This Privacy Policy explains how Medico AI, Inc. ("Medico," "we," "us") collects, uses, shares, and protects information when you use the Medico mobile application and medicoapp.ai (the "Service"). Medico is a consumer health tool for individuals and their family caregivers.
Two things to know up front
1. Your health information is processed by third-party AI providers. To generate insights, answer questions, and transcribe recordings, we send your information to AI companies outside Medico. Section 5 names them and explains what we can and cannot promise about how they handle it.
2. Medico is generally not covered by HIPAA. HIPAA applies to healthcare providers, health plans, and their contractors. When you use Medico directly as a consumer, we are usually none of those, so the health information you enter here is generally not protected by HIPAA. We apply safeguards modeled on HIPAA's Security Rule, described in Section 4, but you should understand the difference. See Section 6.
1. Information We Collect
1.1 Information you provide
- Account information: name, email address, phone number, date of birth.
- Health information: medications, doses, schedules, health conditions, lab reports, care plans, check-in answers, symptom and vital-sign entries, provider details, and anything else you enter or upload.
- Images: photographs you take, including wound and incision photos, and images of documents such as lab reports, prescriptions, and discharge paperwork.
- Audio recordings: recordings of healthcare provider conversations you choose to record, and the transcripts generated from them.
- Caregiver and emergency information: caregiver identities and permissions; emergency contacts, allergies, and critical information you add to your emergency profile.
1.2 Information collected automatically
- Device information: device type, operating system, device identifiers, mobile network information.
- Usage and diagnostic data: feature usage, interaction events, crash and error logs.
- Push tokens: device tokens used to deliver notifications.
- Location: only if you enable it — used for pharmacy and provider search and, if you trigger it, to include your location in an SOS alert. We do not track your location in the background.
- Health platform data: if you connect Apple Health or a similar platform, the categories you approve (such as steps, heart rate, sleep, or blood oxygen).
1.3 Information from third parties
- Authentication: AWS Cognito provides verified identity information when you sign in.
- Drug and provider reference data: we query public databases (RxNorm, FDA, NPPES) for medication and provider information. We do not send your personal or health information to these sources.
2. How We Use Information
- To operate the Service: medication tracking, reminders, records, care plans, and check-ins.
- To generate AI insights, answer your questions, and transcribe recordings you make.
- To provide medication interaction and safety information.
- To deliver notifications you have enabled.
- To enable caregiver access under the permissions you set.
- To select health news related to your conditions.
- To secure the Service, investigate abuse, and debug problems.
- To respond to your support requests.
- To understand aggregate usage and improve the Service.
We do not sell your personal information or health information. We do not share it for cross-context behavioral advertising. We do not use it for advertising at all.
3. Where Your Information Is Stored
- On your device. Medico keeps a local copy of your health data in an on-device database so the app works offline. This local database is not separately encrypted by Medico. It is protected by your device's own security — your passcode, biometric lock, and the operating system's file protection and app sandboxing. If your device is unlocked, lost, shared, or compromised, that local data may be accessible. We strongly recommend enabling a device passcode and biometric lock.
- On our servers. Account data and synchronized health records are stored on servers we operate on Amazon Web Services infrastructure in the United States.
- Files and recordings. Audio recordings, images, and uploaded documents are stored in Amazon S3 with server-side encryption (AES-256) enabled.
- Backups. Encrypted database backups are stored in Amazon S3 in the United States and retained on a rolling basis (currently up to approximately 35 days).
4. Security
We take security seriously and apply safeguards modeled on the HIPAA Security Rule. Specifically, today:
- Traffic between the app and our servers is encrypted using TLS. The current released app will not connect over an unencrypted connection.
- Files and recordings in Amazon S3 are encrypted at rest with AES-256 server-side encryption.
- Database backups are encrypted.
- Authentication is handled by AWS Cognito with managed token handling. Sign-in uses a one-time passcode sent by SMS.
- Administrative access to production servers is restricted to authorized personnel using key-based authentication, and the production database is not exposed to the public internet.
- Security-relevant events are recorded in an audit log.
- Caregiver access is enforced per-permission on the server for each request.
Honest limits. Medico is an early-stage company. We have not completed a SOC 2 audit, HITRUST certification, or independent third-party penetration test, and we do not claim to have. No system is completely secure. We cannot and do not guarantee that your information will never be accessed, disclosed, altered, or destroyed without authorization. We will update this section as our security program matures — and we will not claim protections we have not implemented.
5. Artificial Intelligence and Third-Party Processing
To provide AI features, we transmit your information — including health information — to third-party AI providers for processing. This is required for these features to function.
The AI providers we currently use are:
| Provider | Used for |
| Google (Gemini API) | Health insights, question answering, care plan and news summarization, audio transcription of provider recordings, document and image extraction |
| OpenAI | Selected insight and text-generation features |
| xAI | Selected insight and text-generation features |
What this means for you:
- Your information is transmitted over encrypted connections and is sent to these providers solely to produce results for you.
- OpenAI: we have an executed Business Associate Agreement and a zero-data-retention agreement in place, so data we send is not retained by OpenAI and is not used to train their models.
- Google: we have a Business Associate Agreement with Google. It covers Google Cloud's HIPAA-eligible services. We are in the process of moving our Gemini traffic onto the service that agreement covers; until that move is complete, our Gemini requests run on Google's general-purpose API under its standard commercial terms rather than under the BAA. Those terms state that data submitted through the paid API is not used to train Google's models. We will update this section when the move is finished.
- xAI: used only for non-identifying lookups such as drug-interaction information, and it is excluded from features that process your health record. There is no Business Associate Agreement available for this provider.
- Where we rely on a provider's contractual terms, we do not independently audit them and cannot guarantee their compliance.
- These providers may retain submitted data for a limited period for abuse monitoring and service operation, under their own policies, except where a zero-retention agreement applies.
- Do not enter information into the Service that you are unwilling to have processed by these providers.
- If we add, remove, or change AI providers in a way that materially affects how your information is handled, we will update this Section and notify you as described in Section 12.
6. HIPAA — What Applies and What Does Not
HIPAA governs "covered entities" (healthcare providers, health plans, healthcare clearinghouses) and their "business associates." When you use Medico directly as a consumer, we are generally neither. That means:
- The information you enter into Medico is generally not Protected Health Information under HIPAA, and HIPAA's rights and remedies generally do not apply to it.
- Information your healthcare provider holds about you remains protected by HIPAA in their hands. Sharing it with us does not change their obligations, and does not extend HIPAA's protection to our copy.
- We voluntarily apply safeguards modeled on HIPAA's Security Rule (Section 4) and honor access, correction, and deletion requests (Section 9) — as a matter of policy, not because HIPAA requires it of us.
- Where we do act as a business associate under a signed Business Associate Agreement with a covered entity, that agreement governs that data, and its terms control over this Policy to the extent of any conflict.
- Separately, we hold Business Associate Agreements with certain vendors who process data on our behalf (see Section 5). Those agreements bind those vendors; they do not by themselves make HIPAA applicable to your use of Medico as a consumer.
We tell you this plainly because many health apps imply HIPAA protection they do not provide. You are entitled to know which rules actually apply.
7. When We Share Information
We do not sell your information. We share it only as follows:
- With people you authorize. Caregivers you invite see what your permissions allow. You can change or revoke this at any time.
- Emergency contacts. If you trigger an SOS alert, we send the information in that alert — which may include your location and emergency profile — to the contacts you designated.
- Service providers. Vendors who help operate the Service, under contractual confidentiality obligations: Amazon Web Services (hosting, storage, authentication, email), the AI providers named in Section 5, Twilio (SMS one-time passcodes), Google Firebase (push notifications), and Apple and Google push services.
- Legal requirements. When required by law, subpoena, court order, or regulation, or to respond to lawful government requests.
- Safety. Where we believe in good faith that disclosure is necessary to prevent imminent harm to you or another person.
- Business transfer. In a merger, acquisition, financing, or sale of assets, your information may transfer to the successor, which will remain bound by this Policy or give you notice of any material change.
8. Data Retention and Deletion
- We keep your information while your account is active.
- You can delete your account from within the app or by emailing privacy@medicoapp.ai. On deletion we remove your health records and account data from our active systems within 30 days.
- Backups. Deleted data may persist in encrypted backups for up to approximately 35 additional days before those backups expire on their normal rotation. We do not restore deleted accounts from backup.
- We may retain limited information where required by law, to resolve disputes, or to enforce our agreements — and de-identified or aggregated data that cannot reasonably identify you.
- Data stored locally on your device is removed when you delete the app or clear its data.
9. Your Rights and Choices
Regardless of where you live, you may:
- Access your data in the app at any time, and request a copy by emailing privacy@medicoapp.ai.
- Correct your information directly in the app.
- Delete your account and data (Section 8).
- Control notifications in Settings, and revoke device permissions (camera, microphone, location, calendar) in your device settings.
- Manage caregiver access at any time.
- Opt out of SMS by replying STOP. Note this disables SMS sign-in for that number.
We will not discriminate against you for exercising these rights.
9.1 U.S. state privacy rights
Depending on your state of residence — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others — you may have rights to know, access, correct, delete, obtain a portable copy, and appeal a denied request. California residents: we do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information for purposes beyond those permitted under the CPRA. You may exercise these rights, or ask about the categories we collect and disclose, at privacy@medicoapp.ai. An authorized agent may act for you with proof of authorization.
9.2 Consumer health data (Washington, Nevada, and similar laws)
For residents of Washington State (My Health My Data Act), Nevada, and states with comparable consumer health data laws, this Section serves as our consumer health data notice:
- What we collect: the health information described in Section 1, which you provide directly.
- Why: solely to provide the features described in Section 2. We do not use consumer health data for advertising or profiling.
- Who receives it: the service providers and AI processors named in Sections 5 and 7, and people you authorize.
- We do not sell consumer health data and will not do so without the separate valid authorization those laws require.
- Your rights: to confirm whether we collect your consumer health data, access it, obtain the list of third parties it was shared with, withdraw consent, and have it deleted — including from our backups on their expiry schedule. Contact privacy@medicoapp.ai; we respond within the timeframes those laws require. If we deny a request, you may appeal by replying to our decision.
- Geofencing: we do not use geofencing around healthcare facilities for any purpose.
10. Children's Privacy
The Service is for adults. You must be 18 or older to create an account. We do not knowingly collect information directly from children under 13.
An adult account holder may record health information about a dependent, including a minor, as part of managing that person's care. If you do, you represent that you are the parent, legal guardian, or otherwise legally authorized to provide that information and to consent to this Policy on the dependent's behalf. If you believe a child has created an account independently, contact privacy@medicoapp.ai and we will delete it.
11. International Users
The Service is intended for use in the United States, and your information is stored and processed there. If you access it from elsewhere, you consent to that transfer. We do not currently offer the Service to individuals in the European Economic Area or the United Kingdom, and this Policy is not written to satisfy the GDPR.
12. Changes to This Policy
We may update this Policy. For material changes — including any change to the AI providers in Section 5 or to the security representations in Section 4 — we will give notice through the app or by email at least 30 days before the change takes effect, and will note the new effective date here.
13. Data Breach Notification
If we discover a security incident that compromises your personal or health information, we will notify affected users and any regulators as required by applicable state and federal law, without unreasonable delay, and will tell you what happened, what information was involved, and what steps we are taking.
14. Contact Us
Medico AI, Inc.
Privacy: privacy@medicoapp.ai
Legal: legal@medicoapp.ai
Web: medicoapp.ai/contact-us.html
Last Updated: August 13, 2026