Privacy Policy

Last updated: August 29, 2026

This is a policy document, not legal advice — have it reviewed by a privacy attorney before you rely on it for launch.

Overview

This policy explains what MedBit — the app and the small amount of backend infrastructure behind it — can and cannot see about you. It's written to be precise rather than reassuring: where we genuinely cannot access something, we say so; where we can, we say exactly what and why.

The short version: your medical records, documents, medications, and every other piece of health content you enter are encrypted on your device with a key we never have. We could not read them even if compelled to. You may see MedBit described elsewhere using language like “HIPAA-grade” encryption — that refers to the strength of our technical safeguards, not a legal certification. See “Regulatory framework” below for the precise legal picture.

Definitions

Vault
The collection of encrypted health and personal records you create in the App.
Recovery phrase
The 12-word BIP-39 phrase generated on your device at signup. Every encryption key MedBit uses is derived from it, and it is never transmitted to or stored by MedBit.
End-to-end encrypted (E2EE)
Data is encrypted on your device, with a key only you hold, before it is ever written to storage or transmitted anywhere.
Personal health record (PHR)
A record of identifiable health information that an individual — not a doctor, insurer, or clearinghouse — creates and maintains. Regulators use this term to describe consumer apps like MedBit that are not HIPAA-covered entities.
De-identified data
Data with identifying details removed so it can't reasonably be linked back to you. MedBit does not currently generate or use de-identified data from vault content for any purpose.

How MedBit is built to protect you

MedBit is end-to-end encrypted on the client side. When you create or restore a vault, you receive a 12-word recovery phrase. Every encryption key MedBit uses — the vault key, the backup transport key, the identity key used to sign requests — is derived from that phrase entirely on your device.

The phrase itself, and every key derived from it, is never transmitted to or stored by our servers. Our servers only ever receive a public key (to verify request signatures) and, separately, opaque encrypted bytes they cannot open.

Regulatory framework

MedBit stores information that would typically be considered sensitive health data, so several overlapping frameworks are relevant even though — as explained below — HIPAA itself is not one of them in the traditional sense.

LawApplies because…Our approach
HIPAABinds “covered entities” (health plans, healthcare clearinghouses, most providers) and their “business associates.” MedBit has no clinical, insurance, or provider relationship with you — everything in your vault comes from you — so MedBit is not a HIPAA covered entity or business associate, and HIPAA's rules don't directly govern our practices. There is also no official government “HIPAA certification” that any app can obtain — no federal agency certifies apps as HIPAA compliant.We designed MedBit's architecture to meet or exceed the technical safeguards HIPAA's Security Rule requires of covered entities anyway: encryption of data at rest and in transit, strict access controls, audit logging, and minimum-necessary data collection on our servers.
FTC Health Breach Notification Rule (16 CFR Part 318)Applies to vendors of personal health records offered directly to consumers — like MedBit — that fall outside HIPAA.If a breach of unsecured identifiable health information ever occurs, we will notify affected individuals without unreasonable delay and no later than 60 days after discovery, and will notify the FTC as required (and the media, if a breach affects 500 or more residents of a state or jurisdiction).
State comprehensive health-data laws (e.g., Washington's My Health My Data Act, Nevada SB 370)Give residents of certain states specific rights over “consumer health data,” reaching further than HIPAA — including the right to know what's collected and to withdraw consent for its collection or sharing.We do not sell consumer health data, and any health-adjacent metadata our servers collect is limited to what's needed to run features you've actively chosen to enable. See “Your rights and choices” below.
California CCPA/CPRA & Confidentiality of Medical Information Act (CMIA)CCPA/CPRA classifies health information as “sensitive personal information” and gives California residents rights to know, delete, correct, and limit its use. CMIA separately protects medical information handled by certain California businesses.California residents can exercise the rights described below. We do not sell or share personal information for cross-context behavioral advertising, and we run no advertising or analytics SDKs at all.
COPPAProtects children under 13 from having personal information collected online without parental consent.MedBit is not directed to children under 13, and we do not knowingly collect information from them.
GDPR / UK GDPRMay apply if we process personal data of individuals located in the EU/UK.MedBit is currently designed and offered for a U.S. audience. If you access MedBit from the EU/UK, contact us before relying on this policy for GDPR purposes — our international-transfer safeguards are still being finalized (see “International data transfers”).

Data we can never see

The following lives only in your on-device encrypted vault, and — if you enable Cloud Backup — as a doubly-encrypted blob in cloud storage. We cannot decrypt any of it under any circumstances, including in response to a legal request, because the decryption key never exists anywhere but your device.

CategoryFields
ProfileFull name, date of birth, sex, blood type, height, weight, phone
Emergency contactsName, relationship, phone
AllergiesAllergen, reaction, severity
Insurance plansPayer, plan name/type, member ID, group ID, subscriber name, effective date, phone, attached card scan
Medical recordsVisits, labs, imaging, surgeries, immunizations, and medications, each with their own details
DocumentsUploaded PDFs and photos — insurance cards, lab reports, scans — stored as encrypted files
Medication reminders & intake logsLabels, schedules, and taken/missed/skipped history
Health trackersDefinitions and logged entries across 22 preset kinds (blood pressure, glucose, weight, mood, sleep, and more) plus custom trackers
Care tasks & appointmentsTitles, due dates, locations, providers, and notes
Your on-device activity logA record of your own sign-ins, unlocks, and views — visible only to you, in the App
Entitlement grantsWhich paid features you've unlocked

Data our servers do store

This is the complete list of what we actually collect. None of it is vault content — it's the minimum metadata needed to operate the optional backend features described below.

CategoryFieldsPurpose
AccountAn account ID derived from your public key, the public key itself, account timestampsAuthenticate requests and identify your account, without using any real-world identifier
Account email (optional)The email address you enter at signup, if anyLegally required breach notification only — never used to authenticate, look up, or link accounts, and never linked to vault content
Cloud Backup metadataVersion number, storage location, byte size, checksum, upload timestampOperate the optional Encrypted Cloud Backup feature. The backup content itself is opaque, double-encrypted ciphertext we cannot open.
Caregiver alert configurationYour caregiver's email address, an optional display label, verification statusSend a generic “please check in” email if you enable Caregiver Check-In Alerts — never a medication name, appointment title, or other vault content
Check-in scheduling markersAn opaque ID, a due timestamp, a grace periodKnow that something is due for your account, never what — used only with Caregiver Check-In Alerts enabled
Operational & access logsAccount ID, action type, IP address, timestampSecurity, fraud prevention, and operating the service

Third parties

We share the minimum necessary data with the vendors below, and with no one else. We do not sell your personal information, and we never have. We run no analytics, crash-reporting, or advertising SDKs of any kind, and MedBit collects no product-usage telemetry beyond the operational logs described above.

Third partyData sharedPurpose
Cloud storage (backup hosting)Opaque, double-encrypted backup blobsStore your Encrypted Cloud Backup, only if you enable it
Transactional email providerYour caregiver's email address, and a verification code or generic check-in alertDeliver Caregiver Check-In Alerts, only if you enable them
Apple App Store / Google PlayPurchase transactions, handled entirely by Apple/GoogleProcess in-app purchases — MedBit's server never receives or stores payment information

Biometrics and notifications

Face ID / fingerprint unlock happens entirely inside your device's own operating system. MedBit receives only a success or failure result and never has access to any biometric data, template, or image.

Reminder notifications are scheduled entirely on-device and never touch the network — no reminder content is sent to our servers, and no push token is registered with MedBit. Notification text (which may include a medication name you chose) will appear in your device's own notification tray, governed by your device's settings rather than ours.

Data retention

Vault content lives on your device for as long as you keep it there — we have no copy to retain or delete on your behalf. If you enable Cloud Backup, every historical backup version is retained until you delete your account or manually remove it. Account, billing-adjacent, and operational log data is retained for as long as your account is active and for a limited period afterward as needed for security, fraud prevention, and legal compliance.

Your rights and choices

  • Delete your account at any time from Profile. This permanently erases your local vault and, if used, your server-side backups and account.
  • Export individual records or documents out of the App via your device's native share sheet, at any time.
  • Access requests: because vault content is encrypted with a key only you hold, we cannot produce a decrypted export of your data on your behalf — only you, using your recovery phrase, can access it. This is a direct consequence of true end-to-end encryption, not a limitation on your rights: everything we could hand over, you can already export yourself.
  • Correction: update any vault field directly in the App at any time — we have no separate copy to correct.
  • Opt-out of sale/sharing: not applicable — we do not sell or share personal information with third parties for monetary or other valuable consideration.

Additional rights for California residents

Under the CCPA/CPRA, California residents may request to know the categories of personal information we've collected, request deletion, request correction, and opt out of the sale or sharing of personal information (which, again, we do not do). To exercise these rights, contact us using the information below.

Additional rights for Washington and Nevada residents

Washington's My Health My Data Act and Nevada SB 370 give residents of those states specific rights over consumer health data, including the right to withdraw consent for its collection and sharing. We do not sell consumer health data. If you're a Washington or Nevada resident and want to exercise these rights or have questions about how they apply to MedBit, contact us using the information below.

Children's privacy

MedBit is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

International data transfers

MedBit is currently designed and offered for a U.S. audience, and our infrastructure providers may store data in the United States. If we expand support for international users, this section will be updated with the specific safeguards that apply (such as Standard Contractual Clauses for EU/UK data).

Data breach notification

Because vault content is end-to-end encrypted, a breach of our servers alone could not expose your medical records, documents, or any other vault content — there is nothing decryptable there to expose. If a breach of unsecured identifiable health information (such as an account email or caregiver contact) ever does occur, we will notify affected individuals and regulators as described in “Regulatory framework” above and as required by applicable state breach-notification laws.

Changes to this policy

We may update this policy from time to time. We'll reflect material changes by updating the “Last updated” date above and, for significant changes, by showing an in-app notice.

Quick reference: can MedBit see this?

DataDecrypted access?
Medical records, documents, trackers, reminders, profile, insurance, emergency contactsNo — never, under any circumstance
Your recovery phrase and every key derived from itNo — never leaves your device
Account email (if you provided one)Yes, plaintext — collected only for breach notification
Caregiver alert email and display labelYes, plaintext — needed to send the alert
Check-in due timesYes, but content-free — we know something is due, never what
Backup size, version, checksum, timestampsYes, metadata only — never the backup's content
IP address, request timestamps, action namesYes — via operational and access logs
Purchase or payment detailsNo — handled entirely by Apple/Google
Biometric dataNo — never leaves your device's own authentication layer

Contact us

Questions about this policy, or requests to exercise any of the rights above, can be sent to [support contact email to be added].