M
MedLog
← Back to MedLog
Legal

Privacy Policy

MedLog LLC (Delaware LLC, pending formation) — operator of MedLog
Last updated: May 24, 2026 · Effective: May 24, 2026
The short version. We collect the minimum needed to run a health diary: your email, your name (if you give it), and what you type into MedLog. We encrypt your health entries before storing them. We do not sell your data, show ads, or train AI on your content. You can export everything or delete your account at any time.
Contents
  1. Who we are
  2. What we collect
  3. How we use it
  4. Legal bases (GDPR / UK GDPR)
  5. What we never do
  6. Who we share data with
  7. Security
  8. How long we keep data
  9. Your rights
  10. International transfers
  11. Children
  12. Cookies & tracking
  13. Regional provisions
  14. Changes to this policy
  15. Contact & complaints

1. Who we are

This policy describes how MedLog LLC ("we", "us", "MedLog"), a Delaware limited liability company (pending formation), collects and processes personal data when you use MedLog — our website, web app, progressive web app, and related services (collectively the "Service"). For data protection law, we are the data controller.

2. What we collect

2.1 Information you give us

CategoryWhat it isRequired?
EmailIdentifies your account; receives verification, password reset, and account emailsYes
NameUsed on doctor summaries you exportNo
PasswordStored only as a bcrypt hash, never in plain textYes
Health entriesSymptom notes, severity, tags, timestampsNo (but the app is useless without them)
MedicationsName, dose, schedule, reason, notes, statusNo
Lab valuesTest names, values, units, reference ranges, datesNo
Uploaded filesBloodwork PDFs or images you attachNo

2.2 Information we collect automatically

CategoryWhat it isWhy
IP addressThe IP your request comes fromSecurity audit, rate limiting
User agentYour browser type and versionSecurity audit
TimestampsWhen you log in, change your password, create or edit entries, export your dataSurfaced to you in Settings → Security log
Account stateFailed login count, lockout timeAccount security

We do not use analytics platforms. We do not place tracking pixels. We do not fingerprint your device.

2.3 Special category / sensitive data

Information about your health is "special category" data under GDPR Article 9 and "sensitive personal information" under several US state laws. We treat it with corresponding care: encrypted at rest with AES-256-GCM, keys held separately from the database, processed only to operate the Service for you.

3. How we use it

PurposeLawful basis
Provide the Service to youContract — Art. 6(1)(b)
Process your health entries (special category)Explicit consent — Art. 9(2)(a)
Authenticate and secure the ServiceLegitimate interest — Art. 6(1)(f)
Comply with legal obligationsLegal obligation — Art. 6(1)(c)

You can withdraw consent for health data processing by deleting your account at any time.

5. What we never do

6. Who we share data with

We use a small number of subprocessors to run the Service. Each is bound by a data processing agreement.

SubprocessorPurposeLocation
RailwayApp hosting and database storage (data encrypted by us before storage)USA
ResendSending transactional emailsUSA

Beyond subprocessors, we share data only when: you ask us to (e.g., you email your export to your doctor); the law requires it (we'll notify you where legally permitted); to protect rights against suspected fraud or abuse; or in a business transfer (under terms at least as protective as this policy, with notice to you).

7. Security

No service is perfectly secure. If a security incident affects your data, we will notify you and applicable regulators as required by law (in the US, this includes the FTC Health Breach Notification Rule).

8. How long we keep data

CategoryRetention
Your account and contentUntil you delete them
Encrypted backupsUp to 30 days after deletion, then overwritten
Audit log recordsUp to 2 years; longer where required by law
Email verification tokens30 minutes
Password reset tokens30 minutes; single-use
Server access logsUp to 90 days

9. Your rights

For rights not exposed as a button in the Service, contact us (section 15). We respond within 30 days. We may verify your identity first. Exercising rights is free unless requests are manifestly unfounded or excessive.

10. International data transfers

We are based in the United States. If you access the Service from outside the US, your data is transferred to and processed in the US.

For users in the EU, UK, and regions with similar transfer rules, we rely on the European Commission's Standard Contractual Clauses (SCCs) with Railway and Resend. You can request a copy of the SCCs.

11. Children

MedLog is not for users under 16 years old. We do not knowingly collect personal data from children. If you believe a child under 16 has provided personal data, contact us and we will delete it.

12. Cookies & tracking

NamePurposeLifetime
medlog_sessionKeeps you logged in (HttpOnly, Secure, SameSite=Lax JWT)15 minutes sliding

That's the only cookie we set. We do not use marketing, advertising, analytics, or third-party tracking. We don't respond to "Do Not Track" because we don't track you to begin with.

13. Regional provisions

🇺🇸 United States

California (CCPA/CPRA): Rights to know, delete, correct, and limit use of sensitive personal information. We do not "sell" or "share" personal information as defined under California law. Exercise rights via the Service or contact us.

Other US states (Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Indiana, Kentucky, Maryland, Minnesota, Rhode Island and others): similar rights apply. We don't do targeted advertising or profiling.

HIPAA: MedLog is a consumer-facing personal health record. We are not a HIPAA Covered Entity or Business Associate. We are subject to the FTC Health Breach Notification Rule.

Washington "My Health, My Data" Act and similar consumer-health-data laws: equivalent rights extended regardless of where you live.

🇬🇧 United Kingdom

UK GDPR and DPA 2018 apply. You have rights of access, rectification, erasure, restriction, portability, objection, and to withdraw consent. Complaints to the ICO (ico.org.uk). UK users transferring to the US are protected by the UK Addendum to the EU SCCs.

🇪🇺 European Union & EEA

GDPR applies. Full data subject rights. Health data is special category under Art. 9; we rely on your explicit consent. Complaints to your national DPA (edpb.europa.eu).

EU Representative (Art. 27 GDPR): [EU representative to be appointed before EU launch]

🇨🇦 Canada

PIPEDA federally; Quebec's Law 25, BC's PIPA, Alberta's PIPA may also apply. Complaints to OPC Canada (priv.gc.ca) or your provincial commissioner.

🇦🇺 Australia

Privacy Act 1988 and Australian Privacy Principles apply. Complaints to the OAIC (oaic.gov.au).

🇳🇿 New Zealand

Privacy Act 2020 applies. Complaints to the Office of the Privacy Commissioner.

🌏 Asia

Local laws apply: Japan (APPI), Singapore (PDPA), India (DPDP 2023), South Korea (PIPA), Philippines (Data Privacy Act 2012), Hong Kong (PDPO), Thailand (PDPA), Malaysia (PDPA 2010), Indonesia (PDP Law), Vietnam (PDPD).

The Service may not be available if you are in mainland China, Iran, North Korea, Cuba, Syria, or Crimea.

🌎 Latin America

Local laws apply: Brazil (LGPD — complaints to ANPD), Mexico (LFPDPPP — complaints to INAI), Argentina (PDPA 25,326), Chile, Colombia, Peru, Uruguay and others.

🌍 Africa

Local laws apply: South Africa (POPIA — complaints to the Information Regulator), Nigeria (NDPA 2023), Kenya (DPA 2019), Egypt (Law 151/2020), Ghana (DPA 2012).

Middle East

Local laws apply: UAE (Federal PDPL), Saudi Arabia (PDPL), Israel (Privacy Protection Law 5741-1981), Turkey (KVKK).

14. Changes to this policy

We may update this Privacy Policy from time to time. For material changes (adding a subprocessor, changing what data we collect, changing how we use it), we'll update the "Last updated" date, email you at least 30 days in advance, and show a notice in the Service. For non-material updates, we'll update the date and post the new version.

15. Contact & complaints

MedLog LLC
Email: Contact form
Postal address: [to be added before launch]
EU representative (GDPR Art. 27): [EU representative to be appointed before EU launch]

For privacy questions, rights requests, or complaints, contact us. We aim to respond within 30 days. If not satisfied, you may lodge a complaint with your local data protection authority (section 13).