🔒 Core Privacy Commitment
PromedAI does not sell, rent, or monetize your health or medication tracking data. We process your data locally on your device whenever possible and employ end-to-end encryption for any cloud sync.
1. Scope and Global Applicability
This Privacy Policy governs the processing of personal data by PromedAI ("we", "us", or "our") through our website, mobile application, and related services. Our practices are designed to align with strict global standards, including:
- United States: The Health Insurance Portability and Accountability Act (HIPAA), California Consumer Privacy Act (CCPA/CPRA), and COPPA.
- United Kingdom & European Union: The General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.
- Global Standards: Principles of privacy-by-design, data minimization, and user consent.
2. Data We Process
A. Device-Only Data (Health & Medication Logs)
Medication schedules, adherence logs, and body impact metrics are primarily saved locally on your device. If you enable the secure backup feature, this data is encrypted in transit and at rest using AES-256 keys which you control.
B. Camera Scan Processing
When you use the AI Medication Scanner to read prescription labels:
- The image is processed securely via secure, ephemeral API endpoints.
- We do not store or keep the source photos on our servers after extraction is completed.
- No personal identifying information (PII) from the prescription label is indexed, saved, or shared with third parties.
C. Account & Billing Info
Your name, email address, and billing details are processed securely by our online reseller and Merchant of Record, Lemon Squeezy, to manage your Founder Access subscription. We never see or store your payment card numbers.
3. HIPAA Compliance (United States)
For users in the United States, although PromedAI is a direct-to-consumer application and not a "covered entity" under HIPAA rules in all contexts, we maintain standard HIPAA-aligned administrative, physical, and technical safeguards. This ensures that any personal health information (PHI) you choose to sync is handled with bank-level encryption and access audits.
4. GDPR & UK Data Protection (EU & United Kingdom)
Under GDPR and UK laws, you have specific rights regarding your personal data:
- Right to Access: You can request a complete export of your medication logs and profile data directly from the app settings.
- Right to Erasure (Be Forgotten): You can delete your account and clear all remote and local data instantly at any time.
- Data Portability: You can export your data in structured, machine-readable JSON format.
The legal basis for processing your data is your explicit consent, which you grant when creating your account, and our legitimate interest in providing safety checks on drug interactions.
5. California Consumer Privacy Act (CCPA/CPRA)
We do not "sell" or "share" personal information as defined by California law. California residents have the right to opt-out of data processing, limit the use of sensitive personal information, and request detailed reporting on the categories of data we collect.
6. Third-Party Services and Subprocessors
We restrict our subprocessors to high-security infrastructure providers. Any third-party AI models used for label parsing are bound by strict business associate agreements (BAAs) and data processing agreements (DPAs) that prohibit retaining or using your scans to train their models.
7. Updates to This Policy
We will notify you of any material changes via email or app notice. Your continued use after update verification constitutes acceptance of the new privacy terms.
8. Contact Our Data Protection Officer (DPO)
If you have questions about this policy, or wish to exercise your legal privacy rights, contact us at:
Email: support@promedai.xyz