MediWall
Privacy Policy
Effective July 4, 2026
Your health records stay on your device.
MediWall has no servers that hold your health information. We don't sell or share your data, and we never run analytics on your health records. We do collect de-identified, aggregate usage stats (which you can turn off) to improve the app — never health data and never anything that identifies you. This policy describes what that means in practice, and how it maps to both Canadian (PIPEDA) and U.S. (HIPAA) standards.
1. The short version
- We have no servers that hold your health records — they live on your device only.
- We never sell or share your data, and we never analyse your health information.
- We collect de-identified, aggregate usage stats (no health data) tied only to a random ID you can erase — you can turn this off anytime.
- You can export every record, or delete every record, from Settings.
- Your EHR reads into MediWall on-device. No copies leave the device.
2. What we collect
MediWall stores only the information you choose to enter or import: medications, conditions, allergies, appointments, lab results, symptoms, mental-health entries, care team contacts, and the preferences you set in the app.
We do not collect advertising IDs or any device identifier, and we never read your health records for analytics. To understand how the app is used and to fix bugs, MediWall collects a small amount of de-identified, aggregate usage data: counts of how often the app is opened, which features are used (for example, that “a medication was added” — never what it was), whether the app crashed, your app version, and your device type (iOS/Android). This is tied only to a random, de-identified ID — not your name, email, or location — and that ID is erased when you use “Delete all data”.
Sharing usage data is on by default and can be turned off at any time in Settings → Privacy & Compliance. When it's off, nothing is sent. Separately, if you choose to send feedback from Settings, only the message you type (and an email address, if you add one) is sent — nothing is collected automatically.
3. Where data lives
- On your device. An encrypted SQLite database, protected by your iOS passcode and (optionally) MediWall's biometric lock.
- Your EHR. When you connect a provider via SMART on FHIR, that EHR releases records directly to your device. The connection is governed by the EHR's terms.
- iCloud backup, if you enable it. A backup of the encrypted database is stored in your personal iCloud. We never receive that backup.
4. PIPEDA — Ten Principles PIPEDA
- Accountability. You are the data controller for your records; we publish the tool that holds them.
- Identifying Purposes. Each form in the app states what the data is for.
- Consent. You consent by entering data or toggling a source on. Withdrawal is one tap in Settings → Your Data Controls.
- Limiting Collection. We collect only what you supply. We do not derive new personal data from your input.
- Limiting Use & Retention. Your data is used only by the app on your device, and is retained until you delete it.
- Accuracy. You can edit any record at any time.
- Safeguards. Encrypted local storage, optional biometric lock, no third-party network access for health data.
- Openness. This policy, kept in plain language.
- Individual Access. Settings → Export my data produces a full JSON copy.
- Challenging Compliance. Email [email protected]. You may also contact the Office of the Privacy Commissioner of Canada (priv.gc.ca).
5. HIPAA — Safeguards HIPAA
MediWall is a personal health-record tool you use yourself. In most cases it is not a HIPAA covered entity, because it does not transmit Protected Health Information (PHI) on behalf of a clinic or insurer. We still apply HIPAA's three safeguard categories to how the app handles data on your device.
- Administrative safeguards. The Audit Log (Settings → Access History) records privacy-relevant actions.
- Physical safeguards. Your iPhone's Secure Enclave protects the database encryption key.
- Technical safeguards. AES-256 encryption at rest, biometric authentication, no PHI transmitted to MediWall servers (we have none).
When you connect to a provider via SMART on FHIR, that EHR release is governed by the EHR's own HIPAA-compliant terms; MediWall acts on your behalf as the patient and stores nothing off-device.
6. Your rights
- Access. Export → a single JSON file with every row of your data.
- Correction. Every record is editable from the screen where it lives.
- Deletion. Settings → Delete all local data wipes everything immediately and irreversibly.
- Restriction / Withdrawal of consent. Toggle individual data sources off in Settings → Your Data Controls.
- Portability. The JSON export is yours to keep, archive, or share with a clinician.
- Complaint. Contact us, the Privacy Commissioner of Canada, or the U.S. HHS Office for Civil Rights (hhs.gov/ocr).
7. Children & records you manage for others
MediWall is intended for adults managing their own health information. If you are a parent or guardian using MediWall on behalf of a child, you are responsible for any data entered.
Care Circle lets you keep a separate profile for someone you care for (for example, a parent). Their records are handled exactly like yours: stored only on your device in their own encrypted database, never sent to us, and deletable at any time from Settings → Care Circle. Connecting their EHR uses that EHR's own authorization (their sign-in or your proxy access) — you are responsible for having the authority to hold their information.
8. Changes to this policy
Material changes are surfaced inside the app with a confirmation step before continuing. The effective date at the top of this page always reflects the version currently in force.
9. Contact
[email protected] — for privacy questions, access or deletion requests, or to challenge compliance.