MedDexMedDex

Effective date: 13 September 2026 · Last updated: 13 September 2026

Privacy Policy

This Privacy Policy explains how MedDex EdTech Venture handles personal data when you use MedDex on the web, Android, iOS, or another supported client. It should be read with our Terms of Service. This policy is a product disclosure, not a substitute for advice about Malaysian privacy or healthcare law.

1. Data we receive

2. How features handle health and sensitive data

Treat anything you enter about a patient, symptom, scan, ECG, heart/lung sound, consultation, transcript, or clinical case as sensitive health information. MedDex can receive and process that information when you use Lens, chat image attachments, Clinical Audio, Clerking Copilot, OSCE or medical simulations, uploads, or cloud AI reasoning. Do not submit identifiable patient data unless you are authorised and have required consent. MedDex does not verify your authority or consent.

Lens accepts medical images including JPEG, PNG, WebP and DICOM inputs through the backend. The bytes are normalised, hashed for request/cache control, analysed by the configured MedDex/MedGemma service, RunPod when enabled, and/or Google Gemini or OpenAI vision routes, and the resulting structured report may be cached in Supabase for up to the configured cache period (the code default is 24 hours). The implementation does not justify promising permanent deletion immediately after a request, and provider retention is governed by the provider’s terms. Lens history and reports may be stored in your account until deleted or removed under our retention rules.

Chat prompts and image attachments are sent to the selected cloud provider when cloud chat is used. Authenticated chat history is stored in Supabase; usage and diagnostics may record feature, provider, model, timing, token counts and limited metadata. The OpenAI Responses path requests store:false for that request, but that does not control MedDex history, logs, or OpenAI operational handling. We do not claim that cloud AI providers never retain inputs or use them for training; check their current terms and settings.

Clerking Copilot uses microphone access, local or browser speech handling where available, and cloud OpenAI realtime, transcription, translation, speaker-cleanup, and structured reasoning endpoints. Audio is sent when the relevant recording or transcription action is started. Transcripts, structured information, corrections, examination prompts, and notes may remain in the session or be saved by the client or account feature. Interim audio/transcripts are not represented as permanently deleted, and MedDex cannot control provider retention.

Clinical Audio uses heart and lung sound materials and may use third-party source material or provider-backed explanations. Research Lab queries public literature services and may send the query and related context to OpenAI for synthesis. Results and citations can contain third-party links and are not medical advice.

3. Spatial, camera, AR, and local models

Spatial Intelligence uses camera video, selected frames, object/hand landmarks, OCR, motion/orientation, and AR/world-tracking capabilities. The continuous perception pipeline is designed to run in the browser/on-device and normally does not upload the live video. When you choose Explain, Interpret, Learn, Lens, voice, or another cloud action, a selected crop, OCR text, local labels, prompt, or voice input may be sent to MedDex and an AI provider. Local models, downloaded model files, browser cache, localStorage, Capacitor Preferences, and device cache may store preferences, notes, model state, or generated content. Local storage is not automatically removed when you uninstall, change accounts, or use another device.

4. AI providers and other processors

Depending on the feature, data may be processed by: Supabase for authentication, database, storage, and account data; Netlify for hosting/serverless functions and operational logs; OpenAI for chat, realtime voice, Clerking, transcription, translation, research synthesis, and image generation; Google Gemini/Generative Language and Google AI services for chat, OSCE, Lens, ECG, audio or other model routes; MedGemma and its configured dedicated service, and RunPod when enabled, for medical image inference; Stripe for subscriptions and payments; Google Play for Android billing and verification; Canva for authorised design creation/imports; Google OAuth, Docs, Slides, Drive, Gmail, and Calendar for connected actions; NCBI/PubMed, Europe PMC, OpenAlex, Crossref, Unpaywall, and other literature/public research services for searches and citations; and CDN/model hosts such as jsDelivr, Google Cloud Storage/MediaPipe, Tesseract, 8th Wall, or Zappar when the relevant client capability loads them. Provider availability and configuration can change. Each provider may process data under its own terms and privacy policy.

Connected Google and Canva credentials are stored by MedDex only when the integration is enabled; connected-app tokens are intended to be encrypted in the server-side vault. MedDex uses the scopes and actions shown in the connection flow, which may include creating Docs/Slides, listing Drive files, creating Gmail drafts, creating Calendar events, and creating or importing Canva designs. We do not use those integrations to read unrelated content unless the requested scope and action allow it.

5. Purposes and legal choices

We use data to provide and personalise the service, authenticate users, save and sync content, run AI and educational tools, meter quotas and credits, process payments, manage integrations, send notifications, prevent fraud and abuse, secure and debug the service, respond to support, comply with law, and improve reliability. Where required, we rely on consent for camera, microphone, notifications, uploads, and optional integrations; on contract or requested service for account, billing, and core functions; and on legitimate interests or legal obligations for security, fraud prevention, records, and compliance. You may refuse optional permissions, use text or non-camera alternatives where offered, disconnect integrations, disable notifications, clear local storage, and stop using a feature.

6. Cookies, storage, and notifications

MedDex uses browser localStorage and session storage patterns, service-worker/browser cache, cookies or equivalent authentication state where supplied by the authentication stack, and Capacitor Preferences/filesystem/cache on supported mobile clients. These support sign-in, guest sessions, preferences, offline/local AI, notes, model downloads, generated media, and app operation. The service also registers push tokens for Android, iOS, or web when you enable push notifications; notification providers may deliver notifications and receive device/token data.

7. Retention and deletion

Retention depends on the feature, provider, account state, backups, security records, and legal requirements. Chat conversations, Lens history/cache, profiles, progress, social data, memories, usage events, billing records, connected-app records, push tokens, and uploaded or generated content may persist for different periods. Lens cache defaults to approximately 24 hours in code but may be configured differently. We do not promise a single universal deletion period or immediate deletion from third-party systems, backups, logs, or legally retained records.

You can delete your account through Delete Account. The current flow requires typed confirmation and deletes the authentication account, core personal rows, and profile avatar objects where possible; some billing, audit, fraud, security, or aggregated records may remain or be anonymised. Local files, browser storage, provider copies, shared exports, and content saved in connected apps may require separate deletion by you. Contact us if a deletion request is incomplete.

8. Security and international processing

We use access controls, row-level or server-side authorization in relevant paths, service-role boundaries, token protection, and provider security controls, but no online or device service is perfectly secure. Data may be processed outside Malaysia by our providers and their subprocessors. We do not promise end-to-end encryption, that every transfer or stored object uses a particular encryption method, or that a provider has no access to content.

9. Your rights

Subject to applicable law and verification, you may ask for access, correction, deletion, information about processing, withdrawal of optional consent, or help with a complaint. You may also access or delete content through available product controls. Requests may be limited by security, legal, billing, research, safety, or rights of others. Contact meddexedtech@gmail.com; we may ask for information to verify the request.

10. Children and age requirement

MedDex is intended for adults and students who can lawfully use the service. Do not create an account or submit data if you do not meet the minimum age required in your country or cannot consent to these terms. If you believe a child has provided personal data, contact us so we can review and delete it where appropriate. Founder/legal review is required before marketing MedDex to minors or educational institutions involving minors.

11. Updates and contact

We may update this Policy when the product, providers, law, or data practices change. We will post the revised Policy and update the dates above; material changes may also be notified in the service or by email where appropriate. Questions and privacy requests: meddexedtech@gmail.com.