← MediWall home

Privacy Policy

1. The short version

2. What we collect

MediWall stores only the information you choose to enter or import: medications, conditions, allergies, appointments, lab results, symptoms, mental-health entries, care team contacts, and the preferences you set in the app.

We do not collect advertising IDs or any device identifier, and we never read your health records for analytics. To understand how the app is used and to fix bugs, MediWall collects a small amount of de-identified, aggregate usage data: counts of how often the app is opened, which features are used (for example, that “a medication was added” — never what it was), whether the app crashed, your app version, and your device type (iOS/Android). This is tied only to a random, de-identified ID — not your name, email, or location — and that ID is erased when you use “Delete all data”.

Sharing usage data is on by default and can be turned off at any time in Settings → Privacy & Compliance. When it's off, nothing is sent. Separately, if you choose to send feedback from Settings, only the message you type (and an email address, if you add one) is sent — nothing is collected automatically.

3. Where data lives

4. PIPEDA — Ten Principles PIPEDA

  1. Accountability. You are the data controller for your records; we publish the tool that holds them.
  2. Identifying Purposes. Each form in the app states what the data is for.
  3. Consent. You consent by entering data or toggling a source on. Withdrawal is one tap in Settings → Your Data Controls.
  4. Limiting Collection. We collect only what you supply. We do not derive new personal data from your input.
  5. Limiting Use & Retention. Your data is used only by the app on your device, and is retained until you delete it.
  6. Accuracy. You can edit any record at any time.
  7. Safeguards. Encrypted local storage, optional biometric lock, no third-party network access for health data.
  8. Openness. This policy, kept in plain language.
  9. Individual Access. Settings → Export my data produces a full JSON copy.
  10. Challenging Compliance. Email [email protected]. You may also contact the Office of the Privacy Commissioner of Canada (priv.gc.ca).

5. HIPAA — Safeguards HIPAA

MediWall is a personal health-record tool you use yourself. In most cases it is not a HIPAA covered entity, because it does not transmit Protected Health Information (PHI) on behalf of a clinic or insurer. We still apply HIPAA's three safeguard categories to how the app handles data on your device.

When you connect to a provider via SMART on FHIR, that EHR release is governed by the EHR's own HIPAA-compliant terms; MediWall acts on your behalf as the patient and stores nothing off-device.

6. Your rights

7. Children & records you manage for others

MediWall is intended for adults managing their own health information. If you are a parent or guardian using MediWall on behalf of a child, you are responsible for any data entered.

Care Circle lets you keep a separate profile for someone you care for (for example, a parent). Their records are handled exactly like yours: stored only on your device in their own encrypted database, never sent to us, and deletable at any time from Settings → Care Circle. Connecting their EHR uses that EHR's own authorization (their sign-in or your proxy access) — you are responsible for having the authority to hold their information.

8. Changes to this policy

Material changes are surfaced inside the app with a confirmation step before continuing. The effective date at the top of this page always reflects the version currently in force.

9. Contact

[email protected] — for privacy questions, access or deletion requests, or to challenge compliance.