Effective Date: May 1, 2026 · Last Updated: August 22, 2026 (v1.12.0)
Mediqrate ("we," "us," or "our") is a health and wellness application that helps you track medications, nutrition, and health reports. We are operated by Yogesh Pawar (operating as Mediqrate), located at Rossland Ave, Nepean, ON K2G 2K8, Canada.
Contact for privacy matters: privacy@mediqrate.com — Response time: Within 30 days
Your most sensitive health data is encrypted on your device before it ever leaves it. This applies to specific categories of data — see §3.2 below for the full list, which currently includes lab report AI analysis (the narrative and structured values Gemini generates from your scan), medicines, symptom diary entries, and AI chat history.
Each of these is encrypted using AES-256-GCM with a per-user key stored in your device's Keychain (WHEN_UNLOCKED). The encrypted blob is backed up to our servers so your data can be restored if you reinstall the app — but we hold only unreadable ciphertext for these categories. The decryption key never leaves your device. We cannot read your medicines, your symptom notes, or your chat history with Vita — even if we wanted to. Other health data (see §3.1) — such as meal logs, vitals, and daily check-in mood/sleep scores — is encrypted at rest on our servers using standard database-level encryption, but is not end-to-end encrypted the way the categories above are.
Lab report images are sent to Google Cloud Vertex AI (Gemini models) for analysis via a temporary upload that is deleted immediately after analysis completes. We do not retain your scan images on our servers.
We do not sell, share, or use your health data for advertising.
| Category | Examples | Where Stored |
|---|---|---|
| Account information | Name, email address | Supabase (encrypted at rest, Canada region) |
| Health profile | Age, gender, health conditions, goals | Supabase (encrypted at rest, not end-to-end) |
| Meal logs | Food names, portion sizes, nutrition values, and a reference to the meal's photo on your device (a local file path — the photo itself is only uploaded if you turn on the optional Food Photo Sync feature, see §5.3) | Supabase (encrypted at rest, not end-to-end) |
| Health metrics | Weight, blood pressure, blood glucose, steps | Supabase (encrypted at rest, not end-to-end) |
| Community posts | Text posts, comments, likes | Supabase (encrypted at rest, not end-to-end) |
| Health assessment | Lifestyle, activity level, dietary preferences | Supabase (encrypted at rest, not end-to-end) |
| Daily check-in data | Mood score, sleep hours, sleep quality (collected when you complete the optional morning check-in) | Supabase (encrypted at rest, not end-to-end) |
| Daily check-in notes & goals | Optional free-text daily goal and sleep notes | Encrypted on-device with AES-256-GCM; encrypted backup on Supabase — server cannot decrypt |
| Nutrition priorities | Health focus areas you select (e.g. weight goals, bone health) to steer nutrition insights | Supabase (encrypted at rest, not end-to-end) |
| Supplement & produce details | Supplement facts (active ingredients, serving unit) when you log a supplement; organic/PLU codes when you manually enter one for fresh produce | Supabase (encrypted at rest, not end-to-end) |
| Pattern-finding daily values (HealthIQ, if you've logged vitals or symptoms) | One plaintext number per day per metric (e.g. a blood pressure reading, a symptom severity score) — decrypted and selected on your device from the end-to-end encrypted records in §3.2, sent only for the statistical pattern check described in §5.5 | Supabase (plaintext by design — this is a value your device already chose to share; the underlying encrypted record it came from stays end-to-end encrypted per §3.2) |
| Category | Examples | Where Stored |
|---|---|---|
| Medicines | Medicine names, dosages, schedules | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| Symptom diary | Daily mood, symptoms, notes | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| Lab report AI analysis | Narrative summary and structured test values generated by Gemini | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| AI chat history (Vita) | Your conversation messages with Vita | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| Medicine change history | A log of medicine additions, removals, and dose/time changes (Pro feature: Medicine Journal) | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| HealthIQ insights | AI-generated narrative text describing patterns in your own health trends | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt; auto-deleted after 12 months |
| Monthly HealthIQ Score narrative | AI-generated narrative summarizing your monthly score (Pro feature) | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt; auto-deleted after 24 months |
| Report metadata | Report type, scan date | Supabase (RLS — only your account can read) |
Medicine identification results (brand/generic name, dosage form, active ingredient, common uses, usage instructions, warnings, side effects — the drug-facts data returned by a medicine scan, not the schedule/dosage you personally set) are stored on our servers in readable form, scoped to your account by row-level security, so we can show your past scans without re-analyzing the same medicine. This is separate from the Medicines category above, which covers what you personally record (dosage, schedule, notes) and is end-to-end encrypted.
| Category | Examples | Purpose |
|---|---|---|
| Device identifiers | Installation ID (anonymous) | Track free-tier usage limits without requiring an account |
| Usage patterns | Feature usage counts per month | Enforce AI scan limits fairly |
| App performance data | Crash reports (if you consent) | Fix bugs and improve stability |
| Native health-platform sync (optional, if you grant permission) | Step count, body weight, and sleep duration read from Apple Health (iOS) or Health Connect (Android) | Populate your activity, weight, and sleep metrics automatically instead of manual entry |
| Voice input (only when you actively tap the microphone button) | Your spoken audio, transcribed to text for food logging and the Vita AI chat assistant | Let you log a meal or ask Vita a question by speaking instead of typing |
On Android, the app requests a broader set of Health Connect permissions than it currently reads from (e.g. heart rate, blood pressure, blood glucose, oxygen saturation) to support upcoming features. It does not currently read, store, or use these additional categories — only steps, weight, and sleep are synced today.
| Purpose | Legal Basis (Canada/PIPEDA) | Legal Basis (India/DPDPA) | Legal Basis (EU/GDPR) |
|---|---|---|---|
| Provide core app features | Consent + Contract | Consent | Performance of contract |
| Send medication reminders | Consent | Consent | Consent |
| Power AI health analysis | Consent | Consent | Consent |
| Process subscription payments | Contract | Contract | Performance of contract |
| Improve app features | Legitimate interest | Legitimate interest | Legitimate interest |
| Comply with legal obligations | Legal obligation | Legal obligation | Legal obligation |
We do not use your health data for advertising, sell it to any third party, or use it to make automated decisions that significantly affect you without your knowledge.
When you use Vita, your health data is sent to an AI model to generate personalized responses — specifically: today's logged meals and exact nutrition totals, your medicines including exact dosage and frequency, exact age/height/weight where you've entered them, your wellness score and activity (steps, water), dietary preferences and allergies, nutrition focus areas you've selected, and — where relevant to your question — the status of any lab test results you're monitoring. We send exact values (not rounded ranges) for these because Vita is built to answer specific questions like "how many grams of protein have I had today" or "what's my current dose of X," which requires precision. Some other categories, like mood and general lab trends, are simplified to a qualitative label before being sent, since Vita only needs the general pattern for those. Vita's primary responses are generated by Gemini via Google Cloud Vertex AI; if that service is temporarily unavailable, the request may automatically fall back to Anthropic's Claude AI model instead, so your conversation isn't interrupted. Whichever provider handles the request processes it only to generate your response and does not use this data to train their AI models under our agreement.
If you tap the microphone button to log a meal by speaking, or to talk to Vita, your device's built-in speech recognition (provided by Apple on iOS or Google on Android) converts your speech to text. Depending on your device and OS settings, this may be processed entirely on your device or may send the audio to Apple's or Google's own servers for recognition — Mediqrate does not control which, and neither we nor our AI vendors (Google Cloud Vertex AI, Anthropic) ever receive the raw audio, only the resulting text once transcription is complete. That transcribed text is then handled the same way as if you had typed it (see §5.1 and §5.7). We do not record or store audio ourselves.
When you scan a medicine label or food item, the image is sent to Gemini via Google Cloud Vertex AI for analysis. If that service is unavailable, the scan may automatically retry using Anthropic's Claude AI model as a fallback, so a temporary outage on one provider doesn't block your scan. The image itself is processed and immediately discarded by the AI provider — neither Gemini nor Claude retains your camera images after analysis.
Medicine label and lab report images are never stored on our own servers, with or without any setting below. Food photos are different: if you turn on the optional Food Photo Sync feature (a Pro feature, off by default), a compressed copy of your food photo is stored in our private cloud storage so it's available across your devices. You can turn this off at any time in Manage Consents — turning it off stops new photos from being saved, but photos already synced are kept until you delete the meal or your account.
To avoid re-analyzing the exact same photo twice, we cache the AI's analysis result (not the image) against a one-way cryptographic fingerprint of the image, for up to 48 hours. For food scans specifically, identified food names and their nutrition values are also added to a shared nutrition database that benefits all users' future lookups of that same food, retained for up to 180 days (see §5.7). For medicine scans, barcode/imprint lookups and their drug-facts results are similarly cached and shared across users so a commonly-scanned medicine doesn't need re-analysis. Neither cache ever contains the image itself, and neither is tied to your account.
If you use the drug interaction checker, the AI-generated interaction analysis for a given combination of medicine names and dosages is also cached and shared across users who check the same combination, so it isn't tied to your account or medical history.
Before a lab report photo is sent anywhere, your device runs an on-device check — entirely offline, using on-device text recognition — for personal details commonly printed on a lab report's header, such as your name, date of birth, or a medical record number. If any are detected, we show you a warning and suggest cropping the photo down to just the test results before continuing; you can still choose to send the full photo if you prefer. This check never sends the scanned text anywhere — it runs entirely on your device, and only tells you which categories of personal information it noticed, never what it actually found.
Lab report images are sent to Gemini via Google Cloud Vertex AI for analysis via a temporary upload that is deleted immediately after analysis completes. Lab report scanning always uses Vertex AI and never falls back to another AI provider, given the medical accuracy this feature requires. The full analysis — both the AI-generated narrative summary and the structured test values extracted from your report (individual result names, values, and reference ranges) — is encrypted together on your device using AES-256-GCM before any backup leaves your device. The server holds only unreadable ciphertext, and the decryption key stays in your device's Keychain, so we cannot read any part of it — see §3.2.
If the AI misreads a value, you can correct it yourself directly on the report. A corrected value is stored using the exact same on-device encryption described above — our server never sees the correction in readable form, the same as everything else in your report. The app always displays a small "Edited by [your name]" label next to any value you've corrected, so it's never mistaken for something our AI produced. Correcting a value on your own report is separate from the optional Model Improvement Program described in §5.9 — fixing your own record does not, by itself, send anything to that program.
If you enable HealthIQ in Settings → Notifications → AI Insights and have granted third-party AI consent, Mediqrate looks for statistically real patterns across your own data (sleep, nutrition, activity, medicine adherence, and — if you log them — vitals such as blood pressure and weight, and symptom severity) and, only once a pattern clears a minimum-sample-size and effect-size bar, uses Gemini via Google Cloud Vertex AI to phrase it in plain language. This pattern-finding step is a deterministic statistical calculation, not an AI guess — Gemini only writes one sentence describing an already-validated result; it never sees your raw day-by-day data. Pro subscribers also receive a monthly score narrative.
Only aggregated summaries are sent to Gemini — never raw day-by-day records — and, where you have more than a few distinct medicines, individual medicine names are not included in the request at all.
Vitals and symptom data specifically: those categories are end-to-end encrypted (§3.2) — our server cannot decrypt them. To include them in HealthIQ's pattern-finding, your device decrypts them locally and shares only one number per day per metric (e.g. a blood pressure reading, a symptom severity score) with our server for the statistical calculation — never the encrypted record itself, and never any note or free-text you attached. Patterns touching this data are held to a stricter statistical bar than lifestyle patterns, and are shown with an inline "not medical advice" notice.
You can disable HealthIQ at any time without affecting any other feature, including Vita.
You may generate a health summary document, or a list of AI-suggested questions to bring to your next appointment, for your own use with a healthcare provider. Generating the optional AI-written summary or question list uses Gemini via Google Cloud Vertex AI and the same third-party AI consent as Vita chat. The report or question list is not stored on our servers as part of generating it — it exists only on your device until you choose to share it, and we do not track where you send it. If you separately opt into the Model Improvement Program (see §5.9) and rate the AI-written summary (👍/👎 or a correction), that summary's text is stored at that point as feedback data, under the terms described in §5.9.
If enabled, Mediqrate can generate a short, AI-written note about a meal you've just logged, using Gemini via Google Cloud Vertex AI. This uses the same third-party AI consent as other AI features and is not stored on our servers as part of generating it — the note exists only on your device for the current session. If you separately opt into the Model Improvement Program (see §5.9) and rate that note (👍/👎 or a correction), the note's text is stored at that point as feedback data, under the terms described in §5.9.
You may optionally enable Instant Mode in Profile → Privacy & Data, which downloads a small AI model (roughly 900 MB–1.1 GB) to run entirely on your device. When active, it generates the weekly health story, HealthIQ insight narrative, appointment report summary, and per-meal nutrition notes instantly and offline in place of cloud AI — none of that processing is sent to Mediqrate's servers or to any third party while this mode is active. Lab report analysis and Ask My Doctor always use cloud AI (Gemini via Google Cloud Vertex AI, with Anthropic Claude as an availability fallback) regardless of this setting, since they require more knowledge than an on-device model can safely provide.
Vita chat is different: it normally uses cloud AI regardless of the Instant Mode setting above, but if your device loses connectivity, Vita automatically switches to the same on-device model (downloading it first if needed) so you can keep chatting offline. An offline reply is generated entirely on your device, uses a shorter, cached version of your health context rather than the live data a connected reply uses, and is not sent to Mediqrate's servers or any third party. Vita's chat history is stored the same way either way — see §3.2. You can disable and delete the on-device model at any time.
Several AI-generated outputs in Mediqrate — the weekly health story, HealthIQ insight narrative, doctor report summary, and Nutrition Intelligence notes — show a "Was this helpful?" prompt. Responding to this prompt is entirely optional and only appears if you have separately opted into the Model Improvement Program in Settings → Privacy → Model Improvement.
If you opt in and rate a piece of AI-generated text, we store: the rating (helpful / not helpful), the AI-generated text itself, a one-way hash of that text, and a small set of pre-categorized structural signals about the context it was generated from (for example, a calorie band or a meal type — never raw numeric health values, medicine names, or lab values). If you submit a written correction, that correction is scanned and blocked from being stored if it contains any digits, as a safeguard against accidentally including a health number.
This data is used solely to identify and improve inaccurate AI outputs. It is never sold or shared with third parties, and you can withdraw from the Model Improvement Program at any time in Settings → Privacy → Model Improvement — this stops new feedback from being collected but does not retroactively delete feedback already submitted, which you can request deleted via the process in §8.4.
AI processing runs through Google Cloud's Vertex AI platform — not the public consumer Gemini API. Vertex AI is billed through Google Cloud and can be covered under an enterprise data-processing agreement, which is why we route every AI call this way rather than through the direct consumer service.
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase (Canada) | Database and authentication | Account data, health metrics, meals, medicines |
| Google Cloud Vertex AI (Gemini models) | Primary AI model for Vita chat, medicine/food/lab scans, and all optional AI insight features (HealthIQ, appointment reports, nutrition notes, Ask My Doctor) | Images during scan, health summary for chat, aggregated trend data for optional insight features |
| Anthropic Claude AI | Fallback AI model for Vita chat and medicine/food scans only — used only when Vertex AI is temporarily unavailable. Never used for lab report analysis, HealthIQ, appointment reports, or Ask My Doctor. | Same data as the Vertex AI request it is standing in for — only when Vertex AI cannot respond; neither provider retains your data after processing |
| Fitbit / Garmin (optional) | Wearable integration — only if you choose to connect a device in Profile → Wearables | Step count, activity, and sleep data from your connected device; access tokens are stored so we can keep syncing until you disconnect |
| RevenueCat | Subscription management | Purchase history, subscription status |
| Apple App Store | iOS payment processing | Payment details (Apple handles directly) |
| Google Play | Android payment processing | Payment details (Google handles directly) |
| Expo (EAS) | App delivery and updates | App version, device type |
| PostHog | Product analytics — understanding how the app is used | A unique account identifier, subscription tier, and behavioral events (e.g. app opens, signups, paywall views). Does not receive scan images, chat content, medicine names, or lab values. |
We do not use Google Analytics, Facebook, or any advertising networks. We do use PostHog for product analytics — see the table above for what it receives. You can read PostHog's privacy policy at posthog.com/privacy.
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Health metrics and meals | Until you delete your account or delete individual entries |
| Medication records | Until you delete your account or delete individual medicines |
| AI chat history | Until you delete your account or delete individual sessions |
| Payment transaction records | 7 years (required by tax law in Canada) |
| Lab report AI analysis (encrypted backup) | Until you use "Delete All My Data" or delete your account — server-side copy is unreadable without your device key |
| Lab report structured test values | Until you use "Delete All My Data" or delete your account |
| HealthIQ insights | Automatically deleted after 12 months |
| Pattern-finding daily values (§3.1) | Automatically deleted after 60 days; also deleted immediately on account deletion |
| Monthly HealthIQ Score records | Automatically deleted after 24 months |
| Medicine change history (Medicine Journal) | Automatically deleted after 24 months |
| Daily check-in records | Automatically deleted after 24 months |
| Usage logs (for AI limits) | 60 days |
| Deleted account data | Permanently deleted immediately upon account deletion — all health data, profile, and session records are removed in the same request |
Within the app: Profile tab → Privacy & Data → Export my data, Delete all my data, or Delete my account
By email: privacy@mediqrate.com — We will respond within 30 days.
We protect your data using:
Despite these measures, no method of electronic storage or transmission is 100% secure. We encourage you to use a strong, unique password for your account.
Mediqrate is not directed at children under the age of 13 (or under 16 in the EU) and account creation requires confirming a date of birth that meets this minimum age. We do not knowingly collect personal information from children. If you believe your child has provided us with personal information, contact us at privacy@mediqrate.com and we will delete it promptly.
Your data is stored on Supabase servers in Canada (ca-central-1 region). When you use AI features, your data is briefly processed by Google Cloud Vertex AI in the United States (us-central1 region). This transfer occurs under Google's standard contractual clauses which comply with GDPR and PIPEDA requirements, and under a signed Google Cloud Data Processing Addendum specific to our use of Vertex AI for health-related processing. A full HIPAA Business Associate Agreement with Google is in progress and will be finalized ahead of general availability.
For Indian users: data may be transferred outside India to Canada and the United States for the purposes described above. By using Mediqrate and accepting these terms, you consent to this transfer.
We send push notifications for:
You can turn off any or all notifications in your device's Settings app at any time.
We will notify you of significant changes by sending a push notification, showing an in-app notice when you next open the app, and updating the "Last Updated" date at the top of this page. Continued use of Mediqrate after changes constitutes acceptance of the updated policy.
For privacy questions or to exercise your rights:
Email: privacy@mediqrate.com — Response time: Within 30 days
For general support:
Email: support@mediqrate.com
Mailing address:
Yogesh Pawar (operating as Mediqrate)
Rossland Ave, Nepean, ON K2G 2K8, Canada
This Privacy Policy was last reviewed on August 22, 2026 (policy version 1.12.0).