Effective Date: September 10, 2026 · Version 2026-09-10.2
MedicalGPT ("we," "our," "us") provides an AI-assisted health companion available on the web and as a mobile app ("Service"). See Section 12 for the legal entity operating the Service. Because the Service is built around your health information, this policy is deliberately specific about what we collect, why, and who it's shared with — not just a generic outline. By creating an account or using the Service you agree to the practices described here.
We collect the following categories of information:
Account & identity data
Health & medical information you provide
Technical & usage data
Payment data
We do not use your health data to train third-party general-purpose AI models, and we do not sell your personal or health information to anyone, for any purpose.
We rely on your consent to process the health information you choose to share (given at sign-up, and required before any AI feature that uses it), on contractual necessity to run the account and subscription features you sign up for, and on our legitimate interest in keeping the Service secure to detect and prevent fraud and abuse.
We do not sell your data. We share the minimum data necessary with the following categories of service providers, solely so they can perform the function we use them for:
We may also disclose information if required by law, to protect the rights and safety of our users, or in connection with a merger, acquisition, or sale of assets (subject to this policy continuing to apply to your data).
Our infrastructure is US-based, so data from users elsewhere is transferred to and processed in the US. Our providers (AWS, Stripe, Supabase, and Resend) each participate in the EU-U.S. Data Privacy Framework, and our AI provider's data processing terms incorporate Standard Contractual Clauses — both are recognized safeguards for transferring personal data out of the EU/UK.
We treat everything in Section 2's "Health & medical information" category as sensitive. Where our infrastructure supports it, particularly sensitive fields are stored encrypted at rest, access to them is restricted to what each part of the Service needs to function, and administrative access is logged. Note that the Service is a wellness/health information tool, not a substitute for professional medical diagnosis, treatment, or emergency care — see the Terms & Conditions and in-app disclaimers.
We are not a HIPAA-covered entity or business associate — MedicalGPT is a direct-to-consumer service and does not process protected health information on behalf of a hospital, clinic, insurer, or other HIPAA-covered entity. As a service that lets you manage your own health-related information, we follow the safeguards described in this policy and, where applicable, the notification practices described in the FTC's Health Breach Notification Rule, including notifying affected users without unreasonable delay if a breach of unsecured personal health information occurs.
We use industry-standard safeguards including encryption in transit (HTTPS/TLS) for all traffic, encryption at rest for sensitive stored fields, hashed (not reversible) password storage, access controls on our infrastructure, and monitoring for suspicious activity. No system is 100% secure, and we encourage you to use a strong, unique password and enable two-factor authentication where offered.
Urgency awareness check results are generated automatically from what you enter; they are not used to make any decision about you, but if you'd like a human to look at a specific result with you, contact us (Section 12). We do not sell or share your personal information for cross-context advertising, and California residents can ask us to limit the use of sensitive personal information (such as health data) beyond what's needed to run the Service — again, by contacting us. Exercising any of these rights will not result in different treatment or pricing.
Subscription payments are processed by Stripe. We store your subscription status, plan, and billing history, but we never receive or store your full card number, CVV, or bank details — those go directly to Stripe under its own privacy policy and security standards.
We retain your account and health data for as long as your account is active, so the Service can keep showing you your own history (e.g. medication schedules, symptom trends over time). If you delete your account, we delete your personal and health data within a reasonable period, except for records we're legally required to keep (such as billing/tax records) or data needed to resolve disputes or enforce our agreements.
The Service is not directed to, and is not intended for use by, children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us (Section 12) and we will delete it. We rely on users to accurately confirm their age at registration. If we discover a user is under 13, we will immediately delete their account and all associated health data.
We may update this Privacy Policy as the Service changes. Material changes will be reflected by an updated Effective Date at the top of this page, and where required by law we'll provide additional notice (e.g. by email).
For privacy questions, access/deletion requests, or anything else in this policy, contact us at hello@askmedicalgpt.com — this is also our designated privacy contact for Canadian users under PIPEDA.
TangentX LLC
30 N Gould St Ste N, Sheridan, WY 82801
(650) 300-0125
By using MedicalGPT, you agree to this Privacy Policy.