01
Who this is about
medlog is a personal medical-record app run by an independent developer, not a hospital, a pharmacy, an insurer or a clinic. In data protection language, you are the person the data is about and medlog is the party that decides how it is handled.
This policy covers the medlog website and app. It does not cover anything you do outside them, including the site you came from and any service you choose to sign in with.
02
What is collected
Account details. When you sign in with Google, we receive your name, your email address, your profile picture and the account identifier Google uses for you. That is all we ask for and all we get. We never see your Google password.
The record you build. Everything you or your documents put into the app: the people you keep records for and their name, relationship to you, date of birth, sex, height, blood group and notes; medicines, strengths, doses, schedules and how long each course ran; visits, complaints and diagnoses; the doctors and hospitals involved; lab and scan reports with their values; weight and other vitals; allergies and ongoing conditions.
The documents themselves. Photographs and files you upload — prescriptions, pharmacy bills, discharge summaries, lab reports, the box a medicine came in — along with what was read out of them and how confident that reading was.
The little that is technical. A sign-in session, your time zone so that “today” means your today, when you were last active, and the ordinary server records our providers keep to deliver and secure the service.
We do not ask for and do not want your government identity numbers, your insurance details or your payment details. medlog is free and takes no payments.
03
Records you keep for other people
The app is built for keeping a parent’s or a child’s record alongside your own, so some of what you add is about somebody else. Their data is treated exactly like yours: private to your account, never shared, deleted when you delete it.
You are responsible for having their agreement, or the authority to act for them, before adding their medical history. If they later ask for it to be removed, you can delete it in the app, or write to us and we will.
04
What it is used for
Your data is used to run the product, and for nothing else:
- To sign you in and keep your session going.
- To read your documents and turn them into a record you can check, correct and search.
- To show what you are taking now, what you have taken before, and what a course of treatment looked like.
- To keep the service working: fixing faults, preventing abuse, and protecting accounts.
- To answer you when you write to us.
It is not used to advertise to you, to build a profile of you, to train models, or to be sold or rented to anybody in any form. There is no exception to this and no plan to add one.
05
How documents are read
Reading a photograph of a prescription is done by an automated service, not by a person here. When you upload a document, its image is sent over an encrypted connection to a specialist third-party processing provider, which returns the text and structure it read. The result is shown to you for checking before it becomes part of your record.
We use these providers under business terms that do not permit your content to be used to train their models, and we do not send them your name, your email address or your account identifier along with the image. What they receive is the document and an instruction to read it. Their own terms govern their systems, which we do not control.
Separately, the app looks up general facts about a medicine — what it is for, how it is usually taken. Those lookups contain the name of the medicine and nothing about you, and the answer is stored against the medicine so that the same question is never asked twice.
No person at medlog reads your documents unless you specifically ask for help with one, or unless we are required to look in order to investigate abuse or comply with the law.
06
Where it is kept
Your record lives in a hosted database, and your documents live in a private storage bucket that is not readable from the open internet. When the app shows you one of your own photographs, it does so through a signed link that expires shortly after it is issued.
Everything travels over encrypted connections, and our infrastructure providers encrypt what they store on disk. Access to production systems is limited to the developer running the service.
These providers operate servers outside your country, including in the United States and Europe, so your data is processed there. Where the law requires a legal basis for that transfer, it is the contractual terms we have with each provider.
08
How long it is kept, and deleting it
Your record is kept for as long as your account exists, because that is the point of it: a medication history is only useful if it goes back years.
You can delete anything you added. Deleting a document also deletes the stored image behind it. Deleting a medicine, a visit, a report or a measurement removes it from your record.
To delete the whole account, write to iambasith123@gmail.com from the address you signed in with. Everything — profiles, documents, medicines, reports — is erased within 30 days. Copies may survive a little longer in routine backups before those are cycled out, and they are never restored into the live service after a deletion.
09
Your rights
You can ask us to:
- Tell you what data is held about you.
- Give you a copy of it.
- Correct anything wrong — most of it you can edit yourself.
- Delete your account and everything in it.
- Stop processing it, by closing the account.
Write to iambasith123@gmail.com and you will get an answer within 30 days. There is no charge.
If you are in India, these rights sit under the Digital Personal Data Protection Act, 2023, and you may complain to the Data Protection Board. If you are in the UK or the European Economic Area, the UK GDPR or GDPR applies, our basis for handling your health data is your explicit consent given by choosing to upload it, and you may complain to your national supervisory authority.
11
Security, honestly stated
Sessions are short-lived and re-checked continuously, every request for data is checked against who is asking, document storage is private with expiring links, and secrets are held outside the code.
No service can promise it will never be breached, and one that does is lying. If a breach happened that put your data at risk, you would be told, and so would the relevant authority where the law requires it.
Your account is only as safe as the Google account it is attached to. Two-factor authentication there is the single most useful thing you can do for it.
12
Children
medlog accounts are for adults. A parent or guardian may keep a child’s medical record inside their own account, which is a deliberate feature, but a child should not hold an account themselves. If we learn that one has, it will be removed.
13
Changes to this policy
When this changes, the date at the top changes with it. If a change materially affects what happens to data already held, you will be told by email before it takes effect. Continuing to use medlog after that means the revised policy applies.
14
Contact
Questions, requests and complaints about privacy all go to the same place: iambasith123@gmail.com.
The rules for using the service are in the Terms of Service.

