MedSafeScan Privacy Policy
Last updated: June 2026
1. Introduction
MedSafeScan (“MedSafeScan”, “we”, “us”, or “our”) is an AI-powered medication interaction checker available on Android. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the MedSafeScan mobile application and visit our website at medsafescan.com.
By using MedSafeScan, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the app or website.
For privacy-related inquiries, contact us at: contact@zeitio.com
2. Information We Collect
Account Information: When you create an account, we collect your email address and display name through Firebase Authentication (Google). If you sign in with Google Sign-In, we receive your Google account's email and profile name.
Medication Data: We store the medication profiles you create in the app, including medication names, dosages, frequencies, types (prescription/OTC/supplement), and any notes you add. This data is stored in Firebase Firestore (Google Cloud).
Scan Images: When you use the label scanning feature (Premium), an image of the medication label is sent to OpenAI's API for processing. Scan images are used only for text extraction and are not permanently stored by MedSafeScan unless you choose to save them.
Usage Data: We collect interaction check history (which medications were checked and the results), monthly check counts (to enforce free-tier limits), and in-app feature usage patterns for service improvement.
Subscription Status: We receive subscription status information from RevenueCat and Google Play. We do not store your payment card details — all billing is managed by Google Play.
Device and Technical Data: We may collect app version, operating system version, and crash logs to diagnose and fix bugs.
AI Processing: When you run an interaction check or scan a label, medication names are sent to OpenAI's API for analysis. Per OpenAI's API terms of service, data submitted via the API is not used to train OpenAI's AI models.
3. How We Use Your Information
We use the information we collect to:
- Provide and operate the MedSafeScan service
- Perform AI-powered medication interaction analysis
- Store and retrieve your medication profile and history
- Enforce free-tier interaction check limits
- Manage and verify your subscription status
- Respond to support requests and communications
- Improve app accuracy and user experience
- Monitor for fraud or abuse of the service
- Comply with applicable legal obligations
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA) or UK, we process your personal data on the following legal bases:
- Contract: Processing necessary to provide the MedSafeScan service you have requested
- Consent: Where you have explicitly consented (e.g., enabling crash reporting)
- Legitimate Interest: Improving service quality, preventing abuse, and ensuring security
- Legal Obligation: Where required by applicable law
5. Data Sharing
We share your data only with the following service providers, under appropriate data processing agreements:
- Firebase (Google LLC): Authentication, database (Firestore), and optional file storage. Subject to Google's privacy policy.
- OpenAI: Medication names and label images are sent to OpenAI's API for AI processing. OpenAI does not train on API data per their terms of service.
- RevenueCat: Manages subscription status and in-app purchases across platforms.
- Google Play: Processes payments and subscription billing for Android users.
We do not sell, rent, or trade your personal information to third parties for advertising or marketing purposes.
6. Data Retention
We retain your account data, medication profile, and interaction history for as long as your account is active. If you delete your account, your data will be permanently deleted within 30 days, except:
- Anonymized, aggregated analytics that cannot be linked back to you
- Billing records retained by Google Play and RevenueCat per their policies
- Information we are required to retain by law
To delete your account, see our Account Deletion page.
7. Security
We take the security of your health-related data seriously and implement the following safeguards:
- All data is encrypted in transit using HTTPS/TLS
- Firebase Firestore data is encrypted at rest by Google Cloud
- Firebase Security Rules restrict access to your own data only
- API keys and credentials are stored securely and never exposed in client code
- Subscription and payment processing is handled entirely by Google Play (we never receive raw card data)
No system is 100% secure. If you believe there has been a security incident, please contact us immediately at contact@zeitio.com.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Export: Premium users can export interaction history as PDF within the app
- Opt-out: You may opt out of non-essential data collection by contacting us
- Portability: Request your data in a machine-readable format where applicable
To exercise any of these rights, contact us at contact@zeitio.com. We will respond within 30 days.
9. Children's Privacy
MedSafeScan is not intended for users under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children under these ages. If you believe a child has provided us with personal information, please contact us at contact@zeitio.com and we will delete it promptly.
10. International Data Transfers
MedSafeScan is operated from the United States. Your data may be processed and stored in the United States and other countries where our service providers operate (including Google's and OpenAI's data centers). By using MedSafeScan, you consent to the transfer of your data to countries that may have different data protection laws than your home country.
For EEA/UK users, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses where required.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for significant changes, notify you through the app or by email. We encourage you to review this page periodically.
12. Contact Us
For privacy-related questions, data requests, or concerns, contact us at:
Last updated: June 2026