eForms Privacy Policy
Effective and last updated: 1 October 2026
Independent software. eForms (Android package
app.offlineform.companion) is an independently developed Android client
configured to work with the University of Manchester eForms service. It is not
affiliated with, endorsed by, authorised by, sponsored by or published by the
University of Manchester.
Who provides this app and how to contact the developer
The app is provided by the independent developer identified on its Google Play store listing. Privacy questions or requests about the Android app can be submitted using the monitored developer contact shown under App support on that listing. Questions or rights requests concerning records held in the University of Manchester eForms service should be directed to the University through its official channels.
Data the app accesses and processes
Depending on the forms assigned to the signed-in user, eForms may access or process:
- Manchester authentication session cookies and synchronisation status;
- a University username entered after sign-in, which is immediately converted to a context-separated SHA-256 hash; the username itself is not stored by the app;
- assigned form definitions, workspace names and population or session details;
- identity, education, placement, attendance, health or clinical information present in assigned forms or entered by the user;
- form answers, free text, dates, selections and handwritten signatures;
- existing attachment metadata, drafts, Outbox items, submitted-form copies and related identifiers or timestamps; and
- technical crash and diagnostic data described under “Crash reporting”.
Passwords and multi-factor authentication details are entered into the service owner's secure sign-in pages. eForms does not ask for or save the user's password.
How the data is used
The app uses this information only to authenticate service requests; download, display and search assigned forms; populate supported form fields; enable encrypted offline editing; save and synchronise drafts; queue submissions safely in the Outbox; display Drafts, Outbox and Sent folders; show dashboards and attendance status; and open the correct attendance form for a selected session.
If the user adds the optional attendance home-screen widget, Android schedules a system-batched check approximately hourly. The widget recalculates its green, amber or red status from the encrypted offline cache and, when the user remains signed in and the device is online, may refresh eForms data while the app is not open. It does not display session titles, form answers or other personal details on the home screen. The app does not run a continuous background service.
Storage and security
Offline records are held in app-private storage and encrypted using AES-256-GCM with a non-exportable Android Keystore key. Android cloud backup is disabled. Network traffic is restricted to HTTPS. The sign-in browser may follow secure HTTPS addresses selected by the service's authentication provider, but blocks insecure HTTP and local-file addresses. No system can be guaranteed completely secure.
Sharing and third parties
Real-account information is transmitted directly between the device and
www.onemedforms.manchester.ac.uk to provide actions requested by the user and
the optional attendance refresh described above. Data held by that service is subject to
the University of Manchester's own policies and retention rules.
The app does not sell personal or sensitive data and does not share it with advertisers or data brokers. Google Analytics and advertising SDKs are not included.
Crash reporting
Release builds configured with Google Firebase Crashlytics use it as a service provider to diagnose crashes and application-not-responding events. Reports may include stack traces, relevant application state, app version, device model, Android version and an installation identifier. The app does not deliberately attach names, University usernames, form answers, signatures or session cookies to crash reports.
Crash data is encrypted in transit to Google. Firebase states that Crashlytics crash traces and associated identifiers are retained for 90 days before removal begins. See Privacy and Security in Firebase. Builds in which Crashlytics collection is disabled do not send these reports.
Retention and deletion
Encrypted offline information remains on the device until the user logs out and erases it, clears the app's storage, or uninstalls the app. Logging out removes the local vault, session cookies, account hash and encryption key from the device. This does not delete records already held by Manchester eForms or crash reports already sent to Google.
Draft deletion is a separate confirmed action and may also delete the matching online draft. The app does not create University accounts and cannot delete a user's University or Manchester eForms account. Requests concerning those accounts or server-side records must be made to the University.
Play review demo
The optional Play review demo contains invented sample data only. Demo changes remain on the device and external eForms synchronisation is disabled.
Changes to this policy
This policy will be updated when the app's data practices materially change. The effective date above identifies the latest version. The privacy text available inside the app describes the same core data practices.