an older installation may not have these controls.

Request deletion

Open Privacy → Account deletion. The web request page is also available through the partner portal's Signed-in devices → Delete account or check receipt link. You can reach the page without installing the mobile app.

When requests are available, sign in to your existing account, read the English or Bahasa Malaysia notice, check the processing deadline and confirm the request. Corporate and merchant accounts use email sign-in. Personal accounts can use the separate WhatsApp sign-in on the deletion page. This does not create a new account. You may be asked to sign in again if your last authentication is no longer recent.

Keep the private receipt code. It checks this request's state after your account login is removed. It is not a login code: never share it publicly or put it in a link. Receipt lookup remains available if new requests are temporarily disabled.

Understand the status

StatusMeaning
PendingThe request was received and is waiting for processing.
ProcessingDeletion is underway.
CompletedDeletion of the app data described in the notice has completed.
FailedProcessing did not complete; contact the displayed support channel.

A receipt is available for 30 days. An unknown or expired code cannot show status. After a connection failure, check the saved receipt before repeating the request. Your old MedBuk login cannot retrieve a completed request once its credentials have been erased. A different signed-in account cannot see the deleted account's records.

Deletion removes tracker readings, meals, stored capture images, social profile and connections, notification registrations, onboarding answers and employee leave submissions. Unused welcome claims are cancelled. Clinical authorship/provenance, financial/redemption history, safety, audit and agreement evidence have separate retention rules. Backup handling is also separate. Read the notice shown before confirmation for the current scope; this does not delete WhatsApp or your email account.

Terms and privacy choices

When reviewed terms are published, MedBuk can ask you to read and accept the current version. The receipt records the document version, language, content hash and time. If the text changes while you are reading, reload it before deciding. Draft terms cannot be accepted.

Terms acceptance does not turn on health storage, AI photo uploads, social sharing, notifications or optional analytics. Those choices remain separate. Privacy, deletion and safety controls remain available when a new agreement is required.

Recovery preparation

Scheduled backups now run separately from the public API. Recovery tests include restoring an older backup and checking that a deleted test account's login and readings are removed again before that restored copy could be used.

This is an engineering safeguard. Account deletion remains inactive until the published contact details, retention rules, operational process and device checks are ready. Backup retention and external processor cleanup still require review.

On this page