MediMindLab
  • Home
  • About
  • Contact
  • Try MediWing

Privacy Policy

Last Updated: June 9, 2026

Your privacy matters to us. This Privacy Policy explains what information MediMindLab, Inc. ("MediWing," "we," "us," or "our") collects when you use the MediWing service, how we use it, and your rights regarding your personal data.

In short: We collect only what is necessary to provide our service, we protect your data with strong security controls, we do not sell your data, and we do not use your health information to train artificial intelligence models. You remain in control of your information.

1. Information We Collect

Account Information

When you create an account, we collect:

  • Email address (required for login and notifications)
  • Name (to personalize your experience)
  • Password (never stored in plain text; protected using bcrypt hashing)

Medical Documents

When you upload documents, we store:

  • Document files (PDFs, images of lab results, prescriptions, imaging reports, and other medical documents)
  • Text extracted from those documents
  • AI-generated explanations and analysis derived from them
  • Upload and document dates

Payment Information

We use Stripe to process payments. We do not receive or store your full card details. Stripe processes:

  • Credit/debit card information (handled and stored by Stripe under PCI DSS Level 1, not by us)
  • Billing address
  • Transaction history

Usage Data

To operate and improve the service, we collect:

  • Counts of uploads and analyses
  • Document types processed
  • Feature usage patterns
  • Error and diagnostic logs (to detect and fix problems)

Technical Data

Collected automatically for security and reliability:

  • IP address (for security and rate limiting)
  • Browser type and version
  • Device information
  • Access times

2. How We Use Your Information

We use your data to:

  • Provide the service: process your documents and generate plain-language explanations
  • Operate and improve the service: improve our software, prompts, and product features using aggregate, non-identifying usage metrics and diagnostic logs
  • Communicate with you: send account notifications, analysis-completion notices, and support responses
  • Process payments: manage subscriptions and billing through Stripe
  • Maintain security: prevent fraud, abuse, and unauthorized access
  • Meet legal obligations: comply with applicable law, including GDPR and CCPA where they apply

We do not sell your personal information to anyone. We do not use your medical documents, extracted text, or health information to train artificial intelligence models — not our own, and not those of our AI provider; your document text is processed only to return an analysis to you, on a transient basis, and is never used for model training. We do not show third-party advertising or allow advertisers to target you based on your health information.

3. Third-Party Service Providers (Subprocessors)

๐Ÿค– Anthropic (Claude AI) — AI Analysis

Purpose: Generates plain-language explanations of your medical documents. When you upload a document, the extracted text is sent to Anthropic's Claude API for analysis.

Data Shared: The text extracted from your document and your selected language preference only. Your name, email address, and account identity are never transmitted to Anthropic.

Use & Retention: Anthropic processes the submitted text on a transient basis to return the analysis. Anthropic does not use data submitted through its API to train its models, and does not retain API request content beyond what is necessary for transient processing.

Privacy Policy: Anthropic Privacy Policy

๐Ÿ’ณ Stripe

Purpose: Secure payment and subscription processing

Data Shared: Payment information and billing address, handled directly by Stripe

Note: We never receive or store your full card details

Privacy: Stripe Privacy Policy

๐Ÿ—„๏ธ Supabase

Purpose: Stores account information, uploaded documents, and analysis results

Data Shared: Account information, documents, and analysis results

Security: Data is encrypted in transit and at rest, with database-level access isolation between users

Privacy: Supabase Privacy Policy

๐Ÿ“ง Resend (Transactional Email)

Purpose: Sends verification emails, password resets, and account and analysis notifications

Data Shared: Email address and name

Provider: Resend (resend.com). We update this list when our providers change.

4. How We Protect Your Data

We design for defense-in-depth and apply security controls aligned with recognized healthcare-security practices:

  • Encryption in transit: all traffic is protected with HTTPS/TLS
  • Encryption at rest: sensitive health information — including extracted document text, analysis results, conversation history, and health-timeline data — is encrypted at rest using AES-256-GCM
  • Password protection: passwords are hashed using bcrypt; we never store them in plain text
  • Access isolation: database row-level security ensures you can access only your own data; no cross-user access is possible
  • Audit logging: access to protected health information is recorded in an append-only audit log, consistent with the HIPAA Security Rule audit-controls standard (45 CFR ยง 164.312(b))
  • Session protection: account lockout after repeated failed logins, automatic idle-session timeout, and rate limiting on authentication, upload, and analysis endpoints
  • Audited infrastructure: private documents are served via expiring, signed access links; our database provider (Supabase) maintains SOC 2 Type II and our payment provider (Stripe) maintains PCI DSS Level 1; security issues are monitored and remediated on an ongoing basis

Important: No system can guarantee absolute security. We work hard to protect your data, but we cannot promise that it will never be compromised. Please use a strong, unique password.

5. Your Rights & Choices

โœ“ Access Your Data

View all your documents and analyses in your dashboard at any time.

โœ“ Export Your Data

Request a complete export by emailing privacy@medimindlab.com; we provide it in a portable format within 30 days.

โœ“ Delete Your Data

Permanently delete your account and all associated data through Settings → Delete Account. Deletion is irreversible and supports the GDPR "right to erasure."

โœ“ Correct Your Data

Update your name or email in account settings; contact support for other corrections.

โœ“ Opt Out of Marketing

Unsubscribe from marketing emails via the link in any such email. We will still send essential account notices (for example, password resets and security alerts).

6. How Long We Keep Your Data

We retain your data only as long as necessary:

  • Active accounts: documents, analyses, and account data are retained while your account is active
  • Deleted accounts: personal data is permanently deleted within 30 days of account deletion
  • Billing records: transaction and billing records are retained for up to 7 years to meet tax and legal obligations
  • Aggregate metrics: non-identifying, aggregate usage statistics (which cannot be linked back to you) may be retained to operate and improve the service
  • AI processing cache: extracted document text may be cached for up to 30 days to avoid redundant processing; this cache is encrypted and access-controlled

7. HIPAA and Health Information

For individual consumers: When you use MediWing directly as an individual, MediWing operates as an educational tool. In that role we are not a healthcare provider, health plan, or healthcare clearinghouse, and we are not a HIPAA "covered entity." Your use is voluntary and for educational purposes, and MediWing is not a substitute for professional medical advice, diagnosis, or treatment.

For healthcare organizations and partners: Where MediWing provides services to or on behalf of a HIPAA-covered entity or its business associate, MediWing is prepared to act as a Business Associate and to enter into a Business Associate Agreement (BAA) governing the handling of protected health information.

In all cases, we implement HIPAA-aligned security safeguards as described in Section 4. We do not represent that the consumer service is itself a HIPAA-regulated offering, and there is no government-issued "HIPAA certification" for software; compliance is demonstrated through controls, documentation, and agreements rather than a certificate.

Institutional partners seeking a BAA or our security documentation may contact privacy@medimindlab.com.

8. Children's Privacy

MediWing is intended for adults (18 and older) and is not directed to children. We do not knowingly collect personal information from anyone under 18.

If you are under 18, please ask a parent or guardian to manage any account on your behalf.

If we learn that we have collected information from a person under 18, we will delete it. Contact privacy@medimindlab.com if you believe this has occurred.

9. International Users

MediMindLab, Inc. is based in the United States. Your data may be processed in the United States and in other countries where our service providers operate.

For EU / EEA / UK users: For transfers of personal data outside your region, we rely on appropriate safeguards, including Standard Contractual Clauses where applicable. You have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. To exercise these rights, contact privacy@medimindlab.com.

For California users: Consistent with the CCPA/CPRA, you have the right to know what personal information we collect, to request deletion, and to opt out of any "sale" or "sharing" of personal information. We do not sell or share your personal information. Contact us for a full CCPA disclosure.

For users in Israel, Mexico, and other markets: MediWing is offered as an educational tool operated under U.S. law and is not registered as a medical device or regulated health software in your jurisdiction. Please confirm compliance with your local health-IT and data-protection regulations before use.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice before they take effect.

The "Last Updated" date above reflects the most recent revision.

Continued use after changes take effect indicates acceptance of the updated policy.

11. Contact Us About Privacy

Questions, concerns, or requests about your privacy?

Privacy Team

Email: privacy@medimindlab.com

General Support: support@medimindlab.com

We respond to privacy requests within 30 days.

Privacy in Plain English

  • โœ“ We collect only what's needed to run the service
  • โœ“ We never sell your data
  • โœ“ We do not use your health information to train AI models
  • โœ“ We use Anthropic's Claude AI to interpret your documents; only document text and language preference are sent, never your identity
  • โœ“ Your data is encrypted (AES-256-GCM at rest, TLS in transit) and access-controlled
  • โœ“ You can export or delete your data anytime
  • โœ“ For individuals, MediWing is an educational tool and not a HIPAA-covered entity; for healthcare partners, we can sign a Business Associate Agreement
  • โœ“ We honor GDPR and CCPA rights

MediMindLab

Smart Health In Your Hands

Empowering healthcare understanding through technology.

Product

  • MediWing
  • Pricing
  • Support

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

Contact

  • info@medimindlab.com

© 2026 MediMindLab, Inc. All rights reserved.