Privacy Policy
Last updated: 2026-08-30. Effective immediately.
Short version: MediVaultAI stores your medical records on your device only. We have no servers that store, process, or transmit your health data. We don't have accounts, we don't track you, and we don't share anything with anyone.
Who operates MediVaultAI
MediVaultAI is operated by an individual developer based in Washington State, USA, working under the project name PrivyApps. PrivyApps is not a registered business entity at this time. Contact information is in the Contact section below.
What data MediVaultAI handles
MediVaultAI exists to help you read, understand, and manage your own health data. The data it touches includes:
- Medical records you choose to import — from healthcare providers via SMART on FHIR (Epic MyChart, Oracle Health, athenahealth, and other certified EHRs).
- Documents you scan or upload — PDFs, photos of paperwork, lab printouts.
- Conversations with the on-device AI — questions you ask MediVaultAI about your records and the AI's responses.
- App settings and preferences — which providers you've connected, profile information, app configuration.
Where your data lives
All of the above is stored exclusively in MediVaultAI's local sandbox on your device. The database is encrypted with a key stored in your device's hardware-backed keystore (Apple Keychain on iOS, Android Keystore on Android).
We do not operate any servers that receive, store, or process your medical data. The only thing we host is this website (privacy policy, support information) which you are reading now.
Does anyone else see your health data?
No. We do not share your health data with anyone, and it never passes through our servers — because we do not operate any servers that receive it. There is no third party we hand your records, questions, or AI conversations to.
Healthcare providers are a source, not a recipient
When you connect MediVaultAI to a healthcare provider (e.g., your hospital's MyChart), the connection is inbound only: the provider's servers send your records to your device through an encrypted, OAuth-authenticated connection using the federally standardized SMART on FHIR protocol. The provider already holds your records — connecting simply lets you download your own copy. MediVaultAI does not send your records, documents, questions, notes, or AI conversations back to the provider, and none of it passes through our infrastructure at any point. (The provider does see the standard OAuth sign-in that you perform to authorize the download, the same as any app you connect to your patient portal.)
AI runs on your device
MediVaultAI answers your questions using a language model that runs entirely on your device (for example, Apple Intelligence Foundation Models, MedGemma, Llama, or Phi). Your questions and your records are never sent anywhere for AI processing. MediVaultAI has no cloud-inference feature — the app does not send your data to any remote AI service, and there is no user setting that turns one on.
MediVaultAI is open source, so full transparency: the code contains a developer-only build flag used for local testing of alternative model backends. It is gated to debug builds, is not present in the App Store or Google Play releases, and cannot be enabled by users. Shipped builds are on-device only.
This website
This static website is hosted by Cloudflare. Cloudflare may log standard web server data (IP address, user agent, timestamps) for security and operational purposes per Cloudflare's privacy policy. We do not run analytics, tracking pixels, or behavioral profiling on this site, and the site never receives any of your health data.
What we do NOT collect, embed, or run
- We do not collect personally identifying information (no sign-up, no email, no phone, no demographic prompts).
- We do not collect device identifiers (no IDFA, no Android Advertising ID, no GAID, no device fingerprinting).
- We do not collect product analytics about how you use the app — no Mixpanel, Amplitude, PostHog, Firebase Analytics, Segment, or equivalent SDKs are linked into the app binary.
- We do not collect crash reports that contain personal data — no Crashlytics, Sentry, Bugsnag, etc. The app's source is open on GitHub; the dependency list is auditable.
- We do not embed advertising SDKs (no AdMob, no Meta Audience Network, no Google Ads tags). We do not run advertising of any kind.
- We do not embed any third-party tracker, pixel, beacon, or tag-management script. The static site you're reading carries no third-party JavaScript.
- We do not maintain user profiles or behavioral databases.
- We do not "sell" or "share" personal information under any state-law definition (CCPA/CPRA, CTDPA, WA MHMD, etc.).
App-store-provided information
Apple's App Store and Google Play may, when MediVaultAI is published there, collect their own information about app downloads and updates per their respective privacy policies. We receive only aggregate, anonymous download counts from these platforms — never information that identifies individual users.
Children's privacy
MediVaultAI is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. In accordance with the U.S. Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §6501 et seq.), a parent or legal guardian may install MediVaultAI and use it to maintain a child's medical records on the parent's own device. The records belong to the child; the parent acts as their data steward. If you believe a child under 13 has installed MediVaultAI without parental consent, contact us via the channels below and we'll help you wipe the device-local data (you don't need our help — uninstalling the app deletes everything — but we'll walk you through it).
No biometric data collection
MediVaultAI does not collect, store, transmit, or process biometric identifiers or biometric information (face geometry, fingerprints, voiceprints, retina/iris scans, gait, etc.). Face ID / Touch ID and Android BiometricPrompt are used only as a local unlock gate — your device's biometric hardware verifies you to the OS, the OS hands MediVaultAI a yes/no, and we never see the underlying biometric data. The biometric template stays in the device's secure enclave at all times.
State biometric-privacy laws — Illinois BIPA (740 ILCS 14), Texas CUBI (BCC §503.001), Washington (RCW 19.375), New York (NYC Admin. Code §22-1201) — apply only when an entity collects biometric identifiers. Since MediVaultAI doesn't, these statutes don't reach us. We state this explicitly so users from those states can be certain.
Your rights
Because all of your data lives on your device, you have complete control:
- Access: Open the app — your data is right there.
- Export: Settings → Export — get all data as JSON.
- Deletion: Uninstall the app — all data is gone with it. Or use Settings → Delete All Data to wipe selectively.
- Correction: Edit any record in the app directly.
- Revoke EHR access: Disconnect any healthcare provider from Settings; the provider stops sending data immediately.
State-specific rights
Residents of certain U.S. states have additional protections under consumer-health and general-privacy statutes. We honor them automatically by virtue of not collecting your data on our servers:
- Washington — My Health My Data Act (RCW 19.373): no consumer health data is collected by MediVaultAI's infrastructure, so no consumer-health-data sale, share, or geofence rights are implicated. See atg.wa.gov/MHMD.
- California — CMIA (Cal. Civ. Code §56) + CCPA / CPRA (Cal. Civ. Code §1798.100 et seq.): we do not "sell" or "share" personal information as those terms are defined; we do not run cross-context behavioral advertising; we are not a "business" with respect to your medical records because we never receive them.
- Connecticut — CTDPA (Public Act 22-15) + SB 3 (2023) consumer-health-data amendments: no targeted advertising, no sale of personal data, no profiling.
- Nevada — SB 220 (NRS Chapter 603A) + SB 370 consumer-health-data law: no sale of covered information.
- Texas — TMRPA (Tex. Health & Safety Code Ch. 181) + HB 4 Texas Data Privacy and Security Act: TMRPA covers "covered entities" handling identifiable health information; because MediVaultAI never holds your records on a server, the operative obligations don't attach to us, but we adhere to the substantive standards (no sale, no targeted ads) regardless.
- Colorado — CPA (C.R.S. §6-1-1301 et seq.) + the 2024 sensitive-data amendments: no profiling, no sale of sensitive data (including health data).
- Virginia — VCDPA (Code of Virginia §59.1-575 et seq.): consumer rights honored by design (no data to access, delete, or correct on our end).
- Other states with comprehensive privacy laws (UT, IA, IN, TN, FL, MT, OR, DE, NJ, NH, KY, MD, MN, NE, RI): same posture applies. We collect nothing server-side.
Right of Access — what your providers owe you, not us
MediVaultAI is not a HIPAA covered entity. Your hospital, clinic, and lab are. Under HIPAA's Right of Access (45 CFR §164.524), they must give you an electronic copy of your medical records — and when delivered automatically through certified FHIR APIs as required by ONC §170.315(g)(10), they must do so at no cost to you. MediVaultAI is the tool that lets you exercise that right; we don't grant it to you and we can't take it away.
If a healthcare provider refuses or stalls, that may constitute information blocking under 45 CFR Part 171 — civil monetary penalties up to $1 million per violation apply to vendors who interfere. See our information-blocking guidance for how to file an ONC complaint.
FTC Health Breach Notification Rule
We are not a HIPAA covered entity, but under the FTC's Health Breach Notification Rule (16 CFR Part 318, as amended July 2024 to cover health apps and similar technologies), we treat ourselves as a non-HIPAA "vendor of personal health records" for purposes of breach notification — even though the Rule's collection element is, strictly read, absent (we collect none). If a security incident exposes on-device data to an unauthorized party in a way attributable to MediVaultAI's code, we will notify affected users via this website and any reasonable means available to us within the timeframes the Rule requires (within 60 days; without unreasonable delay), and we will notify the FTC as required.
Because we hold no user data on servers, the realistic scenarios for a notifiable breach are narrow: a vulnerability in the App itself that lets one device's data exfiltrate, or compromise of this static site (which contains no personal data anyway).
Security
On-device data is encrypted at rest, using each platform's hardware-backed protection:
- Android: the local database is encrypted with SQLCipher (256-bit AES), with the key held in the Android Keystore.
- iOS: the local database file is protected by iOS Data Protection (hardware-backed AES), with keys held in the Secure-Enclave-backed Apple Keychain.
OAuth tokens for provider connections are stored in the same hardware-backed keystore/Keychain. Network connections to healthcare providers use TLS 1.2 or higher with certificate validation. The app's source code is open and may be reviewed by anyone at github.com/sgireddy/MedAI.
Changes to this policy
If we change this policy in a material way, we will publish the updated version here and note the change in the in-app About screen. The "Last updated" date at the top of this page reflects the most recent revision. We will not retroactively reduce your privacy protections.
Contact
Privacy questions, security disclosures, and general inquiries:
- GitHub Issues (preferred): github.com/sgireddy/MedAI/issues
- Email: (set up once Cloudflare Email Routing is configured — see support page)
This privacy policy reflects MediVaultAI's actual data handling: zero server-side collection of medical data. We commit to maintaining this posture as a core principle, not just a current practice.