Privacy policy
Last updated: 14 September 2026
This policy covers MyMedi as a whole. Health data is covered separately, in the Consumer Health Data Privacy Policy, because Washington’s My Health My Data Act and Nevada SB 370 require that policy to be a distinct document with its own link. If you are here about your medical records, read that one.
Who we are
MyMedi. Contact: privacy@getmymedi.app
What we collect
Waitlist. If you join from this website, we store the email address you enter so we can tell you when MyMedi is available. That is not health data.
Account information. An email address, or the private relay address Apple provides if you use Sign in with Apple. Nothing else is required to use MyMedi.
Subscription status. If you subscribe, RevenueCat and Apple tell us that an entitlement is active and when it expires. We never see your payment details. Apple processes the payment; we only ever learn the outcome.
Diagnostic information. Crash reports and error logs, if you opt in. These are engineering diagnostics only and are scrubbed of record contents.
Your medical records and everything derived from them are covered by the Consumer Health Data Privacy Policy.
What we do not collect
- No precise location. The app requests no location permission.
- No advertising identifiers. MyMedi has no advertising SDK.
- No cross-app tracking. MyMedi does not use App Tracking Transparency.
- No third-party analytics receiving health data. Ever.
Children
MyMedi is not for children under 13 and we do not knowingly collect their data. If we learn we have, we delete it. A parent or guardian who believes their child has an account should contact us and we will remove it.
Your choices
- Ask us to remove a waitlist email by writing to privacy@getmymedi.app.
- Withdraw consent to third-party AI processing in Settings.
- Delete individual records, or your whole account, from within the app.
- Exercise access, copy, deletion, and appeal rights through Settings → Your rights.
Security
- Row-level security on every table.
- Private storage with short-lived signed links only.
- Session tokens encrypted with a key in the device Keychain.
- Health data is never stored in iCloud.
- Server-side API keys never ship inside the app.
If we discover a breach affecting your data we will notify you and the relevant regulators as required, including under the FTC Health Breach Notification Rule. MyMedi is not a HIPAA covered entity.
MyMedi is not a medical provider
MyMedi stores and restates what your documents say. It does not diagnose, does not assess, and does not advise. Nothing in the app is medical advice, and it is not a substitute for a conversation with a clinician.
Changes
Material changes are announced in the app. Changes affecting how health data is handled require fresh consent rather than continuing on consent already given.