PRIVACY POLICY

Last updated: May 16, 2026


Summary: MediConsult AI is an educational tool, not medical care. We process your chat and uploaded files to generate AI responses via our server and Google Gemini. Consultation history and credits stay on your device. Rewarded ads on mobile use Google AdMob. We do not sell your health data.


1. Introduction

This Privacy Policy explains how MediConsult AI ("we," "us," or "our") collects, uses, discloses, and protects information when you use the MediConsult AI mobile applications (Android and iOS), web application, and related backend services (collectively, the "Service").

By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.


2. Who operates the Service

The Service is operated under the name MediConsult AI (application ID: com.mediconsult.ai). For privacy-related questions, contact us at faujitec@gmail.com or via the support channel listed on your app store listing.


3. Scope

This Policy applies to information processed through:

• Native apps built with Capacitor (Android / iOS)
• Any web or browser-based access to the frontend
• Our backend API hosted at https://mediconsult-ai-gpe9.onrender.com (including legal pages, health checks, and the /api/analyze endpoint)


4. Information we collect and process

4.1 Information you provide

• Chat messages and prompts — text you enter in consultations.
• Uploaded files — images (e.g. symptom photos, dermatology), PDFs (e.g. lab reports), and related metadata (file name, MIME type). Files are converted to base64 in the app and transmitted to our backend for analysis.
• Analysis preferences — optional focus areas you select (e.g. radiology, laboratory results, pathology, cardiology, dermatology, clinical notes).

We do not require account registration, email, or phone number to use the core Service.

4.2 Information stored on your device

The following is stored locally in your browser or app storage and is not synced to our servers as a user profile:

• Consultation history — session titles, messages, and attachment references
• Credit balance — number of analysis credits available
• Theme preference — light or dark mode

Deleting consultations via Settings → Clear all data removes local consultation history but does not reset your credit balance.

Uninstalling the app or clearing app storage typically deletes this local data. Credits and history generally do not survive reinstall unless we add an account or cloud backup feature in the future.

4.3 Information collected automatically

• Network and request data — when you call our API, we receive your IP address, request timestamps, HTTP headers, and error/status information. We apply rate limiting (currently up to 15 analyze requests per minute per IP address) to protect the Service.
• Device and platform data — on native apps, standard mobile SDK data may be collected by third parties (see AdMob below), such as advertising ID on Android where the AD_ID permission is declared.

4.4 Sensitive and health-related information

Content you upload may constitute personal health information or other sensitive personal data under applicable laws. You choose what to submit. Do not submit information you are not authorized to share (including another person's records without permission).

We are not a HIPAA-covered entity or business associate in the United States unless we separately agree in writing. Do not use the Service for regulated clinical workflows or as a medical record system.


5. How we use information

We use information to:

• Provide AI-assisted educational analysis of your prompts and attachments
• Operate, secure, and maintain the backend API
• Enforce rate limits and prevent abuse
• Display rewarded advertisements on supported native platforms
• Comply with legal obligations and respond to lawful requests

We do not use your content to sell personal information. We do not use your uploads for our own independent medical diagnosis or treatment decisions.


6. AI processing (Google Gemini)

When you request an analysis, your prompt, focus areas, and attachment data are sent from your device to our backend and then processed using Google's Gemini API to generate a text response. Processing is performed to deliver the Service only.

Google's handling of API data is governed by the Gemini API Terms (https://ai.google.dev/gemini-api/terms) and Google Privacy Policy (https://policies.google.com/privacy). You should review those documents. We configure the assistant with educational disclaimers and instructions not to request unnecessary personally identifiable information (PII).

AI limitations: Outputs may be inaccurate, incomplete, or outdated. They are for educational purposes only and are not a substitute for professional medical advice.


7. Storage, retention, and deletion

• On your device: You control local data via Clear all data (consultations only) or by uninstalling the app.
• On our servers: Analyze requests are processed to return a response. We do not design the Service to maintain a long-term archive of your medical files or chat history on the server. Nevertheless, transient processing, caching, backups, or infrastructure logs (e.g. on our hosting provider) may temporarily contain request data or metadata.
• Logs: Server logs may retain IP addresses and technical metadata for a limited period for security, debugging, and abuse prevention.


8. Credits and advertising

8.1 Credits

The Service uses a credit system stored on your device:

• New installs receive 2 free credits (one credit is consumed per successful analysis).
• Credits are deducted only when an analysis completes successfully from the server.
• Credits are not reset when you clear consultation data.

Credits are not tied to a user account today and are not guaranteed to persist after uninstall, device change, or storage clear.

8.2 Rewarded ads (Google AdMob)

On Android and iOS native apps, you may watch rewarded video advertisements through Google AdMob to earn additional credits (+1 per completed rewarded view). Web/browser versions do not show rewarded ads; the app may direct you to use the mobile app instead.

AdMob may collect device identifiers, ad interaction data, and related analytics per Google's policies (https://policies.google.com/privacy) and AdMob program policies (https://support.google.com/admob/answer/6128543). In development or test mode, Google sample ad units may be used.

We do not display banner advertisements in the current version of the app.


9. Third-party service providers

We rely on third parties that may process data on our behalf:

• Google (Gemini API) — AI content generation
• Google (AdMob) — rewarded advertising on native apps
• Render (or successor hosting) — backend API hosting
• Google Play / Apple App Store — distribution, payments (if added later), and platform policies

These providers have their own privacy terms. We encourage you to review them.


10. Legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we process personal data based on:

• Contract / service delivery — to provide analyses you request
• Legitimate interests — security, fraud prevention, improving reliability, and advertising on native apps where permitted
• Consent — where required for ads or optional features, which you may withdraw through device ad settings or by not using those features
• Legal obligation — where we must comply with law


11. International data transfers

Our backend and third-party processors may operate in the United States and other countries. If you access the Service from outside those regions, your information may be transferred internationally. We take reasonable steps to ensure appropriate safeguards where required by law.


12. Security

We use reasonable technical and organizational measures (HTTPS transport, server-side API keys, rate limiting, and access controls on infrastructure). No method of transmission or storage is 100% secure. You are responsible for securing your device and avoiding sharing sensitive information unnecessarily.

Android builds may disable automatic cloud backup of app data; this does not replace your own device security practices.


13. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability or withdrawal of consent.

• Local deletion: Settings → Clear all data (consultations); uninstall app to remove local storage
• Advertising choices: Device settings (e.g. "Opt out of Ads Personalization" on Android, Limit Ad Tracking on iOS)
• Contact us: support@mediconsult.ai for other requests. We may need to verify your request and cannot recover data we no longer hold on servers.

California residents may have additional rights under the CCPA/CPRA (know, delete, correct, opt out of sale/share). We do not sell personal information as defined by the CCPA.

You may lodge a complaint with your local supervisory authority in the EEA/UK.


14. Children's privacy

The Service is not directed to children under 13 (or under 16 where applicable law requires parental consent for information society services). We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps to delete it.


15. Educational use only — not medical care

MediConsult AI provides educational information only. It is not a medical device, telehealth service, or emergency service. Do not use the Service for medical emergencies. Call your local emergency number immediately in an emergency.


16. Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change. Material changes may be communicated in-app or on this page. Continued use after changes constitutes acceptance where permitted by law.


17. Contact

Email: faujitec@gmail.com