User guide

Meals and health records

Add photos or manual entries, review them and find meals and readings in Records.

Records is the home for food logs, blood pressure, blood glucose and other supported readings. The four main tabs are Today, Community, Records and You. Controls available on your phone depend on its installed build. Photo availability depends on the API configuration, installed build and permissions.

How do I find an existing record?

Open Records to see the newest entries first. Filter by All records, Food, Blood pressure, Blood glucose or Other records, then load older records when needed. Swipe the category row sideways to see more filters. An empty category has an All records button to return to the full timeline. If loading older entries fails, use Try again beside the message; the entries already loaded stay visible. Related values from one entry appear together, such as the two blood pressure values. Food entries can open their original foods and portions.

Check the date, unit and source. Manual entries, reviewed photo results and imported readings have different origins. Recording a value does not interpret it, diagnose a condition or recommend treatment.

How do I add food, blood pressure or glucose?

Choose Scan photo to identify a meal, blood pressure monitor or glucose meter. Open Record manually to choose food catalogue search, blood pressure, blood glucose, pulse or weight. Tap the heading again to close these secondary choices. These simplified controls are included in mobile 1.6.2 source; an updated installed build is required.

For a meal, search the catalogue, select foods and adjust portions before reviewing and saving. Calories are estimates based on the selected catalogue entries and portions. Some catalogue nutrition values remain provisional. See Log a meal.

How do I enter a reading manually?

Enter the digits from your device. Blood pressure requires both systolic and diastolic values. For glucose, select the unit the meter displays; do not place an mg/dL number in a mmol/L field or the reverse. The app handles supported unit conversion for storage.

Read the health-storage notice, choose whether to save to your private passport, then select Review reading. Check the values, units and time again before confirming. Manual entry currently uses the time when you prepare the review.

If a save is uncertain, keep that review active and retry the same entry. Once you leave or restart, the app retains an attempt receipt rather than a draft containing your health values. Check Records before acknowledging that you checked and starting a new entry. This helps avoid duplicates; it is not an offline save queue.

How does photo review work?

Photo support currently covers food, BP and glucose. The app checks availability before enabling capture. If the category is unavailable, use its manual or food-search option instead.

Read the displayed processing notice, including the named recipients and processing location, before agreeing to upload. Keep the relevant display and its unit visible. Avoid unrelated people, identity documents and other private information in the frame.

A result is a draft. Check the detected values, units, time and confidence against the original device or meal, correct mistakes, then explicitly confirm storage. Both BP values are required; a glucose unit is not guessed from an unreadable display. Confidence is not measured accuracy. For food, check the detected items and portions. The server prefers a matching food catalogue entry. If there is no match, it can use the clearly labelled AI calorie estimate from that photo. Adjusting the portion changes the estimate; you can select a catalogue match instead.

Analysis alone does not save a passport record. If confirmation is uncertain, follow the status/retry action for that same attempt rather than starting a duplicate.

Where does a photo go?

After explicit agreement, supported food, BP and glucose photos can be processed through OpenRouter by Azure in the United States. The route requires provider zero retention, no training and disabled prompt logging. A controlled self-hosted processor may instead be configured; always check the current in-app notice.

MedBuk does not retain food photos. Identified meter images are encrypted and retained for up to 30 days as evidence. Analysis drafts expire after 24 hours. Identity documents, MyKad and lab reports are not supported by this hosted scan flow. If the image is mixed, unclear or unsupported, retake it or enter the relevant record manually.

Are records shared with my employer or a club?

Your passport is private by default. Club participation, welcome rewards and medical-leave requests do not grant access to it. Practitioner access uses a separate care approval flow.

How do I export readings or request deletion?

Open Privacy & data from Records. The readings export is portable JSON, including food-energy readings and corrected history; it does not include practitioner-authored clinical documents. Review its scope and choose a trusted share or save destination. The app removes its temporary export file, but copies you choose to save or send remain at their destination. A failed or oversized export is not shared as if it were complete.

Open Account deletion from Privacy for the current availability, notice and request journey. A new request queues processing; it is not immediate deletion. The private receipt code can check status after the original account login has been erased. An old login cannot retrieve a completed receipt.

Clinical authorship/provenance, financial and reward history, safety, audit and agreement evidence have separately reviewed retention rules. Backup handling and operational activation remain release gates. See Account privacy for request, recovery and terms-acceptance details.

Can I switch off app usage analytics?

Yes. Updated app versions have an optional App usage analytics control in Privacy. It is off by default and records only whether a signed-in account used the app on a Malaysia calendar date. It excludes health values, photographs, contacts and screen paths. Turning it off stops collection and unlinks previous activity. Linked activity older than 90 days is processed by hourly retention cleanup. This is separate from health storage and social sharing. See Account privacy.

On this page