Privacy Policy
Last updated: 2025-11-13. Effective immediately.
Short version: MedAI stores your medical records on your device only. We have no servers that store, process, or transmit your health data. We don't have accounts, we don't track you, and we don't share anything with anyone.
Who operates MedAI
MedAI is operated by an individual developer based in Washington State, USA, working under the project name PrivyApps. PrivyApps is not a registered business entity at this time. Contact information is in the Contact section below.
What data MedAI handles
MedAI exists to help you read, understand, and manage your own health data. The data it touches includes:
- Medical records you choose to import — from healthcare providers via SMART on FHIR (Epic MyChart, Oracle Health, athenahealth, and other certified EHRs).
- Documents you scan or upload — PDFs, photos of paperwork, lab printouts.
- Conversations with the on-device AI — questions you ask MedAI about your records and the AI's responses.
- App settings and preferences — which providers you've connected, profile information, app configuration.
Where your data lives
All of the above is stored exclusively in MedAI's local sandbox on your device. The database is encrypted with a key stored in your device's hardware-backed keystore (Apple Keychain on iOS, Android Keystore on Android).
We do not operate any servers that receive, store, or process your medical data. The only thing we host is this website (privacy policy, support information) which you are reading now.
Who else sees your data
Healthcare providers (you authorize)
When you connect MedAI to a healthcare provider (e.g., your hospital's MyChart), the provider's servers transmit your medical records directly to your device through an encrypted, OAuth-authenticated connection. This is the federally standardized SMART on FHIR protocol. Your records do not pass through our infrastructure at any point.
AI inference
MedAI's AI runs on-device using local language models (e.g., Apple Intelligence Foundation Models, MedGemma, Llama, or Phi). Your questions and your records never leave your device for AI processing.
If you explicitly opt-in to remote AI inference for better results (a feature you must enable in Settings), MedAI can send queries to your own self-hosted backend or to a third-party model provider you configure. In that case, the third party's privacy policy governs that data. Remote inference is off by default.
This website
This static website is hosted by Cloudflare. Cloudflare may log standard web server data (IP address, user agent, timestamps) for security and operational purposes per Cloudflare's privacy policy. We do not run analytics, tracking pixels, or behavioral profiling on this site.
What we do NOT collect, embed, or run
- We do not collect personally identifying information (no sign-up, no email, no phone, no demographic prompts).
- We do not collect device identifiers (no IDFA, no Android Advertising ID, no GAID, no device fingerprinting).
- We do not collect product analytics about how you use the app — no Mixpanel, Amplitude, PostHog, Firebase Analytics, Segment, or equivalent SDKs are linked into the app binary.
- We do not collect crash reports that contain personal data — no Crashlytics, Sentry, Bugsnag, etc. The app's source is open on GitHub; the dependency list is auditable.
- We do not embed advertising SDKs (no AdMob, no Meta Audience Network, no Google Ads tags). We do not run advertising of any kind.
- We do not embed any third-party tracker, pixel, beacon, or tag-management script. The static site you're reading carries no third-party JavaScript.
- We do not maintain user profiles or behavioral databases.
- We do not "sell" or "share" personal information under any state-law definition (CCPA/CPRA, CTDPA, WA MHMD, etc.).
App-store-provided information
Apple's App Store and Google Play may, when MedAI is published there, collect their own information about app downloads and updates per their respective privacy policies. We receive only aggregate, anonymous download counts from these platforms — never information that identifies individual users.
Children's privacy
MedAI is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. In accordance with the U.S. Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §6501 et seq.), a parent or legal guardian may install MedAI and use it to maintain a child's medical records on the parent's own device. The records belong to the child; the parent acts as their data steward. If you believe a child under 13 has installed MedAI without parental consent, contact us via the channels below and we'll help you wipe the device-local data (you don't need our help — uninstalling the app deletes everything — but we'll walk you through it).
No biometric data collection
MedAI does not collect, store, transmit, or process biometric identifiers or biometric information (face geometry, fingerprints, voiceprints, retina/iris scans, gait, etc.). Face ID / Touch ID and Android BiometricPrompt are used only as a local unlock gate — your device's biometric hardware verifies you to the OS, the OS hands MedAI a yes/no, and we never see the underlying biometric data. The biometric template stays in the device's secure enclave at all times.
State biometric-privacy laws — Illinois BIPA (740 ILCS 14), Texas CUBI (BCC §503.001), Washington (RCW 19.375), New York (NYC Admin. Code §22-1201) — apply only when an entity collects biometric identifiers. Since MedAI doesn't, these statutes don't reach us. We state this explicitly so users from those states can be certain.
Your rights
Because all of your data lives on your device, you have complete control:
- Access: Open the app — your data is right there.
- Export: Settings → Export — get all data as JSON.
- Deletion: Uninstall the app — all data is gone with it. Or use Settings → Delete All Data to wipe selectively.
- Correction: Edit any record in the app directly.
- Revoke EHR access: Disconnect any healthcare provider from Settings; the provider stops sending data immediately.
State-specific rights
Residents of certain U.S. states have additional protections under consumer-health and general-privacy statutes. We honor them automatically by virtue of not collecting your data on our servers:
- Washington — My Health My Data Act (RCW 19.373): no consumer health data is collected by MedAI's infrastructure, so no consumer-health-data sale, share, or geofence rights are implicated. See atg.wa.gov/MHMD.
- California — CMIA (Cal. Civ. Code §56) + CCPA / CPRA (Cal. Civ. Code §1798.100 et seq.): we do not "sell" or "share" personal information as those terms are defined; we do not run cross-context behavioral advertising; we are not a "business" with respect to your medical records because we never receive them.
- Connecticut — CTDPA (Public Act 22-15) + SB 3 (2023) consumer-health-data amendments: no targeted advertising, no sale of personal data, no profiling.
- Nevada — SB 220 (NRS Chapter 603A) + SB 370 consumer-health-data law: no sale of covered information.
- Texas — TMRPA (Tex. Health & Safety Code Ch. 181) + HB 4 Texas Data Privacy and Security Act: TMRPA covers "covered entities" handling identifiable health information; because MedAI never holds your records on a server, the operative obligations don't attach to us, but we adhere to the substantive standards (no sale, no targeted ads) regardless.
- Colorado — CPA (C.R.S. §6-1-1301 et seq.) + the 2024 sensitive-data amendments: no profiling, no sale of sensitive data (including health data).
- Virginia — VCDPA (Code of Virginia §59.1-575 et seq.): consumer rights honored by design (no data to access, delete, or correct on our end).
- Other states with comprehensive privacy laws (UT, IA, IN, TN, FL, MT, OR, DE, NJ, NH, KY, MD, MN, NE, RI): same posture applies. We collect nothing server-side.
Right of Access — what your providers owe you, not us
MedAI is not a HIPAA covered entity. Your hospital, clinic, and lab are. Under HIPAA's Right of Access (45 CFR §164.524), they must give you an electronic copy of your medical records — and when delivered automatically through certified FHIR APIs as required by ONC §170.315(g)(10), they must do so at no cost to you. MedAI is the tool that lets you exercise that right; we don't grant it to you and we can't take it away.
If a healthcare provider refuses or stalls, that may constitute information blocking under 45 CFR Part 171 — civil monetary penalties up to $1 million per violation apply to vendors who interfere. See our information-blocking guidance for how to file an ONC complaint.
FTC Health Breach Notification Rule
We are not a HIPAA covered entity, but under the FTC's Health Breach Notification Rule (16 CFR Part 318, as amended July 2024 to cover health apps and similar technologies), we treat ourselves as a non-HIPAA "vendor of personal health records" for purposes of breach notification — even though the Rule's collection element is, strictly read, absent (we collect none). If a security incident exposes on-device data to an unauthorized party in a way attributable to MedAI's code, we will notify affected users via this website and any reasonable means available to us within the timeframes the Rule requires (within 60 days; without unreasonable delay), and we will notify the FTC as required.
Because we hold no user data on servers, the realistic scenarios for a notifiable breach are narrow: a vulnerability in the App itself that lets one device's data exfiltrate, or compromise of this static site (which contains no personal data anyway).
Security
On-device data is encrypted at rest using SQLCipher with a 256-bit key stored in your device's secure enclave or hardware-backed keystore. Network connections to healthcare providers use TLS 1.2 or higher with certificate validation. The app's source code is open and may be reviewed by anyone at github.com/sgireddy/MedAI.
Changes to this policy
If we change this policy in a material way, we will publish the updated version here and note the change in the in-app About screen. The "Last updated" date at the top of this page reflects the most recent revision. We will not retroactively reduce your privacy protections.
Contact
Privacy questions, security disclosures, and general inquiries:
- GitHub Issues (preferred): github.com/sgireddy/MedAI/issues
- Email: (set up once Cloudflare Email Routing is configured — see support page)
This privacy policy reflects MedAI's actual data handling: zero server-side collection of medical data. We commit to maintaining this posture as a core principle, not just a current practice.