eForms Privacy Policy

Effective and last updated: 1 October 2026

Independent software. eForms (Android package app.offlineform.companion) is an independently developed Android client configured to work with the University of Manchester eForms service. It is not affiliated with, endorsed by, authorised by, sponsored by or published by the University of Manchester.

Summary: eForms uses data only to provide its form, offline storage, synchronisation, attendance and reliability features. It has no advertising, does not sell personal data, and has no developer-operated database or analytics service. Data required for real eForms use is sent directly to the Manchester eForms service. A release configured for crash reporting may also send technical crash data to Google Firebase Crashlytics as described below.

Who provides this app and how to contact the developer

The app is provided by the independent developer identified on its Google Play store listing. Privacy questions or requests about the Android app can be submitted using the monitored developer contact shown under App support on that listing. Questions or rights requests concerning records held in the University of Manchester eForms service should be directed to the University through its official channels.

Data the app accesses and processes

Depending on the forms assigned to the signed-in user, eForms may access or process:

Passwords and multi-factor authentication details are entered into the service owner's secure sign-in pages. eForms does not ask for or save the user's password.

How the data is used

The app uses this information only to authenticate service requests; download, display and search assigned forms; populate supported form fields; enable encrypted offline editing; save and synchronise drafts; queue submissions safely in the Outbox; display Drafts, Outbox and Sent folders; show dashboards and attendance status; and open the correct attendance form for a selected session.

If the user adds the optional attendance home-screen widget, Android schedules a system-batched check approximately hourly. The widget recalculates its green, amber or red status from the encrypted offline cache and, when the user remains signed in and the device is online, may refresh eForms data while the app is not open. It does not display session titles, form answers or other personal details on the home screen. The app does not run a continuous background service.

Storage and security

Offline records are held in app-private storage and encrypted using AES-256-GCM with a non-exportable Android Keystore key. Android cloud backup is disabled. Network traffic is restricted to HTTPS. The sign-in browser may follow secure HTTPS addresses selected by the service's authentication provider, but blocks insecure HTTP and local-file addresses. No system can be guaranteed completely secure.

Sharing and third parties

Real-account information is transmitted directly between the device and www.onemedforms.manchester.ac.uk to provide actions requested by the user and the optional attendance refresh described above. Data held by that service is subject to the University of Manchester's own policies and retention rules.

The app does not sell personal or sensitive data and does not share it with advertisers or data brokers. Google Analytics and advertising SDKs are not included.

Crash reporting

Release builds configured with Google Firebase Crashlytics use it as a service provider to diagnose crashes and application-not-responding events. Reports may include stack traces, relevant application state, app version, device model, Android version and an installation identifier. The app does not deliberately attach names, University usernames, form answers, signatures or session cookies to crash reports.

Crash data is encrypted in transit to Google. Firebase states that Crashlytics crash traces and associated identifiers are retained for 90 days before removal begins. See Privacy and Security in Firebase. Builds in which Crashlytics collection is disabled do not send these reports.

Retention and deletion

Encrypted offline information remains on the device until the user logs out and erases it, clears the app's storage, or uninstalls the app. Logging out removes the local vault, session cookies, account hash and encryption key from the device. This does not delete records already held by Manchester eForms or crash reports already sent to Google.

Draft deletion is a separate confirmed action and may also delete the matching online draft. The app does not create University accounts and cannot delete a user's University or Manchester eForms account. Requests concerning those accounts or server-side records must be made to the University.

Play review demo

The optional Play review demo contains invented sample data only. Demo changes remain on the device and external eForms synchronisation is disabled.

Changes to this policy

This policy will be updated when the app's data practices materially change. The effective date above identifies the latest version. The privacy text available inside the app describes the same core data practices.