MedAI

Privacy Policy

Last updated: 2025-11-13. Effective immediately.

Short version: MedAI stores your medical records on your device only. We have no servers that store, process, or transmit your health data. We don't have accounts, we don't track you, and we don't share anything with anyone.

Who operates MedAI

MedAI is operated by an individual developer based in Washington State, USA, working under the project name PrivyApps. PrivyApps is not a registered business entity at this time. Contact information is in the Contact section below.

What data MedAI handles

MedAI exists to help you read, understand, and manage your own health data. The data it touches includes:

Where your data lives

All of the above is stored exclusively in MedAI's local sandbox on your device. The database is encrypted with a key stored in your device's hardware-backed keystore (Apple Keychain on iOS, Android Keystore on Android).

We do not operate any servers that receive, store, or process your medical data. The only thing we host is this website (privacy policy, support information) which you are reading now.

Who else sees your data

Healthcare providers (you authorize)

When you connect MedAI to a healthcare provider (e.g., your hospital's MyChart), the provider's servers transmit your medical records directly to your device through an encrypted, OAuth-authenticated connection. This is the federally standardized SMART on FHIR protocol. Your records do not pass through our infrastructure at any point.

AI inference

MedAI's AI runs on-device using local language models (e.g., Apple Intelligence Foundation Models, MedGemma, Llama, or Phi). Your questions and your records never leave your device for AI processing.

If you explicitly opt-in to remote AI inference for better results (a feature you must enable in Settings), MedAI can send queries to your own self-hosted backend or to a third-party model provider you configure. In that case, the third party's privacy policy governs that data. Remote inference is off by default.

This website

This static website is hosted by Cloudflare. Cloudflare may log standard web server data (IP address, user agent, timestamps) for security and operational purposes per Cloudflare's privacy policy. We do not run analytics, tracking pixels, or behavioral profiling on this site.

What we do NOT collect, embed, or run

App-store-provided information

Apple's App Store and Google Play may, when MedAI is published there, collect their own information about app downloads and updates per their respective privacy policies. We receive only aggregate, anonymous download counts from these platforms — never information that identifies individual users.

Children's privacy

MedAI is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. In accordance with the U.S. Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §6501 et seq.), a parent or legal guardian may install MedAI and use it to maintain a child's medical records on the parent's own device. The records belong to the child; the parent acts as their data steward. If you believe a child under 13 has installed MedAI without parental consent, contact us via the channels below and we'll help you wipe the device-local data (you don't need our help — uninstalling the app deletes everything — but we'll walk you through it).

No biometric data collection

MedAI does not collect, store, transmit, or process biometric identifiers or biometric information (face geometry, fingerprints, voiceprints, retina/iris scans, gait, etc.). Face ID / Touch ID and Android BiometricPrompt are used only as a local unlock gate — your device's biometric hardware verifies you to the OS, the OS hands MedAI a yes/no, and we never see the underlying biometric data. The biometric template stays in the device's secure enclave at all times.

State biometric-privacy laws — Illinois BIPA (740 ILCS 14), Texas CUBI (BCC §503.001), Washington (RCW 19.375), New York (NYC Admin. Code §22-1201) — apply only when an entity collects biometric identifiers. Since MedAI doesn't, these statutes don't reach us. We state this explicitly so users from those states can be certain.

Your rights

Because all of your data lives on your device, you have complete control:

State-specific rights

Residents of certain U.S. states have additional protections under consumer-health and general-privacy statutes. We honor them automatically by virtue of not collecting your data on our servers:

Right of Access — what your providers owe you, not us

MedAI is not a HIPAA covered entity. Your hospital, clinic, and lab are. Under HIPAA's Right of Access (45 CFR §164.524), they must give you an electronic copy of your medical records — and when delivered automatically through certified FHIR APIs as required by ONC §170.315(g)(10), they must do so at no cost to you. MedAI is the tool that lets you exercise that right; we don't grant it to you and we can't take it away.

If a healthcare provider refuses or stalls, that may constitute information blocking under 45 CFR Part 171 — civil monetary penalties up to $1 million per violation apply to vendors who interfere. See our information-blocking guidance for how to file an ONC complaint.

FTC Health Breach Notification Rule

We are not a HIPAA covered entity, but under the FTC's Health Breach Notification Rule (16 CFR Part 318, as amended July 2024 to cover health apps and similar technologies), we treat ourselves as a non-HIPAA "vendor of personal health records" for purposes of breach notification — even though the Rule's collection element is, strictly read, absent (we collect none). If a security incident exposes on-device data to an unauthorized party in a way attributable to MedAI's code, we will notify affected users via this website and any reasonable means available to us within the timeframes the Rule requires (within 60 days; without unreasonable delay), and we will notify the FTC as required.

Because we hold no user data on servers, the realistic scenarios for a notifiable breach are narrow: a vulnerability in the App itself that lets one device's data exfiltrate, or compromise of this static site (which contains no personal data anyway).

Security

On-device data is encrypted at rest using SQLCipher with a 256-bit key stored in your device's secure enclave or hardware-backed keystore. Network connections to healthcare providers use TLS 1.2 or higher with certificate validation. The app's source code is open and may be reviewed by anyone at github.com/sgireddy/MedAI.

Changes to this policy

If we change this policy in a material way, we will publish the updated version here and note the change in the in-app About screen. The "Last updated" date at the top of this page reflects the most recent revision. We will not retroactively reduce your privacy protections.

Contact

Privacy questions, security disclosures, and general inquiries:


This privacy policy reflects MedAI's actual data handling: zero server-side collection of medical data. We commit to maintaining this posture as a core principle, not just a current practice.