Last Updated: February 8, 2026
Legal Documents:
MedReminder is built on a "Best-Effort Medical Grade" standard. We implement strict PII Segregation, storing your identity data (name, phone) in a separate collection from your medical/wellness records.
Identity and wellness data are linked only by a random internal reference code, ensuring that a compromise of one data layer does not inherently expose your identity.
To comply with global data protection laws (GDPR, HIPAA, PIPEDA), we utilize Geographic Sharding:
| Region | Data Center |
|---|---|
| EU/UK Residents | European Region (Google Cloud) |
| US/Global Residents | Americas Region (Google Cloud) |
We do not store your plaintext phone number or name in our scheduling engine. PII is decrypted using Military-grade encryption only at the millisecond of call initiation by the Automated Scheduler. Personal data is then immediately wiped from memory.
Market trends are processed via HMAC-SHA256 hashing with a rotating salt. Individual unique identifier records are never present in our materialized views for reporting.
Every access to patient data is recorded in an immutable audit log, including the actor's identity and timestamp.
You may trigger an account deletion request via your profile dashboard. This executes an immediate, irreversible cascading purge that removes all active caregiver credentials, patient profiles, prescriptions, dosage schedules, and recurring automated reminder calls from operational databases.
Statutory 180-Day Forensic Telecommunications Metadata: In strict compliance with applicable cybersecurity and telecommunications legislation (including Egyptian Cybercrime Law No. 175 of 2018, Article 2, and European GDPR Article 17(3)(e) for the establishment, exercise, or defense of legal claims), minimal pseudonymized communication traffic metadata (Call Detail Records containing encrypted destination numbers, call timestamps, connection duration, and cryptographic SHA-256 initiator hashes) is securely retained in cold storage for exactly 180 days solely for the prevention of abuse and compliance with lawful judicial inquiries, after which it is automatically purged via automated TTL mechanisms.
For privacy-related questions or data requests, contact us at: