Privacy Policy
MedKid
Version 1.2 - Effective: June 12, 2026
Plain Language Summary
What MedKid does with your data - in simple terms:
MedKid is a family health tracking app that helps you manage your children's health records. Here's what you need to know about your privacy:
What we collect:
- Your account info: Email address for login
- Health records: Your children's symptoms, medications, growth data (all encrypted)
- Technical data: Basic app usage info to keep things running smoothly
- Crash reports: Only if you opt-in, to help us fix bugs
What's new in Version 1.2:
- AI-assisted template creation: Family admins can now use an AI chat feature to create custom observation templates. When you use this feature, the template description you type is sent to Mistral AI (our AI sub-processor) for processing. No health records, no names, and no personal data are sent — only the text of your template description.
How we protect your data:
- End-to-end encryption: Your health data is encrypted before leaving your device
- Zero-knowledge: We can't read your encrypted health records
- Local storage first: Data stays on your device unless you enable sync
- EU servers: All data stored in Germany and Poland (GDPR compliant)
You're in control:
- Access your data: View everything anytime in the app
- Export your data: Download all your data as JSON
- Delete everything: Request account deletion (instant deletion)
- Turn off tracking: Disable crash reporting in settings
Family features:
- Multi-device sync: Share data across family devices (optional)
- Family encryption: Each family has unique encryption keys
- Device management: Add/remove devices from your family
Your rights (GDPR):
- Right to access your data
- Right to correct mistakes
- Right to delete your account
- Right to export your data
- Right to object to processing
Questions?
Contact us at: [email protected]
Full Privacy Policy
This Application collects some Personal Data from its Users.
This document contains sections dedicated to Users in the United States, Switzerland, and the European Union regarding their privacy rights.
This document can be printed for reference by using the print command in the settings of any browser.
Owner and Data Controller
Code Publishing sp. z o.o.
ul. Fabryczna 6
53-609 Wroclaw
Poland
Owner contact email: [email protected]
Types of Data Collected
Among the types of Personal Data that this Application collects, by itself or through third parties, there are:
- Account Data (required for Family+): Email address, user identifier, device identifiers (including device marketing name such as "iPhone 15 Pro" or "Samsung Galaxy S24", unique device codes for secure encryption and multi-device synchronization, and sync identifiers used by the sync engine for conflict resolution when multiple devices edit the same data)
- Health Data (required, encrypted): Children's health records including symptoms, medications, measurements, growth charts, medical appointments
- Usage Data: App interactions, feature usage, synchronization metadata
- Technical Data: Device information, operating system, app version
- Diagnostic Data (optional): Crash reports and performance metrics (only with explicit consent)
- AI Template Descriptions (only when using the AI template creation feature): Plain-text description of an observation category typed by a family admin. This text is sent to Mistral AI for processing; no health records or personal identifying information are included.
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application.
Unless specified otherwise, all Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Health Data constitutes special category data under GDPR Article 9. By using this Application for health tracking, Users explicitly consent to the processing of such data for the purposes described in this policy.
Users are responsible for any third-party Personal Data obtained, published or shared through this Application.
Mode and Place of Processing the Data
Methods of Processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. Health Data is encrypted end-to-end using family-based encryption keys, ensuring that only authorized family members can access it.
In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Important: Due to end-to-end encryption, the Owner and third-party service providers cannot access or read User's health data.
Place
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.
Server infrastructure is located in:
- Primary servers: Germany (Hetzner Online GmbH)
- Secondary servers: Poland (Scaleway S.A.S.)
- Data centers: Germany (Hetzner Online GmbH), Poland (Scaleway S.A.S.)
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Retention Time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.
Therefore:
- Account Data: Retained for the duration of the account
- Health Data: Retained until User requests deletion
- Deleted Data: Permanently removed immediately upon deletion request
- Consent Records: Retained for 12 months after account deletion (legal requirement)
- Diagnostic Data: Retained for 90 days
- AI Template Descriptions: Not retained by Mistral AI beyond the scope of the single API call (no training, no storage per our data processing agreement)
The Purposes of Processing
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:
- Registration and authentication: Creating and managing User accounts
- Health data management: Storing and synchronizing children's health records
- Family sharing: Enabling multi-device access within families
- Service improvement: Optional crash reporting and diagnostics
- Backup and recovery: Encrypted backup of User data
- Legal compliance: Meeting GDPR and other regulatory requirements
- AI-assisted template creation (optional, admin-only): Generating custom observation templates using AI assistance
For specific information about the Personal Data used for each purpose, the User may refer to the section "Detailed information on the processing of Personal Data".
Detailed Information on the Processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Registration and Authentication
Internal Authentication
This Application uses our internal backend system for User registration and login.
Personal Data processed: Email address, user identifier, authentication tokens
Place of processing: European Union
EmailLabs - Vercom S.A.
Transactional emails for email verification, one-time passwords, and account recovery.
Personal Data processed: Email address
Place of processing: Poland - Privacy Policy
Hosting and Backend Infrastructure
This type of service has the purpose of hosting Data and files that enable this Application to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of this Application.
Hetzner Online GmbH
Hetzner provides cloud hosting and storage services for this Application.
Personal Data processed: Encrypted data, usage data
Place of processing: Germany - Privacy Policy
Scaleway S.A.S.
Scaleway provides cloud infrastructure services for this Application.
Personal Data processed: Encrypted data, usage data
Place of processing: Poland - Privacy Policy
Platform Services
Google Play Store (Google Ireland Limited)
This Application is distributed on the Google Play Store, a platform for the distribution of mobile apps.
By virtue of being distributed via this app store, Google collects usage and diagnostics data and shares aggregate information with the Owner. Much of this information is processed on an opt-in basis.
Users may opt-out of this analytics feature directly through their device settings.
Personal Data processed: Usage Data (opt-in basis)
Place of processing: Ireland - Privacy Policy
App Store (Apple Inc.)
This Application is distributed on Apple's App Store, a platform for the distribution of mobile apps.
App Store Connect provides analytics data on user engagement and app discovery only for Users who have agreed to share them with the Owner.
Personal Data processed: Diagnostics, product interaction, usage data (opt-in basis)
Place of processing: United States - Privacy Policy
Diagnostics and Crash Reporting
Sentry (Functional Software, Inc.)
Sentry is an error tracking and performance monitoring system that helps developers identify and fix application errors in real time.
This service is ONLY active if the User explicitly opts in through the consent settings.
Technical Data processed: App crashes, error logs, device information (only with explicit consent, no personal or health information)
Place of processing: European Union (Germany) - Privacy Policy
Users can disable crash reporting at any time in Settings > Privacy > Crash Reporting.
AI-Assisted Template Creation
How your data is processed by AI
MedKid offers an optional AI-assisted feature (available to family admins only) that helps create custom observation templates. When a family admin uses this feature, the following occurs:
- The family admin types a plain-text description of the observation category they want to track (for example, "blood pressure" or "daily mood").
- This text description is sent over an encrypted HTTPS connection to our backend server.
- Our server queries standard medical terminology databases (LOINC and SNOMED CT) locally — no health records leave our server during this step.
- The text description (not any health records) is sent to Mistral AI for AI-assisted template generation.
- The AI returns a suggested template structure. The family admin reviews and must explicitly accept or reject it before it is saved.
What is NOT sent to Mistral AI:
- Any health records or journal entries
- Any personal identifying information (names, email addresses, device identifiers)
- Any data about your children
Health Icons:
Template icons are sourced from the Health Icons project (https://healthicons.org), which releases all icons under a Creative Commons Zero (CC0) license. Icons are served as static files from a content delivery network (CDN). No user data is sent to any CDN to load icons.
Mistral AI (Mistral AI SAS)
Mistral AI provides large language model services used for AI-assisted template creation.
Data processed: Plain-text template description typed by the family admin (no health data, no personal identifying information)
Place of processing: European Union (France) - Privacy Policy
Mistral AI acts as a data processor under a Data Processing Agreement with the Owner. Template descriptions are not used for training Mistral AI models and are not retained beyond the duration of the API call.
Offline Processing
Google ML Kit
ML Kit is a set of on-device machine learning tools provided by Google that enable the use of machine learning on Android and iOS platforms.
All processing happens locally on the User's device. No data is sent to Google servers.
Personal Data processed: None (all processing is local)
Further Information for Users
Legal Basis of Processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Consent: Users have given their consent for one or more specific purposes (primary basis for health data processing under GDPR Article 9)
- Contract: Provision of Data is necessary for the performance of an agreement with the User
- Legal obligations: Processing is necessary for compliance with a legal obligation
- Vital interests: Processing is necessary to protect vital interests
- Legitimate interests: Processing is necessary for legitimate interests pursued by the Owner or third parties
The Rights of Users Based on the General Data Protection Regulation (GDPR)
Users may exercise certain rights regarding their Data processed by the Owner.
In particular, Users have the right to:
- Withdraw their consent at any time: Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
- Object to processing of their Data: Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
- Access their Data: Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
- Verify and seek rectification: Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
- Restrict the processing of their Data: Users have the right to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
- Have their Personal Data deleted or otherwise removed: Users have the right to obtain the erasure of their Data from the Owner.
- Receive their Data and have it transferred to another controller: Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
- Lodge a complaint: Users have the right to bring a claim before their competent data protection authority.
How to Exercise These Rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law.
Data Export
Users can export all their data at any time through the app:
- Go to Settings > Privacy > Export Data
- Choose export format (JSON)
- Save or share the exported file
The export includes all health records, child profiles, and associated metadata in a machine-readable format.
Account Deletion
Users can request account deletion through the app:
- Go to Settings > Account > Delete Account
- Confirm the deletion request
- Data will be permanently removed immediately
Account deletion is instant and cannot be undone. All data (except consent records) is deleted from servers immediately.
Device and Consent Lifecycle
MedKid implements a privacy-preserving consent management system:
- Device Registration: Each device is registered with a unique identifier and signing key
- Consent Signing: All consent is cryptographically signed using Ed25519 keys
- Device Removal: When a device is removed, consent records are preserved for audit
- Account Deletion: Triggers device removal and consent orphaning
- Consent Retention: Orphaned consent records retained for 12 months for legal compliance
This approach balances the right to deletion with legal requirements for consent record retention.
Further Information for Users in Switzerland
This section applies to Users in Switzerland, and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy.
The Rights of Users According to the Swiss Federal Act on Data Protection
Users may exercise certain rights regarding their Data within the limits of law, including:
- Right of access to Personal Data
- Right to object to the processing of Personal Data
- Right to receive Personal Data and have it transferred (data portability)
- Right to ask for incorrect Personal Data to be corrected
How to Exercise These Rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible, providing Users with the information required by law.
Further Information for Users in the United States
This part of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the business running this Application.
Notice at Collection
The following categories of Personal Information are collected:
Identifiers
- Email address, user ID, device identifiers
Health Information
- Children's health records (encrypted, with explicit consent)
Internet or Electronic Network Activity
- Usage data, app interactions (limited collection)
Your Privacy Rights Under US State Laws
Depending on your state of residence, you may have additional rights including:
- Right to know/access: Request information about data collection and processing
- Right to delete: Request deletion of your Personal Information
- Right to correct: Request correction of inaccurate information
- Right to opt-out: Opt out of certain processing activities
- Right to non-discrimination: Not be discriminated against for exercising privacy rights
California Residents
California residents have additional rights under the CCPA including:
- Right to know what Personal Information is collected, used, shared or sold
- Right to delete Personal Information
- Right to opt-out of the sale of Personal Information (we do not sell Personal Information)
- Right to non-discrimination for exercising privacy rights
How to Exercise Your Rights
Contact us at [email protected] to exercise your privacy rights. We will respond within the timeframe required by applicable law.
Additional Information About Data Collection and Processing
Legal Action
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services.
The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
System Logs and Maintenance
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) or use other Personal Data (such as the IP Address) for this purpose.
Information Not Contained in This Policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
Changes to This Privacy Policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.
Definitions and Legal References
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information allows for the identification or identifiability of a natural person.
Health Data
Personal data related to the physical or mental health of a natural person, including health services, which reveal information about their health status. This is special category data under GDPR Article 9.
Usage Data
Information collected automatically through this Application, including IP addresses, device information, and app interaction data.
User
The individual using this Application.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
Data Controller (or Owner)
Code Publishing sp. z o.o., which determines the purposes and means of the processing of Personal Data.
This Application
MedKid - the family health tracking application through which the Personal Data of the User is collected and processed.
Service
The service provided by this Application as described in the relative terms and on this Application.
European Union (or EU)
All references to the European Union include all current member states to the European Union and the European Economic Area.
Legal Information
This privacy statement has been prepared based on provisions of multiple legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).
This privacy policy relates solely to this Application.