Legal

Privacy Policy

Effective Date: May 1, 2026  ·  Last Updated: August 22, 2026 (v1.12.0)

1. Who We Are

Mediqrate ("we," "us," or "our") is a health and wellness application that helps you track medications, nutrition, and health reports. We are operated by Yogesh Pawar (operating as Mediqrate), located at Rossland Ave, Nepean, ON K2G 2K8, Canada.

Contact for privacy matters: privacy@mediqrate.com — Response time: Within 30 days

2. How Your Health Data Is Stored

Your most sensitive health data is encrypted on your device before it ever leaves it. This applies to specific categories of data — see §3.2 below for the full list, which currently includes lab report AI analysis (the narrative and structured values Gemini generates from your scan), medicines, symptom diary entries, and AI chat history.

Each of these is encrypted using AES-256-GCM with a per-user key stored in your device's Keychain (WHEN_UNLOCKED). The encrypted blob is backed up to our servers so your data can be restored if you reinstall the app — but we hold only unreadable ciphertext for these categories. The decryption key never leaves your device. We cannot read your medicines, your symptom notes, or your chat history with Vita — even if we wanted to. Other health data (see §3.1) — such as meal logs, vitals, and daily check-in mood/sleep scores — is encrypted at rest on our servers using standard database-level encryption, but is not end-to-end encrypted the way the categories above are.

Lab report images are sent to Google Cloud Vertex AI (Gemini models) for analysis via a temporary upload that is deleted immediately after analysis completes. We do not retain your scan images on our servers.

We do not sell, share, or use your health data for advertising.

3. What Information We Collect

3.1 Information You Provide

CategoryExamplesWhere Stored
Account informationName, email addressSupabase (encrypted at rest, Canada region)
Health profileAge, gender, health conditions, goalsSupabase (encrypted at rest, not end-to-end)
Meal logsFood names, portion sizes, nutrition values, and a reference to the meal's photo on your device (a local file path — the photo itself is only uploaded if you turn on the optional Food Photo Sync feature, see §5.3)Supabase (encrypted at rest, not end-to-end)
Health metricsWeight, blood pressure, blood glucose, stepsSupabase (encrypted at rest, not end-to-end)
Community postsText posts, comments, likesSupabase (encrypted at rest, not end-to-end)
Health assessmentLifestyle, activity level, dietary preferencesSupabase (encrypted at rest, not end-to-end)
Daily check-in dataMood score, sleep hours, sleep quality (collected when you complete the optional morning check-in)Supabase (encrypted at rest, not end-to-end)
Daily check-in notes & goalsOptional free-text daily goal and sleep notesEncrypted on-device with AES-256-GCM; encrypted backup on Supabase — server cannot decrypt
Nutrition prioritiesHealth focus areas you select (e.g. weight goals, bone health) to steer nutrition insightsSupabase (encrypted at rest, not end-to-end)
Supplement & produce detailsSupplement facts (active ingredients, serving unit) when you log a supplement; organic/PLU codes when you manually enter one for fresh produceSupabase (encrypted at rest, not end-to-end)
Pattern-finding daily values (HealthIQ, if you've logged vitals or symptoms)One plaintext number per day per metric (e.g. a blood pressure reading, a symptom severity score) — decrypted and selected on your device from the end-to-end encrypted records in §3.2, sent only for the statistical pattern check described in §5.5Supabase (plaintext by design — this is a value your device already chose to share; the underlying encrypted record it came from stays end-to-end encrypted per §3.2)

3.2 Sensitive Health Data (AES-256-GCM encrypted — server holds ciphertext only)

CategoryExamplesWhere Stored
MedicinesMedicine names, dosages, schedulesEncrypted on-device; encrypted backup on Supabase — server cannot decrypt
Symptom diaryDaily mood, symptoms, notesEncrypted on-device; encrypted backup on Supabase — server cannot decrypt
Lab report AI analysisNarrative summary and structured test values generated by GeminiEncrypted on-device; encrypted backup on Supabase — server cannot decrypt
AI chat history (Vita)Your conversation messages with VitaEncrypted on-device; encrypted backup on Supabase — server cannot decrypt
Medicine change historyA log of medicine additions, removals, and dose/time changes (Pro feature: Medicine Journal)Encrypted on-device; encrypted backup on Supabase — server cannot decrypt
HealthIQ insightsAI-generated narrative text describing patterns in your own health trendsEncrypted on-device; encrypted backup on Supabase — server cannot decrypt; auto-deleted after 12 months
Monthly HealthIQ Score narrativeAI-generated narrative summarizing your monthly score (Pro feature)Encrypted on-device; encrypted backup on Supabase — server cannot decrypt; auto-deleted after 24 months
Report metadataReport type, scan dateSupabase (RLS — only your account can read)

Medicine identification results (brand/generic name, dosage form, active ingredient, common uses, usage instructions, warnings, side effects — the drug-facts data returned by a medicine scan, not the schedule/dosage you personally set) are stored on our servers in readable form, scoped to your account by row-level security, so we can show your past scans without re-analyzing the same medicine. This is separate from the Medicines category above, which covers what you personally record (dosage, schedule, notes) and is end-to-end encrypted.

3.3 Information Collected Automatically

CategoryExamplesPurpose
Device identifiersInstallation ID (anonymous)Track free-tier usage limits without requiring an account
Usage patternsFeature usage counts per monthEnforce AI scan limits fairly
App performance dataCrash reports (if you consent)Fix bugs and improve stability
Native health-platform sync (optional, if you grant permission)Step count, body weight, and sleep duration read from Apple Health (iOS) or Health Connect (Android)Populate your activity, weight, and sleep metrics automatically instead of manual entry
Voice input (only when you actively tap the microphone button)Your spoken audio, transcribed to text for food logging and the Vita AI chat assistantLet you log a meal or ask Vita a question by speaking instead of typing

On Android, the app requests a broader set of Health Connect permissions than it currently reads from (e.g. heart rate, blood pressure, blood glucose, oxygen saturation) to support upcoming features. It does not currently read, store, or use these additional categories — only steps, weight, and sleep are synced today.

3.4 Information We Do NOT Collect

4. How We Use Your Information

PurposeLegal Basis (Canada/PIPEDA)Legal Basis (India/DPDPA)Legal Basis (EU/GDPR)
Provide core app featuresConsent + ContractConsentPerformance of contract
Send medication remindersConsentConsentConsent
Power AI health analysisConsentConsentConsent
Process subscription paymentsContractContractPerformance of contract
Improve app featuresLegitimate interestLegitimate interestLegitimate interest
Comply with legal obligationsLegal obligationLegal obligationLegal obligation

We do not use your health data for advertising, sell it to any third party, or use it to make automated decisions that significantly affect you without your knowledge.

5. AI Features and Your Health Data

5.1 How Vita (AI Chat) Works

When you use Vita, your health data is sent to an AI model to generate personalized responses — specifically: today's logged meals and exact nutrition totals, your medicines including exact dosage and frequency, exact age/height/weight where you've entered them, your wellness score and activity (steps, water), dietary preferences and allergies, nutrition focus areas you've selected, and — where relevant to your question — the status of any lab test results you're monitoring. We send exact values (not rounded ranges) for these because Vita is built to answer specific questions like "how many grams of protein have I had today" or "what's my current dose of X," which requires precision. Some other categories, like mood and general lab trends, are simplified to a qualitative label before being sent, since Vita only needs the general pattern for those. Vita's primary responses are generated by Gemini via Google Cloud Vertex AI; if that service is temporarily unavailable, the request may automatically fall back to Anthropic's Claude AI model instead, so your conversation isn't interrupted. Whichever provider handles the request processes it only to generate your response and does not use this data to train their AI models under our agreement.

5.2 Voice Input

If you tap the microphone button to log a meal by speaking, or to talk to Vita, your device's built-in speech recognition (provided by Apple on iOS or Google on Android) converts your speech to text. Depending on your device and OS settings, this may be processed entirely on your device or may send the audio to Apple's or Google's own servers for recognition — Mediqrate does not control which, and neither we nor our AI vendors (Google Cloud Vertex AI, Anthropic) ever receive the raw audio, only the resulting text once transcription is complete. That transcribed text is then handled the same way as if you had typed it (see §5.1 and §5.7). We do not record or store audio ourselves.

5.3 Medicine and Food Scanning

When you scan a medicine label or food item, the image is sent to Gemini via Google Cloud Vertex AI for analysis. If that service is unavailable, the scan may automatically retry using Anthropic's Claude AI model as a fallback, so a temporary outage on one provider doesn't block your scan. The image itself is processed and immediately discarded by the AI provider — neither Gemini nor Claude retains your camera images after analysis.

Medicine label and lab report images are never stored on our own servers, with or without any setting below. Food photos are different: if you turn on the optional Food Photo Sync feature (a Pro feature, off by default), a compressed copy of your food photo is stored in our private cloud storage so it's available across your devices. You can turn this off at any time in Manage Consents — turning it off stops new photos from being saved, but photos already synced are kept until you delete the meal or your account.

To avoid re-analyzing the exact same photo twice, we cache the AI's analysis result (not the image) against a one-way cryptographic fingerprint of the image, for up to 48 hours. For food scans specifically, identified food names and their nutrition values are also added to a shared nutrition database that benefits all users' future lookups of that same food, retained for up to 180 days (see §5.7). For medicine scans, barcode/imprint lookups and their drug-facts results are similarly cached and shared across users so a commonly-scanned medicine doesn't need re-analysis. Neither cache ever contains the image itself, and neither is tied to your account.

If you use the drug interaction checker, the AI-generated interaction analysis for a given combination of medicine names and dosages is also cached and shared across users who check the same combination, so it isn't tied to your account or medical history.

5.4 Lab Report Scanning

Before a lab report photo is sent anywhere, your device runs an on-device check — entirely offline, using on-device text recognition — for personal details commonly printed on a lab report's header, such as your name, date of birth, or a medical record number. If any are detected, we show you a warning and suggest cropping the photo down to just the test results before continuing; you can still choose to send the full photo if you prefer. This check never sends the scanned text anywhere — it runs entirely on your device, and only tells you which categories of personal information it noticed, never what it actually found.

Lab report images are sent to Gemini via Google Cloud Vertex AI for analysis via a temporary upload that is deleted immediately after analysis completes. Lab report scanning always uses Vertex AI and never falls back to another AI provider, given the medical accuracy this feature requires. The full analysis — both the AI-generated narrative summary and the structured test values extracted from your report (individual result names, values, and reference ranges) — is encrypted together on your device using AES-256-GCM before any backup leaves your device. The server holds only unreadable ciphertext, and the decryption key stays in your device's Keychain, so we cannot read any part of it — see §3.2.

If the AI misreads a value, you can correct it yourself directly on the report. A corrected value is stored using the exact same on-device encryption described above — our server never sees the correction in readable form, the same as everything else in your report. The app always displays a small "Edited by [your name]" label next to any value you've corrected, so it's never mistaken for something our AI produced. Correcting a value on your own report is separate from the optional Model Improvement Program described in §5.9 — fixing your own record does not, by itself, send anything to that program.

5.5 HealthIQ Insights & Monthly Score (optional, requires your consent)

If you enable HealthIQ in Settings → Notifications → AI Insights and have granted third-party AI consent, Mediqrate looks for statistically real patterns across your own data (sleep, nutrition, activity, medicine adherence, and — if you log them — vitals such as blood pressure and weight, and symptom severity) and, only once a pattern clears a minimum-sample-size and effect-size bar, uses Gemini via Google Cloud Vertex AI to phrase it in plain language. This pattern-finding step is a deterministic statistical calculation, not an AI guess — Gemini only writes one sentence describing an already-validated result; it never sees your raw day-by-day data. Pro subscribers also receive a monthly score narrative.

Only aggregated summaries are sent to Gemini — never raw day-by-day records — and, where you have more than a few distinct medicines, individual medicine names are not included in the request at all.

Vitals and symptom data specifically: those categories are end-to-end encrypted (§3.2) — our server cannot decrypt them. To include them in HealthIQ's pattern-finding, your device decrypts them locally and shares only one number per day per metric (e.g. a blood pressure reading, a symptom severity score) with our server for the statistical calculation — never the encrypted record itself, and never any note or free-text you attached. Patterns touching this data are held to a stricter statistical bar than lifestyle patterns, and are shown with an inline "not medical advice" notice.

You can disable HealthIQ at any time without affecting any other feature, including Vita.

5.6 Appointment Reports & Ask My Doctor (optional, requires your consent)

You may generate a health summary document, or a list of AI-suggested questions to bring to your next appointment, for your own use with a healthcare provider. Generating the optional AI-written summary or question list uses Gemini via Google Cloud Vertex AI and the same third-party AI consent as Vita chat. The report or question list is not stored on our servers as part of generating it — it exists only on your device until you choose to share it, and we do not track where you send it. If you separately opt into the Model Improvement Program (see §5.9) and rate the AI-written summary (👍/👎 or a correction), that summary's text is stored at that point as feedback data, under the terms described in §5.9.

5.7 Nutrition Intelligence (optional, requires your consent)

If enabled, Mediqrate can generate a short, AI-written note about a meal you've just logged, using Gemini via Google Cloud Vertex AI. This uses the same third-party AI consent as other AI features and is not stored on our servers as part of generating it — the note exists only on your device for the current session. If you separately opt into the Model Improvement Program (see §5.9) and rate that note (👍/👎 or a correction), the note's text is stored at that point as feedback data, under the terms described in §5.9.

5.8 Instant Mode (optional, on-device AI, formerly "Enhanced Privacy Mode")

You may optionally enable Instant Mode in Profile → Privacy & Data, which downloads a small AI model (roughly 900 MB–1.1 GB) to run entirely on your device. When active, it generates the weekly health story, HealthIQ insight narrative, appointment report summary, and per-meal nutrition notes instantly and offline in place of cloud AI — none of that processing is sent to Mediqrate's servers or to any third party while this mode is active. Lab report analysis and Ask My Doctor always use cloud AI (Gemini via Google Cloud Vertex AI, with Anthropic Claude as an availability fallback) regardless of this setting, since they require more knowledge than an on-device model can safely provide.

Vita chat is different: it normally uses cloud AI regardless of the Instant Mode setting above, but if your device loses connectivity, Vita automatically switches to the same on-device model (downloading it first if needed) so you can keep chatting offline. An offline reply is generated entirely on your device, uses a shorter, cached version of your health context rather than the live data a connected reply uses, and is not sent to Mediqrate's servers or any third party. Vita's chat history is stored the same way either way — see §3.2. You can disable and delete the on-device model at any time.

5.9 Model Improvement Program (optional, separate opt-in)

Several AI-generated outputs in Mediqrate — the weekly health story, HealthIQ insight narrative, doctor report summary, and Nutrition Intelligence notes — show a "Was this helpful?" prompt. Responding to this prompt is entirely optional and only appears if you have separately opted into the Model Improvement Program in Settings → Privacy → Model Improvement.

If you opt in and rate a piece of AI-generated text, we store: the rating (helpful / not helpful), the AI-generated text itself, a one-way hash of that text, and a small set of pre-categorized structural signals about the context it was generated from (for example, a calorie band or a meal type — never raw numeric health values, medicine names, or lab values). If you submit a written correction, that correction is scanned and blocked from being stored if it contains any digits, as a safeguard against accidentally including a health number.

This data is used solely to identify and improve inaccurate AI outputs. It is never sold or shared with third parties, and you can withdraw from the Model Improvement Program at any time in Settings → Privacy → Model Improvement — this stops new feedback from being collected but does not retroactively delete feedback already submitted, which you can request deleted via the process in §8.4.

6. Third-Party Services We Use

AI processing runs through Google Cloud's Vertex AI platform — not the public consumer Gemini API. Vertex AI is billed through Google Cloud and can be covered under an enterprise data-processing agreement, which is why we route every AI call this way rather than through the direct consumer service.

ServicePurposeData Shared
Supabase (Canada)Database and authenticationAccount data, health metrics, meals, medicines
Google Cloud Vertex AI (Gemini models)Primary AI model for Vita chat, medicine/food/lab scans, and all optional AI insight features (HealthIQ, appointment reports, nutrition notes, Ask My Doctor)Images during scan, health summary for chat, aggregated trend data for optional insight features
Anthropic Claude AIFallback AI model for Vita chat and medicine/food scans only — used only when Vertex AI is temporarily unavailable. Never used for lab report analysis, HealthIQ, appointment reports, or Ask My Doctor.Same data as the Vertex AI request it is standing in for — only when Vertex AI cannot respond; neither provider retains your data after processing
Fitbit / Garmin (optional)Wearable integration — only if you choose to connect a device in Profile → WearablesStep count, activity, and sleep data from your connected device; access tokens are stored so we can keep syncing until you disconnect
RevenueCatSubscription managementPurchase history, subscription status
Apple App StoreiOS payment processingPayment details (Apple handles directly)
Google PlayAndroid payment processingPayment details (Google handles directly)
Expo (EAS)App delivery and updatesApp version, device type
PostHogProduct analytics — understanding how the app is usedA unique account identifier, subscription tier, and behavioral events (e.g. app opens, signups, paywall views). Does not receive scan images, chat content, medicine names, or lab values.

We do not use Google Analytics, Facebook, or any advertising networks. We do use PostHog for product analytics — see the table above for what it receives. You can read PostHog's privacy policy at posthog.com/privacy.

7. Data Retention

Data TypeRetention Period
Account informationUntil you delete your account
Health metrics and mealsUntil you delete your account or delete individual entries
Medication recordsUntil you delete your account or delete individual medicines
AI chat historyUntil you delete your account or delete individual sessions
Payment transaction records7 years (required by tax law in Canada)
Lab report AI analysis (encrypted backup)Until you use "Delete All My Data" or delete your account — server-side copy is unreadable without your device key
Lab report structured test valuesUntil you use "Delete All My Data" or delete your account
HealthIQ insightsAutomatically deleted after 12 months
Pattern-finding daily values (§3.1)Automatically deleted after 60 days; also deleted immediately on account deletion
Monthly HealthIQ Score recordsAutomatically deleted after 24 months
Medicine change history (Medicine Journal)Automatically deleted after 24 months
Daily check-in recordsAutomatically deleted after 24 months
Usage logs (for AI limits)60 days
Deleted account dataPermanently deleted immediately upon account deletion — all health data, profile, and session records are removed in the same request

8. Your Rights

8.1 Rights for Canadian Users (PIPEDA)

8.2 Rights for Indian Users (DPDPA 2023)

8.3 Rights for EU/UK Users (GDPR)

8.4 How to Exercise Your Rights

Within the app: Profile tab → Privacy & Data → Export my data, Delete all my data, or Delete my account

By email: privacy@mediqrate.com — We will respond within 30 days.

9. Data Security

We protect your data using:

Despite these measures, no method of electronic storage or transmission is 100% secure. We encourage you to use a strong, unique password for your account.

10. Children's Privacy

Mediqrate is not directed at children under the age of 13 (or under 16 in the EU) and account creation requires confirming a date of birth that meets this minimum age. We do not knowingly collect personal information from children. If you believe your child has provided us with personal information, contact us at privacy@mediqrate.com and we will delete it promptly.

11. Data Transfers

Your data is stored on Supabase servers in Canada (ca-central-1 region). When you use AI features, your data is briefly processed by Google Cloud Vertex AI in the United States (us-central1 region). This transfer occurs under Google's standard contractual clauses which comply with GDPR and PIPEDA requirements, and under a signed Google Cloud Data Processing Addendum specific to our use of Vertex AI for health-related processing. A full HIPAA Business Associate Agreement with Google is in progress and will be finalized ahead of general availability.

For Indian users: data may be transferred outside India to Canada and the United States for the purposes described above. By using Mediqrate and accepting these terms, you consent to this transfer.

12. Push Notifications

We send push notifications for:

You can turn off any or all notifications in your device's Settings app at any time.

13. Changes to This Policy

We will notify you of significant changes by sending a push notification, showing an in-app notice when you next open the app, and updating the "Last Updated" date at the top of this page. Continued use of Mediqrate after changes constitutes acceptance of the updated policy.

14. Contact Us

For privacy questions or to exercise your rights:
Email: privacy@mediqrate.com — Response time: Within 30 days

For general support:
Email: support@mediqrate.com

Mailing address:
Yogesh Pawar (operating as Mediqrate)
Rossland Ave, Nepean, ON K2G 2K8, Canada


This Privacy Policy was last reviewed on August 22, 2026 (policy version 1.12.0).