Introduction
Your privacy is fundamental to us at MyMedVisit. This Privacy Policy describes how we collect, use, protect, and handle your information when you use our voice-first health companion mobile application.
By using MyMedVisit, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Personal Information
- Phone number – Used for account authentication and verification
- Name and demographic information – To personalize your experience
- Profile information – Any additional details you choose to provide
Health Information
- Voice recordings – Temporarily processed to understand your health queries (not permanently stored)
- Health journal entries – Symptoms, concerns, and notes you record
- Medication information – Prescriptions and supplements you track
- Health insights – AI-generated recommendations based on your queries
Technical Information
- Device data – Device type, operating system version, unique device identifiers
- Usage analytics – Features you use, session duration, interaction patterns
- Performance data – Crash reports, error logs, and diagnostic information
How We Use Your Information
We use your information to:
- Provide our core services – Process voice queries, generate health insights, and maintain your health journal
- Personalize your experience – Tailor recommendations and reminders to your needs
- Secure your account – Verify your identity and prevent unauthorized access
- Improve our services – Analyze usage patterns and enhance AI accuracy
- Communicate with you – Send health reminders, app updates, and important notifications
- Ensure compliance – Meet legal and regulatory requirements
Voice Data Processing
Your voice recordings are:
- Processed in real-time to convert speech to text
- Sent to OpenAI's API for natural language understanding
- Not permanently stored after processing is complete
- Used only to answer your specific health query
Data Security
We employ robust security measures to protect your information:
- Encryption – All sensitive data is encrypted in transit (TLS) and at rest (AES-256)
- HIPAA compliance – We follow HIPAA guidelines for handling protected health information
- Secure infrastructure – Data stored on Firebase with enterprise-grade security
- Access controls – Strict authentication and role-based access limitations
- Regular audits – Ongoing security assessments and penetration testing
- Incident response – Established protocols for detecting and responding to breaches
Third-Party Services
We work with trusted service providers who help us deliver our services:
| Service Provider | Purpose | Data Shared |
|---|
| OpenAI | AI processing and natural language understanding | Voice transcripts, health queries |
| Twilio | SMS authentication and notifications | Phone number, verification codes |
| Firebase (Google) | Cloud storage and authentication | User data, health journals |
All third-party providers are bound by strict confidentiality agreements and process data only as directed by us.
Data Sharing and Disclosure
We do not sell, rent, or trade your personal or health information.
We may disclose your information only in these limited circumstances:
- With your explicit consent – When you authorize sharing with your healthcare provider
- Legal obligations – To comply with court orders, subpoenas, or applicable laws
- Safety and security – To protect against fraud, abuse, or threats to safety
- Business transfers – In the event of a merger or acquisition (with advance notice to you)
Your Privacy Rights
You have the following rights regarding your data:
- Access – Request a copy of all personal data we hold about you
- Correction – Update inaccurate or incomplete information
- Deletion – Request complete removal of your account and associated data
- Export – Download your health journal and personal data in a portable format
- Opt-out – Disable notifications, analytics, or specific features
- Withdraw consent – Revoke permissions you've previously granted
To exercise these rights, visit Settings > Privacy in the app or contact us at privacy@mymedvisit.app.
Data Retention
- Active accounts – We retain your data for as long as your account remains active
- Deleted accounts – Data is permanently deleted within 30 days of account deletion request
- Legal retention – Certain data may be retained longer when required by law or for legitimate business purposes (e.g., fraud prevention, dispute resolution)
International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable laws.
Children's Privacy
MyMedVisit is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@mymedvisit.app, and we will delete such information.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. When we make material changes:
- We will update the "Last Updated" date at the top
- We will notify you via in-app notification or email
- Continued use of the app after changes constitutes acceptance of the updated policy
We encourage you to review this policy regularly to stay informed about how we protect your information.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices:
Email: privacy@mymedvisit.app
Response time: We aim to respond within 48 hours