Privacy policy
1. Who we are and what this policy covers
medk.AI (the “Service”, “we”, “us”) operates the website and application available at medk.ai. medk.AI is the operator and the data controller for the processing described in this policy. The Service stores the documents you choose to upload, analyses them using an artificial intelligence reading service, and presents the results to you in a personal dashboard. This Privacy Policy explains what personal data we process, why we process it, on what legal basis, where it is stored, with whom it is shared, how long it is kept, and the rights you hold over it. It applies to every visitor to our website and every holder of an account. Questions about this policy or about your data should be addressed to privacy@medk.ai. We have appointed this address as the single point of contact for all privacy matters.
2. The data we process
We process the following categories of personal data. We do not collect any category not listed here.
- Account data. When you sign in with Google, we receive and store your name, email address, and account picture. When you sign in with an email link instead, we store your email address, and a name only if you add one in your settings. If you choose a password, it is stored encrypted, never as readable text. We use this data to operate your account, to secure it, and to communicate with you about the Service.
- Invitation. While the Service is open by invitation, we hold the email address an invitation was sent to, the plan it carries, and a short note about it, so you can sign up and receive that plan. It is deleted when you close your account.
- Documents and extracted results. The documents you upload, such as laboratory and imaging reports, and the individual results, values, dates, and narrative findings our reading service extracts from them. We process them for one purpose only: to display it to you, organised and explained, in your dashboard. We do not use it for advertising, we do not sell it, we do not share it with any third party except the processors listed in section 5, and we do not use it to train any artificial intelligence model. On a family plan, a plan owner may also see a member’s results, readings and files, and the profile facts the member gives for the people they manage, but only where both of these hold: the invite carried the owner’s per-member request to see them, and the member agreed to it in the app. That agreement is recorded with a version and timestamp, it defaults to off, it is revocable by the member at any time with effect for the future, and it is one-directional: the member never sees the owner’s data. The owner never sees the profile facts a member gives about themselves, even with that agreement, although the member’s readings and the results worked out for them may reflect those facts.
- Optional profile facts. Sex, the month and year of your birth, and whether you have diabetes, are pregnant, or have been through menopause. Each answer is optional and provided by you, and you can change or clear it at any time. These answers exist solely because safe reference ranges for certain results differ by sex, age, diabetic status, pregnancy, and menopause. The month of birth lets a range that changes with age change in the month you reach that age, rather than up to a year early. We never ask for the day you were born, and we deliberately do not collect your full date of birth, address, national identifiers, or any insurance information. These answers come only from what you enter; we never take them from your documents.
- Profiles you manage. The names or labels you give to people whose documents you manage on your account and, if you choose to give them, the same optional profile facts for each of them: sex, the month and year of their birth, and whether they have diabetes, are pregnant, or have been through menopause. Each is used only to set that person’s safe ranges, and the day of birth is never asked. These are records inside your account, not accounts of their own. If you are a member of a family plan and agree to let its owner see your results, the owner can also see these facts. Where you add a person under eighteen years of age, we record your confirmation that you hold parental responsibility for that person.
- Family-plan membership. When you join a family plan, or invite someone to yours, the plan owner and the member each hold their own account and their own sign-in credentials. Membership itself stores only what membership needs: the invited email address, the date the person joined, their role on the plan (owner or member), and the visibility setting described under documents and results below. Joining a family plan never gives either side access to the other side’s documents.
- Consent records. The version and timestamp of each consent you give. These records are our legal evidence that your data was processed lawfully, and they are retained even if you later delete your data.
- Technical data. Records generated by operating the Service, such as processing status of uploaded files and token counts of AI processing, held for reliability and cost accounting. Where you agree through the cookie notice, we measure how the public site is used, which pages are visited, an approximate region, device type, and how far visitors get through signing up, and, inside the signed-in app, the fixed steps set out here. On the marketing pages, PostHog may also record how visitors move through a page; what visitors type and anything that looks like an email is masked before it leaves the browser. Inside the app we count that a screen was opened, that an upload was started or finished, or that a report was opened, linked to your account by an internal identifier only. Nothing we measure sees your reports, your results, or the values in them: your reports are read only to build your own dashboard, and only with your permission. Recording never runs on the sign-in pages or inside the signed-in dashboard. This measurement rests on your consent: declining leaves these tools unloaded, and you can withdraw your answer at any time from the cookie control in section 7, after which measurement stops and your use of the Service is unaffected. Apart from that choice, the only cookie-like storage keeps you signed in and remembers your theme preference. We also keep simple usage counts for each account, such as how often the dashboard is opened and how many reports are uploaded, and we use them only to improve the product; these counts contain no health information.
- Error reports. When a page fails, your browser sends us the error message, the technical trace, and the page address, so we can fix the problem. No document content is included.
- Referral code. If you arrived through someone's invitation link, your browser remembers that code for thirty days so we can credit the person who invited you.
- Email delivery records. When a report arrives at our documents address, we record the sender, the subject, and the outcome, so we can tell you what happened to it.
- Messages you send us. What you write through the contact form, with the name and email address you give so we can reply, and your answer to the short check-in question in the app. We use them only to answer you and to improve the Service, and keep them only as long as that needs. Closing your account deletes the messages sent from it; a check-in answer then no longer carries your account.
- Service emails. To run your account we send: one-time sign-in links; a notice when a report you uploaded has been read; a first-week check-in; a reminder when a measurement you track may be due for a fresh reading; and payment notices before and after your trial ends. The payment notices are required and cannot be switched off; every other kind can be turned off from your settings.
3. Why we process it, and on what legal basis
We process the documents you upload, and the results taken from them, on the basis of your explicit consent. Because those documents can carry data concerning health, that consent is the explicit consent such data requires: we ask for it on a dedicated screen before the Service first processes anything, and we record it with a version and timestamp. You may withdraw this consent at any time by deleting your data or your account, after which no further processing occurs. We process account data and technical data because they are necessary to perform our contract with you, namely operating the Service you signed up for. We process consent records because we are legally required to be able to demonstrate that consent was given. Where a law requires a distinct or additional consent, for example for data concerning a person under eighteen, we collect that consent separately as described above. We process the optional profile facts described in section 2 only because you choose to give them, on the basis of your consent. Where an answer concerns your health, such as diabetes, pregnancy, or menopause, that consent is explicit: you give it by entering the answer after being told why it is asked. Clearing an answer withdraws that consent for it, with effect for the future. For a person you manage, you give these answers for them, under the same authority you hold for their documents. Where a family-plan owner is shown a member’s results, readings and files, and the profile facts the member gives for the people they manage, that disclosure rests on the member’s own explicit consent: the owner’s request alone unlocks nothing, the agreement is recorded with its version and timestamp, and the member may withdraw it at any time with effect for the future.
4. Where your data lives
Your documents and results are stored in a database and file store located in Frankfurt, Germany, in the European Union, operated for us by Supabase. Access to your rows of data is enforced at the database layer: every request must prove your identity before a single record is returned. Your original documents live in a private storage area that only your authenticated account can open, through links that expire.
5. Who touches your data
Seven categories of service providers, called processors, act on our documented instructions. Each is bound by a written data processing agreement, and each appears here by name so you always know the full list. We use no other processors. If this list ever changes, this policy will be updated before the change takes effect.
- Supabase (database, storage, and sign-in infrastructure), processing in Frankfurt, Germany.
- Anthropic (the artificial intelligence reading service that extracts and explains your results). Your documents, or the text taken from them, are sent to this provider for reading under a data processing agreement that incorporates the European Union’s Standard Contractual Clauses. The provider’s terms forbid it from training models on your content. Its published policy is to delete inputs and outputs from its systems within thirty days, and to keep for up to two years anything its safety systems flag for review. Reading happens in the service’s own data centres, outside the European Union, under the Standard Contractual Clauses named above.
- Netlify (delivery of the website and application). Netlify serves the application’s pages and never receives or stores your documents or results.
- Google (sign-in only). Google processes the authentication handshake when you sign in and receives no documents and no results.
- Google Analytics 4 (public-site measurement, only with your agreement through the cookie notice). Counts visits to the public pages and the steps of signing up. It never receives your documents, your results, or any page inside the signed-in dashboard, and it is not used for advertising.
- Microsoft Clarity (public-site measurement, currently switched off, and only ever with your agreement through the cookie notice). When it runs it produces heatmaps and recordings of how the public pages are used, with what you type masked; masked, not anonymous. It has never run inside the signed-in app.
- PostHog (measurement of the site and the app, only with your agreement through the cookie notice). Counts visits to the public pages and the steps of signing up, records movement through the marketing pages with what visitors type and email-shaped text masked before it leaves the browser, and counts fixed steps of using the signed-in app against your account, such as a screen being opened or an upload starting and finishing. It never receives your documents, your reports, your results, or the values in them, and it is not used for advertising.
- Resend (email delivery). When you sign in with an email link, or when the Service sends you one of the notices listed in section 2, Resend carries that mail on our behalf, from a medk.AI address, and uses the address for nothing else.
Where any processing occurs outside the jurisdiction in which you live, it takes place under the safeguards described above, including the European Union’s Standard Contractual Clauses where they apply. Payment processing, when paid subscriptions are active, is performed by a merchant of record acting as an independent controller of the payment data you provide to it; the merchant of record never receives your documents or your results.
6. How long we keep it
Your documents and results are kept for as long as your account holds them, because the Service’s purpose is to preserve your history and show it to you over time. You may delete individual documents, reset your dashboard, or delete everything at any moment. Deleting everything removes your documents, results, profile answers, the people you manage together with their answers, and reading snapshots, including the transcript cache those readings draw on. It also clears the subject line of every report you emailed to us. Resetting the dashboard keeps the reading cache and your profile answers on purpose, so re-uploading the same documents restores your readings instantly; deleting everything removes them too. The account itself stays, signed in and empty, so a mistake can be repaired by starting fresh. What stays with it is what running the account needs: your sign-in details, plan, family-plan membership, referral rewards and settings, the usage counts and technical records described in section 2, the record that a report emailed to us arrived (the sender, the time and the outcome, which limits how many reports one sender can send in a day), and any message you have sent us. Two categories also stay because the law requires them to: the consent records described in section 2, and transactional records where tax or accounting law demands their retention. If you want the account gone too, you can close it completely. Closing deletes the account and its sign-in together with all of your data, including your consent records, your family-plan membership, your settings, the records of reports you emailed to us, the messages you sent us from your account, the invitation you joined with, and our copies of your billing records. If you own a family plan, its members keep their own accounts and their own data. What remains afterwards is a copy of your consent records that can no longer be linked to you, kept as proof that consent was given, and the payment provider event records described below until their thirteen-month limit. A backup copy of deleted data, held only for disaster recovery, is gone from every backup within seven days.
Some technical records are kept on a fixed schedule. The input of a completed reading job is cleared after thirty days, a failed job is deleted after ninety days, a cached reading is deleted after eighteen months without use, the scheduling log is kept for seven days, billing payload records (the payment provider event ledger and the checkout funnel) are pruned after thirteen months, and the measurement records (the per-account usage counts and what our analytics provider holds) are kept for up to thirteen months. The steps counted inside the app are linked to your account by an internal identifier only, never your name, your email address, your plan, or anything from a report, and we keep no profile that identifies you in the measurement provider.
When a family-plan membership ends (the owner removes the member, or the member leaves), the owner’s access to the member’s data is revoked immediately. The member’s data belongs to the member, and stays in the member’s own account. Where the owner removes a member, the member’s data is kept for a thirty-day download grace so nothing is lost in the transition, and is then deleted on the schedule we publish; the member may instead ask for immediate deletion, and an explicit erasure request is always honoured at once, without waiting for the grace period. Where the member leaves of their own accord, their data simply stays in their account. Consent records survive as the law requires.
7. Your rights
Depending on where you live, the law grants you some or all of the following rights, and we honour all of them everywhere, without requiring you to establish which law applies to you:
- Access and portability. Your dashboard is itself continuous access to your data. From Settings you can download, at any time, every document you have uploaded in one archive, and your results and the profile facts you have given as spreadsheet files.
- Rectification. Where an extracted value is wrong, you may re-upload a corrected document or write to us and we will correct the record.
- Erasure. The delete controls described in section 6 execute this right without our involvement, at any time, without notice periods.
- Withdrawal of consent. As described in section 3, with effect for the future.
- Objection and restriction. Since we process only to show you your own data, an objection is honoured by deletion or by ceasing the contested processing.
- Complaint. You may complain to us first at privacy@medk.ai, and we will answer. You also always hold the right to complain to the data protection authority of your country of residence.
Your answer to the cookie notice can be changed at any time, and the notice reopens for you here.
We answer every rights request within one month. We never charge for exercising a right.
8. Children
Account holders must be at least eighteen years of age. Records of a person under eighteen may be managed within an adult’s account only where that adult has confirmed holding parental responsibility for the person concerned, and this confirmation is recorded. Children are never given sign-in credentials and are never contacted by the Service. Where you give a child’s month and year of birth, it is used only to set that child’s safe ranges, and the day of birth is never asked.
9. Automated processing
The Service’s reading of your documents is automated: an artificial intelligence system extracts values and produces plain-language explanations. This processing does not make any decision producing legal or similarly significant effects about you. It organises and explains your own records for your own reading. The Service is not a medical device, its output is not a diagnosis or medical advice, and every page of the dashboard reminds you to consult a qualified professional about your results.
10. Security
We protect your data with measures including encryption of data in transit, database-level row security that binds every record to its owning account, private storage with expiring access links, self-hosted fonts and images so the signed-in application never calls third-party servers, and access accounting on processing jobs. No system is perfectly secure; if a breach ever affects your data, we will notify you and the competent authorities promptly and in plain words, within the timelines the applicable law sets, including the seventy-two hour standard where it applies.
11. Changes to this policy
If we change this policy in any way that matters, we will present the new version to you and ask for your agreement again before the Service continues processing your documents. The version date at the top of the policy is the version you agreed to, and your consent records preserve the history.
12. Contact
Privacy matters: privacy@medk.ai. All other matters: support@medk.ai. We answer both.
Privacy matters: privacy@medk.ai · Everything else: support@medk.ai