User guide

Changelog

Changes to MedBuk+, written for people using the app.

User guide 0.1.9 — 14 September 2026

Staging portal addresses now use purpose.medbuk.cenvora.dev. The access guide lists the new Platform, Corporate, Merchant and Partner links. Old web addresses redirect; users sign in again because cookies remain isolated to each host. The personal-user PWA address is planned and is not yet available.

Mobile 1.7.0 candidate / user guide 0.1.8 — 14 September 2026

The next mobile candidate supports configured Apple, Google and email-code sign-in, with a smaller Use Phone OTP instead option. Phone is not required after email or social signup. These options are not yet active in the installed 1.6.3 Preview; provider setup, deployment and device checks remain pending. Existing accounts should use their original method; automatic account merging is disabled.

Mobile 1.6.3 source / user guide 0.1.7 — 13 September 2026

Internal build setup now identifies the failed readiness check, retries a temporary server connection failure once and offers a check that does not start another build. The testing guide distinguishes device registration, Apple signing and installation. This source patch does not change app screens. A new signed iPhone/Android candidate and physical-device checks remain pending; no OTA or public store release is announced.

Mobile 1.6.2 source / user guide 0.1.6 — 13 September 2026

Records now has one Scan photo action and a collapsible Record manually menu for food, blood pressure, glucose, pulse and weight. The timeline renders a window of entries as you scroll. Empty categories offer a return to all records, and failed older-page requests show Try again beside the error while retaining loaded entries. Record labels and recovery messages are available in English, Bahasa Malaysia and Chinese.

The welcome overview now settles its version before showing the first slide, with a bounded bundled fallback when the network is unavailable. Late replies cannot replace visible artwork. Photo consent, review before saving and private-record access checks remain in place.

This is a source update with browser rehearsal; a new signed build and physical iOS/Android acceptance remain pending. The earlier Android 1.6.1 Preview APK does not include these changes. No OTA or public store release is announced.

Mobile 1.6.1 / user guide 0.1.5 — 12 September 2026

Internal mobile builds now prepare the shared app packages before bundling. This fixes an Android cloud-build failure that local builds did not reveal. An updated installed build is still required for the employee invitation screens; the older 1.2.0 development client does not contain them. iPhone Preview signing and exact-device verification remain separate steps. No public store release is announced.

Mobile 1.6.0 / Corporate 0.3.0 / user guide 0.1.4 — 12 September 2026

Corporate web invitations now offer employees a user initiated Open in MedBuk+ button before web sign-in or private preview. The invitation remains account-bound, expires within seven days and requires WhatsApp sign-in, separate invited-email proof and explicit acceptance. First-sign-in onboarding returns to the join flow. The button hides when preview identifies an owner, HR or another non-employee role; owners and HR use the email portal. Legacy Partner email links can be pasted directly into the app.

Production handoff guidance accepts the original Corporate or legacy Partner link or the raw private code. Staging uses a raw code or matching Preview/Beta scheme and does not use production links. The API is 1.16.0 and there is no schema change. An updated mobile build is required. Source, isolated integration and local browser checks passed. Mobile 1.6.0 is source only: a new signed build and physical iOS/Android acceptance remain pending. No public store download or store release is announced.

Portals 0.2.0 / Partner 0.3.0 / user guide 0.1.3 — 12 September 2026

Selection dropdowns now include search across Platform, Corporate, Merchant and the legacy Partner portal. Find workspaces, roles, stages, business/reward types, report periods, welcome versions and onboarding settings by typing part of the option label. Keyboard selection, required fields and existing save/review actions are preserved. Language selectors retain the same available documents and separate consent actions. See using searchable menus.

Platform 0.1.2 / user guide 0.1.2 — 12 September 2026

Platform reports now make automatic updates explicit. The Refresh now and Retry buttons are removed; visible online reports continue polling every 30 seconds, and returning to the tab or window or reconnecting after an outage requests a fresh snapshot immediately when no retry delay or access check is pending. Network and rate-limit backoff remains automatic. Invalid periods and removed or expired access still stop the report and require date correction or sign-in/access correction. This update applies to Platform analytics; Corporate and Merchant controls are unchanged.

See the Platform analytics guide.

Platform 0.1.1 / user guide 0.1.1 — 12 September 2026

Platform analytics now uses one Date range button with presets and a branded calendar with Apply and Cancel. Date changes are applied together; Cancel, Escape and outside dismissal discard unapplied edits. Malaysia-time weeks, inclusive ranges up to 366 days, future dates through next month and 30-second live polling remain unchanged. See the Platform analytics guide for the updated controls.

User guide 0.1.0 — 12 September 2026

The guide is now organised by role: Platform owner, Corporate, Merchant and App user. Each has its own starting page, task guides and sidebar navigation. Web portal sign-in links are included in the relevant guides and the access directory. Existing page links redirect to the new sections. Public app-store download links remain pending; invited testers should use the current installation instructions.

Separate portals — 12 September 2026

API 1.16.0 and portals 0.1.0 introduce separate access points for Platform, Corporate and Merchant.

Use your existing MedBuk email account where it has access. Each portal asks for its own sign-in. Platform uses a password; Corporate and Merchant offer a password or email code, including password recovery. Existing Partner links remain available. See portal access for the login and invitation journeys.

Backup and recovery safeguards — 12 September 2026

API 1.15.1 separates scheduled backups and maintenance from the public API. Backup access is read-only; maintenance can remove expired private receipt codes. Failed jobs are recorded and retried with a delay.

An off-host recovery test restored the stored backup and used a synthetic account to check that deletion replay removes its login and readings from an older snapshot. New account-deletion requests and mandatory terms acceptance remain inactive while company review, operational activation and device checks are completed. See Account privacy.

Account privacy preparation — 12 September 2026

API 1.15.0, mobile 1.5.0 and Partner 0.2.0 add account-deletion requests, private status receipts and versioned terms acceptance. Receipt checks work after the deleted account's login is removed. The web request flow includes a separate existing-account WhatsApp login; corporate and merchant login remains email-based.

New deletion requests and mandatory terms acceptance remain inactive pending legal publication, monitored contacts, retention and deletion/backup operations review. No effective terms or App Store/Google Play release is announced. See Account privacy.

Website 0.2.0 preparation — 12 September 2026

The website now describes corporate invitation and medical-leave reporting more accurately, and distinguishes passport-data deletion from complete account closure. Outdated API and provider-availability statements have been removed.

A branded legal reading layout and versioned publication checks are prepared for review. Draft terms are kept out of the public site while the legal pack and support/deletion journeys are completed. This entry does not announce effective terms or a mobile-store release.

Mobile 1.4.0 testing preparation — 12 September 2026

MedBuk now has separate Dev, Preview, Beta and production build configurations. Preview and Beta use the staging service; their app names and build details identify them as testing apps. Testers will receive installation links after the corresponding builds finish. This entry does not announce an App Store or Google Play release.

The API 1.14.1 patch supports the testing apps’ sign-in verification links and a deployment check used before submitting builds. Existing personal and workspace sign-in methods are preserved. See Testing MedBuk.

Website icons — 12 September 2026

MedBuk’s partner portal, landing page, user guide and API reference now use the same approved passport icon in browser tabs, bookmarks and Apple home-screen shortcuts. Partner and landing version: 0.1.1; documentation sites: 0.0.25.

1.14.0 — Email sign-in for workspaces

Corporate and merchant clients can choose Password or Email code at sign-in. New invitees verify their email before creating an account and explicitly accept their workspace invitation. The portal also includes Forgot password and code-based reset; a completed reset signs out existing sessions.

Merchant owners can now receive reviewed email invitations, with separate delivery and acceptance status, replacement links and revocation. Corporate and merchant workspaces keep their own navigation, permissions and analytics within one portal.

Platform administrators continue to use email and password. Personal mobile sign-in is unchanged. See Email sign-in and invitations.

1.13.0 — Workspace settings, employee lists and MC photos · 11 September 2026

Mobile changes require an updated build and physical-device checks. An older installed app may not include the new photo controls; this API entry is not a mobile-store release.

  • Both documentation sites now use the MedBuk+ logo, colours and clearer navigation. Overview links that led to missing pages are fixed, with automatic link checks for future updates.
  • Active corporate owners can edit company and business-contact display names in Workspace settings with a fresh passkey. HR has read-only access. Version checks prevent overwriting a newer edit; contact email remains read-only. Active-company email changes and ownership transfers are not included.
  • Owners and HR can review a pasted list of up to 20 employee emails before sending. Invitations run one at a time through the existing flow. Its 10-per-minute limit still applies, so a list may stop partway through. Errors and uncertain outcomes stop sending; nothing is silently retried. Remaining unsent recipients require another review. This is not a CSV importer.
  • Medical-leave requests can include one JPEG or PNG photo up to 2 MiB. The photo is normalized to JPEG, stripped of EXIF metadata and encrypted, with a 90-day expiry and 20 unexpired photos per account. Photo-storage consent and employer photo-sharing consent are separate; drafts stay private.
  • Current authorised owners/HR with a fresh passkey can view explicitly shared MC photos from current employees. Withdrawal and offboarding stop further HR viewing; account erasure and expiry also remove access. Previously viewed copies cannot be recalled. MC photos are not sent to hosted AI; PDF upload, authenticity verification and automatic clinical-record transfer are not included.
  • Platform owner invitations more clearly separate pending acceptance from email delivery status, with a Resend invitation control for replacing an unused link. Pending-prospect contact changes still require revoking the existing invitation first.

Read Corporate workspaces, Workspace invitations and Medical-leave requests.

1.12.0 — Corporate workspaces and invitations · 11 September 2026

API and partner portal released. Native app and inbox-delivery acceptance remain separate.

  • Corporate administrators can prepare company prospects, invite an owner by email, and suspend or reactivate an onboarded workspace. Each company stays separate.
  • Owners and HR can review recipients before sending team invitations. Employees sign in by phone and verify the invited email separately. Owners, HR and merchant staff must finish passkey setup and a fresh passkey sign-in before accepting a role. Platform administrators continue to use email/password.
  • Merchant and corporate analytics have separate platform and workspace views. Corporate reports show membership and invitation operations, with no health values. The MC summary is available: only company owners/HR with a fresh passkey can see counts of already-submitted requests and pending/approved calendar days, including future leave dates. Platform reports cannot see these counts; they are not predictions.
  • Date choices include full calendar weeks/months and custom Malaysia-time ranges up to 366 days. Future dates have no observations; activity outside retained coverage is unavailable. Analytics update every 30 seconds while visible and online and pause when sign-in is needed.
  • Reviewed non-owner access removal is available and passed integration tests. It preserves the person's account and records; owner transfer is not included.

This release added email configuration for controlled onboarding verification; provider acceptance does not prove inbox delivery. Medical leave in 1.12.0 accepted a text certificate reference only. Optional MC photos are part of 1.13.0.

Read Corporate workspaces, Workspace invitations, Analytics definitions and Medical leave. Mobile installation and device validation are separate from the API release.

1.11.0 — App analytics and Singapore hosting · 11 September 2026

  • A new Analytics page groups sign-up dates, active users, welcome progress, rewards and merchant performance, with Malaysia calendar dates and 7/30/90-day views.
  • Optional app usage measurement is off by default. Updated mobile source includes its Privacy control; older installed builds do not provide active-user data.
  • The portal's server functions now run in Singapore near the API and database. Repeated session reads within one page render are shared.
  • The existing five-merchant pilot and admin reward approval remain available.

Read metric definitions and coverage. API 1.11.0 remains compatible with /v1. Mobile changes are development source, not a store release.

API 1.10.0 — 11 September 2026 · Merchant pilot

  • Added a collapsible platform sidebar, live overview and searchable merchant directory.
  • Service and product merchants can be invited into a five-place pilot using links tied to their verified WhatsApp number.
  • Merchant owners can upload sign-up reward images and submit offers for admin review. Drafts stay private; only approved offers appear in the app.
  • Admins choose one reward per merchant or one across the pilot before publication. The choice locks when the first offer is published.
  • Added invitation expiry, replacement and revocation, conflict protection and audited reward approvals.

API 1.9.1 — 11 September 2026

Successful admin logins no longer count toward the failed-password limit.

API 1.9.0 — 11 September 2026

Platform administrators now use their email address and password. The admin page has two fields and a single sign-in action. Operator-managed passwords attach to existing accounts; replacing one signs out every device. Public admin signup is closed, and account recovery is handled by an authorized operator.

API 1.8.0 — 11 September 2026

Platform administrators can now sign in with a WhatsApp verification code. The admin entry goes directly from phone verification to the workspace; no passkey setup is required. Access still needs an explicitly assigned platform role and a recent successful sign-in.

API 1.7.0 — 11 September 2026

Platform administrators now have a setup page showing phone verification, passkey registration, passkey sign-in and role approval. After approval, the workspace links directly to the onboarding editor. Platform access remains separate from merchant and employer access, and does not expose individual questionnaire answers.

API 1.6.0 / mobile 1.2.0 development — 10 September 2026

  • Cleaner club and member profiles, with Followers / Following lists and a member directory inside each club.
  • Separate controls for showing connections and appearing in a club. Existing memberships stay hidden unless you choose otherwise. Leaving clears that choice.
  • Private follow requests, club-owner approvals and report/block controls remain available. Health passports stay separate from social profiles.
  • English, Malay and Simplified Chinese labels, plus clearer loading and retry states.
  • WhatsApp verification codes for phone sign-in, with a clear delivery notice, resend controls and messages for connection or delivery problems.

The API and partner portal are deployed. The mobile app remains a development release. Returning from WhatsApp keeps the code-entry form; an existing code can also be entered without requesting another. Some retries may ask for a Cloudflare security check. Workspace access additionally requires a passkey and an assigned role.

Existing records are preserved. An older account is linked to a phone only after its ownership has been independently verified; signing in does not claim someone else’s records.

Mobile 1.1.0 development build — not generally released

API 1.5.0 is deployed with versioned onboarding and automatic photo recognition. Mobile development build 6 is ready for installation; installation and real-device checks are still in progress. A finished build does not mean every flow is enabled or verified on your phone.

  • Getting started is shorter and optional. Explore the welcome screens, create an account or sign in, then choose goals and interests when you want to. Setup questions can be skipped. You can resume, export or remove your saved setup data. Platform administrators see completion and grouped answers, not individual response lists. See Welcome and setup.
  • One photo can start a record. Choose Scan photo under Records for food, a blood-pressure display or a glucose display. After your processor consent, AI identifies the category and prepares editable results. Review values and units before saving; food calories are estimates. Unreadable or unsupported photos need a retake. Manual entry remains available. See Meals and health records.
  • Community previews have illustrated covers. Demo clubs, events and challenges have photorealistic artwork labelled AI-generated. Images load into stable frames and respect reduced motion; the activity information stays readable if an image cannot load. This interface update is in the development app JavaScript.
  • Records brings meals and readings together. Food, blood pressure, glucose and other supported entries share one timeline. Choose a category, add a photo or enter values manually, review before saving, and load older records. Food entries can open their saved foods and portions. See Meals and health records.
  • Your sharing choices stay separate. Join clubs, events and challenges, manage follows, and choose whether to appear on a leaderboard or event display. Challenge steps start counting when you join. Foreground progress is provisional and does not qualify for reward payouts. See Community.
  • Care and work requests have their own approvals. Review a practitioner's request before granting temporary access. Medical-leave drafts stay private until you submit them to a workplace. See Care access and Medical leave.
  • Welcome rewards have a complete claim and collection flow. Review the campaign rules, reserve an available offer and show a private QR or short code to its merchant. Staff verify before confirming redemption. No welcome campaign has been published in this batch; offer details, dates and stock still need confirmation. See Welcome rewards.
  • Notifications and language have more controls. Manage your private inbox, categories and device registration, and choose English, Bahasa Melayu or Simplified Chinese for supported screens and generic messages. Push delivery needs separate service setup; some screens and authored content are still English. See Notifications and language.
  • Privacy controls show what an action does. Export readings as JSON or request account-data deletion and check its receipt. Deletion is queued, with separate handling for retained clinical/financial/audit records, login-provider accounts and backups. A request is not immediate erasure of every record.
  • MedBuk+ has its corporate identity and onboarding artwork. A short mascot clip has a static fallback and respects reduced motion. Navigation remains available without waiting for playback.

Photo analysis is enabled with explicit consent and pilot request limits. The app shows availability before upload. Push delivery remains disabled and no welcome campaign is published. Real sign-in, permissions and the complete signed-in phone flows still need verification. The app records information and estimates; it does not diagnose a condition or interpret readings as medical advice.

On this page