Privacy Policy
Last updated: 18 May 2026
This Privacy Policy is currently available only in English. Localised versions will be published after legal review in each language.
MedicalYou Privacy Policy
| Field | Detail |
|---|---|
| Document Title | MedicalYou Privacy Policy |
| Effective Date | Monday, 18 May 2026 |
| Version | 1.0 |
| Intended Audience | Consumers / Users |
| Purpose | Public privacy policy for web, iOS, Android, App Store, and Google Play |
Table of Contents
- Who We Are
- Scope and Products Covered
- Data We Collect
- How We Use Your Data
- Legal Bases and Consent Model
- AI Processing Disclosures
- Wearables and Third-Party Integrations
- Subprocessors
- International Transfers
- Data Taxonomy
- Anonymised and De-Identified Data — Commercialisation
- Retention, Security, and Data Breach Notification
- Your Rights
- Children’s Data
- Region-Specific Notices
- Changes to This Policy
- How to Contact Us
- Sources
1. Who We Are
Medical You Pte. Ltd (“MedicalYou”, “we”, “us”, or “our”) is a company incorporated in Singapore.
| Detail | Information |
|---|---|
| Legal name | Medical You Pte. Ltd |
| Registered address | 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914 |
| Data Protection Officer | Samuel Banks |
| Privacy enquiries | privacy@medicalyouglobal.com |
| General support | hello@medicalyouglobal.com |
Medical You Pte. Ltd is the data controller (under GDPR terminology) and the organisation responsible for your personal data (under Singapore PDPA terminology) in respect of all personal data processed through the MedicalYou platform.
Our Data Protection Officer, Samuel Banks, is responsible for overseeing our data protection compliance and may be contacted directly at privacy@medicalyouglobal.com with the subject line “Attention: DPO”.
2. Scope and Products Covered
This Privacy Policy applies to personal data processed through all MedicalYou products and services, including:
- MedicalYou Web Application — hosted at medicalyouglobal.com and served via Vercel.
- MedicalYou iOS Application — available on the Apple App Store, bundle identifier com.medicalyouglobal.app.
- MedicalYou Android Application — available on the Google Play Store, package identifier com.medicalyouglobal.app.
This policy applies whether you access MedicalYou as a registered user, a trial user, or a visitor to our web presence. It does not apply to third-party websites, applications, or services that may be linked from within MedicalYou; you should review the privacy notices of those services independently.
MedicalYou is a personal health record application. It is designed to allow users to store, organise, and review their own health records and to receive AI-generated summaries and insights. MedicalYou is not a medical device, does not provide medical diagnosis or treatment, and is not intended for use in medical emergencies. Nothing in MedicalYou constitutes clinical advice.
3. Data We Collect
We collect several categories of data, described below. Categories marked [SPECIAL-CATEGORY / SENSITIVE HEALTH DATA] receive the highest level of protection we apply and require your explicit, separate consent in applicable jurisdictions (see Section 5).
3.1 Profile Data
Information you provide when you create and maintain your account, including your name, date of birth, sex, nationality, and profile photograph.
3.2 Health and Medical Records — [SPECIAL-CATEGORY / SENSITIVE HEALTH DATA]
The following categories constitute health data (special-category personal data under GDPR Art 9, sensitive personal information under the CPRA, “consumer health data” under the Washington My Health My Data Act, and sensitive/special-category data under UAE PDPL and DIFC DP Law):
- Lab reports — pathology, blood work, and diagnostic laboratory results uploaded by you or imported from a connected provider.
- Imaging reports — radiology, MRI, CT, ultrasound, X-ray, and other medical imaging documents and reports.
- Prescriptions — medication prescriptions, dosage instructions, and pharmacy records.
- Health notes — freeform notes, symptom logs, and any other personal health narratives you enter.
- Wearable data — biometric and fitness data ingested via connected wearable devices and apps (e.g., heart rate, steps, sleep, activity, blood oxygen), received through the Terra integration (see Section 7).
3.3 Emergency Contacts
Names, relationships, and contact details of individuals you designate as emergency contacts.
3.4 Family and Carer Relationship Data — [SPECIAL-CATEGORY / SENSITIVE HEALTH DATA]
Where you share access to your records with a family member or carer, or manage another person’s records, we process the relationship designation, the relevant user identifiers, and any health records to which access is granted. Where another person’s health data is involved, that data is also special-category / sensitive health data.
3.5 Account and Authentication Data
Account credentials and identity information managed through our authentication provider Clerk, including email address, authentication tokens, session identifiers, and linked OAuth identities (e.g., Google, Apple Sign In). Passwords are hashed and are not accessible to Medical You Pte. Ltd.
3.6 Device and Diagnostic Data
Technical information automatically collected when you use MedicalYou, including:
- Device type, operating system, and version;
- Browser type and version (web);
- App version;
- IP address;
- Device identifiers;
- Crash logs, error reports, and diagnostic data.
3.7 Usage and App Activity Data
Information about how you interact with MedicalYou, including:
- Features accessed and actions performed;
- Upload and viewing activity (file types, frequency — not content for analytics);
- Session duration and navigation patterns;
- In-app search queries;
- Timestamps of key events.
We do not use advertising tracking pixels, sell advertising inventory, or share your data with advertisers.
4. How We Use Your Data
We use your personal data only for the purposes described below. Where a purpose is limited to a specific legal basis, that is set out in Section 5.
4.1 Providing the MedicalYou Service
To create and maintain your account; to store, organise, and display your health records; to enable family/carer sharing at your direction; to process uploads and attachments; and to deliver all core features of the platform.
4.2 AI Summaries and Health Insights
To generate AI-powered summaries of your health records and insights derived from your uploaded data, using Anthropic AI models accessed through the Vercel AI Gateway (see Section 6). These outputs are provided to you as informational tools only and do not constitute medical advice.
4.3 Wearable Data Integration
To receive and display biometric and fitness data from wearable devices and health apps you choose to connect through the Terra integration (see Section 7).
4.4 Security and Fraud Prevention
To authenticate users; to detect, prevent, and investigate unauthorised access, fraudulent activity, and abuse of the platform; to enforce rate limits; and to protect the security and integrity of your data and our systems.
4.5 Customer Support
To respond to your enquiries, troubleshoot issues, and process requests you direct to our support or privacy teams.
4.6 Legal and Regulatory Compliance
To comply with applicable laws and regulations, respond to lawful requests from authorities, enforce our Terms of Service, exercise or defend legal claims, and meet our data-breach notification obligations.
4.7 Product Improvement and Analytics (Aggregate and Anonymised)
To understand aggregate usage patterns, improve the platform, and conduct internal research — using only anonymised or aggregated data that cannot identify you individually. We do not perform individual-level behavioural analysis for product improvement without your explicit consent.
4.8 Anonymised Data Commercialisation (Separate Opt-In)
Subject to a separate, granular, opt-in consent (default-OFF), to create anonymised, de-identified, or aggregated datasets for commercialisation purposes as described in Section 11. This purpose is entirely separate from the core service and will not be activated without your affirmative action.
5. Legal Bases and Consent Model
We process your personal data on the following legal grounds, which vary by jurisdiction and by the category of data involved.
5.1 EU / UK GDPR Legal Bases
For users in the European Economic Area and United Kingdom, we rely on the following legal bases under the GDPR:
| Processing Activity | Legal Basis | GDPR Reference |
|---|---|---|
| Providing the service (non-health data) | Contract performance (Art 6(1)(b)) | Art 6 |
| Health data processing — core service | Explicit consent (Art 6(1)(a) + Art 9(2)(a)) | Art 9 |
| Family/carer health data sharing | Explicit consent of the data subject (Art 9(2)(a)) | Art 9 |
| Security and fraud prevention | Legitimate interests (Art 6(1)(f)) | Art 6 |
| Legal obligations (breach notification, court orders) | Legal obligation (Art 6(1)(c)) | Art 6 |
| Establishing or defending legal claims | Legal claims (Art 9(2)(f)) | Art 9 |
| Anonymised dataset creation | Explicit consent (Art 6(1)(a) + Art 9(2)(a)) | Art 9 |
Special-category data requires explicit consent. Under GDPR Art 9, health data is special-category personal data that generally may only be processed with your explicit, freely given, specific, informed, and unambiguous consent. We obtain this through a dedicated Health Data Processing Consent presented at onboarding and accessible at any time in your account settings. This consent is separate from, and in addition to, acceptance of our Terms of Service.
Withdrawal of consent: You may withdraw your consent at any time (see Section 13). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, but it will result in suspension of health-data processing and may render the core service inoperable.
5.2 Singapore PDPA Consent Model
For users in Singapore, we rely on the PDPA consent obligation as the primary basis for collecting, using, and disclosing your personal data. We also rely on the “contractual necessity” and “legal obligation” deemed-consent bases where applicable under the PDPA.
Consent is obtained at account creation. You are notified of all purposes for which your data will be used prior to or at the time of collection. Health data is treated as sensitive and processed only with explicit, purpose-specific consent.
5.3 UAE / DIFC Consent Model
For users in the United Arab Emirates and the Dubai International Financial Centre, we process sensitive personal data (including health data) only on the basis of your explicit consent, consistent with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and DIFC Data Protection Law No. 5 of 2020.
5.4 Cross-Reference: Health Data Processing Consent
The Health Data Processing Consent is a separate, standalone document presented at onboarding. It details the specific categories of health data processed, the AI processing performed via the Vercel AI Gateway and Anthropic, retention periods, and your rights. If you accepted a Health Data Processing Consent on or after the effective date of this policy, its terms are incorporated by reference. Where any inconsistency exists between this policy and the Health Data Processing Consent on matters of health-data processing, the Health Data Processing Consent prevails.
6. AI Processing Disclosures
6.1 How Our AI Processing Works
MedicalYou uses the Vercel AI Gateway, an AI routing service operated by Vercel, to send requests to Anthropic, our third-party AI model provider, in order to generate textual summaries of your uploaded health records and to produce health insights derived from your data. When you request an AI summary or insight:
- The relevant health record text (or extracted text from uploaded documents) is transmitted through the Vercel AI Gateway to Anthropic for processing. This processing takes place on those providers’ infrastructure, which is located outside Singapore.
- Anthropic’s AI model processes the input and returns a generated text response.
- This output is displayed to you within the MedicalYou application and stored alongside your records.
Vercel and Anthropic are subprocessors of Medical You Pte. Ltd for this purpose and process data under contractual data processing terms. We use this AI processing only to provide MedicalYou features to you. We do not authorise Vercel or Anthropic to use your data to train or improve general-purpose AI models, and we do not currently grant any such authorisation.
6.2 AI Outputs Are Not Medical Advice
AI-generated summaries and insights produced by MedicalYou are informational only. They do not constitute medical advice, diagnosis, treatment recommendations, or clinical opinion. You should always consult a qualified healthcare professional regarding any health concern. MedicalYou accepts no liability for actions taken in reliance on AI-generated outputs.
6.3 Automated Processing and Human Oversight
The generation of AI summaries is an automated process. It does not constitute automated decision-making that produces legal or similarly significant effects on you within the meaning of GDPR Art 22. No automated decisions are taken about your healthcare, insurance eligibility, employment, or any other consequential matter based solely on AI outputs from MedicalYou.
Medical You Pte. Ltd does not currently employ a clinical review step for individual AI-generated outputs, and we are transparent that AI models may produce inaccurate, incomplete, or misleading outputs. You bear responsibility for verifying AI-generated content against your source records and with qualified clinicians.
6.4 Limitations
AI-generated summaries:
- May contain errors, omissions, or misinterpretations of complex medical terminology;
- Are only as accurate as the documents you upload;
- Are not reviewed in real time by a qualified clinician;
- Do not replace clinical assessment.
7. Wearables and Third-Party Integrations
7.1 Terra Integration
MedicalYou integrates with Terra, a wearable data aggregation platform, to allow you to connect your wearable devices and health apps (such as Garmin, Fitbit, Apple Health, Google Fit, Whoop, Oura, and others supported by Terra). Terra operates as a subprocessor of Medical You Pte. Ltd.
When you connect a wearable or health app through Terra:
- Terra receives your authorisation to access data from that device or app.
- Terra transmits wearable data to MedicalYou via secure webhook.
- MedicalYou stores that data in your health record within our AWS infrastructure.
7.2 What Wearable Data Flows In
Depending on the device or app connected, data may include: heart rate and heart rate variability, step count and distance, sleep stages and duration, active energy and calorie burn, blood oxygen saturation, blood glucose (where supported), body weight and composition, respiratory rate, activity type and intensity, menstrual cycle data (where applicable), and similar biometric metrics.
All wearable data constitutes health data / special-category personal data and is handled accordingly.
7.3 User Control
Connecting wearables is entirely optional. You may:
- Choose not to connect any wearable device or health app;
- Revoke access to a connected device or app at any time through the MedicalYou settings or directly within Terra’s connected services;
- Delete wearable data already stored in MedicalYou by submitting a deletion request to privacy@medicalyouglobal.com.
Revocation of Terra access prevents future data transmission but does not automatically delete historical data already stored in your MedicalYou record; you must submit an explicit deletion request for that data.
8. Subprocessors
We engage the following categories of subprocessors to operate the MedicalYou platform. All subprocessors are engaged under written data processing agreements that impose confidentiality and data protection obligations at least equivalent to those in this policy.
| Subprocessor | Category | Purpose | Processing Location |
|---|---|---|---|
| Vercel | Web hosting / CDN | Serves the MedicalYou web application to users’ browsers | Global CDN; compute in US East / EU (Vercel regions); no persistent health data stored on Vercel edge |
| Amazon Web Services (AWS) | Cloud infrastructure | Backend API compute, database, and storage | ap-southeast-1 (Singapore) |
| Amazon Aurora PostgreSQL (AWS) | Database | Stores structured health records and user account data | ap-southeast-1 (Singapore) |
| Amazon S3 (AWS) | Object storage | Stores uploaded documents, imaging files, avatars, and audit archives | ap-southeast-1 (Singapore) |
| Amazon ElastiCache (AWS) | Cache / session state | Rate limiting, OAuth state management, application caching | ap-southeast-1 (Singapore) |
| Vercel AI Gateway | AI gateway / routing | Routes AI requests to our model provider to generate summaries and health insights | Global (Vercel infrastructure); processed outside Singapore |
| Anthropic | AI model provider | Generates AI summaries and health insights from submitted record text | US-based (Anthropic infrastructure) |
| Clerk | Authentication / identity | User authentication, session management, identity verification, OAuth | US-based (Clerk infrastructure); data minimisation applied |
| Terra | Wearable data aggregation | Receives wearable and health-app data on your behalf and transmits to MedicalYou | Global; governed by Terra’s data processing terms |
We will publish an updated subprocessor list, or notify registered users, if we engage new subprocessors who will process health data. EU/UK GDPR users have the right to object to new subprocessors.
9. International Transfers
9.1 Primary Data Residency
Our primary data residency is Singapore (AWS ap-southeast-1). All health data, structured records, and uploaded documents are stored in Singapore. However, your personal data may be processed or stored in countries outside your country of residence — for example, by the subprocessors identified in Section 8 that operate in the United States. Where this occurs, we apply the safeguards described below. In addition, where you yourself choose to share your data overseas (for example, with a clinician, carer, or family member located in another country), that onward transfer is made at your direction. The detailed governance of cross-border transfers is set out in our internal Cross-Border Data Transfer Policy.
9.2 Transfer Mechanisms
Certain subprocessors (including Clerk, Vercel’s CDN infrastructure, and the Vercel AI Gateway and Anthropic used for AI processing) involve data being processed outside Singapore. We address this as follows:
Singapore (PDPA): Transfers of personal data outside Singapore are governed by the PDPA Transfer Limitation Obligation. We ensure comparable protection through:
- ASEAN Model Contractual Clauses (MCCs) with subprocessors where applicable; and/or
- Binding contractual obligations requiring subprocessors to provide a standard of protection comparable to the PDPA.
EU GDPR: For users whose data is subject to the EU GDPR, international transfers to countries without an adequacy decision are governed by the EU Standard Contractual Clauses (SCCs) (June 2021 version, Module Two: Controller-to-Processor) incorporated into our subprocessor agreements, supported by a Transfer Risk Assessment (TRA) and supplementary measures for transfers to higher-risk jurisdictions.
UK GDPR: For users whose data is subject to the UK GDPR, the EU SCCs are not valid on their own. Restricted transfers are instead governed by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, together with a Transfer Risk Assessment.
UAE PDPL / DIFC: Transfers outside the UAE or DIFC are subject to the requirements of UAE Federal Decree-Law No. 45 of 2021 and the DIFC Data Protection Law No. 5 of 2020, including adequate safeguards and, where required, your explicit consent to the transfer.
9.3 Your Rights Regarding Transfers
You may request details of the specific transfer mechanisms and safeguards applicable to transfers of your data by contacting privacy@medicalyouglobal.com.
10. Data Taxonomy
We use the following definitions consistently across all MedicalYou legal documents and internal policies. Precise classification governs the protections applied to your data.
10.1 Personal Data
Information relating to an identified or identifiable natural person. Under GDPR Art 4(1), a person is “identifiable” if they can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, or one or more factors specific to that person’s physical, physiological, genetic, or similar identity. Under Singapore PDPA, “personal data” has equivalent meaning.
All data categories collected by MedicalYou (Sections 3.1–3.7) constitute personal data.
10.2 Health Data / Data Concerning Health — Special-Category / Sensitive
Health data is a subset of personal data relating to the physical or mental health of a natural person, including information which reveals information about their health status. Under GDPR Art 4(15) and Art 9, health data is special-category personal data, subject to strict processing conditions. It is also: sensitive personal information under the California CPRA; “consumer health data” under the Washington My Health My Data Act; and sensitive/special-category data under the UAE PDPL and DIFC DP Law.
Data in Sections 3.2, 3.4, and 3.7 (lab reports, imaging, prescriptions, health notes, wearable data, family/carer health data) is health data.
10.3 PHI (Protected Health Information)
Under US HIPAA (45 CFR Parts 160–164), PHI means individually identifiable health information held or transmitted by a covered entity (e.g., healthcare provider, health plan) or its business associate. Medical You Pte. Ltd is a direct-to-consumer technology company and is generally neither a covered entity nor a business associate under HIPAA; accordingly, most user data stored in MedicalYou does not constitute PHI for HIPAA purposes. However, MedicalYou may be subject to the FTC Health Breach Notification Rule as a personal health record vendor for US users (see Section 15.4).
10.4 Pseudonymised Data
Data that has been processed so that it can no longer be attributed to a specific individual without reference to separately-held additional information. Under GDPR Art 4(5), pseudonymised data remains personal data and is subject to all data protection obligations. It is not anonymous. We explicitly state: pseudonymised data is not anonymous and is treated as personal data in all circumstances. Pseudonymised data does not fall within our anonymised-data commercialisation activities (Section 11). This position is confirmed by GDPR Recital 26 and ICO guidance on personal data.
10.5 Anonymised Data
Data that has been irreversibly processed such that no individual can be identified by any means reasonably likely to be used, including by the original controller. Under GDPR Recital 26, genuinely anonymised data falls outside the scope of GDPR. Anonymisation is irreversible by definition. We apply rigorous technical and procedural standards before classifying any dataset as anonymised.
10.6 De-Identified Data (HIPAA Standard)
Under 45 CFR § 164.514 and HHS de-identification guidance, data may be de-identified by: (a) Safe Harbor — removal of 18 specified identifiers with no actual knowledge of re-identification risk; or (b) Expert Determination — a qualified expert certifies that re-identification risk is very small. De-identified data falls outside HIPAA’s definition of PHI and may be used or disclosed without HIPAA authorisation. We apply these standards when relevant to US user data.
10.7 Aggregated Data
Statistical or summary outputs derived from data relating to multiple users, presented at a group level with no individual-level records. Aggregated data does not identify any individual and is not personal data for the purposes of any applicable law.
11. Anonymised and De-Identified Data — Commercialisation
11.1 Our Position on Selling Identifiable Data
We do not sell your identifiable personal information, identifiable health data, or pseudonymised data.
This commitment is unconditional. Medical You Pte. Ltd will never sell, licence, or otherwise commercially transfer any data that identifies you, directly or indirectly, to any third party for commercial purposes.
11.2 Anonymised Data Commercialisation
Medical You Pte. Ltd reserves the right to create, use, disclose, licence, and sell datasets that have been fully anonymised, de-identified, or aggregated such that they cannot reasonably be used to identify any individual. Such datasets may include, by way of example: population-level health trends, aggregated biometric benchmarks, or anonymised patterns derived from health records across our user base.
This right is exercised subject to the following strict conditions:
- No re-identification: We commit not to attempt to re-identify anonymised or de-identified data, and we do not permit recipients to attempt re-identification.
- Contractual restrictions: Every recipient of anonymised or de-identified datasets is bound by contractual terms prohibiting re-identification, onward sale of identifiable data, and use for purposes incompatible with the original anonymisation intent.
- Technical standards: We apply recognised technical standards (including methods consistent with 45 CFR § 164.514 Safe Harbor and Expert Determination, and GDPR Recital 26 anonymisation principles) before treating any dataset as anonymised.
- Separate opt-in consent: Commercialisation of anonymised datasets derived from your health records is governed by a separate, granular, opt-in consent toggle, presented distinctly from your Health Data Processing Consent and from acceptance of our Terms of Service. This toggle is default-OFF. You will only be included in commercialised anonymised datasets if you have affirmatively activated this toggle.
- No linkage: We do not sell any dataset in a form that could be linked back to your account, your records, or any pseudonymous identifier traceable to you.
11.3 Jurisdiction-Specific Notes
- GDPR/UK GDPR: Creating anonymised datasets from special-category (health) data requires a lawful basis and Art 9 condition for the anonymisation processing step itself. We rely on your explicit consent (Art 9(2)(a)) for this purpose, captured through the separate opt-in toggle.
- California CPRA: De-identified data meeting the CPRA’s definition falls outside “personal information.” We nonetheless offer an opt-out mechanism as a matter of best practice.
- Washington MHMDA: Data that is genuinely de-identified under RCW 19.373 is exempt from the Act. For any data that does not meet that threshold, we treat it as requiring the separate signed authorisation mandated by the Act before sale. Our global default-OFF opt-in toggle satisfies this requirement.
- UAE PDPL / DIFC: Explicit consent is required for processing sensitive data, including the creation of anonymised derivatives. The separate opt-in toggle captures this consent.
11.4 Right to Opt Out at Any Time
You may withdraw consent for anonymised-data commercialisation at any time by toggling off the relevant setting in your MedicalYou account settings, or by contacting privacy@medicalyouglobal.com. Withdrawal does not affect the lawfulness of any commercialisation carried out before withdrawal, and does not affect your core health-data processing consent or your access to MedicalYou.
12. Retention, Security, and Data Breach Notification
12.1 Retention Periods
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law, in accordance with the PDPA Retention Limitation Obligation and the GDPR storage-limitation principle (Art 5(1)(e)). The following retention periods apply. These periods are drawn from, and are consistent with, our internal Data Retention and Deletion Schedule, which is the authoritative source and which we review at least annually:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and profile data | Active account lifetime; hard-deleted within 30 days of account closure | Contractual necessity |
| Health records (lab reports, imaging, prescriptions, health notes) | Active account lifetime; deleted within 30 days of account closure or a valid erasure request, subject to legal holds | User-controlled; service provision |
| Wearable / Terra data | Active account lifetime while the integration is connected; deleted within 30 days of disconnection or account closure | User-controlled |
| Emergency contacts and family/carer data | Active account lifetime; deleted within 30 days of account closure, or within 24 hours of the user removing the contact or revoking access | User-controlled |
| AI-generated summaries and insights (derived data) | Deleted within 30 days of deletion of the underlying source records, or on direct deletion or account-closure request | Derived from source; follows source deletion |
| Authentication and identity data (Clerk) | Clerk profile deleted within 30 days of account closure; login history retained 12 months per the Clerk agreement | Service provision; security |
| Cache and OAuth state (ElastiCache) | Automatic time-to-live expiry (OAuth tokens 24 hours; rate-limit counters 15 minutes; session cache 1 hour) | Operational necessity |
| Support communications | 3 years from ticket closure; health-data attachments deleted within 90 days of ticket closure unless required for an ongoing matter | Dispute resolution; evidence of DSR responses |
| Consent records | 6 years from the consent event to evidence lawful processing; user identifier anonymised on account deletion | Accountability (GDPR Art 5(2); PDPA) |
| Usage and app activity data | 12 months rolling | Product analytics |
| Audit archive (S3 — access logs, security events) | 7 years; identifiers anonymised on account deletion | Legal and regulatory compliance, legal claims |
| Backup snapshots | Rolling cycle (Aurora point-in-time recovery 35 days; S3 backups 90 days), then overwritten | Disaster recovery |
Anonymised, de-identified, and aggregated datasets are not personal data and may be retained beyond the periods above; where you have given the separate, opt-in consent for de-identified data commercialisation, such datasets persist under the controls in our De-Identification and Anonymisation Methodology. You may request deletion of your data at any time (see Section 13). Note that some data may be retained beyond these periods where required by applicable law or to establish, exercise, or defend legal claims.
12.2 Deletion of Derived Data
When you delete a source record (e.g., a lab report), we will delete the AI-generated summaries and insights derived from that record within 30 days. If you request deletion of your entire account, all personal data, health data, and derived data will be deleted within 30 days, subject to any legally required retention of audit records.
12.3 Audit Archive
We maintain a security and compliance audit archive in Amazon S3 (ap-southeast-1, Singapore), which records access events, authentication logs, and security events. Audit archive records are retained for up to 7 years for legal, regulatory, and fraud prevention purposes. Audit archive records are access-controlled and are not used for product analytics or commercialisation.
12.4 Security Measures
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction, including:
- Encryption in transit: All data transmitted between your device and MedicalYou, and between MedicalYou components, is encrypted using TLS 1.2 or higher.
- Encryption at rest: All data stored in Amazon Aurora PostgreSQL, Amazon S3, and Amazon ElastiCache is encrypted at rest using AES-256 or equivalent.
- Access controls: Role-based access controls restrict access to personal data to authorised personnel on a need-to-know basis. Multi-factor authentication is required for administrative access.
- Network security: Our AWS infrastructure is deployed within a Virtual Private Cloud (VPC) with appropriate network segmentation, firewalls, and intrusion detection controls.
- Vendor security: Subprocessors are required to maintain security standards consistent with their obligations under applicable law and our data processing agreements.
- Penetration testing and security reviews: We conduct regular security assessments of our platform.
No security measure is infallible. If you believe your MedicalYou account has been compromised, please contact hello@medicalyouglobal.com immediately.
12.5 Data Breach Notification
In the event of a personal data breach, we will:
Singapore (PDPA): Assess the breach within 30 days of becoming aware. Where the breach is notifiable (likely significant harm to any affected individual, or affecting 500 or more individuals), we will notify the Personal Data Protection Commission (PDPC) within 3 calendar days of determining the breach is notifiable, and notify affected individuals where there is likely significant harm, as required by the PDPA Data Breach Notification Obligation.
EU / UK GDPR: Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with GDPR Art 33–34.
US (FTC Health Breach Notification Rule): As a personal health record vendor for US users, Medical You Pte. Ltd may be subject to the FTC Health Breach Notification Rule. In the event of a breach of unsecured identifiable health data of US users, we will notify affected individuals and the FTC in accordance with the Rule’s requirements.
13. Your Rights
You have the following rights in respect of your personal data. The applicable rights depend on your jurisdiction of residence.
13.1 Right of Access
You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data together with information about how it is processed. You can obtain a machine-readable copy of your data at any time using the in-app Export my data feature, available under Settings → Security → Your data (see Section 13.9).
13.2 Right to Correction / Rectification
You have the right to request that we correct inaccurate or incomplete personal data. You may also correct much of your profile data directly within the MedicalYou application.
13.3 Right to Deletion / Erasure
You have the right to request deletion of your personal data where: it is no longer necessary for the purpose for which it was collected; you withdraw consent and no other legal basis applies; you object to processing and there are no overriding legitimate grounds; or the data has been unlawfully processed. Certain data may be retained where required by law or for legal claims.
13.4 Data Export / Portability
You have the right to receive a copy of your personal data in a structured, commonly used, machine-readable format (such as JSON or PDF), and to transmit that data to another controller. This right applies to data you provided to us and which is processed by automated means on the basis of your consent or a contract. You can exercise this right immediately and without charge using the in-app Export my data feature under Settings → Security → Your data, which generates a complete JSON copy of your profile, clinical records, documents, imaging, insights, and activity log.
13.5 Withdrawal of Consent
Where we process your data on the basis of consent (including explicit consent for health data), you may withdraw your consent at any time. Withdrawal is prospective and does not affect the lawfulness of processing prior to withdrawal. Withdrawal of Health Data Processing Consent will result in suspension of health-data features and may render the core MedicalYou service inoperable for you.
13.6 Right to Object / Restriction
You have the right to object to processing based on legitimate interests, and to request restriction of processing in certain circumstances (e.g., where you contest the accuracy of data while we verify it).
13.7 Opt-Out of Sale or Sharing (US Users)
US residents have the right to opt out of the sale or sharing of their personal information. As stated in Section 11, we do not sell identifiable personal information. You may nonetheless submit an opt-out request and we will confirm that no such sale is occurring or has occurred. See also the California-specific and Washington-specific notices in Section 15.
13.8 Right to Lodge a Complaint
You have the right to lodge a complaint with the relevant data protection authority:
| Jurisdiction | Supervisory Authority |
|---|---|
| Singapore | Personal Data Protection Commission (PDPC) — pdpc.gov.sg |
| EU Member States | Competent national Data Protection Authority (DPA) in your country of residence |
| United Kingdom | Information Commissioner’s Office (ICO) — ico.org.uk |
| UAE / DIFC | UAE Data Office / DIFC Commissioner of Data Protection |
We encourage you to contact us first to resolve any concern before escalating to a supervisory authority.
13.9 How to Exercise Your Rights
For your right of access and data portability (Sections 13.1 and 13.4), the fastest route is the in-app Export my data feature under Settings → Security → Your data, which lets you download a complete, machine-readable (JSON) copy of your personal data on demand without contacting us.
For any other rights request — or if you are unable to use the in-app export — submit your request by email to privacy@medicalyouglobal.com, addressed to the attention of our Data Protection Officer, Samuel Banks. Please include your full name, registered email address, and a clear description of the right you wish to exercise. We will respond within 30 days (or within the applicable statutory period for your jurisdiction). We may need to verify your identity before processing your request.
14. Children’s Data
MedicalYou is intended for adults and is not directed to, or available to, individuals under the age of 18. We do not knowingly create accounts for, or knowingly collect personal data directly from, individuals under 18. Account registration is subject to a neutral age screen, and individuals who indicate they are under 18 are not permitted to register.
Where an adult uses the family/carer functionality to manage the health records of a dependant who is under 18, the managing adult must be the parent or legal guardian (or otherwise lawfully authorised), must provide any consent required on the dependant’s behalf, and takes responsibility for the dependant’s records. Any health data of a dependant processed in this way is treated as special-category / sensitive health data and is never included in any anonymised, de-identified, or aggregated dataset that we create, use, license, or sell.
Where US users are concerned, we do not permit registration by children under 13 and do not knowingly collect their personal data, consistent with the Children’s Online Privacy Protection Rule (COPPA). Our full position on minimum age, age assurance, and the handling of dependants’ data is set out in our Children’s Data and Age-Gating Policy.
If you believe we have inadvertently collected personal data from a person under 18 without appropriate authorisation, please contact us at privacy@medicalyouglobal.com and we will take prompt steps to delete that data.
15. Region-Specific Notices
15.1 Singapore — Personal Data Protection Act (PDPA)
This notice supplements the main policy for users in Singapore.
Medical You Pte. Ltd complies with the Singapore Personal Data Protection Act 2012 (No. 26 of 2012) and the PDPC’s nine data protection obligations: Consent; Purpose Limitation; Notification; Access and Correction; Accuracy; Protection; Retention Limitation; Transfer Limitation; Data Breach Notification; and Accountability.
Consent: We obtain your consent before or at the time of collecting your personal data for each identified purpose. You may withdraw consent at any time subject to the limitations described in Section 13.5.
Access and Correction: You may request access to, or correction of, your personal data held by us by contacting privacy@medicalyouglobal.com. We will respond within 30 days.
Breach notification: Where a data breach is notifiable under the PDPA (likely significant harm or ≥ 500 individuals affected), we will notify the PDPC within 3 calendar days of determination and notify affected individuals where significant harm may result.
Transfer Limitation: Transfers of your personal data outside Singapore are made only where comparable protection is ensured, including through ASEAN Model Contractual Clauses or equivalent contractual safeguards, consistent with the PDPA Transfer Limitation Obligation.
Accountability: Our DPO, Samuel Banks, is responsible for our compliance with the PDPA and may be contacted at privacy@medicalyouglobal.com.
15.2 European Union and United Kingdom — GDPR / UK GDPR
This notice supplements the main policy for users in the EEA and United Kingdom.
Data controller: Medical You Pte. Ltd, 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914.
DPO: Samuel Banks, privacy@medicalyouglobal.com.
Legal bases: Detailed in Section 5.1. Health data is processed on the basis of explicit consent under GDPR Art 9(2)(a).
Special-category data: Your health records are special-category personal data under GDPR Art 9 and require your explicit, separate consent. The ICO confirms that explicit consent is an appropriate condition for processing health data for health management purposes.
Data subject rights: Access, rectification, erasure, restriction, portability, objection, and right not to be subject to solely automated decisions — all available as described in Section 13. Response within 30 days, extendable by a further 60 days for complex requests.
Breach notification: Within 72 hours of awareness to the competent supervisory authority; direct notification to affected individuals where high risk.
Supervisory authority (UK): Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk.
Pseudonymisation and anonymisation: We apply GDPR Recital 26 and ICO guidance to distinguish pseudonymised data (still personal data, never sold) from genuinely anonymised data.
15.3 United Arab Emirates — UAE PDPL and DIFC Data Protection Law
This notice supplements the main policy for users in the UAE, including those accessing MedicalYou from the Dubai International Financial Centre (DIFC).
UAE Federal Decree-Law No. 45 of 2021 (PDPL): Medical You Pte. Ltd processes the personal data of UAE users in accordance with the UAE PDPL, which entered into force on 2 January 2022. The PDPL classifies health data as sensitive personal data requiring explicit consent before processing. We obtain this through our Health Data Processing Consent at onboarding.
DIFC Data Protection Law No. 5 of 2020: For users located within or whose data is processed in connection with the DIFC, we comply with the DIFC DP Law, including its requirements for explicit consent for sensitive data and restrictions on international transfers.
Your rights under UAE PDPL / DIFC DP Law include: access, rectification, erasure, restriction, objection, and data portability. Exercise these rights by contacting privacy@medicalyouglobal.com.
15.4 United States
15.4.1 California — CPRA (California Privacy Rights Act)
California residents have the following rights under the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA):
- Know: The right to know what personal information we collect, use, disclose, and sell.
- Delete: The right to request deletion of personal information we have collected.
- Correct: The right to request correction of inaccurate personal information.
- Opt out of sale or sharing: The right to opt out of the sale or sharing of personal information. We do not sell your identifiable personal information. You may nonetheless submit an opt-out request.
- Limit the use of sensitive personal information: Health data constitutes “sensitive personal information” under the CPRA. You have the right to direct us to limit the use and disclosure of your sensitive personal information to purposes necessary to perform the services you have requested. We do not use your sensitive personal information for purposes beyond those described in this policy without your consent.
- Non-discrimination: You have the right not to be discriminated against for exercising your CPRA rights.
Categories of sensitive personal information collected: Health and medical data, biometric data derived from wearables.
Do Not Sell or Share My Personal Information: To exercise this right, email privacy@medicalyouglobal.com with the subject line “California — Do Not Sell or Share.”
Shine the Light (Cal. Civ. Code § 1798.83): California residents may request information about disclosures of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
15.4.2 Washington State — My Health My Data Act (MHMDA)
Washington State residents have specific rights under the Washington My Health My Data Act, RCW 19.373, in respect of “consumer health data.”
Key rights and our practices:
- Opt-in consent to collect consumer health data: We obtain your explicit consent before collecting consumer health data.
- Separate consent to share: We obtain separate explicit consent before sharing consumer health data with third parties beyond our operational subprocessors.
- Separate signed authorisation to sell: We obtain a separate, signed valid authorisation before selling consumer health data. We do not sell your consumer health data. Anonymised data commercialisation (Section 11) is conducted under a separate opt-in and only where data meets the Act’s de-identification standards.
- Right to withdraw consent: You may withdraw consent for collection or sharing of consumer health data at any time.
- Right to deletion: You may request deletion of your consumer health data.
To exercise rights under MHMDA, contact privacy@medicalyouglobal.com.
15.4.3 FTC Health Breach Notification Rule
Medical You Pte. Ltd operates as a personal health record (PHR) vendor for US users. As a direct-to-consumer PHR vendor that is not a HIPAA-covered entity, we are subject to the FTC Health Breach Notification Rule as interpreted and enforced by the Federal Trade Commission.
In the event of a breach of security involving unsecured individually identifiable health information held in a personal health record, we will notify affected US users, the FTC, and (where applicable) prominent media outlets, in accordance with the Rule’s requirements and timelines.
Most data stored in MedicalYou does not constitute PHI under HIPAA (see Section 10.3) because Medical You Pte. Ltd is generally neither a covered entity nor a business associate under 45 CFR § 164.514. However, we apply the FTC Health Breach Notification Rule as the applicable framework for US users’ health data.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
Where we make material changes, we will:
- Publish the updated policy at medicalyouglobal.com/privacy with a new effective date;
- Provide in-app notification to registered users;
- Where required by law (e.g., for changes affecting health-data processing under GDPR or PDPA), seek fresh consent before the changes take effect.
Your continued use of MedicalYou after the effective date of a revised policy constitutes acceptance of the revised policy in respect of non-material changes. For material changes affecting your health-data consent, we will obtain your affirmative consent before processing continues on the new basis.
Previous versions of this policy are available on request by contacting privacy@medicalyouglobal.com.
17. How to Contact Us
For any privacy-related enquiry, rights request, complaint, or question about this policy, please contact:
Medical You Pte. Ltd 160 Robinson Road, #14-04 Singapore Business Federation Center Singapore 068914
Data Protection Officer: Samuel Banks Email (privacy / DPO): privacy@medicalyouglobal.com Email (general support): hello@medicalyouglobal.com
Please mark your email “Attention: DPO” for privacy and data protection matters. We will acknowledge your enquiry within 5 business days and respond fully within 30 days (or the applicable statutory period).
18. Sources
The following primary legal sources are cited in this policy:
- GDPR Art 4 — Definitions (personal data, pseudonymisation, health data): https://gdpr-info.eu/art-4-gdpr/
- GDPR Art 9 — Special categories of personal data; explicit consent (Art 9(2)(a)): https://gdpr-info.eu/art-9-gdpr/
- GDPR Recital 26 — Anonymous data outside GDPR; pseudonymised data remains personal data: https://www.privacy-regulation.eu/en/recital-26-GDPR.htm
- ICO — What is personal data (pseudonymisation, anonymisation): https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/personal-information-what-is-it/what-is-personal-data/what-is-personal-data/
- ICO — Special category data: conditions for processing: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-are-the-conditions-for-processing/
- Singapore PDPA — PDPC Data Protection Obligations: https://www.pdpc.gov.sg/data-protection-obligations
- PDPC — Required to Notify the PDPC (breach notification): https://www.pdpc.gov.sg/required-to-notify-the-pdpc
- HIPAA De-Identification — 45 CFR § 164.514: https://www.law.cornell.edu/cfr/text/45/164.514
- HHS De-Identification Guidance: https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification/index.html
- FTC — Collecting, Using, or Sharing Consumer Health Information (HIPAA/FTC Act/Health Breach Notification Rule): https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach
- UAE Federal Decree-Law No. 45 of 2021 (PDPL): https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws
- UAE Legislation — PDPL text (download): https://uaelegislation.gov.ae/en/legislations/1972/download
- DIFC Data Protection Law No. 5 of 2020: https://www.linklaters.com/en/insights/data-protected/data-protected-difc
- California CCPA/CPRA (California AG): https://oag.ca.gov/privacy/ccpa
- Washington My Health My Data Act, RCW 19.373: https://app.leg.wa.gov/RCW/default.aspx?cite=19.373&full=true
- Apple App Store — App Privacy Details: https://developer.apple.com/app-store/app-privacy-details/
- Google Play — Data Safety: https://support.google.com/googleplay/android-developer/answer/10787469
This document was prepared by Medical You Pte. Ltd and is intended for public distribution. It does not constitute legal advice. Effective 18 May 2026, Version 1.0.
