Effective 18 September 2026. This notice covers My Medical's native app and its testing programme. The app is being prepared for release; described features may be unavailable during testing. The private browser review has separate host-managed sign-in. Public availability will depend on the completed release and country-specific requirements.
Who is responsible
TRUSTWELL SAFETY LIMITED operates My Medical from New Zealand, trading as Trustwell Safety. Company number: 9347523. NZBN: 9429052891755. Niel Meyer is the privacy and support contact at niella69@gmail.com. Postal contact: 8 Winton Street, St Albans, Christchurch 8014, New Zealand.
What you choose to share
You choose whether to send a health question, mental-wellbeing message, written report, report photo/PDF or eligible adult skin photo. We ask for consent before AI processing. Without consent, we cannot provide an AI response. Remove unnecessary names, addresses and other identifiers before uploading. Adult intimate medical photos are accepted only through the separate Adult intimate health flow, after confirming you are 18 or older, the photo is of your own external skin, and you understand the processing. Do not upload children, sexual activity, internal images, diagnostic scans or intimate photos of other people. Only share records you are entitled to share.
Our backend forwards the content needed for your request to OpenAI. A chat request may include up to eight recent messages so the reply can follow the conversation. Images may be resized or compressed; this does not guarantee that identifying information is removed. Written reports are sent inline and their original filenames are not forwarded by the report feature. No radiology provider is connected.
Mental-health content is handled in the same way as other health content. This is AI support, not confidential therapy. No clinician or crisis team monitors the conversation.
Accounts and devices
Before native health features are enabled for your account, we ask for your declared age group (under 16, 16–17 or 18+) and country of residence. We store these details, your account ID and the declaration time to apply age, feature and country restrictions. We do not request a date of birth or identity document in this flow. The declaration is not independent age verification. Contact support to correct a mistake or update your age group; it cannot be changed directly in the app. Successful account deletion removes this declaration. An account that is not eligible can still use account-deletion and support options.
When native sign-in is enabled, Supabase processes your email address, account ID and information needed to verify login codes and protect the account. Google Gmail delivers sign-in messages from niella69@gmail.com, with the sender name My Medical. Google processes the recipient address, message content and delivery information for this purpose. Sign-in emails do not include your health questions or uploads. The app stores a refresh token in the device's secure storage; active sessions are also checked by the backend. Your language preference is stored separately on your device.
Questions, uploaded content, answers and journal entries are held temporarily in the app's session. Clearing the session, signing out or reloading removes these in-app entries. The journal is not a permanent medical record or backup. Original files in your camera roll, downloads, device caches or personal backups are outside this control.
The application does not intentionally save ordinary questions, uploads or AI replies in its backend database. Choosing Report response is a separate exception, described below. Technical providers may still process information while delivering and protecting the service.
Reports, support and payments
If you choose Report response and consent, we store the excerpt you review, category, language, feature, account ID, receipt and submission time to investigate it. Photos and conversation history are not automatically attached. Niel reviews these reports. Reports normally expire after 30 days at the next hourly cleanup; an ongoing complaint may require a documented longer hold. Deleting the app account removes its submitted reports.
If you contact support, we receive your email address and message through Gmail and use them to answer the request. Send a brief description and app/device version, not medical records, passwords, login codes or card details. Support correspondence is kept while needed to resolve the request and related complaints or legal obligations, then reviewed for deletion.
When paid subscriptions become available, Apple or Google handles payment and RevenueCat helps verify and restore subscription access using an app account ID and purchase information. We do not receive your full card details through the app. A pending-purchase marker may be stored securely on your device until the transaction is resolved. Purchases are currently unavailable.
Account-linked request counters enforce usage limits and protect service capacity. They store counts and time periods, not the contents of health conversations. The app has no advertising or analytics SDK, HealthKit or Health Connect integration. We do not sell health content or use it for targeted advertising.
Providers, international processing and retention
The native Supabase database is hosted in Sydney, Australia. OpenAI processes AI requests; Cloudflare hosts public information pages; Gmail handles sign-in and support mail. RevenueCat and the relevant app store process purchase information when connected. Provider operations and support can involve the United States and other countries. A Sydney database does not mean every part of the service stays in Australia. We assess applicable safeguards before introducing a provider or releasing the service in a new market.
AI requests use the provider's setting to avoid saving responses as retrievable application history. This is not a zero-retention promise. OpenAI's standard API policy permits abuse-monitoring retention for up to 30 days, with longer retention for specified legal or safety reasons; image/file safety review and temporary processing caches can have separate rules. Clearing My Medical cannot retract completed processing. See OpenAI's data controls.
Account information and owned counters remain while the account exists, then are removed on successful deletion. Authentication/security audit records, infrastructure logs and provider records may remain for security, fraud prevention, accounting, complaints or legal purposes under applicable provider schedules. Backups, where enabled, expire on their own schedule rather than being individually rewritten for each deletion. We do not promise immediate erasure from every provider or backup.
Provider information: Supabase privacy, OpenAI privacy, Cloudflare privacy, Google privacy, RevenueCat privacy, and Apple privacy.
Your choices, rights and complaints
You can decline AI processing, remove selected uploads before sending, manage camera permissions, clear session notes, sign out and request account deletion. Information needed to operate an account or process a request is necessary for those features; optional health content is your choice.
Contact niella69@gmail.com to request access, correction, deletion or an explanation of our handling of your information. We may make proportionate ownership checks. Do not send identity documents unless we agree a suitable method with you. Where applicable law requires a response deadline or other rights, those requirements apply. If we cannot fulfil a request, we explain why and the available complaint route.
Raise privacy concerns with Niel first. You can also contact the New Zealand Privacy Commissioner or, where Australian privacy law applies, the OAIC. Other mandatory rights in your jurisdiction are not excluded.
Account deletion instructions explain what is deleted and what may remain. Account deletion does not cancel an Apple or Google subscription; cancel renewal separately through the store.
Eligibility and changes
My Medical is intended for people aged 16 and older. We plan international availability, with access limited to countries and features supported by the app stores, our providers and applicable local requirements. A higher local age requirement takes precedence. A planned worldwide rollout does not mean that the service is already available or approved in every country.
People aged 16 or 17 may use eligible written health questions, written-report explanations and mental-wellbeing information where supported. Body-photo features remain for adults aged 18 and older, including intimate medical photos of your own external skin through the separate consent flow. Do not submit body photos of anyone under 18. Self-attestation does not independently verify age or ownership. Diagnostic scans are not assessed.
Information for younger users must be understandable and age-appropriate. Where local requirements call for parental or guardian permission or additional age assurance, these requirements must be satisfied through a supported process before access is offered. The app does not currently provide a verified parental-consent service. If required permission cannot be obtained appropriately, the relevant service will not be offered. We do not automatically share a young person's conversations with parents or guardians; requests are assessed for authority, privacy and applicable law.
The service is not intended for users under 16. If you believe an underage account or an underage body photo has been submitted, contact support with the minimum information needed; do not email or resend the photograph. Availability in a language does not mean the service or its medical wording has been approved or clinically reviewed in every country.
We update this notice when relevant practices change and show the effective date with the published version. Material changes requiring notice or consent will be presented before the changed processing begins.
My Medical privacy notice · My Medical terms of use · My Medical support · Delete your My Medical account