MediFlow AI
Legal

Privacy Policy

This policy describes what data MediFlow AI collects, how it's used, and how it's protected. It reflects what the platform actually does today.

What We Collect

  • Account information for registered users (name, email, hashed password, role).
  • Patient health information entered by clinical staff — including demographics, vitals, symptoms, AI-assisted clinical assessments, prescriptions, and counselling records.
  • Operational metadata needed to run the platform, such as appointment schedules, reminders, and notification records.

How We Use It

  • To run the core clinical workflow: registering patients, recording vitals and symptoms, generating AI-assisted clinical assessments, drafting and reviewing prescriptions, and scheduling follow-ups and reminders.
  • To maintain a complete audit trail of actions taken on patient records, for accountability and compliance purposes.
  • We do not sell patient or account data to third parties.

Subscription and Payment Information

  • MediFlow AI may collect information necessary to process and verify manual subscription payments, including the selected subscription plan, payment method, transaction or reference information, payment amount, and payment proof submitted by the user.
  • This information is used to verify payments, manage subscriptions, prevent fraudulent or duplicate payment submissions, and provide access to subscribed services.

Payment Verification

  • Manual payment submissions remain pending until reviewed and verified by an authorized MediFlow AI administrator. Submission of payment information does not automatically activate a subscription.
  • MediFlow AI uses manual payment verification and does not process card or bank payments automatically. We do not store complete bank or card credentials.

Email Communications

  • MediFlow AI may use the email address associated with a user's account to send important service-related communications, including payment submission confirmations, payment verification updates, subscription activation notifications, account-related notifications, and other essential service messages.

Data Storage & Security

  • Data is stored in a PostgreSQL database. Connections to the database are encrypted in transit.
  • Account passwords are hashed with bcrypt and are never stored in plain text.
  • Access to the API is authenticated with JWTs and enforced by role-based access control, so accounts can only reach the data appropriate to their role.
  • All create, update, and review actions on patient records are logged in an audit trail.
  • MediFlow AI takes reasonable technical and organizational measures to protect account, payment-related, and healthcare information from unauthorized access, alteration, disclosure, or misuse.

Third-Party Services

  • MediFlow AI uses Groq, a third-party AI inference provider, to process clinical data (vitals, symptoms, and medications) when generating an AI clinical assessment or patient counselling content. This processing is limited to what's needed to generate that specific output.
  • AI-generated clinical output is explicitly labeled as decision support and is intended to be reviewed by a licensed clinician before it informs care.

Your Rights

  • You can request access to the personal or patient data associated with your account.
  • You can request correction of inaccurate data or deletion of data where we are not required to retain it for clinical or legal record-keeping purposes.
  • To exercise any of these rights, contact us using the details below.

Contact

  • Questions about this policy or requests regarding your data can be sent through our contact page.

Have a question about your data, or want to make a request under this policy? Contact us.