Privacy Policy
Last Updated: June 9, 2026
Your privacy matters to us. This Privacy Policy explains what information MediMindLab, Inc. ("MediWing," "we," "us," or "our") collects when you use the MediWing service, how we use it, and your rights regarding your personal data.
In short: We collect only what is necessary to provide our service, we protect your data with strong security controls, we do not sell your data, and we do not use your health information to train artificial intelligence models. You remain in control of your information.
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address (required for login and notifications)
- Name (to personalize your experience)
- Password (never stored in plain text; protected using bcrypt hashing)
Medical Documents
When you upload documents, we store:
- Document files (PDFs, images of lab results, prescriptions, imaging reports, and other medical documents)
- Text extracted from those documents
- AI-generated explanations and analysis derived from them
- Upload and document dates
Payment Information
We use Stripe to process payments. We do not receive or store your full card details. Stripe processes:
- Credit/debit card information (handled and stored by Stripe under PCI DSS Level 1, not by us)
- Billing address
- Transaction history
Usage Data
To operate and improve the service, we collect:
- Counts of uploads and analyses
- Document types processed
- Feature usage patterns
- Error and diagnostic logs (to detect and fix problems)
Technical Data
Collected automatically for security and reliability:
- IP address (for security and rate limiting)
- Browser type and version
- Device information
- Access times
2. How We Use Your Information
We use your data to:
- Provide the service: process your documents and generate plain-language explanations
- Operate and improve the service: improve our software, prompts, and product features using aggregate, non-identifying usage metrics and diagnostic logs
- Communicate with you: send account notifications, analysis-completion notices, and support responses
- Process payments: manage subscriptions and billing through Stripe
- Maintain security: prevent fraud, abuse, and unauthorized access
- Meet legal obligations: comply with applicable law, including GDPR and CCPA where they apply
We do not sell your personal information to anyone. We do not use your medical documents, extracted text, or health information to train artificial intelligence models — not our own, and not those of our AI provider; your document text is processed only to return an analysis to you, on a transient basis, and is never used for model training. We do not show third-party advertising or allow advertisers to target you based on your health information.
3. Third-Party Service Providers (Subprocessors)
๐ค Anthropic (Claude AI) — AI Analysis
Purpose: Generates plain-language explanations of your medical documents. When you upload a document, the extracted text is sent to Anthropic's Claude API for analysis.
Data Shared: The text extracted from your document and your selected language preference only. Your name, email address, and account identity are never transmitted to Anthropic.
Use & Retention: Anthropic processes the submitted text on a transient basis to return the analysis. Anthropic does not use data submitted through its API to train its models, and does not retain API request content beyond what is necessary for transient processing.
Privacy Policy: Anthropic Privacy Policy
๐ณ Stripe
Purpose: Secure payment and subscription processing
Data Shared: Payment information and billing address, handled directly by Stripe
Note: We never receive or store your full card details
Privacy: Stripe Privacy Policy
๐๏ธ Supabase
Purpose: Stores account information, uploaded documents, and analysis results
Data Shared: Account information, documents, and analysis results
Security: Data is encrypted in transit and at rest, with database-level access isolation between users
Privacy: Supabase Privacy Policy
๐ง Resend (Transactional Email)
Purpose: Sends verification emails, password resets, and account and analysis notifications
Data Shared: Email address and name
Provider: Resend (resend.com). We update this list when our providers change.
4. How We Protect Your Data
We design for defense-in-depth and apply security controls aligned with recognized healthcare-security practices:
- Encryption in transit: all traffic is protected with HTTPS/TLS
- Encryption at rest: sensitive health information — including extracted document text, analysis results, conversation history, and health-timeline data — is encrypted at rest using AES-256-GCM
- Password protection: passwords are hashed using bcrypt; we never store them in plain text
- Access isolation: database row-level security ensures you can access only your own data; no cross-user access is possible
- Audit logging: access to protected health information is recorded in an append-only audit log, consistent with the HIPAA Security Rule audit-controls standard (45 CFR ยง 164.312(b))
- Session protection: account lockout after repeated failed logins, automatic idle-session timeout, and rate limiting on authentication, upload, and analysis endpoints
- Audited infrastructure: private documents are served via expiring, signed access links; our database provider (Supabase) maintains SOC 2 Type II and our payment provider (Stripe) maintains PCI DSS Level 1; security issues are monitored and remediated on an ongoing basis
Important: No system can guarantee absolute security. We work hard to protect your data, but we cannot promise that it will never be compromised. Please use a strong, unique password.
5. Your Rights & Choices
โ Access Your Data
View all your documents and analyses in your dashboard at any time.
โ Export Your Data
Request a complete export by emailing privacy@medimindlab.com; we provide it in a portable format within 30 days.
โ Delete Your Data
Permanently delete your account and all associated data through Settings → Delete Account. Deletion is irreversible and supports the GDPR "right to erasure."
โ Correct Your Data
Update your name or email in account settings; contact support for other corrections.
โ Opt Out of Marketing
Unsubscribe from marketing emails via the link in any such email. We will still send essential account notices (for example, password resets and security alerts).
6. How Long We Keep Your Data
We retain your data only as long as necessary:
- Active accounts: documents, analyses, and account data are retained while your account is active
- Deleted accounts: personal data is permanently deleted within 30 days of account deletion
- Billing records: transaction and billing records are retained for up to 7 years to meet tax and legal obligations
- Aggregate metrics: non-identifying, aggregate usage statistics (which cannot be linked back to you) may be retained to operate and improve the service
- AI processing cache: extracted document text may be cached for up to 30 days to avoid redundant processing; this cache is encrypted and access-controlled
7. HIPAA and Health Information
For individual consumers: When you use MediWing directly as an individual, MediWing operates as an educational tool. In that role we are not a healthcare provider, health plan, or healthcare clearinghouse, and we are not a HIPAA "covered entity." Your use is voluntary and for educational purposes, and MediWing is not a substitute for professional medical advice, diagnosis, or treatment.
For healthcare organizations and partners: Where MediWing provides services to or on behalf of a HIPAA-covered entity or its business associate, MediWing is prepared to act as a Business Associate and to enter into a Business Associate Agreement (BAA) governing the handling of protected health information.
In all cases, we implement HIPAA-aligned security safeguards as described in Section 4. We do not represent that the consumer service is itself a HIPAA-regulated offering, and there is no government-issued "HIPAA certification" for software; compliance is demonstrated through controls, documentation, and agreements rather than a certificate.
Institutional partners seeking a BAA or our security documentation may contact privacy@medimindlab.com.
8. Children's Privacy
MediWing is intended for adults (18 and older) and is not directed to children. We do not knowingly collect personal information from anyone under 18.
If you are under 18, please ask a parent or guardian to manage any account on your behalf.
If we learn that we have collected information from a person under 18, we will delete it. Contact privacy@medimindlab.com if you believe this has occurred.
9. International Users
MediMindLab, Inc. is based in the United States. Your data may be processed in the United States and in other countries where our service providers operate.
For EU / EEA / UK users: For transfers of personal data outside your region, we rely on appropriate safeguards, including Standard Contractual Clauses where applicable. You have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. To exercise these rights, contact privacy@medimindlab.com.
For California users: Consistent with the CCPA/CPRA, you have the right to know what personal information we collect, to request deletion, and to opt out of any "sale" or "sharing" of personal information. We do not sell or share your personal information. Contact us for a full CCPA disclosure.
For users in Israel, Mexico, and other markets: MediWing is offered as an educational tool operated under U.S. law and is not registered as a medical device or regulated health software in your jurisdiction. Please confirm compliance with your local health-IT and data-protection regulations before use.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice before they take effect.
The "Last Updated" date above reflects the most recent revision.
Continued use after changes take effect indicates acceptance of the updated policy.
11. Contact Us About Privacy
Questions, concerns, or requests about your privacy?
Privacy Team
Email: privacy@medimindlab.com
General Support: support@medimindlab.com
We respond to privacy requests within 30 days.
Privacy in Plain English
- โ We collect only what's needed to run the service
- โ We never sell your data
- โ We do not use your health information to train AI models
- โ We use Anthropic's Claude AI to interpret your documents; only document text and language preference are sent, never your identity
- โ Your data is encrypted (AES-256-GCM at rest, TLS in transit) and access-controlled
- โ You can export or delete your data anytime
- โ For individuals, MediWing is an educational tool and not a HIPAA-covered entity; for healthcare partners, we can sign a Business Associate Agreement
- โ We honor GDPR and CCPA rights