Medicod

Privacy Policy

Effective date: August 11, 2026

Medicod provides an informational service that helps users understand laboratory test results. This Privacy Policy explains what data we process, why we process it, and how users can contact us about privacy requests. The data controller for medicod.app is NWTC INC, 30 North Gould Street Ste R, Sheridan, WY 82801, USA.

1. Important Medical Disclaimer

Medicod is not a medical device and does not provide medical consultations, diagnoses, treatment, or emergency services. The app provides educational and informational explanations only. Always consult a qualified healthcare professional before making health decisions.

2. Data We Process

  • Uploaded lab report images, PDFs, or text needed to extract medical markers.
  • Medical marker names, values, units, and reference ranges.
  • Optional profile information such as age, sex, and health context if provided by the user.
  • Account identifiers, email address, app user ID, and purchase/unlock records.
  • Your email address, preferred platform, page URL, site host, and referrer if you join the app launch list.
  • Technical data such as device information, app version, logs, and crash reports.
  • Analytics events such as page views, button clicks, signup events, browser language, and traffic source.

3. Medical Data and AI Processing

Lab results and related health context may be sensitive health information. We use this information only to provide the requested report explanation, diagnose a specific recognition failure, prevent abuse, process purchases, and support user requests. We do not use health data to train our own models or for unrelated research or advertising.

For the international Medicod service, a selected source image or PDF may be sent to Google Cloud Vision through its EU endpoint to extract text. Yandex Cloud Vision is not used in this international data region. OCR necessarily happens before redaction, so the OCR provider may receive names or other identifiers visible in the source. After OCR, we reduce recognizable identifiers and send only the text needed for the explanation to Google Gemini as the AI provider. Redaction reduces risk but does not guarantee that the data is anonymous. We do not send the source file to Gemini. AI output may be inaccurate or incomplete and must not be used as a diagnosis.

Before you upload a report, Medicod requests consent to process sensitive health information through OCR and AI providers and to make cross-border data transfers where those providers operate. Core international account, report, quality-review, and backup data is stored in Germany on encrypted Medicod-controlled storage. AI and other service providers may process limited data in the United States, the European Economic Area, or other countries. If you do not agree to this processing, do not upload a lab report. You may withdraw consent by contacting support, subject to records we must retain for legal, security, or transaction purposes.

4. Payments

Web payments are handled by Stripe. We receive the checkout or payment identifier, status, amount, currency, customer email, and the internal analysis reference needed to unlock a report. For Google Play and Apple App Store purchases, payment processing is handled by the relevant app store and RevenueCat. We receive purchase identifiers and entitlement data needed to unlock the paid report. We do not receive or store full card numbers or card verification codes (CVCs).

5. App Launch List

If you join the iOS or Android launch list, we use your email to notify you when the app becomes available and to understand platform demand. You can request removal by emailing support.

6. Sharing

We use Hetzner infrastructure in Germany for the international service; Google Cloud Vision through its EU endpoint for OCR; Google Gemini for AI processing; Stripe for web payments; RevenueCat, Google Play, and Apple App Store for mobile purchase verification; Firebase Analytics for optional app analytics after a separate consent choice; Sentry for redacted technical error monitoring; and providers of email and customer support. Firebase Analytics and Sentry do not receive uploaded reports, lab values, photos, email addresses, or internal report identifiers from Medicod telemetry. These providers process data only as needed for the disclosed purpose. We do not sell personal data.

7. Retention and Deletion

We retain records only as long as needed for service, security, legal, accounting, and support purposes. An uploaded source image or PDF is normally deleted after processing. If Medicod detects a recognition-quality issue, the source file may be kept in protected storage for no more than 14 days solely to investigate and correct that issue, and is then deleted. Generated reports may remain available until the user deletes them. Minimal payment, consent, security, and deletion records may be retained where required to meet legal obligations or establish that a request was fulfilled. Users can request deletion of their account and related data in the app or through the account deletion page.

Access-restricted security backups may contain deleted records for up to 14 days. They are not restored except for disaster recovery; after an isolated restore, deletion requests are reapplied before the service is reopened. The backups are then deleted or overwritten on schedule.

8. User Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data. Contact us to submit a request.

9. Contact

For privacy requests, support, or account deletion, email [email protected] or call +1 260 308 6515.

Privacy Policy - Medicod | Medicod