Privacy

Privacy Policy

This policy explains how MedBrief handles information when you organize health records, use AI features, back up data, or manage a subscription.

Effective July 16, 2026

In short: MedBrief is local-first. Your records are primarily kept on your device. Data leaves your device only when a feature needs it, such as user-triggered AI processing, optional Google Drive backup, authentication, or subscription management.

1. Who we are

MedBrief is provided by PrismMind ("PrismMind," "we," "us," or "our"). This Privacy Policy applies to the MedBrief Android application, its supporting Cloudflare Worker services, and related support interactions.

Questions or privacy requests can be sent to med@sapiens8.com.

2. Information MedBrief handles

Information stored primarily on your device

Depending on what you choose to enter or import, MedBrief may handle profile details and health-related information such as names or labels, relationships, dates of birth, sex or gender, blood type, height, weight, conditions, allergies, medications, lifestyle notes, symptoms, health logs, document metadata, record snapshots, chat history, and attachments.

Imported photos, PDFs, other supported files, and recognition results are also stored locally unless you choose a feature that sends or backs up that information.

Authentication and technical information

MedBrief uses Firebase Authentication, including anonymous authentication, to create a technical user identifier and authenticate requests to our services. Requests may also include technical metadata such as app version, operating-system version, locale, request identifiers, route or model identifiers, file type and size, response status, duration, and a one-way hashed user identifier.

Our service logging is designed to avoid recording uploaded file names, document contents, chat contents, or model output. Even with those controls, no logging or security system can be guaranteed to prevent every accidental disclosure.

Subscription information

Google Play processes purchases and payment details. RevenueCat helps us verify and manage subscription status. We may receive and store information such as the technical app user identifier, product, entitlement, renewal or expiration status, and monthly feature-usage counters. We do not receive your full payment-card number.

Support communications

If you contact us, we receive the email address, message, and attachments you choose to send. Please do not email sensitive health records unless we specifically ask for information needed to resolve your request.

3. When information leaves your device

User-triggered AI recognition and Ask

When you choose to analyze a file or use Ask, MedBrief sends the information needed for that request to PrismMind's backend hosted on Cloudflare. Depending on your request, this may include a selected file, extracted text, your question, recent conversation context, selected profile details, and results returned by local app tools.

Our backend sends the necessary request content through OpenRouter to a selected AI model provider. The provider or model may change as we improve the service. Cloudflare, OpenRouter, and the selected model provider process information under their own service terms, configurations, and privacy practices.

We do not promise that every third-party processor provides zero retention or that submitted data is never used for model improvement. Retention and training controls can depend on the selected provider, account configuration, law, and provider policy. Do not submit information that is unnecessary for your request.

Optional Google Drive backup

If you connect Google Drive and start a backup, MedBrief may upload profile metadata, structured health data, record snapshots, and original source files to the application's private Google Drive app-data folder. MedBrief requests access only to app data it creates or manages, rather than your general Drive files.

Your Google account display name, email address, or avatar may be stored locally so the app can show which account is connected. Disconnecting or revoking Drive access does not by itself delete an existing backup. When authorization remains available, in-app backup or profile deletion can attempt to remove the corresponding Drive data.

4. How we use information

We do not sell health information or use it to target advertising.

5. Service providers and transfers

We share information only as needed to operate the features described above, including with Cloudflare, OpenRouter, the selected AI model provider, Google Firebase, Google Play, RevenueCat, and—only when you enable backup—Google Drive. These providers may process information in countries other than where you live and apply their own legal and technical safeguards.

We may also disclose information if required by law, to protect users or the service, or as part of a business transaction subject to appropriate protections.

6. Retention

7. Your choices and deletion requests

You can delete individual records, conversations, profiles, and supported backups through available in-app controls. Deleting a profile removes its local data and, when Drive authorization is available, attempts to remove its linked Drive backup.

Deleting app content does not necessarily delete the Firebase anonymous identity, RevenueCat subscriber record, backend entitlement or usage records, operational logs, or records that a provider must retain. To ask for additional access or deletion help, email med@sapiens8.com. We may ask for enough technical information to locate the relevant account and may retain limited records where required for billing, fraud prevention, security, or law.

8. Security

We use measures such as encrypted network transport, platform authentication, Android application storage protections, access controls, and minimized logging. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

9. Adults, caregivers, and family profiles

MedBrief is intended for adults, including adults organizing information for family members or people in their care. It is not designed for independent use by children. If you add another person's information, you are responsible for having appropriate authority or permission.

10. Medical-information notice

MedBrief is an information-organization tool, not a medical device. It does not diagnose, treat, cure, or prevent any disease and is not a substitute for a qualified healthcare professional. For an emergency, contact local emergency services immediately.

11. Changes and contact

We may update this policy as the product, providers, or law changes. We will publish the revised policy here and update the effective date. Material changes may also be communicated in the app when appropriate.

PrismMind / MedBrief

Email: med@sapiens8.com

Support: MedBrief Support Center