Effective Date: May 1, 2026 · Last Updated: July 21, 2026 (v1.5.0)
Mediqrate ("we," "us," or "our") is a health and wellness application that helps you track medications, nutrition, and health reports. We are operated by Yogesh Pawar (operating as Mediqrate), located at Rossland Ave, Nepean, ON K2G 2K8, Canada.
Contact for privacy matters: privacy@mediqrate.com — Response time: Within 30 days
Your most sensitive health data is encrypted on your device before it ever leaves it. This applies to four categories of data: lab report analysis, medicines, symptom diary entries, and AI chat history.
Each of these is encrypted using AES-256-GCM with a per-user key stored in your device's Keychain (WHEN_UNLOCKED). The encrypted blob is backed up to our servers so your data can be restored if you reinstall the app — but we hold only unreadable ciphertext. The decryption key never leaves your device. We cannot read your medicines, your symptom notes, your chat history with Vita, or your lab results — even if we wanted to.
Lab report images are sent to Google Gemini for analysis via a temporary upload that is deleted immediately after analysis completes. We do not retain your scan images on our servers.
We do not sell, share, or use your health data for advertising.
| Category | Examples | Where Stored |
|---|---|---|
| Account information | Name, email address | Supabase (encrypted at rest, Canada region) |
| Health profile | Age, gender, health conditions, goals | Supabase (encrypted at rest, not end-to-end) |
| Meal logs | Food names, portion sizes, nutrition values | Supabase (encrypted at rest, not end-to-end) |
| Health metrics | Weight, blood pressure, blood glucose, steps | Supabase (encrypted at rest, not end-to-end) |
| Community posts | Text posts, comments, likes | Supabase (encrypted at rest, not end-to-end) |
| Health assessment | Lifestyle, activity level, dietary preferences | Supabase (encrypted at rest, not end-to-end) |
| Daily check-in data | Mood score, sleep hours, sleep quality (collected when you complete the optional morning check-in) | Supabase (encrypted at rest, not end-to-end) |
| Daily check-in notes & goals | Optional free-text daily goal and sleep notes | Encrypted on-device with AES-256-GCM; encrypted backup on Supabase — server cannot decrypt |
| Nutrition priorities | Health focus areas you select (e.g. weight goals, bone health) to steer nutrition insights | Supabase (encrypted at rest, not end-to-end) |
| Category | Examples | Where Stored |
|---|---|---|
| Medicines | Medicine names, dosages, schedules | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| Symptom diary | Daily mood, symptoms, notes | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| Lab report AI analysis | Narrative summary and structured test values generated by Gemini | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| AI chat history (Vita) | Your conversation messages with Vita | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| Medicine change history | A log of medicine additions, removals, and dose/time changes (Pro feature: Medicine Journal) | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt |
| HealthIQ insights | AI-generated narrative text describing patterns in your own health trends | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt; auto-deleted after 12 months |
| Monthly HealthIQ Score narrative | AI-generated narrative summarizing your monthly score (Pro feature) | Encrypted on-device; encrypted backup on Supabase — server cannot decrypt; auto-deleted after 24 months |
| Report metadata | Report type, scan date | Supabase (RLS — only your account can read) |
| Category | Examples | Purpose |
|---|---|---|
| Device identifiers | Installation ID (anonymous) | Track free-tier usage limits without requiring an account |
| Usage patterns | Feature usage counts per month | Enforce AI scan limits fairly |
| App performance data | Crash reports (if you consent) | Fix bugs and improve stability |
| Purpose | Legal Basis (Canada/PIPEDA) | Legal Basis (India/DPDPA) | Legal Basis (EU/GDPR) |
|---|---|---|---|
| Provide core app features | Consent + Contract | Consent | Performance of contract |
| Send medication reminders | Consent | Consent | Consent |
| Power AI health analysis | Consent | Consent | Consent |
| Process subscription payments | Contract | Contract | Performance of contract |
| Improve app features | Legitimate interest | Legitimate interest | Legitimate interest |
| Comply with legal obligations | Legal obligation | Legal obligation | Legal obligation |
We do not use your health data for advertising, sell it to any third party, or use it to make automated decisions that significantly affect you without your knowledge.
When you use Vita, your health data (today's meals, medicines, wellness score, health conditions from your profile) is sent to an AI model to generate personalized responses. Vita's primary responses are generated by Google Gemini; if Google's service is temporarily unavailable, the request may automatically fall back to Anthropic's Claude AI model instead, so your conversation isn't interrupted. Whichever provider handles the request processes it only to generate your response and does not use this data to train their AI models under our agreement.
When you scan a medicine label or food item, the image is sent to Google Gemini for analysis. If Gemini is unavailable, the scan may automatically retry using Anthropic's Claude AI model as a fallback, so a temporary outage on one provider doesn't block your scan. The image is processed and immediately discarded — we do not store your camera images on our servers with either provider.
Lab report images are sent to Google Gemini for analysis via a temporary upload that is deleted immediately after analysis completes. Lab report scanning always uses Google Gemini and never falls back to another AI provider, given the medical accuracy this feature requires. The AI-generated narrative analysis is encrypted on your device using AES-256-GCM before any backup leaves your device — the server holds only unreadable ciphertext. The decryption key stays in your device's Keychain; we cannot read your lab results.
If you enable HealthIQ in Settings → Notifications → AI Insights and have granted third-party AI consent, Mediqrate periodically analyses aggregated trends across your own data (sleep, nutrition, activity, medicine adherence) using Google Gemini to generate plain-language insights and, for Pro subscribers, a monthly score narrative. Only aggregated summaries are sent — never raw day-by-day records — and, where you have more than a few distinct medicines, individual medicine names are not included in the request at all. You can disable this at any time without affecting any other feature, including Vita.
You may generate a health summary document, or a list of AI-suggested questions to bring to your next appointment, for your own use with a healthcare provider. Generating the optional AI-written summary or question list uses Google Gemini and the same third-party AI consent as Vita chat. The report or question list is not stored on our servers — it exists only on your device until you choose to share it, and we do not track where you send it.
If enabled, Mediqrate can generate a short, AI-written note about a meal you've just logged, using Google Gemini. This uses the same third-party AI consent as other AI features and is not stored — the note exists only on your device for the current session.
You may optionally enable Enhanced Privacy Mode in Profile → Privacy & Data, which downloads a small AI model (roughly 900 MB–1.1 GB) to run entirely on your device. When active, it replaces cloud AI for the weekly health story, HealthIQ insight narrative, appointment report summary, and per-meal nutrition notes — none of that processing is sent to Mediqrate's servers or to any third party while this mode is active. Lab report analysis, Vita chat, and Ask My Doctor always use cloud AI (Google Gemini, with Anthropic Claude as an availability fallback) regardless of this setting, since they require more knowledge than an on-device model can safely provide. You can disable and delete the on-device model at any time.
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase (Canada) | Database and authentication | Account data, health metrics, meals, medicines |
| Google Gemini AI | Primary AI model for Vita chat, medicine/food/lab scans, and all optional AI insight features (HealthIQ, appointment reports, nutrition notes, Ask My Doctor) | Images during scan, health summary for chat, aggregated trend data for optional insight features |
| Anthropic Claude AI | Fallback AI model for Vita chat and medicine/food scans only — used only when Google Gemini is temporarily unavailable. Never used for lab report analysis, HealthIQ, appointment reports, or Ask My Doctor. | Same data as the Gemini request it is standing in for — only when Gemini cannot respond; neither provider retains your data after processing |
| RevenueCat | Subscription management | Purchase history, subscription status |
| Apple App Store | iOS payment processing | Payment details (Apple handles directly) |
| Google Play | Android payment processing | Payment details (Google handles directly) |
| Expo (EAS) | App delivery and updates | App version, device type |
| PostHog | Product analytics — understanding how the app is used | A unique account identifier, subscription tier, and behavioral events (e.g. app opens, signups, paywall views). Does not receive scan images, chat content, medicine names, or lab values. |
We do not use Google Analytics, Facebook, or any advertising networks. We do use PostHog for product analytics — see the table above for what it receives. You can read PostHog's privacy policy at posthog.com/privacy.
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Health metrics and meals | Until you delete your account or delete individual entries |
| Medication records | Until you delete your account or delete individual medicines |
| AI chat history | Until you delete your account or delete individual sessions |
| Payment transaction records | 7 years (required by tax law in Canada) |
| Lab report AI analysis (encrypted backup) | Until you use "Delete All My Data" or delete your account — server-side copy is unreadable without your device key |
| Lab report structured test values | Until you use "Delete All My Data" or delete your account |
| HealthIQ insights | Automatically deleted after 12 months |
| Monthly HealthIQ Score records | Automatically deleted after 24 months |
| Medicine change history (Medicine Journal) | Automatically deleted after 24 months |
| Daily check-in records | Automatically deleted after 24 months |
| Usage logs (for AI limits) | 60 days |
| Deleted account data | Permanently deleted immediately upon account deletion — all health data, profile, and session records are removed in the same request |
Within the app: Profile tab → Privacy & Data → Export My Data or Delete All My Data
By email: privacy@mediqrate.com — We will respond within 30 days.
We protect your data using:
Despite these measures, no method of electronic storage or transmission is 100% secure. We encourage you to use a strong, unique password for your account.
Mediqrate is not directed at children under the age of 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe your child has provided us with personal information, contact us at privacy@mediqrate.com and we will delete it promptly.
Your data is stored on Supabase servers in Canada (ca-central-1 region). When you use AI features, your data is briefly processed by Google Gemini servers, which may be located in the United States. This transfer occurs under Google's standard contractual clauses which comply with GDPR and PIPEDA requirements.
For Indian users: data may be transferred outside India to Canada and the United States for the purposes described above. By using Mediqrate and accepting these terms, you consent to this transfer.
We send push notifications for:
You can turn off any or all notifications in your device's Settings app at any time.
We will notify you of significant changes by sending a push notification, showing an in-app notice when you next open the app, and updating the "Last Updated" date at the top of this page. Continued use of Mediqrate after changes constitutes acceptance of the updated policy.
For privacy questions or to exercise your rights:
Email: privacy@mediqrate.com — Response time: Within 30 days
For general support:
Email: support@mediqrate.com
Mailing address:
Yogesh Pawar (operating as Mediqrate)
Rossland Ave, Nepean, ON K2G 2K8, Canada
This Privacy Policy was last reviewed on July 21, 2026 (policy version 1.5.0).