01 Who we are
Medichive (“Medichive”, “we”, “us”) provides a personal and family health record that puts you in control of your medical data, with an optional clinical workspace for the doctors you choose to share it with. We are based in Kochi, Kerala, India.
This Privacy Policy covers the Medichive web application, our Android and iOS mobile apps, and the marketing website at medichive.in (together, the “Services”). By using the Services, you agree to the practices described here.
Medichive is a tool for storing and sharing your health information. It does not provide medical advice, diagnosis, or treatment, and is not a substitute for professional medical care.
02 Information we collect
We only collect what we need to run your record and the features you choose to use. Most data in Medichive is information you add or connect.
Account & identity
- Your name, email address, and (if you add it) phone number.
- A profile photo — taken from your Google account if you sign in with Google, or one you upload.
- Authentication is handled by Google Firebase Authentication. You can sign in with Google or with an email and password. We never see or store your Google password.
- For doctors using the clinical workspace: professional details such as specialty and medical council / registration ID.
Health & medical information
For you and any family members you add to your record, we store the health information you choose to put in, including:
- Demographics — date of birth, sex/gender, blood type, address, emergency contact, and similar profile fields.
- Allergies, medical problems / conditions (including diagnostic codes), and medications, plus any medication-reminder schedules you set.
- Reports and documents you upload — lab results, imaging and scans (including DICOM), prescriptions, discharge summaries and other clinical files.
- Vitals and measurements, including readings synced from your wearables and connected health platforms.
- Voice notes and their transcripts, where you or your clinician record a consultation.
Insurance information
- Policy details you add or capture by photographing your insurance card — payer, plan name, member ID, coverage type, sum assured and covered benefits — and the card image itself.
Wearable & connected device data
If you choose to connect them, we sync health metrics from wearable and platform providers, including Apple Health, Android Health Connect, Google Fit, WHOOP, Fitbit, Oura, Garmin, and Withings. Metrics may include heart rate, resting heart rate, heart-rate variability, blood pressure, oxygen saturation (SpO₂), sleep, steps, body temperature, weight and height.
- To connect a provider you authorise it via OAuth. We store the resulting access tokens encrypted (see Security) and never share them.
- You can disconnect any provider at any time, which stops further syncing.
Location
- To help you find nearby network hospitals where your insurance is cashless, we use a location you provide (city, PIN code or address) or — only with your permission — your device’s approximate location. We use it to look up nearby hospitals and do not use it to track you.
Device & technical data
- If you enable notifications, a push token (Firebase Cloud Messaging) so we can deliver alerts to your browser or device.
- Basic technical information needed to operate and secure the Services, such as IP address (used for rate-limiting and recorded in security audit logs).
No advertising, no tracking, no sale of data. Medichive contains no third-party advertising or analytics SDKs and sets no tracking cookies. We do not sell or rent your personal or health information to anyone, and we never use it for advertising.
03 How we use information
We use the information above to:
- Create and maintain your health record and those of the family members you manage.
- Read and structure the documents you upload — for example, turning a lab PDF into structured allergies, problems and medications you can review and approve.
- Sync, display and chart vitals from your connected wearables.
- Help you find cashless network hospitals near you.
- Let you share your record on your terms, and let the doctors you authorise view it.
- Send you notifications you’ve asked for (such as when a result or note is ready, or a medication reminder).
- Keep the Services secure, prevent abuse, and meet our legal obligations.
Our legal bases for processing (where applicable, e.g. under GDPR) are your consent, performance of our contract with you, and our legitimate interest in operating and securing the Services. Health data is processed on the basis of your explicit consent.
04 AI processing
Medichive uses Anthropic’s Claude models to make sense of the documents and recordings you add — for example, extracting structured allergies, conditions and medications from a report, reading an insurance card, or turning a recorded consultation into a structured clinical note.
- Content sent for processing may include document text, transcripts and relevant parts of your record. It is processed to return a result to you.
- We use Anthropic as a service provider under their commercial terms. Anthropic does not use data submitted through their API to train their models.
- AI-generated suggestions are drafts for you (or your clinician) to review and approve — they are not medical advice.
Clinical use: Medichive’s clinical workspace is in limited beta while we finalise a Business Associate Agreement (BAA) with Anthropic covering protected health information.
06 Platform health data disclosures
Apple Health (HealthKit)
On iOS, with your permission, Medichive reads health data from Apple Health (such as heart rate, sleep, steps, blood pressure and SpO₂) to display it in your record. Data obtained through HealthKit is used only to provide health features to you. We never use HealthKit data for advertising or data-mining, and we do not sell it or disclose it to third parties other than to sync it into your own Medichive record. You can revoke Health access at any time in the iOS Settings app.
Android Health Connect & Google Fit
On Android, with your permission, Medichive reads health data from Health Connect (and, where applicable, Google Fit). Our use of Health Connect data follows the Health Connect Permissions policy, and our access to data from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use this data only to provide and improve health features visible to you. You can revoke access at any time in Health Connect or Google account settings.
Medichive does not transfer Apple Health, Health Connect, Google Fit or other connected-provider data to third parties for advertising, and does not use it to train AI models.
07 Data retention
- We keep your information for as long as your account is active, so your record stays available to you.
- You can delete individual items (documents, readings, family members) at any time within the app.
- When you delete your account, we delete your records, documents, recordings, connected-provider links and associated data. Some security audit logs are retained for a limited period as required for safety and compliance, with personal health details removed.
- Backups are purged on a rolling basis.
08 Security
We build on a HIPAA-aware Google Cloud architecture with patient-set consent at its core:
- Encryption in transit (TLS 1.2+) and at rest. Stored files and database records are encrypted; wearable OAuth tokens are additionally envelope-encrypted using Cloud KMS keys.
- Access control on every read: a record is only readable by its owner or by someone they have consented to.
- Security audit logging of sensitive access, with health details scrubbed from the logs.
- Rate limiting and other abuse protections.
No system is perfectly secure, but we work hard to protect your data and to limit who can ever see it.
09 Your rights & choices
You are in control of your record. You can:
- Access & export the information in your record at any time through the app.
- Correct any detail, and approve or reject AI-suggested entries before they’re saved.
- Delete individual items or your entire account — from inside the app, or by requesting deletion at medichive.in/delete-account.
- Withdraw consent — revoke a share link, stop family sharing, remove a doctor’s access, or disconnect a wearable — at any time.
- Manage permissions — turn off location, notifications, camera, microphone or health access in your device settings.
Depending on where you live, you may have additional rights (such as access, portability, correction, erasure, or to lodge a complaint with a regulator). To exercise any right, contact us at dev@medichive.in and we will respond as required by law.
10 Children
Medichive is intended for adults. An adult account holder may add and manage records for children in their family. We do not knowingly allow children to create their own accounts. If you believe a child has created an account, contact us and we will remove it.
11 Where your data is stored
Your data is primarily stored and processed on Google Cloud infrastructure in India (asia-south1). Some service providers (such as AI processing) may process limited data in other countries under appropriate contractual safeguards. By using the Services you understand your information may be processed in these locations.
12 Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app. Continued use of the Services after an update means you accept the revised policy.
13 Contact us
Questions about this policy or your data? We’re here to help.
- Email: dev@medichive.in
- Medichive · Kochi, Kerala, India