Skip to main content
My Med Journal app icon My Med Journal Download
← Back to home

Privacy Policy for My Med Journal

Effective Date: October 17, 2025  |  Last Updated: July 7, 2026  |  Version: 1.2.1


Introduction

My Med Journal ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how our mobile application ("App", "Application", or "My Med Journal") handles your personal health information.

Our Core Privacy Principle: We collect NO data from you.

This policy is designed to be clear and transparent about exactly what happens to your data when you use My Med Journal.


Table of Contents

  1. Data We Do NOT Collect
  2. Data You Store Locally
  3. How Your Data is Stored
  4. Data Security
  5. Data You Choose to Export
  6. Subscription and Payment
  7. Third-Party Services
  8. Children's Privacy
  9. How to Delete Your Data
  10. Your Privacy Rights
  11. Changes to This Policy
  12. Contact Information

Data We Do NOT Collect

My Med Journal does not collect, transmit, or have access to any of your data.

We do not:

  • ❌ Collect any personal information
  • ❌ Collect any health information
  • ❌ Transmit data to our servers (we don't have servers)
  • ❌ Use analytics or tracking tools
  • ❌ Use advertising networks
  • ❌ Share information with third parties
  • ❌ Require account creation or login
  • ❌ Store data in the cloud
  • ❌ Access your contacts, photos, or other device data (except as needed for app functionality)
  • ❌ Track your location
  • ❌ Monitor your app usage
  • ❌ Collect device identifiers for tracking

We literally cannot see your data because it never leaves your device.


Data You Store Locally

All information you enter into My Med Journal is stored locally on your device only. This includes:

Health Tracking Data

  • Medications: Names, dosages, timing, and notes
  • Symptoms: Types, severity levels (1–10), and notes
  • Vital Signs:
    • Blood pressure (systolic/diastolic)
    • Blood sugar/glucose levels
    • Body temperature
    • Heart rate/pulse
    • Oxygen saturation (SpO2)
    • Pain levels (0–10)
    • Weight measurements
  • Food & Nutrition: Foods consumed, quantities, and timing
  • Liquid Intake: Beverages consumed, amounts, and timing
  • Menstrual Cycle: Cycle dates, flow, related symptoms, and notes
  • Mental Health: Mood and mental-health states (such as anxiety), severity, and notes
  • Notes: Free-form text entries about your health

Optional Profile Information

  • Name: Optional, used only for exports
  • Date of Birth: Optional, used only for exports
  • Unit Preferences: Weight (kg/lbs/stones), Blood Sugar (mg/dL/mmol/L), Liquid (ml/fl oz), Temperature (°F/°C)
  • Regional Settings: Your selected region for default unit preferences

App Settings & Preferences

  • Dashboard Configuration: Tile order and visibility preferences
  • Appearance Settings: Theme mode (light/dark/auto), selected font
  • Custom Items: User-created medications, foods, liquids, and symptoms
  • Reminders: Medication and water reminder schedules (stored locally, notifications handled by device OS)

Important Notes

  • This information never leaves your device except when you explicitly choose to export it
  • We cannot access any of this information
  • You have complete control over all of this data

How Your Data is Stored

Local Database Storage

Your data is stored in an encrypted SQLite database on your device.

Storage Location:

  • Android: App-specific directory (accessible only to the app)
  • iOS: App sandbox (isolated from other apps)

Encryption:

  • iOS encrypts data at rest using iOS Data Protection (NSFileProtectionCompleteUntilFirstUserAuthentication); Android uses SQLCipher with the Android Keystore.
  • Access Control: Protected by your device authentication (PIN, fingerprint, face unlock, or pattern)

Data Persistence

Your data persists on your device until you:

  • Manually delete individual entries within the app
  • Clear the app's data through device settings
  • Uninstall the application

When you uninstall the app, ALL your local data is permanently deleted from your device.


Data Security

Security Measures We Implement

  1. Encryption at Rest
    • iOS: OS-level Data Protection encryption (AES-256)
    • Android: SQLCipher database encryption (AES-256) with key in Android Keystore
    • Cannot be accessed without device authentication
  2. Device Authentication
    • App requires device PIN, pattern, fingerprint, or face unlock
    • Leverages your device's built-in security
    • No app-specific passwords to remember
  3. No Network Transmission
    • Your health data is never transmitted over the internet
    • No servers to breach — your data stays on your device
  4. Encrypted Backups
    • Backup files are encrypted with AES-GCM before export
    • Backups require a passphrase to open — even we cannot read them

What We Cannot Do

  • ❌ We cannot access your health data
  • ❌ We cannot reset or recover your data
  • ❌ We cannot see what you've logged
  • ❌ We cannot identify you from your app usage

Data You Choose to Export

The app lets you export your data in two ways:

PDF / CSV Reports

  • Created entirely on your device
  • Contain whichever data you select for the report
  • Not encrypted (plain-text, shareable with doctors)
  • Once shared, the data is governed by the recipient's privacy practices

Encrypted Backup Files

  • Encrypted with AES-GCM on your device before export
  • Can only be decrypted with your passphrase
  • We never see these files or your passphrase
  • If you lose your passphrase, the backup cannot be recovered by anyone

You decide when and with whom to share any exported data. We have no involvement.


Subscription and Payment

How Billing Works

  • Subscriptions are purchased and billed through your app store (Google Play or Apple App Store)
  • We do not process payments or receive your payment details
  • All billing is governed by your app store's terms of service

RevenueCat — Subscription Verification

We use RevenueCat (RevenueCat, Inc.) to verify and manage subscription status. RevenueCat receives:

  • ✅ An anonymous app-store purchase record
  • ✅ A random device/install identifier
  • ❌ None of your health data
  • ❌ None of your personal identity information

RevenueCat's privacy policy is available at revenuecat.com/privacy.


Third-Party Services

My Med Journal uses one third-party service in the mobile app, and collects minimal data on the website roadmap page:

Service / FeaturePurposeData Stored
RevenueCat Subscription verification Anonymous purchase record & random identifier only — no health data, no identity
Roadmap voting & suggestions (website) Community feature prioritization A salted SHA-256 hash of your IP address (irreversible; used only for deduplication and rate-limiting), your vote selections, and any idea text you voluntarily submit. Raw IP addresses are never stored.

We do not use analytics, advertising, crash-reporting, or any other third-party SDKs in the app.


Children's Privacy

My Med Journal is not directed at children under 13. We do not knowingly collect data from children under 13. Since all data is local and we collect nothing, there is no data to delete — but if you believe a child under 13 has used the app on your device, simply clear the app's data or uninstall it.


How to Delete Your Data

All your data is under your direct control:

Delete Individual Entries

  • Tap any entry in the Timeline and use the delete option

Delete All Data

  • Go to Settings → Danger Zone → Delete All Data
  • Or uninstall the app (permanently deletes everything on-device)

Delete Backup Files

  • Delete backup files from wherever you saved them (Files app, cloud storage, etc.)
  • We hold no copies

No request to us needed — you're always in control.


Your Privacy Rights

Exercising Your Rights

You can exercise all rights directly within the app:

  • Access: Tap Timeline to view all entries
  • Edit: Tap any entry to edit it
  • Delete: See How to Delete Your Data
  • Export: Settings → Share/Export Journal
  • Backup: Settings → Backup & Restore

California Privacy Rights (CCPA)

  • ❌ We collect no personal information
  • ❌ We sell no personal information
  • ❌ We share no personal information with third parties
  • ✅ All data stays on your device

European Union Privacy Rights (GDPR)

  • ❌ We are not a data controller (we don't control your data)
  • ❌ We are not a data processor
  • ✅ You are the sole controller of your data
  • ✅ All data processing happens locally on your device

HIPAA Compliance Note

Important: My Med Journal is not a HIPAA-covered entity — we are not a healthcare provider, health plan, clearinghouse, or business associate. HIPAA does not apply to us. However, we implement privacy practices that align with HIPAA principles. If you share exported data with a healthcare provider, that data may become part of your official medical record and your provider is responsible for HIPAA compliance regarding it.


Changes to This Policy

We may update this Privacy Policy to reflect changes in features, law, or privacy practices. When we update:

  • We will update the "Last Updated" date at the top
  • We will increment the version number
  • Material changes will be announced through the app
  • Continued use after changes constitutes acceptance

You can always find the current version at mymedjournal.app/privacypolicy.


Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

Support Email: support@mymedjournal.app
Website: https://mymedjournal.app

We typically respond within 48 hours (2 business days).


Summary — Privacy Policy in Plain English

  • What We Collect: Nothing. Zero. Nada.
  • Where Your Data Goes: Nowhere. It stays on your phone.
  • Who Can See Your Data: Only you (and anyone you share your phone or exports with).
  • How We Use Your Data: We can't use what we can't see.
  • How to Delete Your Data: Delete entries in the app or uninstall the app.
  • Your Privacy: 100% private. We can't see your data even if we wanted to.

Legal Disclaimer

Medical Information: This app is for personal health tracking only. It is not intended to diagnose any medical condition, provide medical advice or treatment, replace consultation with healthcare professionals, or be used in medical emergencies.

Always consult qualified healthcare providers for medical advice.

Data Loss: While we implement security measures and backup features, we are not responsible for data loss due to device failure, user error, software bugs, operating system changes, or failure to create backups. You are responsible for maintaining your own backups.


Transparency Report

Data Requests Received: 0 (we have no data to provide)
Data Shared with Third Parties: 0 (we have no data to share)
Government Requests: 0 (we have no data to provide)
Data Breaches: 0 (we have no centralized data to breach)
Last Updated: July 7, 2026


Version History

VersionDateChanges
1.0.0 October 17, 2025 Initial public release
1.1.0 June 8, 2026 Added RevenueCat as subscription-verification processor; clarified encrypted backups vs. plain PDF/CSV exports; updated iOS storage description to reflect iOS Data Protection
1.2.0 June 24, 2026 Added roadmap voting & suggestions disclosure: salted-hash IP stored for dedup/rate-limit; raw IPs never stored
1.2.1 July 7, 2026 Added menstrual-cycle and mental-health tracking to the enumerated health data categories

My Med Journal — Your Health. Your Privacy. Your Control.

© 2026 My Med Journal

  • Privacy Policy
  • Terms & EULA