Legal
Privacy Policy
Version 2.1.0 — Effective 2026-10-01 — Last updated 2026-10-01
1.Data Controller
Medodi is developed and maintained by an independent individual developer based in Romania (EU). This person acts as the Data Controller responsible for the processing of your personal data.
Under GDPR Article 27, an EU Representative is not required as the controller is established within the EU.
2.Data Protection Contact
For any data protection inquiries, you may contact us directly. We handle all data protection matters personally and will respond to all requests within 30 days.
3.Data We Process
We process the following categories of personal data, always with the minimum amount necessary:
- Authentication data — Email address and hashed password (processed by Supabase Auth)
- Medical records (encrypted) — Documents, test results, medication data, appointments, vital signs. All encrypted end-to-end with XChaCha20-Poly1305 before leaving your device
- Crash reports (opt-in only) — Device model, OS version, error traces. No medical data is ever included
- Age verification flag — A boolean confirming you are 18+. Your date of birth is NOT stored
4.Special Category Data (Health Data — GDPR Art. 9)
Medical and health data is classified as "special category" data under GDPR Article 9. Processing requires your EXPLICIT consent, which you provide during the onboarding process through clearly marked checkboxes.
You can withdraw this consent at any time in Settings → Compliance. Withdrawal will prevent you from adding new records but will not delete existing data unless you explicitly request deletion.
Due to our zero-knowledge architecture, we technically cannot access your health data even if we wanted to — the server only stores encrypted ciphertext that is mathematically impossible to decrypt without your personal Master Key.
5.Legal Basis for Processing
We process your data based on the following legal bases:
- GDPR Art. 6(1)(a) — Consent — For health data processing, analytics, crash reporting
- GDPR Art. 6(1)(b) — Contractual necessity — For authentication and encrypted cloud sync
- GDPR Art. 9(2)(a) — Explicit consent — For processing special category health data
All data processing is transparent and documented in our Records of Processing Activities (ROPA), available upon request at contact@medodi.com.
6.Data Retention
| Data Type | Retention Period |
|---|---|
| Medical records | Until you delete them (user-controlled) |
| Encrypted audit log | Max 20,000 entries (rotating) |
| Sync data (ciphertext) | Until account deletion |
| Session data | Auto-locked after 15s background / 2min inactivity |
| Crash reports | 90 days |
| Consent records | 5 years (legal proof requirement) |
7.Data Security
We implement state-of-the-art encryption and security measures:
- XChaCha20-Poly1305 — Per-record end-to-end encryption
- XChaCha20-Poly1305 — Key wrapping and attachment encryption
- Argon2id — Key derivation (64 MiB, 3 iterations, 4 lanes)
- Hardware-backed Secure Enclave — Key storage on iOS/Android
- Zero-Knowledge Protocol — The server cannot decrypt any of your data
- Certificate Pinning — TLS/SSL pinning for all API connections
Data is encrypted at rest, in transit, and during processing.
8.International Data Transfers
Our primary servers are located in the EU (Supabase EU region). Some processors may process limited data in the US under EU Standard Contractual Clauses (SCCs).
9.Automated Decision-Making
Medodi does NOT use any form of automated decision-making, profiling, or AI analysis of your health data. The app is purely a storage and organization tool with no clinical decision support features.
Medodi is NOT a medical device under EU MDR 2017/745.
10.Your Rights Under GDPR
Under GDPR, you have the following rights:
- Art. 15 — Right of access to your data
- Art. 16 — Right to rectification
- Art. 17 — Right to erasure (right to be forgotten)
- Art. 18 — Right to restriction of processing
- Art. 19 — Right to notification regarding rectification/erasure
- Art. 20 — Right to data portability
- Art. 21 — Right to object
- Art. 22 — Right not to be subject to automated decision-making
- Art. 7(3) — Right to withdraw consent
To exercise any of these rights, contact us at contact@medodi.com or contact@medodi.com. We will respond within 30 days.
12.Data Breach Notification
In the event of a personal data breach, we will notify the competent supervisory authority (ANSPDCP) within 72 hours of becoming aware, as required by GDPR Article 33. If the breach poses a high risk to your rights and freedoms, we will notify you without undue delay as required by GDPR Article 34.
Due to our zero-knowledge architecture, a server-side breach would only expose encrypted ciphertext — mathematically impossible to decrypt without your personal Master Key.
13.Third-Party Processors
We use the following third-party processors, all GDPR-compliant:
Supabase
Authentication, encrypted database, object storage
EU (Ireland/Frankfurt)
Upstash Redis
Server-side caching (encrypted records only)
EU (Frankfurt)
Sentry
Error tracking (opt-in only, no medical data)
EU (Frankfurt)
RevenueCat
Subscription and entitlement management infrastructure (no medical data)
US (Standard Contractual Clauses applied)
Google Drive API
Personal cloud backup (user-initiated, encrypted)
User account region
iCloud Drive
Personal cloud backup (user-initiated, encrypted)
User account region
14.Children's Privacy
Medodi is intended exclusively for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us immediately at contact@medodi.com.
15.Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will notify you in-app and require re-acceptance of the updated terms. The version number and effective date are displayed at the top of this policy.
16.Contact and Complaints
For any privacy-related questions, data subject rights requests, or complaints:
Medodi is NOT a medical device under EU MDR 2017/745. It is a personal data organizer with zero-knowledge encryption.
Last updated: 2026-10-01