Legal

Privacy Policy

Effective Date: May 1, 2026  ·  Last Updated: July 21, 2026 (v1.5.0)

1. Who We Are

Mediqrate ("we," "us," or "our") is a health and wellness application that helps you track medications, nutrition, and health reports. We are operated by Yogesh Pawar (operating as Mediqrate), located at Rossland Ave, Nepean, ON K2G 2K8, Canada.

Contact for privacy matters: privacy@mediqrate.com — Response time: Within 30 days

2. How Your Health Data Is Stored

Your most sensitive health data is encrypted on your device before it ever leaves it. This applies to four categories of data: lab report analysis, medicines, symptom diary entries, and AI chat history.

Each of these is encrypted using AES-256-GCM with a per-user key stored in your device's Keychain (WHEN_UNLOCKED). The encrypted blob is backed up to our servers so your data can be restored if you reinstall the app — but we hold only unreadable ciphertext. The decryption key never leaves your device. We cannot read your medicines, your symptom notes, your chat history with Vita, or your lab results — even if we wanted to.

Lab report images are sent to Google Gemini for analysis via a temporary upload that is deleted immediately after analysis completes. We do not retain your scan images on our servers.

We do not sell, share, or use your health data for advertising.

3. What Information We Collect

3.1 Information You Provide

CategoryExamplesWhere Stored
Account informationName, email addressSupabase (encrypted at rest, Canada region)
Health profileAge, gender, health conditions, goalsSupabase (encrypted at rest, not end-to-end)
Meal logsFood names, portion sizes, nutrition valuesSupabase (encrypted at rest, not end-to-end)
Health metricsWeight, blood pressure, blood glucose, stepsSupabase (encrypted at rest, not end-to-end)
Community postsText posts, comments, likesSupabase (encrypted at rest, not end-to-end)
Health assessmentLifestyle, activity level, dietary preferencesSupabase (encrypted at rest, not end-to-end)
Daily check-in dataMood score, sleep hours, sleep quality (collected when you complete the optional morning check-in)Supabase (encrypted at rest, not end-to-end)
Daily check-in notes & goalsOptional free-text daily goal and sleep notesEncrypted on-device with AES-256-GCM; encrypted backup on Supabase — server cannot decrypt
Nutrition prioritiesHealth focus areas you select (e.g. weight goals, bone health) to steer nutrition insightsSupabase (encrypted at rest, not end-to-end)

3.2 Sensitive Health Data (AES-256-GCM encrypted — server holds ciphertext only)

CategoryExamplesWhere Stored
MedicinesMedicine names, dosages, schedulesEncrypted on-device; encrypted backup on Supabase — server cannot decrypt
Symptom diaryDaily mood, symptoms, notesEncrypted on-device; encrypted backup on Supabase — server cannot decrypt
Lab report AI analysisNarrative summary and structured test values generated by GeminiEncrypted on-device; encrypted backup on Supabase — server cannot decrypt
AI chat history (Vita)Your conversation messages with VitaEncrypted on-device; encrypted backup on Supabase — server cannot decrypt
Medicine change historyA log of medicine additions, removals, and dose/time changes (Pro feature: Medicine Journal)Encrypted on-device; encrypted backup on Supabase — server cannot decrypt
HealthIQ insightsAI-generated narrative text describing patterns in your own health trendsEncrypted on-device; encrypted backup on Supabase — server cannot decrypt; auto-deleted after 12 months
Monthly HealthIQ Score narrativeAI-generated narrative summarizing your monthly score (Pro feature)Encrypted on-device; encrypted backup on Supabase — server cannot decrypt; auto-deleted after 24 months
Report metadataReport type, scan dateSupabase (RLS — only your account can read)

3.3 Information Collected Automatically

CategoryExamplesPurpose
Device identifiersInstallation ID (anonymous)Track free-tier usage limits without requiring an account
Usage patternsFeature usage counts per monthEnforce AI scan limits fairly
App performance dataCrash reports (if you consent)Fix bugs and improve stability

3.4 Information We Do NOT Collect

4. How We Use Your Information

PurposeLegal Basis (Canada/PIPEDA)Legal Basis (India/DPDPA)Legal Basis (EU/GDPR)
Provide core app featuresConsent + ContractConsentPerformance of contract
Send medication remindersConsentConsentConsent
Power AI health analysisConsentConsentConsent
Process subscription paymentsContractContractPerformance of contract
Improve app featuresLegitimate interestLegitimate interestLegitimate interest
Comply with legal obligationsLegal obligationLegal obligationLegal obligation

We do not use your health data for advertising, sell it to any third party, or use it to make automated decisions that significantly affect you without your knowledge.

5. AI Features and Your Health Data

5.1 How Vita (AI Chat) Works

When you use Vita, your health data (today's meals, medicines, wellness score, health conditions from your profile) is sent to an AI model to generate personalized responses. Vita's primary responses are generated by Google Gemini; if Google's service is temporarily unavailable, the request may automatically fall back to Anthropic's Claude AI model instead, so your conversation isn't interrupted. Whichever provider handles the request processes it only to generate your response and does not use this data to train their AI models under our agreement.

5.2 Medicine and Food Scanning

When you scan a medicine label or food item, the image is sent to Google Gemini for analysis. If Gemini is unavailable, the scan may automatically retry using Anthropic's Claude AI model as a fallback, so a temporary outage on one provider doesn't block your scan. The image is processed and immediately discarded — we do not store your camera images on our servers with either provider.

5.3 Lab Report Scanning

Lab report images are sent to Google Gemini for analysis via a temporary upload that is deleted immediately after analysis completes. Lab report scanning always uses Google Gemini and never falls back to another AI provider, given the medical accuracy this feature requires. The AI-generated narrative analysis is encrypted on your device using AES-256-GCM before any backup leaves your device — the server holds only unreadable ciphertext. The decryption key stays in your device's Keychain; we cannot read your lab results.

5.4 HealthIQ Insights & Monthly Score (optional, requires your consent)

If you enable HealthIQ in Settings → Notifications → AI Insights and have granted third-party AI consent, Mediqrate periodically analyses aggregated trends across your own data (sleep, nutrition, activity, medicine adherence) using Google Gemini to generate plain-language insights and, for Pro subscribers, a monthly score narrative. Only aggregated summaries are sent — never raw day-by-day records — and, where you have more than a few distinct medicines, individual medicine names are not included in the request at all. You can disable this at any time without affecting any other feature, including Vita.

5.5 Appointment Reports & Ask My Doctor (optional, requires your consent)

You may generate a health summary document, or a list of AI-suggested questions to bring to your next appointment, for your own use with a healthcare provider. Generating the optional AI-written summary or question list uses Google Gemini and the same third-party AI consent as Vita chat. The report or question list is not stored on our servers — it exists only on your device until you choose to share it, and we do not track where you send it.

5.6 Nutrition Intelligence (optional, requires your consent)

If enabled, Mediqrate can generate a short, AI-written note about a meal you've just logged, using Google Gemini. This uses the same third-party AI consent as other AI features and is not stored — the note exists only on your device for the current session.

5.7 Enhanced Privacy Mode (optional, on-device AI)

You may optionally enable Enhanced Privacy Mode in Profile → Privacy & Data, which downloads a small AI model (roughly 900 MB–1.1 GB) to run entirely on your device. When active, it replaces cloud AI for the weekly health story, HealthIQ insight narrative, appointment report summary, and per-meal nutrition notes — none of that processing is sent to Mediqrate's servers or to any third party while this mode is active. Lab report analysis, Vita chat, and Ask My Doctor always use cloud AI (Google Gemini, with Anthropic Claude as an availability fallback) regardless of this setting, since they require more knowledge than an on-device model can safely provide. You can disable and delete the on-device model at any time.

6. Third-Party Services We Use

ServicePurposeData Shared
Supabase (Canada)Database and authenticationAccount data, health metrics, meals, medicines
Google Gemini AIPrimary AI model for Vita chat, medicine/food/lab scans, and all optional AI insight features (HealthIQ, appointment reports, nutrition notes, Ask My Doctor)Images during scan, health summary for chat, aggregated trend data for optional insight features
Anthropic Claude AIFallback AI model for Vita chat and medicine/food scans only — used only when Google Gemini is temporarily unavailable. Never used for lab report analysis, HealthIQ, appointment reports, or Ask My Doctor.Same data as the Gemini request it is standing in for — only when Gemini cannot respond; neither provider retains your data after processing
RevenueCatSubscription managementPurchase history, subscription status
Apple App StoreiOS payment processingPayment details (Apple handles directly)
Google PlayAndroid payment processingPayment details (Google handles directly)
Expo (EAS)App delivery and updatesApp version, device type
PostHogProduct analytics — understanding how the app is usedA unique account identifier, subscription tier, and behavioral events (e.g. app opens, signups, paywall views). Does not receive scan images, chat content, medicine names, or lab values.

We do not use Google Analytics, Facebook, or any advertising networks. We do use PostHog for product analytics — see the table above for what it receives. You can read PostHog's privacy policy at posthog.com/privacy.

7. Data Retention

Data TypeRetention Period
Account informationUntil you delete your account
Health metrics and mealsUntil you delete your account or delete individual entries
Medication recordsUntil you delete your account or delete individual medicines
AI chat historyUntil you delete your account or delete individual sessions
Payment transaction records7 years (required by tax law in Canada)
Lab report AI analysis (encrypted backup)Until you use "Delete All My Data" or delete your account — server-side copy is unreadable without your device key
Lab report structured test valuesUntil you use "Delete All My Data" or delete your account
HealthIQ insightsAutomatically deleted after 12 months
Monthly HealthIQ Score recordsAutomatically deleted after 24 months
Medicine change history (Medicine Journal)Automatically deleted after 24 months
Daily check-in recordsAutomatically deleted after 24 months
Usage logs (for AI limits)60 days
Deleted account dataPermanently deleted immediately upon account deletion — all health data, profile, and session records are removed in the same request

8. Your Rights

8.1 Rights for Canadian Users (PIPEDA)

8.2 Rights for Indian Users (DPDPA 2023)

8.3 Rights for EU/UK Users (GDPR)

8.4 How to Exercise Your Rights

Within the app: Profile tab → Privacy & Data → Export My Data or Delete All My Data

By email: privacy@mediqrate.com — We will respond within 30 days.

9. Data Security

We protect your data using:

Despite these measures, no method of electronic storage or transmission is 100% secure. We encourage you to use a strong, unique password for your account.

10. Children's Privacy

Mediqrate is not directed at children under the age of 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe your child has provided us with personal information, contact us at privacy@mediqrate.com and we will delete it promptly.

11. Data Transfers

Your data is stored on Supabase servers in Canada (ca-central-1 region). When you use AI features, your data is briefly processed by Google Gemini servers, which may be located in the United States. This transfer occurs under Google's standard contractual clauses which comply with GDPR and PIPEDA requirements.

For Indian users: data may be transferred outside India to Canada and the United States for the purposes described above. By using Mediqrate and accepting these terms, you consent to this transfer.

12. Push Notifications

We send push notifications for:

You can turn off any or all notifications in your device's Settings app at any time.

13. Changes to This Policy

We will notify you of significant changes by sending a push notification, showing an in-app notice when you next open the app, and updating the "Last Updated" date at the top of this page. Continued use of Mediqrate after changes constitutes acceptance of the updated policy.

14. Contact Us

For privacy questions or to exercise your rights:
Email: privacy@mediqrate.com — Response time: Within 30 days

For general support:
Email: support@mediqrate.com

Mailing address:
Yogesh Pawar (operating as Mediqrate)
Rossland Ave, Nepean, ON K2G 2K8, Canada


This Privacy Policy was last reviewed on July 21, 2026 (policy version 1.5.0).