Privacy Policy
Last updated: July 2, 2026
Mivimed (“the App”) is operated by Mitech Digital (“we”, “us”). This policy explains what data we collect, why, and what rights you have. Contact: support@mivimed.com.
1. What data we collect
Account data — email address, optional name and avatar, authentication identifiers (including Google Sign-In identifiers if you sign in with Google).
Health-related content you choose to upload — photos or PDFs of medical documents (prescriptions, lab results, reports), and the information the App extracts from them: document text, summaries, lab values, medication names and schedules, diagnoses, doctor and facility names, and appointment details. This is sensitive (“special category”) data under GDPR Article 9. We process it only with your explicit consent, given when you create your account, and only to provide the App’s features to you.
Calendar data — appointments, medication reminders, and related notes you create in the App.
Usage analytics — pseudonymous usage events (screens viewed, features used, errors) tied to a random user identifier. We do not send your name, email, document contents, or any health information to analytics. We do not show ads and do not sell or share your data for advertising.
Security logs — counts of AI feature usage per account (to enforce fair usage limits) and standard server logs.
2. How your data is processed
- Storage: your documents are stored in a private cloud storage bucket; your structured data is stored in a database hosted in the EU (Supabase, region eu-central). Files are accessible only through short-lived signed URLs generated after verifying your identity. All data is protected by row-level security so each account can only access its own records.
- AI analysis: when you request analysis of a document, the document image is transmitted to an AI model provider (via OpenRouter) to extract the information listed above. The result is stored in your account. We send only the document being analyzed — no account identifiers beyond a pseudonymous ID. AI output may contain errors and is not medical advice.
- Location suggestions: if you use the address-suggestion feature, the address text you typed is sent to an AI model and to the OpenStreetMap Nominatim geocoding service to resolve coordinates.
3. Service providers (data processors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, serverless functions | EU (eu-central) |
| Amazon Web Services (S3) | Encrypted file storage for your documents | [fill in your S3 region] |
| OpenRouter (and its underlying AI model providers) | AI document analysis, address normalization | USA |
| PostHog | Pseudonymous product analytics | USA |
| Optional Google Sign-In | USA |
Where providers are outside the EEA, transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses as applicable.
4. Legal bases (GDPR)
- Contract (Art. 6(1)(b)) — account, storage, and calendar features.
- Explicit consent (Art. 9(2)(a)) — processing of the health-related content you upload, including AI analysis. You can withdraw consent at any time by deleting your data or your account in the App.
- Legitimate interest (Art. 6(1)(f)) — security, abuse prevention, and fair-usage limits on AI features.
5. Retention
Your data is kept until you delete it. Deleting a document removes the file and its analysis. “Delete My Data” and “Delete Account” in the Profile screen permanently remove all your content (account deletion also removes your login). AI usage logs are retained for up to 30 days. Backups expire on the provider’s standard schedule.
6. Your rights
You can, at any time, in the App:
- Access & export your data (Profile → Export My Data — JSON export)
- Correct your data (edit documents, profile, events)
- Delete your data or your entire account (Profile → Danger Zone)
You also have the right to withdraw consent, object to processing, and lodge a complaint with your data protection authority (in Romania: ANSPDCP). For anything else, email support@mivimed.com — we respond within 30 days.
7. Security
Data is encrypted in transit (TLS). Files live in a private bucket accessed only through expiring signed URLs. Database access is enforced per-account with row-level security. AI features are rate-limited and monitored for abuse.
8. Children
Mivimed is not directed at children under 16, and we do not knowingly process their data. If you believe a child is using the App, contact us.
9. Changes
We will post any changes to this policy here and update the date above. Material changes will be announced in the App.
Questions? Email support@mivimed.com