MedKid Logo

MedKid

🇺🇸 English 🇵🇱 Polski

Privacy Policy

MedKid

Version 1.2 - Effective: June 12, 2026

Plain Language Summary

What MedKid does with your data - in simple terms:

MedKid is a family health tracking app that helps you manage your children's health records. Here's what you need to know about your privacy:

What we collect:

  • Your account info: Email address for login
  • Health records: Your children's symptoms, medications, growth data (all encrypted)
  • Technical data: Basic app usage info to keep things running smoothly
  • Crash reports: Only if you opt-in, to help us fix bugs

What's new in Version 1.2:

  • AI-assisted template creation: Family admins can now use an AI chat feature to create custom observation templates. When you use this feature, the template description you type is sent to Mistral AI (our AI sub-processor) for processing. No health records, no names, and no personal data are sent — only the text of your template description.

How we protect your data:

  • End-to-end encryption: Your health data is encrypted before leaving your device
  • Zero-knowledge: We can't read your encrypted health records
  • Local storage first: Data stays on your device unless you enable sync
  • EU servers: All data stored in Germany and Poland (GDPR compliant)

You're in control:

  • Access your data: View everything anytime in the app
  • Export your data: Download all your data as JSON
  • Delete everything: Request account deletion (instant deletion)
  • Turn off tracking: Disable crash reporting in settings

Family features:

  • Multi-device sync: Share data across family devices (optional)
  • Family encryption: Each family has unique encryption keys
  • Device management: Add/remove devices from your family

Your rights (GDPR):

  • Right to access your data
  • Right to correct mistakes
  • Right to delete your account
  • Right to export your data
  • Right to object to processing

Questions?

Contact us at: [email protected]


Full Privacy Policy

This Application collects some Personal Data from its Users.

This document contains sections dedicated to Users in the United States, Switzerland, and the European Union regarding their privacy rights.

This document can be printed for reference by using the print command in the settings of any browser.

Owner and Data Controller

Code Publishing sp. z o.o.
ul. Fabryczna 6
53-609 Wroclaw
Poland

Owner contact email: [email protected]

Types of Data Collected

Among the types of Personal Data that this Application collects, by itself or through third parties, there are:

  • Account Data (required for Family+): Email address, user identifier, device identifiers (including device marketing name such as "iPhone 15 Pro" or "Samsung Galaxy S24", unique device codes for secure encryption and multi-device synchronization, and sync identifiers used by the sync engine for conflict resolution when multiple devices edit the same data)
  • Health Data (required, encrypted): Children's health records including symptoms, medications, measurements, growth charts, medical appointments
  • Usage Data: App interactions, feature usage, synchronization metadata
  • Technical Data: Device information, operating system, app version
  • Diagnostic Data (optional): Crash reports and performance metrics (only with explicit consent)
  • AI Template Descriptions (only when using the AI template creation feature): Plain-text description of an observation category typed by a family admin. This text is sent to Mistral AI for processing; no health records or personal identifying information are included.

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.

Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application.

Unless specified otherwise, all Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.

Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.

Health Data constitutes special category data under GDPR Article 9. By using this Application for health tracking, Users explicitly consent to the processing of such data for the purposes described in this policy.

Users are responsible for any third-party Personal Data obtained, published or shared through this Application.

Mode and Place of Processing the Data

Methods of Processing

The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.

The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. Health Data is encrypted end-to-end using family-based encryption keys, ensuring that only authorized family members can access it.

In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.

Important: Due to end-to-end encryption, the Owner and third-party service providers cannot access or read User's health data.

Place

The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.

Server infrastructure is located in:

  • Primary servers: Germany (Hetzner Online GmbH)
  • Secondary servers: Poland (Scaleway S.A.S.)
  • Data centers: Germany (Hetzner Online GmbH), Poland (Scaleway S.A.S.)

Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.

Retention Time

Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.

Therefore:

  • Account Data: Retained for the duration of the account
  • Health Data: Retained until User requests deletion
  • Deleted Data: Permanently removed immediately upon deletion request
  • Consent Records: Retained for 12 months after account deletion (legal requirement)
  • Diagnostic Data: Retained for 90 days
  • AI Template Descriptions: Not retained by Mistral AI beyond the scope of the single API call (no training, no storage per our data processing agreement)

The Purposes of Processing

The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:

  • Registration and authentication: Creating and managing User accounts
  • Health data management: Storing and synchronizing children's health records
  • Family sharing: Enabling multi-device access within families
  • Service improvement: Optional crash reporting and diagnostics
  • Backup and recovery: Encrypted backup of User data
  • Legal compliance: Meeting GDPR and other regulatory requirements
  • AI-assisted template creation (optional, admin-only): Generating custom observation templates using AI assistance

For specific information about the Personal Data used for each purpose, the User may refer to the section "Detailed information on the processing of Personal Data".

Detailed Information on the Processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Registration and Authentication

Internal Authentication
This Application uses our internal backend system for User registration and login.

Personal Data processed: Email address, user identifier, authentication tokens

Place of processing: European Union

EmailLabs - Vercom S.A.
Transactional emails for email verification, one-time passwords, and account recovery.

Personal Data processed: Email address

Place of processing: Poland - Privacy Policy

Hosting and Backend Infrastructure

This type of service has the purpose of hosting Data and files that enable this Application to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of this Application.

Hetzner Online GmbH
Hetzner provides cloud hosting and storage services for this Application.

Personal Data processed: Encrypted data, usage data

Place of processing: Germany - Privacy Policy

Scaleway S.A.S.
Scaleway provides cloud infrastructure services for this Application.

Personal Data processed: Encrypted data, usage data

Place of processing: Poland - Privacy Policy

Platform Services

Google Play Store (Google Ireland Limited)
This Application is distributed on the Google Play Store, a platform for the distribution of mobile apps.

By virtue of being distributed via this app store, Google collects usage and diagnostics data and shares aggregate information with the Owner. Much of this information is processed on an opt-in basis.

Users may opt-out of this analytics feature directly through their device settings.

Personal Data processed: Usage Data (opt-in basis)

Place of processing: Ireland - Privacy Policy

App Store (Apple Inc.)
This Application is distributed on Apple's App Store, a platform for the distribution of mobile apps.

App Store Connect provides analytics data on user engagement and app discovery only for Users who have agreed to share them with the Owner.

Personal Data processed: Diagnostics, product interaction, usage data (opt-in basis)

Place of processing: United States - Privacy Policy

Diagnostics and Crash Reporting

Sentry (Functional Software, Inc.)
Sentry is an error tracking and performance monitoring system that helps developers identify and fix application errors in real time.

This service is ONLY active if the User explicitly opts in through the consent settings.

Technical Data processed: App crashes, error logs, device information (only with explicit consent, no personal or health information)

Place of processing: European Union (Germany) - Privacy Policy

Users can disable crash reporting at any time in Settings > Privacy > Crash Reporting.

AI-Assisted Template Creation

How your data is processed by AI

MedKid offers an optional AI-assisted feature (available to family admins only) that helps create custom observation templates. When a family admin uses this feature, the following occurs:

  1. The family admin types a plain-text description of the observation category they want to track (for example, "blood pressure" or "daily mood").
  2. This text description is sent over an encrypted HTTPS connection to our backend server.
  3. Our server queries standard medical terminology databases (LOINC and SNOMED CT) locally — no health records leave our server during this step.
  4. The text description (not any health records) is sent to Mistral AI for AI-assisted template generation.
  5. The AI returns a suggested template structure. The family admin reviews and must explicitly accept or reject it before it is saved.

What is NOT sent to Mistral AI:

  • Any health records or journal entries
  • Any personal identifying information (names, email addresses, device identifiers)
  • Any data about your children

Health Icons:
Template icons are sourced from the Health Icons project (https://healthicons.org), which releases all icons under a Creative Commons Zero (CC0) license. Icons are served as static files from a content delivery network (CDN). No user data is sent to any CDN to load icons.

Mistral AI (Mistral AI SAS)
Mistral AI provides large language model services used for AI-assisted template creation.

Data processed: Plain-text template description typed by the family admin (no health data, no personal identifying information)

Place of processing: European Union (France) - Privacy Policy

Mistral AI acts as a data processor under a Data Processing Agreement with the Owner. Template descriptions are not used for training Mistral AI models and are not retained beyond the duration of the API call.

Offline Processing

Google ML Kit
ML Kit is a set of on-device machine learning tools provided by Google that enable the use of machine learning on Android and iOS platforms.

All processing happens locally on the User's device. No data is sent to Google servers.

Personal Data processed: None (all processing is local)

Terms of Service

Further Information for Users

Legal Basis of Processing

The Owner may process Personal Data relating to Users if one of the following applies:

  • Consent: Users have given their consent for one or more specific purposes (primary basis for health data processing under GDPR Article 9)
  • Contract: Provision of Data is necessary for the performance of an agreement with the User
  • Legal obligations: Processing is necessary for compliance with a legal obligation
  • Vital interests: Processing is necessary to protect vital interests
  • Legitimate interests: Processing is necessary for legitimate interests pursued by the Owner or third parties

The Rights of Users Based on the General Data Protection Regulation (GDPR)

Users may exercise certain rights regarding their Data processed by the Owner.

In particular, Users have the right to:

  • Withdraw their consent at any time: Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
  • Object to processing of their Data: Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
  • Access their Data: Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
  • Verify and seek rectification: Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
  • Restrict the processing of their Data: Users have the right to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
  • Have their Personal Data deleted or otherwise removed: Users have the right to obtain the erasure of their Data from the Owner.
  • Receive their Data and have it transferred to another controller: Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
  • Lodge a complaint: Users have the right to bring a claim before their competent data protection authority.

How to Exercise These Rights

Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law.

Data Export

Users can export all their data at any time through the app:

  1. Go to Settings > Privacy > Export Data
  2. Choose export format (JSON)
  3. Save or share the exported file

The export includes all health records, child profiles, and associated metadata in a machine-readable format.

Account Deletion

Users can request account deletion through the app:

  1. Go to Settings > Account > Delete Account
  2. Confirm the deletion request
  3. Data will be permanently removed immediately

Account deletion is instant and cannot be undone. All data (except consent records) is deleted from servers immediately.

Device and Consent Lifecycle

MedKid implements a privacy-preserving consent management system:

  • Device Registration: Each device is registered with a unique identifier and signing key
  • Consent Signing: All consent is cryptographically signed using Ed25519 keys
  • Device Removal: When a device is removed, consent records are preserved for audit
  • Account Deletion: Triggers device removal and consent orphaning
  • Consent Retention: Orphaned consent records retained for 12 months for legal compliance

This approach balances the right to deletion with legal requirements for consent record retention.

Further Information for Users in Switzerland

This section applies to Users in Switzerland, and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy.

The Rights of Users According to the Swiss Federal Act on Data Protection

Users may exercise certain rights regarding their Data within the limits of law, including:

  • Right of access to Personal Data
  • Right to object to the processing of Personal Data
  • Right to receive Personal Data and have it transferred (data portability)
  • Right to ask for incorrect Personal Data to be corrected

How to Exercise These Rights

Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible, providing Users with the information required by law.

Further Information for Users in the United States

This part of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the business running this Application.

Notice at Collection

The following categories of Personal Information are collected:

Identifiers

  • Email address, user ID, device identifiers

Health Information

  • Children's health records (encrypted, with explicit consent)

Internet or Electronic Network Activity

  • Usage data, app interactions (limited collection)

Your Privacy Rights Under US State Laws

Depending on your state of residence, you may have additional rights including:

  • Right to know/access: Request information about data collection and processing
  • Right to delete: Request deletion of your Personal Information
  • Right to correct: Request correction of inaccurate information
  • Right to opt-out: Opt out of certain processing activities
  • Right to non-discrimination: Not be discriminated against for exercising privacy rights

California Residents

California residents have additional rights under the CCPA including:

  • Right to know what Personal Information is collected, used, shared or sold
  • Right to delete Personal Information
  • Right to opt-out of the sale of Personal Information (we do not sell Personal Information)
  • Right to non-discrimination for exercising privacy rights

How to Exercise Your Rights

Contact us at [email protected] to exercise your privacy rights. We will respond within the timeframe required by applicable law.

Additional Information About Data Collection and Processing

Legal Action

The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services.

The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.

System Logs and Maintenance

For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) or use other Personal Data (such as the IP Address) for this purpose.

Information Not Contained in This Policy

More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.

Changes to This Privacy Policy

The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.

Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.

Definitions and Legal References

Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information allows for the identification or identifiability of a natural person.

Health Data
Personal data related to the physical or mental health of a natural person, including health services, which reveal information about their health status. This is special category data under GDPR Article 9.

Usage Data
Information collected automatically through this Application, including IP addresses, device information, and app interaction data.

User
The individual using this Application.

Data Subject
The natural person to whom the Personal Data refers.

Data Processor
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.

Data Controller (or Owner)
Code Publishing sp. z o.o., which determines the purposes and means of the processing of Personal Data.

This Application
MedKid - the family health tracking application through which the Personal Data of the User is collected and processed.

Service
The service provided by this Application as described in the relative terms and on this Application.

European Union (or EU)
All references to the European Union include all current member states to the European Union and the European Economic Area.

Legal Information
This privacy statement has been prepared based on provisions of multiple legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).

This privacy policy relates solely to this Application.


Latest update: June 12, 2026

Podsumowanie w prostym języku

Co MedKid robi z Twoimi danymi - w prostych słowach:

MedKid to aplikacja do śledzenia zdrowia rodziny, która pomaga zarządzać dokumentacją medyczną Twoich dzieci. Oto co musisz wiedzieć o swojej prywatności:

Co zbieramy:

  • Dane konta: Adres e-mail do logowania
  • Dokumentacja medyczna: Objawy, leki, dane wzrostu Twoich dzieci (wszystko zaszyfrowane)
  • Dane techniczne: Podstawowe informacje o używaniu aplikacji dla płynnego działania
  • Raporty awarii: Tylko za Twoją zgodą, aby pomóc nam naprawić błędy

Co nowego w wersji 1.2:

  • Tworzenie szablonów z pomocą AI: Administratorzy rodziny mogą teraz korzystać z czatu AI, aby tworzyć niestandardowe szablony obserwacji. Gdy używasz tej funkcji, opis szablonu, który wpisujesz, jest wysyłany do Mistral AI (naszego podprocesora AI) w celu przetworzenia. Nie są wysyłane żadne dokumenty medyczne, imiona ani dane osobowe — tylko tekst opisu szablonu.

Jak chronimy Twoje dane:

  • Szyfrowanie end-to-end: Dane zdrowotne są szyfrowane zanim opuszczą Twoje urządzenie
  • Zero wiedzy: Nie możemy odczytać Twoich zaszyfrowanych danych medycznych
  • Najpierw lokalnie: Dane pozostają na Twoim urządzeniu, chyba że włączysz synchronizację
  • Serwery w UE: Wszystkie dane przechowywane w Niemczech i Polsce (zgodnie z RODO)

Ty masz kontrolę:

  • Dostęp do danych: Przeglądaj wszystko w dowolnym momencie w aplikacji
  • Eksport danych: Pobierz wszystkie swoje dane jako JSON
  • Usuń wszystko: Zażądaj usunięcia konta (natychmiastowe usunięcie)
  • Wyłącz śledzenie: Wyłącz raportowanie awarii w ustawieniach

Funkcje rodzinne:

  • Synchronizacja wielu urządzeń: Udostępniaj dane między urządzeniami rodziny (opcjonalnie)
  • Szyfrowanie rodzinne: Każda rodzina ma unikalne klucze szyfrowania
  • Zarządzanie urządzeniami: Dodawaj/usuwaj urządzenia z rodziny

Twoje prawa (RODO):

  • Prawo dostępu do danych
  • Prawo do poprawiania błędów
  • Prawo do usunięcia konta
  • Prawo do eksportu danych
  • Prawo sprzeciwu wobec przetwarzania

Pytania?

Skontaktuj się z nami: [email protected]


Pełna Polityka Prywatności

Niniejsza Aplikacja zbiera pewne Dane Osobowe od swoich Użytkowników.

Niniejszy dokument zawiera sekcje przeznaczone dla Użytkowników w Stanach Zjednoczonych, Szwajcarii i Unii Europejskiej dotyczące ich praw w zakresie prywatności.

Właściciel i Administrator Danych

Code Publishing sp. z o.o.
ul. Fabryczna 6
53-609 Wrocław
Polska

Adres e-mail Właściciela: [email protected]

Rodzaje zbieranych Danych

Wśród rodzajów Danych Osobowych, które niniejsza Aplikacja zbiera samodzielnie lub za pośrednictwem osób trzecich, znajdują się:

  • Dane konta (wymagane dla Family+): Adres e-mail, identyfikator użytkownika, identyfikatory urządzeń (w tym marketingowa nazwa urządzenia, np. „iPhone 15 Pro" lub „Samsung Galaxy S24", unikalne kody urządzeń do bezpiecznego szyfrowania i synchronizacji wielourządzeniowej)
  • Dane zdrowotne (wymagane, zaszyfrowane): Dokumentacja zdrowotna dzieci, w tym objawy, leki, pomiary, wykresy wzrostu, wizyty lekarskie
  • Dane użytkowania: Interakcje z aplikacją, korzystanie z funkcji, metadane synchronizacji
  • Dane techniczne: Informacje o urządzeniu, systemie operacyjnym, wersji aplikacji
  • Dane diagnostyczne (opcjonalne): Raporty awarii i wskaźniki wydajności (tylko za wyraźną zgodą)
  • Opisy szablonów AI (tylko podczas korzystania z funkcji tworzenia szablonów AI): Tekst opisu kategorii obserwacji wpisany przez administratora rodziny. Tekst ten jest wysyłany do Mistral AI w celu przetworzenia; nie zawiera żadnych dokumentów medycznych ani danych osobowych umożliwiających identyfikację.

Tryb i Miejsce Przetwarzania Danych

Metody przetwarzania

Właściciel stosuje odpowiednie środki bezpieczeństwa, aby zapobiegać nieautoryzowanemu dostępowi, ujawnieniu, modyfikacji lub nieuprawnionemu zniszczeniu Danych.

Dane zdrowotne są szyfrowane end-to-end przy użyciu kluczy szyfrowania opartych na rodzinie, zapewniając, że tylko upoważnieni członkowie rodziny mogą uzyskać do nich dostęp.

Ważne: Ze względu na szyfrowanie end-to-end, Właściciel i zewnętrzni dostawcy usług nie mogą uzyskać dostępu ani odczytać danych zdrowotnych Użytkownika.

Miejsce

Infrastruktura serwerów znajduje się w:

  • Serwery główne: Niemcy (Hetzner Online GmbH)
  • Serwery zapasowe: Polska (Scaleway S.A.S.)

Czas przechowywania

  • Dane konta: Przechowywane do momentu usunięcia konta
  • Dane zdrowotne: Przechowywane do momentu żądania usunięcia przez Użytkownika
  • Usunięte dane: Trwale usuwane natychmiast po żądaniu usunięcia
  • Zapisy zgody: Przechowywane przez 12 miesięcy po usunięciu konta (wymóg prawny)
  • Dane diagnostyczne: Przechowywane przez 90 dni
  • Opisy szablonów AI: Nie są przechowywane przez Mistral AI dłużej niż czas trwania pojedynczego wywołania API (bez szkolenia, bez przechowywania zgodnie z naszą umową o przetwarzaniu danych)

Cele przetwarzania

  • Rejestracja i uwierzytelnianie: Tworzenie i zarządzanie kontami Użytkowników
  • Zarządzanie danymi zdrowotnymi: Przechowywanie i synchronizacja dokumentacji zdrowotnej dzieci
  • Udostępnianie w rodzinie: Umożliwienie dostępu wielourządzeniowego w rodzinach
  • Poprawa usług: Opcjonalne raportowanie awarii i diagnostyka
  • Tworzenie szablonów z pomocą AI (opcjonalne, tylko dla administratorów): Generowanie niestandardowych szablonów obserwacji przy użyciu AI

Szczegółowe informacje o przetwarzaniu Danych Osobowych

Rejestracja i uwierzytelnianie

Wewnętrzny system uwierzytelniania
Niniejsza Aplikacja korzysta z naszego wewnętrznego systemu backendu do rejestracji i logowania Użytkowników.

EmailLabs - Vercom S.A.
Transakcyjne wiadomości e-mail do weryfikacji e-mail, jednorazowych haseł i odzyskiwania konta.

Dane osobowe przetwarzane: Adres e-mail

Miejsce przetwarzania: Polska - Polityka Prywatności

Hosting i infrastruktura backendu

Hetzner Online GmbH
Dane osobowe przetwarzane: Zaszyfrowane dane, dane użytkowania

Miejsce przetwarzania: Niemcy - Polityka Prywatności

Scaleway S.A.S.
Dane osobowe przetwarzane: Zaszyfrowane dane, dane użytkowania

Miejsce przetwarzania: Polska - Polityka Prywatności

Diagnostyka i raportowanie awarii

Sentry (Functional Software, Inc.)
Ta usługa jest aktywna TYLKO wtedy, gdy Użytkownik wyraźnie wyrazi na to zgodę w ustawieniach zgody.

Dane techniczne przetwarzane: Awarie aplikacji, logi błędów, informacje o urządzeniu (tylko za wyraźną zgodą, bez danych osobowych ani zdrowotnych)

Miejsce przetwarzania: Unia Europejska (Niemcy) - Polityka Prywatności

Tworzenie szablonów z pomocą AI

Jak Twoje dane są przetwarzane przez AI

MedKid oferuje opcjonalną funkcję wspomaganą przez AI (dostępną tylko dla administratorów rodziny), która pomaga tworzyć niestandardowe szablony obserwacji. Gdy administrator rodziny korzysta z tej funkcji:

  1. Administrator rodziny wpisuje krótki opis kategorii obserwacji, którą chce śledzić (np. „ciśnienie krwi" lub „codzienny nastrój").
  2. Ten opis tekstowy jest wysyłany zaszyfrowanym połączeniem HTTPS do naszego serwera backendowego.
  3. Nasz serwer zapytuje lokalne bazy danych terminologii medycznej (LOINC i SNOMED CT) — żadne dokumenty medyczne nie opuszczają naszego serwera podczas tego kroku.
  4. Opis tekstowy (nie żadne dokumenty medyczne) jest wysyłany do Mistral AI w celu generowania szablonu wspomaganego przez AI.
  5. AI zwraca sugerowaną strukturę szablonu. Administrator rodziny musi ją wyraźnie zaakceptować lub odrzucić przed zapisaniem.

Co NIE jest wysyłane do Mistral AI:

  • Żadne dokumenty medyczne ani wpisy w dzienniku
  • Żadne dane osobowe umożliwiające identyfikację (imiona, adresy e-mail, identyfikatory urządzeń)
  • Żadne dane o Twoich dzieciach

Ikony zdrowia:
Ikony szablonów pochodzą z projektu Health Icons (https://healthicons.org), który udostępnia wszystkie ikony na licencji Creative Commons Zero (CC0). Ikony są serwowane jako pliki statyczne z sieci dostarczania treści (CDN). Żadne dane użytkownika nie są wysyłane do CDN w celu załadowania ikon.

Mistral AI (Mistral AI SAS)
Mistral AI świadczy usługi dużych modeli językowych używane do tworzenia szablonów wspomaganego przez AI.

Dane przetwarzane: Krótki opis szablonu wpisany przez administratora rodziny (bez danych zdrowotnych, bez danych osobowych umożliwiających identyfikację)

Miejsce przetwarzania: Unia Europejska (Francja) - Polityka Prywatności

Mistral AI działa jako podmiot przetwarzający dane na podstawie Umowy o przetwarzaniu danych z Właścicielem. Opisy szablonów nie są używane do szkolenia modeli Mistral AI i nie są przechowywane po zakończeniu wywołania API.

Dalsze informacje dla Użytkowników

Podstawa prawna przetwarzania

  • Zgoda: Użytkownicy wyrazili zgodę na jeden lub więcej określonych celów
  • Umowa: Podanie Danych jest niezbędne do wykonania umowy z Użytkownikiem
  • Obowiązki prawne: Przetwarzanie jest niezbędne do spełnienia obowiązku prawnego
  • Uzasadnione interesy: Przetwarzanie jest niezbędne dla uzasadnionych interesów Właściciela lub osób trzecich

Prawa Użytkowników na podstawie RODO

  • Wycofanie zgody w dowolnym momencie
  • Sprzeciw wobec przetwarzania Danych
  • Dostęp do swoich Danych
  • Weryfikacja i żądanie sprostowania
  • Ograniczenie przetwarzania swoich Danych
  • Usunięcie swoich Danych Osobowych
  • Przenoszenie Danych
  • Złożenie skargi

Eksport danych

Użytkownicy mogą w dowolnym momencie wyeksportować wszystkie swoje dane przez aplikację:

  1. Przejdź do Ustawienia > Prywatność > Eksportuj dane
  2. Wybierz format eksportu (JSON)
  3. Zapisz lub udostępnij wyeksportowany plik

Usunięcie konta

Użytkownicy mogą zażądać usunięcia konta przez aplikację:

  1. Przejdź do Ustawienia > Konto > Usuń konto
  2. Potwierdź żądanie usunięcia
  3. Dane zostaną trwale usunięte natychmiast

Cykl życia urządzenia i zgody

MedKid wdraża system zarządzania zgodami chroniący prywatność:

  • Rejestracja urządzenia: Każde urządzenie jest rejestrowane z unikalnym identyfikatorem i kluczem podpisującym
  • Podpisywanie zgody: Wszystkie zgody są kryptograficznie podpisywane przy użyciu kluczy Ed25519
  • Usunięcie urządzenia: Po usunięciu urządzenia zapisy zgody są zachowane do celów audytu
  • Usunięcie konta: Wyzwala usunięcie urządzenia i osierocenie zgody
  • Przechowywanie zgody: Osierocone zapisy zgody są przechowywane przez 12 miesięcy ze względów prawnych

Dodatkowe informacje o zbieraniu i przetwarzaniu Danych

Zmiany w niniejszej Polityce Prywatności

Właściciel zastrzega sobie prawo do wprowadzania zmian w niniejszej polityce prywatności w dowolnym momencie, powiadamiając o tym Użytkowników na tej stronie.

Jeśli zmiany dotyczą czynności przetwarzania wykonywanych na podstawie zgody Użytkownika, Właściciel zbierze nową zgodę od Użytkownika, jeśli jest to wymagane.

Definicje i Odniesienia Prawne

Dane Osobowe (lub Dane)
Wszelkie informacje, które bezpośrednio, pośrednio lub w połączeniu z innymi informacjami umożliwiają identyfikację osoby fizycznej.

Dane Zdrowotne
Dane osobowe związane ze zdrowiem fizycznym lub psychicznym osoby fizycznej. Są to dane szczególnej kategorii na mocy art. 9 RODO.

Administrator Danych (lub Właściciel)
Code Publishing sp. z o.o., które określa cele i środki przetwarzania Danych Osobowych.

Niniejsza Aplikacja
MedKid - aplikacja do śledzenia zdrowia rodziny, za pośrednictwem której zbierane i przetwarzane są Dane Osobowe Użytkownika.


Ostatnia aktualizacja: 12 czerwca 2026