Privacy Policy
Last Updated: August 20, 2026 · Effective Immediately
Privacy at a Glance
- Your Data is Yours: We never sell, rent, license, share, or monetize your personal or health data to advertisers, data brokers, insurers, employers, or any third party.
- Zero Ad Targeting: Your medical reports and extracted lab results are used solely to provide the Service to you. Period.
- Right to Deletion: You can delete any uploaded document, metric, or your entire account at any time.
- Encrypted in Transit: All data is encrypted via TLS 1.3 / HTTPS in transit and gated behind authenticated sessions at rest.
- No Tracking Pixels or Ad Networks: We do not embed any third-party advertising trackers, social media pixels, or analytics SDKs that share your data with advertisers.
1. Scope & Applicability
This Privacy Policy (“Policy”) applies to all users of the MedTrack AI web application (the “Service”) accessible at https://medtrack-ai.live. By accessing or using the Service, you consent to the collection, use, and storage of your information as described in this Policy.
2. Information We Collect
We collect only information that is strictly necessary to provide document parsing, metric tracking, and account management:
A. Account Information (via Google OAuth)
When you sign in with Google, we receive your email address, full name, Google account identifier, and profile photo URL. We use this exclusively to create your profile and maintain your authenticated session.
B. Uploaded Health Documents & Medical Reports
Files you voluntarily upload, including blood test panels, pathology reports, radiology reports, prescriptions, and clinical notes (in PDF, JPEG, or PNG format). We do not collect or request medical documents proactively — uploads are entirely user-initiated.
C. Extracted Biomarkers & Clinical Metrics
Structured data extracted by AI from your reports: test names (e.g., HbA1c, Cholesterol, TSH), numeric values, reference ranges, units, test dates, and facility/doctor names. These are stored solely for your personal trend tracking.
D. Payment & Subscription Data
Subscription status, plan type, billing cycle dates, and country for pricing. We do not store credit card numbers, CVVs, or full bank details — all payment processing is handled entirely by Razorpay (PCI-DSS Level 1 certified).
E. Technical & Log Data
IP addresses, browser user-agent strings, operating system identifiers, timestamps, and hashed identifiers used solely for security auditing, rate limiting, abuse prevention, and DDoS mitigation. These logs are retained for a maximum of 90 days before automatic deletion.
3. How We Use Your Information
We process your information strictly for the following purposes and no others:
- AI Document Processing: Sending uploaded documents to Google Gemini for structured text extraction of clinical biomarkers.
- Personal Trend Visualization: Displaying your lab results, historical comparisons, and metric charts within your private dashboard.
- Account Authentication & Access Control: Verifying your identity and ensuring no other user can access your records.
- Security & Abuse Prevention: Enforcing upload and API rate limits, detecting fraud, and preventing unauthorized access.
- Payment Processing: Verifying subscription status via Razorpay payment callbacks.
- Service Improvement: Aggregated, de-identified technical metrics (e.g., page load times, error rates) to maintain and improve system reliability. We never use your medical data for analytics.
4. What We Will Never Do With Your Data
We make the following absolute commitments:
- Never sell your personal data, health records, or usage patterns to any third party for any reason.
- Never share your medical documents or extracted biomarkers with advertisers, data brokers, insurance companies, pharmaceutical companies, employers, or government agencies (except where compelled by valid legal process).
- Never use your uploaded medical data to build marketing profiles, train AI models, or serve targeted advertisements.
- Never contact you with unsolicited marketing emails or sell your email address to mailing lists.
5. Artificial Intelligence & Third-Party Processors
MedTrack AI relies on the following trusted, enterprise-grade providers. Your data is shared with them only to the minimum extent necessary to operate the Service:
- Google Cloud / Gemini API: Documents are processed via Google's enterprise AI infrastructure for structured text and table extraction only. Under Google's API Terms of Service, customer data submitted via the paid Gemini API is not used by Google to train, improve, or develop its generalized AI or machine learning models.
- Supabase (PostgreSQL & Authentication): User authentication (via Google OAuth) and encrypted database records are hosted on Supabase infrastructure with Row Level Security (RLS) enabled on all tables.
- Vercel (Hosting & Edge Compute): Application hosting, serverless function execution, and encrypted traffic delivery via a global CDN.
- Razorpay (Payment Gateway): All payment card information is collected, processed, and stored directly by Razorpay under PCI-DSS Level 1 compliance. MedTrack AI never receives, processes, transmits, or stores credit/debit card numbers, CVVs, or bank account details.
6. Data Security & Storage Architecture
We implement comprehensive technical and organizational safeguards to protect your data:
- Isolated Document Storage: Uploaded medical files are stored in private server directories outside the publicly accessible web root. Direct URL access to raw files is permanently disabled.
- Session-Gated File Access: Every document download request requires a valid authenticated session and strict profile-ownership verification before files are streamed.
- Row Level Security (RLS): All database tables enforce cryptographic profile separation, preventing any cross-account data access.
- HTTPS Everywhere: All client–server communication is encrypted via TLS 1.2+ (HSTS enforced).
- Security Headers: Strict Content Security Policy, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), and Referrer-Policy headers are enforced on every response.
- Cryptographic Payment Verification: All Razorpay payment callbacks and webhooks are verified using constant-time HMAC-SHA256 signature comparison.
- Rate Limiting: API endpoints are protected with per-profile rate limits and daily AI usage caps to prevent abuse.
7. Cookies & Local Storage
MedTrack AI uses cookies strictly for functional purposes:
- Authentication Cookies: Supabase session cookies (prefixed
sb-) to maintain your logged-in state. These are HttpOnly, Secure, and SameSite=Lax. - PKCE Code Verifier: A temporary cookie used during the Google OAuth sign-in flow, automatically deleted after authentication completes.
We do not use advertising cookies, tracking pixels, third-party analytics cookies, or any form of cross-site tracking technology.
8. International Data Transfers
Your data may be processed in data centers located outside your country of residence (including the United States, European Union, and Asia-Pacific regions) through our cloud infrastructure providers (Google Cloud, Supabase/AWS, Vercel). All such transfers are protected by the security measures described in this Policy, including encryption in transit and strict access controls.
9. Data Retention, Erasure & Your Rights
You maintain full control over your personal and health records:
- Document Deletion: When you delete a report from your dashboard, the source file is immediately and permanently deleted from disk storage, and all associated extracted metrics are removed from the database.
- Account Erasure: You may request complete deletion of your profile, all uploaded documents, all extracted metrics, and subscription records by emailing vinayhadimani99@gmail.com. We will process erasure requests within 30 days.
- Data Portability: You may view and access your clinical metric trends directly from your dashboard at any time.
- Correction: If you believe any extracted data is incorrect, you may delete the report and re-upload with corrections.
- Objection & Restriction: You may contact us at any time to object to or request restriction of specific processing activities.
10. Children's Privacy
MedTrack AI is not intended for use by individuals under the age of 18 without the involvement and consent of a parent or legal guardian. We do not knowingly collect personal information from children under 18. If we discover that we have inadvertently collected data from a minor without appropriate consent, we will delete it promptly upon notification.
11. Data Breach Notification
In the unlikely event of a data breach that compromises your personal information, we will notify affected users via their registered email address within 72 hours of becoming aware of the breach, and will take immediate steps to mitigate harm and secure the affected systems.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this page. Your continued use of the Service after any modifications constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.
13. Contact & Privacy Inquiries
If you have any questions about this Privacy Policy, wish to exercise your data rights, or need to report a security concern:
MedTrack AI — Privacy & Data Protection
Email: vinayhadimani99@gmail.com
Website: https://medtrack-ai.live