Legal

Privacy Policy

Version 2.1.0 — Effective 2026-10-01 — Last updated 2026-10-01

1.Data Controller

Medodi is developed and maintained by an independent individual developer based in Romania (EU). This person acts as the Data Controller responsible for the processing of your personal data.

DeveloperMedodi — Independent Developer
Emailcontact@medodi.com
CountryRomania (EU)

Under GDPR Article 27, an EU Representative is not required as the controller is established within the EU.

2.Data Protection Contact

For any data protection inquiries, you may contact us directly. We handle all data protection matters personally and will respond to all requests within 30 days.

ContactMedodi Data Protection
Emailcontact@medodi.com

3.Data We Process

We process the following categories of personal data, always with the minimum amount necessary:

  • Authentication data — Email address and hashed password (processed by Supabase Auth)
  • Medical records (encrypted) — Documents, test results, medication data, appointments, vital signs. All encrypted end-to-end with XChaCha20-Poly1305 before leaving your device
  • Crash reports (opt-in only) — Device model, OS version, error traces. No medical data is ever included
  • Age verification flag — A boolean confirming you are 18+. Your date of birth is NOT stored
We DO NOT have access to your medical records. All health data is end-to-end encrypted and the decryption keys exist ONLY on your device (Zero-Knowledge Architecture).

4.Special Category Data (Health Data — GDPR Art. 9)

Medical and health data is classified as "special category" data under GDPR Article 9. Processing requires your EXPLICIT consent, which you provide during the onboarding process through clearly marked checkboxes.

You can withdraw this consent at any time in Settings → Compliance. Withdrawal will prevent you from adding new records but will not delete existing data unless you explicitly request deletion.

Due to our zero-knowledge architecture, we technically cannot access your health data even if we wanted to — the server only stores encrypted ciphertext that is mathematically impossible to decrypt without your personal Master Key.

6.Data Retention

Data TypeRetention Period
Medical recordsUntil you delete them (user-controlled)
Encrypted audit logMax 20,000 entries (rotating)
Sync data (ciphertext)Until account deletion
Session dataAuto-locked after 15s background / 2min inactivity
Crash reports90 days
Consent records5 years (legal proof requirement)

7.Data Security

We implement state-of-the-art encryption and security measures:

  • XChaCha20-Poly1305 — Per-record end-to-end encryption
  • XChaCha20-Poly1305 — Key wrapping and attachment encryption
  • Argon2id — Key derivation (64 MiB, 3 iterations, 4 lanes)
  • Hardware-backed Secure Enclave — Key storage on iOS/Android
  • Zero-Knowledge Protocol — The server cannot decrypt any of your data
  • Certificate Pinning — TLS/SSL pinning for all API connections

Data is encrypted at rest, in transit, and during processing.

8.International Data Transfers

Our primary servers are located in the EU (Supabase EU region). Some processors may process limited data in the US under EU Standard Contractual Clauses (SCCs).

All medical data is end-to-end encrypted BEFORE leaving your device. Even if data passes through non-EU infrastructure, it remains encrypted and unreadable.

9.Automated Decision-Making

Medodi does NOT use any form of automated decision-making, profiling, or AI analysis of your health data. The app is purely a storage and organization tool with no clinical decision support features.

Medodi is NOT a medical device under EU MDR 2017/745.

10.Your Rights Under GDPR

Under GDPR, you have the following rights:

  • Art. 15 — Right of access to your data
  • Art. 16 — Right to rectification
  • Art. 17 — Right to erasure (right to be forgotten)
  • Art. 18 — Right to restriction of processing
  • Art. 19 — Right to notification regarding rectification/erasure
  • Art. 20 — Right to data portability
  • Art. 21 — Right to object
  • Art. 22 — Right not to be subject to automated decision-making
  • Art. 7(3) — Right to withdraw consent

To exercise any of these rights, contact us at contact@medodi.com or contact@medodi.com. We will respond within 30 days.

11.Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your supervisory authority:

AuthorityANSPDCP (Romania)
Websitehttps://www.dataprotection.ro
Emailanspdcp@dataprotection.ro
Phone+40 318 059 211

12.Data Breach Notification

In the event of a personal data breach, we will notify the competent supervisory authority (ANSPDCP) within 72 hours of becoming aware, as required by GDPR Article 33. If the breach poses a high risk to your rights and freedoms, we will notify you without undue delay as required by GDPR Article 34.

Due to our zero-knowledge architecture, a server-side breach would only expose encrypted ciphertext — mathematically impossible to decrypt without your personal Master Key.

13.Third-Party Processors

We use the following third-party processors, all GDPR-compliant:

Supabase

Authentication, encrypted database, object storage

EU (Ireland/Frankfurt)

Upstash Redis

Server-side caching (encrypted records only)

EU (Frankfurt)

Sentry

Error tracking (opt-in only, no medical data)

EU (Frankfurt)

RevenueCat

Subscription and entitlement management infrastructure (no medical data)

US (Standard Contractual Clauses applied)

Google Drive API

Personal cloud backup (user-initiated, encrypted)

User account region

iCloud Drive

Personal cloud backup (user-initiated, encrypted)

User account region

All third-party processors that handle medical data only receive encrypted ciphertext that they cannot decrypt.

14.Children's Privacy

Medodi is intended exclusively for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us immediately at contact@medodi.com.

15.Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will notify you in-app and require re-acceptance of the updated terms. The version number and effective date are displayed at the top of this policy.

16.Contact and Complaints

For any privacy-related questions, data subject rights requests, or complaints:

Data ControllerMedodi — Independent Developer
Privacy Emailcontact@medodi.com
Data Protectioncontact@medodi.com
Securitycontact@medodi.com
You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. Withdrawal will NOT result in any detriment or reduced service quality.

Medodi is NOT a medical device under EU MDR 2017/745. It is a personal data organizer with zero-knowledge encryption.

Last updated: 2026-10-01