Privacy Policy
Last updated: July 19, 2026
1. The short version
- Your health data is yours. You can export it (JSON or FHIR R4) or erase it, self-service, at any time.
- We sell nothing. We do not sell or rent your personal data, and we do not use your health data for advertising.
- Sharing is consent-gated. Clinicians and organizations see your record only with a legitimate, consented care relationship — every access is logged and auditable.
- Security first. Sensitive health fields are encrypted at rest (AES-256), transport is TLS, access is role-based with two-factor step-up, and tenants are isolated at the database layer.
- AI with guardrails. Medicup AI processes your questions and photos to answer you — its output is safety-checked, and your data is not used to train third-party models.
2. Who is responsible for your data
The data controller for personal data processed through medicup.ai and the Medicup apps is Medicup (the operating entity stated on the contact page of medicup.ai). Where Medicup processes patient data on behalf of a healthcare organization using our enterprise features, that organization is the controller and Medicup acts as its processor under a data-processing agreement.
Privacy contact: [email protected]
3. What we collect
You provide: account details (name, email, sign-in identity), your health profile and records (conditions, medications, allergies, vitals, documents and images you upload), consultation and prescription records, consents, and anything you send to Medicup AI (questions, meal and symptom photos).
From your devices, with permission: camera-based heart readings, connected-wearable vitals, and location when you use Find Care or emergency features. Background monitoring runs only if you enable it.
Automatically: technical logs (IP address, device and app version, timestamps, security events), needed to run and secure the Services. We use only essential storage in the browser and apps (session, preferences, cache) — no advertising trackers.
Professional verification: for clinician and organization accounts, identity and license documents (KYC/KYB).
4. Why we process it (and the legal bases)
- Providing the Services — your record, AI answers, consultations, prescriptions, monitoring (performance of contract; for health data, your explicit consent and/or provision of care under applicable health law).
- Safety — emergency escalation you configure, abuse and fraud prevention, account security (vital interests; legitimate interests).
- Legal compliance — clinical record-keeping, audit trails, responding to lawful requests (legal obligation).
- Service improvement — aggregate, de-identified analytics; optional, consent-based contribution of de-identified data to improve medical answering. You can decline or withdraw without losing features.
Where consent is the basis, you can withdraw it at any time in the app, with effect for the future.
5. Medicup AI and your data
Your questions, photos, and relevant profile context are processed to generate answers, with retrieval from medical knowledge sources and safety checks. AI processing runs on infrastructure under our control or with vetted cloud providers under contractual data protections. Your identifiable health data is not used to train third-party foundation models, and any use of data to improve our own quality is either aggregate/de-identified or based on your explicit opt-in consent.
7. How we protect it
- Encryption in transit (TLS) and field-level AES-256-GCM encryption at rest for sensitive health fields;
- role-based access control enforced server-side, with mandatory two-factor step-up for critical clinical actions;
- database-level tenant isolation (row-level security) between organizations;
- append-only audit trails for record access and consent decisions;
- encrypted, off-site backups with tested restore procedures;
- verification of professional accounts (KYC/KYB) and email verification for all accounts.
No system is perfectly secure; if a breach affects your data we will notify you and the competent authorities as the law requires. Report vulnerabilities to [email protected].
8. HIPAA and regional health rules
Medicup is engineered to support HIPAA-grade handling of health information: encryption, access controls, audit trails, and FHIR-standard export. Where Medicup processes protected health information on behalf of a HIPAA-covered entity, it does so as a business associate under a Business Associate Agreement, and we maintain corresponding agreements with our HIPAA-eligible infrastructure providers. Equivalent protections are applied for users in other jurisdictions in line with local health-data law.
9. How long we keep data
Your account data is kept while your account exists. Clinical records created through licensed care (consultations, prescriptions) are retained for the period medical record-keeping law requires, even after account deletion, then deleted. Security and audit logs are kept for a limited period appropriate to their purpose. When you erase your account, personal health data is deleted immediately except where a legal retention duty applies; consent and audit trails are preserved in minimized form because the law requires us to be able to demonstrate them.
10. Your rights
Depending on where you live (including under GDPR), you have the right to:
- access your data and get a copy (in-app: Export, JSON or FHIR R4);
- rectify inaccurate data;
- erase your data (in-app: Erase my data) subject to legal retention;
- restrict or object to certain processing;
- portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time, without affecting past processing;
- complain to your data-protection authority.
Export and erasure are self-service in the app; for anything else contact [email protected] — we respond within the timelines the law sets (one month under GDPR).
11. International transfers
Our primary infrastructure is hosted in the European Union. Where data is transferred to providers outside your jurisdiction, we rely on recognized safeguards such as adequacy decisions or Standard Contractual Clauses, plus the technical protections described in Section 7.
12. Children
The Services are not directed at children. Accounts require the user to be an adult; health profiles for minors may only be managed by a parent or legal guardian where the Services support it, and we delete data collected from a child without such authority once we learn of it.
13. Changes to this policy
We will post any changes here and update the date above; for material changes we will notify you in the app or by email before they take effect.
14. Contact
Privacy requests and questions: [email protected]
General support: [email protected]
