Privacy Policy
Last updated: August 29, 2026
This is a policy document, not legal advice — have it reviewed by a privacy attorney before you rely on it for launch.
Overview
This policy explains what MedBit — the app and the small amount of backend infrastructure behind it — can and cannot see about you. It's written to be precise rather than reassuring: where we genuinely cannot access something, we say so; where we can, we say exactly what and why.
The short version: your medical records, documents, medications, and every other piece of health content you enter are encrypted on your device with a key we never have. We could not read them even if compelled to. You may see MedBit described elsewhere using language like “HIPAA-grade” encryption — that refers to the strength of our technical safeguards, not a legal certification. See “Regulatory framework” below for the precise legal picture.
Definitions
- Vault
- The collection of encrypted health and personal records you create in the App.
- Recovery phrase
- The 12-word BIP-39 phrase generated on your device at signup. Every encryption key MedBit uses is derived from it, and it is never transmitted to or stored by MedBit.
- End-to-end encrypted (E2EE)
- Data is encrypted on your device, with a key only you hold, before it is ever written to storage or transmitted anywhere.
- Personal health record (PHR)
- A record of identifiable health information that an individual — not a doctor, insurer, or clearinghouse — creates and maintains. Regulators use this term to describe consumer apps like MedBit that are not HIPAA-covered entities.
- De-identified data
- Data with identifying details removed so it can't reasonably be linked back to you. MedBit does not currently generate or use de-identified data from vault content for any purpose.
How MedBit is built to protect you
MedBit is end-to-end encrypted on the client side. When you create or restore a vault, you receive a 12-word recovery phrase. Every encryption key MedBit uses — the vault key, the backup transport key, the identity key used to sign requests — is derived from that phrase entirely on your device.
The phrase itself, and every key derived from it, is never transmitted to or stored by our servers. Our servers only ever receive a public key (to verify request signatures) and, separately, opaque encrypted bytes they cannot open.
Regulatory framework
MedBit stores information that would typically be considered sensitive health data, so several overlapping frameworks are relevant even though — as explained below — HIPAA itself is not one of them in the traditional sense.
| Law | Applies because… | Our approach |
|---|---|---|
| HIPAA | Binds “covered entities” (health plans, healthcare clearinghouses, most providers) and their “business associates.” MedBit has no clinical, insurance, or provider relationship with you — everything in your vault comes from you — so MedBit is not a HIPAA covered entity or business associate, and HIPAA's rules don't directly govern our practices. There is also no official government “HIPAA certification” that any app can obtain — no federal agency certifies apps as HIPAA compliant. | We designed MedBit's architecture to meet or exceed the technical safeguards HIPAA's Security Rule requires of covered entities anyway: encryption of data at rest and in transit, strict access controls, audit logging, and minimum-necessary data collection on our servers. |
| FTC Health Breach Notification Rule (16 CFR Part 318) | Applies to vendors of personal health records offered directly to consumers — like MedBit — that fall outside HIPAA. | If a breach of unsecured identifiable health information ever occurs, we will notify affected individuals without unreasonable delay and no later than 60 days after discovery, and will notify the FTC as required (and the media, if a breach affects 500 or more residents of a state or jurisdiction). |
| State comprehensive health-data laws (e.g., Washington's My Health My Data Act, Nevada SB 370) | Give residents of certain states specific rights over “consumer health data,” reaching further than HIPAA — including the right to know what's collected and to withdraw consent for its collection or sharing. | We do not sell consumer health data, and any health-adjacent metadata our servers collect is limited to what's needed to run features you've actively chosen to enable. See “Your rights and choices” below. |
| California CCPA/CPRA & Confidentiality of Medical Information Act (CMIA) | CCPA/CPRA classifies health information as “sensitive personal information” and gives California residents rights to know, delete, correct, and limit its use. CMIA separately protects medical information handled by certain California businesses. | California residents can exercise the rights described below. We do not sell or share personal information for cross-context behavioral advertising, and we run no advertising or analytics SDKs at all. |
| COPPA | Protects children under 13 from having personal information collected online without parental consent. | MedBit is not directed to children under 13, and we do not knowingly collect information from them. |
| GDPR / UK GDPR | May apply if we process personal data of individuals located in the EU/UK. | MedBit is currently designed and offered for a U.S. audience. If you access MedBit from the EU/UK, contact us before relying on this policy for GDPR purposes — our international-transfer safeguards are still being finalized (see “International data transfers”). |
Data we can never see
The following lives only in your on-device encrypted vault, and — if you enable Cloud Backup — as a doubly-encrypted blob in cloud storage. We cannot decrypt any of it under any circumstances, including in response to a legal request, because the decryption key never exists anywhere but your device.
| Category | Fields |
|---|---|
| Profile | Full name, date of birth, sex, blood type, height, weight, phone |
| Emergency contacts | Name, relationship, phone |
| Allergies | Allergen, reaction, severity |
| Insurance plans | Payer, plan name/type, member ID, group ID, subscriber name, effective date, phone, attached card scan |
| Medical records | Visits, labs, imaging, surgeries, immunizations, and medications, each with their own details |
| Documents | Uploaded PDFs and photos — insurance cards, lab reports, scans — stored as encrypted files |
| Medication reminders & intake logs | Labels, schedules, and taken/missed/skipped history |
| Health trackers | Definitions and logged entries across 22 preset kinds (blood pressure, glucose, weight, mood, sleep, and more) plus custom trackers |
| Care tasks & appointments | Titles, due dates, locations, providers, and notes |
| Your on-device activity log | A record of your own sign-ins, unlocks, and views — visible only to you, in the App |
| Entitlement grants | Which paid features you've unlocked |
Data our servers do store
This is the complete list of what we actually collect. None of it is vault content — it's the minimum metadata needed to operate the optional backend features described below.
| Category | Fields | Purpose |
|---|---|---|
| Account | An account ID derived from your public key, the public key itself, account timestamps | Authenticate requests and identify your account, without using any real-world identifier |
| Account email (optional) | The email address you enter at signup, if any | Legally required breach notification only — never used to authenticate, look up, or link accounts, and never linked to vault content |
| Cloud Backup metadata | Version number, storage location, byte size, checksum, upload timestamp | Operate the optional Encrypted Cloud Backup feature. The backup content itself is opaque, double-encrypted ciphertext we cannot open. |
| Caregiver alert configuration | Your caregiver's email address, an optional display label, verification status | Send a generic “please check in” email if you enable Caregiver Check-In Alerts — never a medication name, appointment title, or other vault content |
| Check-in scheduling markers | An opaque ID, a due timestamp, a grace period | Know that something is due for your account, never what — used only with Caregiver Check-In Alerts enabled |
| Operational & access logs | Account ID, action type, IP address, timestamp | Security, fraud prevention, and operating the service |
Third parties
We share the minimum necessary data with the vendors below, and with no one else. We do not sell your personal information, and we never have. We run no analytics, crash-reporting, or advertising SDKs of any kind, and MedBit collects no product-usage telemetry beyond the operational logs described above.
| Third party | Data shared | Purpose |
|---|---|---|
| Cloud storage (backup hosting) | Opaque, double-encrypted backup blobs | Store your Encrypted Cloud Backup, only if you enable it |
| Transactional email provider | Your caregiver's email address, and a verification code or generic check-in alert | Deliver Caregiver Check-In Alerts, only if you enable them |
| Apple App Store / Google Play | Purchase transactions, handled entirely by Apple/Google | Process in-app purchases — MedBit's server never receives or stores payment information |
Biometrics and notifications
Face ID / fingerprint unlock happens entirely inside your device's own operating system. MedBit receives only a success or failure result and never has access to any biometric data, template, or image.
Reminder notifications are scheduled entirely on-device and never touch the network — no reminder content is sent to our servers, and no push token is registered with MedBit. Notification text (which may include a medication name you chose) will appear in your device's own notification tray, governed by your device's settings rather than ours.
Data retention
Vault content lives on your device for as long as you keep it there — we have no copy to retain or delete on your behalf. If you enable Cloud Backup, every historical backup version is retained until you delete your account or manually remove it. Account, billing-adjacent, and operational log data is retained for as long as your account is active and for a limited period afterward as needed for security, fraud prevention, and legal compliance.
Your rights and choices
- Delete your account at any time from Profile. This permanently erases your local vault and, if used, your server-side backups and account.
- Export individual records or documents out of the App via your device's native share sheet, at any time.
- Access requests: because vault content is encrypted with a key only you hold, we cannot produce a decrypted export of your data on your behalf — only you, using your recovery phrase, can access it. This is a direct consequence of true end-to-end encryption, not a limitation on your rights: everything we could hand over, you can already export yourself.
- Correction: update any vault field directly in the App at any time — we have no separate copy to correct.
- Opt-out of sale/sharing: not applicable — we do not sell or share personal information with third parties for monetary or other valuable consideration.
Additional rights for California residents
Under the CCPA/CPRA, California residents may request to know the categories of personal information we've collected, request deletion, request correction, and opt out of the sale or sharing of personal information (which, again, we do not do). To exercise these rights, contact us using the information below.
Additional rights for Washington and Nevada residents
Washington's My Health My Data Act and Nevada SB 370 give residents of those states specific rights over consumer health data, including the right to withdraw consent for its collection and sharing. We do not sell consumer health data. If you're a Washington or Nevada resident and want to exercise these rights or have questions about how they apply to MedBit, contact us using the information below.
Children's privacy
MedBit is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
International data transfers
MedBit is currently designed and offered for a U.S. audience, and our infrastructure providers may store data in the United States. If we expand support for international users, this section will be updated with the specific safeguards that apply (such as Standard Contractual Clauses for EU/UK data).
Data breach notification
Because vault content is end-to-end encrypted, a breach of our servers alone could not expose your medical records, documents, or any other vault content — there is nothing decryptable there to expose. If a breach of unsecured identifiable health information (such as an account email or caregiver contact) ever does occur, we will notify affected individuals and regulators as described in “Regulatory framework” above and as required by applicable state breach-notification laws.
Changes to this policy
We may update this policy from time to time. We'll reflect material changes by updating the “Last updated” date above and, for significant changes, by showing an in-app notice.
Quick reference: can MedBit see this?
| Data | Decrypted access? |
|---|---|
| Medical records, documents, trackers, reminders, profile, insurance, emergency contacts | No — never, under any circumstance |
| Your recovery phrase and every key derived from it | No — never leaves your device |
| Account email (if you provided one) | Yes, plaintext — collected only for breach notification |
| Caregiver alert email and display label | Yes, plaintext — needed to send the alert |
| Check-in due times | Yes, but content-free — we know something is due, never what |
| Backup size, version, checksum, timestamps | Yes, metadata only — never the backup's content |
| IP address, request timestamps, action names | Yes — via operational and access logs |
| Purchase or payment details | No — handled entirely by Apple/Google |
| Biometric data | No — never leaves your device's own authentication layer |
Contact us
Questions about this policy, or requests to exercise any of the rights above, can be sent to [support contact email to be added].