Privacy Policy
MedKid
Version 1.1 - Effective: December 22, 2025
Plain Language Summary
What MedKid does with your data - in simple terms:
MedKid is a family health tracking app that helps you manage your children's health records. Here's what you need to know about your privacy:
What we collect:
- Your account info: Email address for login
- Health records: Your children's symptoms, medications, growth data (all encrypted)
- Technical data: Basic app usage info to keep things running smoothly
- Crash reports: Only if you opt-in, to help us fix bugs
How we protect your data:
- End-to-end encryption: Your health data is encrypted before leaving your device
- Zero-knowledge: We can't read your encrypted health records
- Local storage first: Data stays on your device unless you enable sync
- EU servers: All data stored in Germany and Poland (GDPR compliant)
You're in control:
- Access your data: View everything anytime in the app
- Export your data: Download all your data as JSON
- Delete everything: Request account deletion (instant deletion)
- Turn off tracking: Disable crash reporting in settings
Family features:
- Multi-device sync: Share data across family devices (optional)
- Family encryption: Each family has unique encryption keys
- Device management: Add/remove devices from your family
Your rights (GDPR):
- Right to access your data
- Right to correct mistakes
- Right to delete your account
- Right to export your data
- Right to object to processing
Questions?
Contact us at: [email protected]
Full Privacy Policy
This Application collects some Personal Data from its Users.
This document contains sections dedicated to Users in the United States, Switzerland, and the European Union regarding their privacy rights.
Owner and Data Controller
Code Publishing sp. z o.o.
ul. Fabryczna 6
53-609 Wrocław, Poland
Owner contact email:
[email protected]
Types of Data Collected
Among the types of Personal Data that this Application collects, by itself or through third parties, there are:
- Account Data (required for Family+): Email address, user identifier, device identifiers (including device marketing name such as "iPhone 15 Pro" or "Samsung Galaxy S24", unique device codes for secure encryption and multi-device synchronization, and sync identifiers used by the sync engine for conflict resolution when multiple devices edit the same data)
- Health Data (required, encrypted): Children's health records including symptoms, medications, measurements, growth charts, medical appointments
- Usage Data: App interactions, feature usage, synchronization metadata
- Technical Data: Device information, operating system, app version
- Diagnostic Data (optional): Crash reports and performance metrics (only with explicit consent)
Health Data constitutes special category data under GDPR Article 9. By using this Application for health tracking, Users explicitly consent to the processing of such data for the purposes described in this policy.
Mode and Place of Processing the Data
Methods of Processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. Health Data is encrypted end-to-end using family-based encryption keys, ensuring that only authorized family members can access it.
Important: Due to end-to-end encryption, the Owner and third-party service providers cannot access or read User's health data.
Place
Server infrastructure is located in:
- Primary servers: Germany (Hetzner Online GmbH)
- Secondary servers: Poland (Scaleway S.A.S.)
- Data centers: Germany (Hetzner Online GmbH), Poland (Scaleway S.A.S.)
Retention Time
- Account Data: Retained for the duration of the account
- Health Data: Retained until User requests deletion
- Deleted Data: Permanently removed immediately upon deletion request
- Consent Records: Retained for 12 months after account deletion (legal requirement)
- Diagnostic Data: Retained for 90 days
The Purposes of Processing
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:
- Registration and authentication: Creating and managing User accounts
- Health data management: Storing and synchronizing children's health records
- Family sharing: Enabling multi-device access within families
- Service improvement: Optional crash reporting and diagnostics
- Backup and recovery: Encrypted backup of User data
- Legal compliance: Meeting GDPR and other regulatory requirements
Detailed Information on the Processing of Personal Data
Registration and Authentication
Internal Authentication
This Application uses our internal backend system for User
registration and login.
Personal Data processed: Email address, user identifier,
authentication tokens
Place of processing: European Union
EmailLabs - Vercom S.A.
Transactional emails for email verification, one-time
passwords, and account recovery.
Personal Data processed: Email address
Place of processing: Poland -
Privacy Policy
Hosting and Backend Infrastructure
Hetzner Online GmbH
Hetzner provides cloud hosting and storage services for this
Application.
Personal Data processed: Encrypted data, usage data
Place of processing: Germany -
Privacy Policy
Scaleway S.A.S.
Scaleway provides cloud infrastructure services for this
Application.
Personal Data processed: Encrypted data, usage data
Place of processing: Poland -
Privacy Policy
Platform Services
Google Play Store (Google Ireland Limited)
This Application is distributed on the Google Play Store.
Google collects usage and diagnostics data and shares
aggregate information with the Owner. Users may opt-out
directly through their device settings.
Personal Data processed: Usage Data (opt-in basis)
Place of processing: Ireland -
Privacy Policy
App Store (Apple Inc.)
This Application is distributed on Apple's App Store. App
Store Connect provides analytics data only for Users who
have agreed to share them.
Personal Data processed: Diagnostics, product interaction,
usage data (opt-in basis)
Place of processing: United States -
Privacy Policy
Diagnostics and Crash Reporting
Sentry (Functional Software, Inc.)
Sentry is an error tracking and performance monitoring
system. This service is ONLY active if the User explicitly
opts in through the consent settings.
Technical Data processed: App crashes, error logs, device
information (only with explicit consent, no personal or
health information)
Place of processing: European Union (Germany) -
Privacy Policy
Users can disable crash reporting at any time in Settings > Privacy > Crash Reporting.
Offline Processing
Google ML Kit
ML Kit is a set of on-device machine learning tools. All
processing happens locally on the User's device. No data is
sent to Google servers.
Personal Data processed: None (all processing is local)
Terms of Service
The Rights of Users Based on the GDPR
Users may exercise certain rights regarding their Data processed by the Owner. In particular, Users have the right to:
- Withdraw their consent at any time
- Object to processing of their Data
- Access their Data: Obtain disclosure and a copy of the Data
- Verify and seek rectification: Verify accuracy and request updates
- Restrict the processing of their Data
- Have their Personal Data deleted
- Receive their Data and have it transferred to another controller
- Lodge a complaint with a data protection authority
How to Exercise These Rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered within one month.
Data Export
Users can export all their data at any time through the app:
- Go to Settings > Privacy > Export Data
- Choose export format (JSON)
- Save or share the exported file
Account Deletion
Users can request account deletion through the app:
- Go to Settings > Account > Delete Account
- Confirm the deletion request
- Data will be permanently removed immediately
Account deletion is instant and cannot be undone.
Further Information for Users in Switzerland
Users in Switzerland have the following rights:
- Right of access to Personal Data
- Right to object to the processing of Personal Data
- Right to receive Personal Data and have it transferred (data portability)
- Right to ask for incorrect Personal Data to be corrected
Further Information for Users in the United States
Depending on your state of residence, you may have additional rights including:
- Right to know/access: Request information about data collection
- Right to delete: Request deletion of your Personal Information
- Right to correct: Request correction of inaccurate information
- Right to opt-out: Opt out of certain processing activities
- Right to non-discrimination: Not be discriminated against for exercising privacy rights
Contact us at [email protected] to exercise your privacy rights.
Terms of Service
To learn more about the terms and conditions governing the use of this Application, please refer to our Terms of Service.
Changes to This Privacy Policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application. Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.
Contact
Code Publishing sp. z o.o.
Email:
[email protected]
Address: ul. Fabryczna 6, 53-609 Wrocław, Poland