Last updated: August 2026
Account Information: Full name, email address, profile picture (if authenticated via Google), and role selection (Patient or Doctor).
Medical Documents: Files you upload (PDFs, JPGs, PNGs) are stored in private Cloudflare R2 encrypted buckets. We do not read or analyze your documents except through automated AI summarization that you explicitly initiate.
Structured Medical Facts: Summaries, extracted conditions, medications, and timeline entries generated directly from your uploaded files.
Usage & Quota Data: Document counts, storage bytes consumed, and AI calls for subscription tier management.
We process your data strictly to: provide medical document organization and summarization, compile your chronological health timeline, facilitate secure, patient-controlled sharing with healthcare providers, and manage billing via Paddle.
When you initiate document processing, file text is transmitted to our server-side AI provider (Google Gemini) for factual entity extraction. We do NOT sell your data or use your personal medical documents to train public AI models. Processing happens once per document, and results are permanently cached in your private Firestore database.
We do not sell, rent, or monetize your health data with advertisers, data brokers, or third parties. Your records are only visible to you and healthcare providers with whom you share a secure access link.
You have complete ownership of your data. Deleting a record immediately purges the binary object from Cloudflare R2 and deletes associated Firestore metadata, summaries, and timeline entries. Account deletion purges your entire account history permanently.
For questions regarding our privacy practices, contact us at privacy@medicalhistoryai.com.