Legal
Privacy policy
Last updated June 10, 2026
Replaces: the version last updated 2025-01-10.
A note on words we use
We try to write in plain language. A few terms appear throughout, so we define them once here:
- Personal information (PI) — any information about you as an identifiable person. Your name, email address, and date of birth are personal information.
- Protected health information (PHI) — the subset of personal information that is about your health and is tied to you as an identifiable person. In medwallet this includes things like your medications, your vital signs, lab documents you upload, voice notes you record, and the health profile of family members you add. Throughout this policy, when we say "health information" we mean PHI.
- You — the person using medwallet, and (where you manage records for a family member or dependent) the people whose records you manage.
- We / us / medwallet — the company that operates the medwallet app.
1. Who we are
medwallet is a consumer health-records app. It lets you keep your own and your family's health records — medications, vitals, documents, voice notes, and more — in one place on your device and in our secure backend.
- The person in charge of your personal information (our Privacy Officer): By default this is our Chief Executive Officer, who holds the role of the person in charge of personal-information protection under Quebec Law 25 (P-39.1, s. 3.1), the HIPAA Privacy Official and complaints contact (45 CFR §164.530(a)(1)), and the PIPEDA accountable individual (Schedule 1, Principle 4.1). Quebec Law 25 s. 3.1 and HIPAA §164.530(a)(1)(ii) both require us to publish this person's title and contact information.
2. What this policy covers and how medwallet is regulated
medwallet is built to handle real health information under the privacy and health-records laws that apply to our users. Those users are in Canada, and their health information is stored and processed in Canada.
The laws we have designed medwallet around are:
- HIPAA (the U.S. Health Insurance Portability and Accountability Act) — the U.S. health-privacy framework.
- Quebec Law 25 (the Act respecting the protection of personal information in the private sector, P-39.1) — the Quebec private-sector privacy law.
- PIPEDA (the Personal Information Protection and Electronic Documents Act) — the Canadian federal private-sector privacy law.
3. What personal information we collect
We collect only what we need to run the app and provide its features.
| Category | Examples | Is it health information (PHI)? |
|---|---|---|
| Account and identity | Your email address; sign-in details; if you use Sign in with Apple, an identity token from Apple | Personal information, not health information |
| Health records you enter | Medications and dose logs; vital signs (e.g. weight, height); allergies; conditions; consent choices; mood check-ins | Yes — health information |
| Documents and voice notes | Lab PDFs and other files you upload; voice notes you record, and their text transcripts | Yes — health information |
| Family / dependent records | The same kinds of records, for family members or dependents you add and manage | Yes — health information |
| Billing | Your subscription status and opaque billing identifiers from our payment providers. We do not receive or store your full card number — our payment providers handle that. | Personal information, not health information |
| Device and technical | An opaque device identifier used to deliver notifications; app version and platform; basic diagnostic and usage signals | Personal information; designed to carry no health information (see § 6) |
We do not sell your personal information.
4. Why we collect it
We collect and use your information for these purposes:
- To provide the app: to store, display, and organize your and your family's health records; to send dose reminders; to transcribe voice notes; to manage your household and dependents.
- To run your account: to sign you in and keep you signed in; to manage your subscription and billing.
- To keep the service safe and reliable: to detect and fix errors, prevent abuse, and maintain a security and access audit trail as health-records law requires.
- To communicate with you: to send transactional messages (for example, an account or invite email, or a notice that your data export is ready).
Under Quebec Law 25, our purposes must be serious and legitimate and are determined before we collect. Under PIPEDA we identify our purposes at or before collection. Under HIPAA, we apply the minimum-necessary principle to uses and disclosures.
5. Who we share it with (our service providers)
We use a small set of vetted service providers (sometimes called subprocessors) to run medwallet. Where a provider handles your health information, we have a signed Business Associate Agreement (BAA) — the contract HIPAA requires before a provider may handle PHI on our behalf — in place. We list them openly here.
Providers that handle your health information (under a signed BAA):
| Provider | What it does | Health information handled |
|---|---|---|
| Supabase | Our database, file storage, and sign-in system — the main system that stores your records, documents, and voice notes | Yes — this is where your records live |
| Microsoft Azure (Speech service) | Converts your voice notes into text | Yes — the audio of your voice note and its transcript |
Providers used in a way designed to carry no health information:
| Provider | What it does | Health information handled |
|---|---|---|
| Microsoft Azure (audit storage, transactional email, secrets, monitoring) | Stores a health-information-free audit trail; sends transactional email; holds secrets; monitors system health | No — designed to be free of health information |
| Sentry | Error reporting (helps us find and fix crashes) | No — a filter removes health information before anything is sent |
| PostHog | Product analytics (helps us understand how the app is used) | No — a filter removes health information before anything is sent |
| Stripe and RevenueCat | Process subscription payments and track entitlements | No — billing status and opaque identifiers only; not your health records |
| Firebase Cloud Messaging (Google) | Delivers push notifications (like dose reminders) | No — the notification carries only an opaque code; the readable text is built on your own device |
| Apple (Sign in with Apple) | Lets you sign in with your Apple ID | No — an identity token only |
How we keep health information out of the "no health information" providers: our app is built so that anything not on a small approved list of fields is automatically stripped out before it leaves our systems. This is a deny-by-default design — if a field is not explicitly allowed, it is removed.
6. Where your information is stored (data residency)
Your health information is stored and processed in Canada. It lives in a Canadian region (Canada Central, ca-central-1), in-country, and is not moved to another region. Our backups stay within Canada as well.
The one time your health information leaves our control is when you ask for a copy of it (see § 7, "Get a copy of your data / portability"). At that point you are pulling your own data to your own device. That is you exercising your right of access, not us sending your data somewhere.
Cross-border note for billing: Our payment providers operate in both Canada and the United States. The information that reaches them is billing status and opaque identifiers — not your health records. Because some billing information may be processed outside Quebec, Quebec Law 25 requires us to assess that transfer.
7. Your rights and how to use them
You have rights over your personal information. Depending on where you live, these come from HIPAA, Quebec Law 25, and PIPEDA. You can:
- Access — get confirmation of what we hold about you and a copy of it.
- Correct — fix information that is inaccurate or incomplete.
- Delete — ask us to delete your account and your health records (see "Deleting your account" below for how this works and what is kept).
- Restrict — ask us to limit certain uses of your information.
- Get a copy of your data (portability) — receive a copy of the health information you have provided, in a structured, commonly used technological format. medwallet provides this as a FHIR R4 export (FHIR is a widely used health-data interchange standard), plus a labelled companion file for any data that does not map to FHIR. You request it inside the app; you download your own copy.
- Withdraw consent — where we rely on your consent, you can withdraw it. Withdrawing is as easy as giving it.
- Complain — to us, and to the relevant privacy regulator (see § 12).
How to make a request: Contact our Privacy Officer (see § 1). We respond within 30 days.
Deleting your account — how it works, honestly
When you delete your account, we want to be straight with you about what happens, because health-records law requires us to keep a small, health-information-free record of certain events even after you delete.
- Your health records are deleted. When you delete your account, your and your dependents' live health records (medications, vitals, documents, voice notes, mood check-ins, and so on) are permanently removed from our active systems.
- A health-information-free audit trail is kept. Health-records law (HIPAA's audit-control and disclosure-accounting requirements, and Quebec/Canadian retention rules) requires us to keep a record that certain events happened — for example, when records were accessed or shared. This trail contains no clinical health information — it records only that an event occurred, using non-identifying internal references. We keep it for a legally required retention period (at least the HIPAA floor of about six years), then destroy or anonymize it.
- Backups age out. For disaster-recovery reasons, deleted information can remain in our encrypted backups for up to 28 days before those backups age out and the information is gone from them too. We do not restore it except to recover from a disaster.
- Export first. Before you delete, you can export a copy of your data (see "Get a copy of your data" above). The delete flow offers this.
- Some things we can't undo for you. If you had a paid subscription, deleting your account does not automatically refund it, and a subscription bought through Apple or Google must be cancelled through Apple or Google. We tell you this in the delete flow.
8. How long we keep your information (retention)
We keep your information only as long as we need it for the purposes above, and then we destroy or anonymize it. In summary:
| Category | How long we keep it |
|---|---|
| Live health records | While your account is active; deleted when you delete your account (see § 7) |
| Account and identity | While your account is active; identity details are scrubbed when your account is purged |
| Audit / compliance trail (health-information-free) | A legally required retention period — at least the HIPAA floor of about six years — then destroyed or anonymized |
| Backups | Up to 28 days in the encrypted point-in-time backup chain, then aged out |
9. How we protect your information (safeguards)
We protect your information with technical and organizational measures, including:
- Encryption of your information in transit (TLS) and at rest, and on your device.
- Strict access controls. Access to your records is enforced at the database level, so one household's records cannot be read by another. Our system is built so that no ordinary app request runs with elevated database privileges.
- An audit trail of access to health information, as health-records law requires.
- A health-information-stripping layer that removes health information from anything sent to our error-reporting, analytics, billing, email, and push providers (see § 5).
- Vendor agreements (BAAs and service-provider mandates) requiring our providers to protect your information.
10. Children's and dependents' information
medwallet lets an adult account holder manage health records for family members and dependents, including children.
- Age gate. A person under 14 cannot be the account holder.
- Dependents. An account holder can add and manage records for dependents. For a dependent aged 14 or older, medwallet records whether they may be eligible to consent for themselves, consistent with Quebec Law 25, which requires the consent of the person with parental authority for a minor under 14 (P-39.1 s. 4.1).
- Health information about a child or dependent is treated as the sensitive health information it is, with the same protections as any other health information in medwallet.
11. If there is a data breach
If there is a confidentiality incident or breach affecting your personal information, and it meets the legal threshold for notification, we will notify the affected individuals and the relevant privacy regulator as the law requires. We maintain an internal incident register and follow a breach-response procedure.
The thresholds and timelines are set by law:
- Quebec Law 25 (s. 3.5): we notify the Commission d'accès à l'information (CAI) and affected individuals where there is a risk of serious injury, and we keep a register of confidentiality incidents (s. 3.8).
- PIPEDA (s. 10.1 / s. 10.2 / s. 10.3): we report to the Office of the Privacy Commissioner of Canada (OPC) and notify affected individuals where there is a real risk of significant harm, and we keep breach records.
- HIPAA (45 CFR §164.400–414): we follow the Breach Notification Rule where it applies.
We commit to notifying without unreasonable delay once the legal threshold is met. We do not promise a fixed number of hours, because the law sets the standard and a premature or inaccurate notice can do more harm than good.
12. Who regulates us and how to complain
If you have a concern, contact our Privacy Officer first (see § 1). You also have the right to complain to a regulator:
- Quebec: Commission d'accès à l'information du Québec (CAI).
- Canada (federal): Office of the Privacy Commissioner of Canada (OPC).
13. French version (version française)
Quebec law — Quebec Law 25 and the Charter of the French Language — requires a French-language version of this policy for Quebec users, and the French version is the authoritative version for Quebec legal purposes.
15. Changes to this policy
If we make a significant change to how we handle your information, we will update this policy and update the effective date.
17. Google user data
Google user data. If you connect your Gmail account, medwallet reads your mail (read-only) solely to find health-related documents and import them into your own medwallet record. We never send, change, or delete your mail. We do not use your Gmail data for advertising, never sell it, and our staff do not read it except with your explicit consent, for security, or where the law requires. You can disconnect Gmail at any time, which stops all access and deletes our stored connection tokens.
medwallet's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
medwallet does not retain user data obtained through Workspace APIs to develop, improve, or train non-personalized artificial-intelligence or machine-learning models.