Security & privacy

Health record privacy.
Built into every step.

MedVault’s July 2026 privacy policy states that personal information is not sold and health information is not shared with advertisers. The product also describes encryption in transit, access-controlled cloud storage and consent controls.

Clear controls

Privacy language people can actually understand.

Privacy is treated as a core feature, with plain-language explanations placed next to the actions they affect.

Encrypted transmission

MedVault states that documents are encrypted in transit using HTTPS/TLS.

Access-controlled storage

The published policy describes uploaded documents as access-controlled at rest in cloud storage, with production access restricted to authorized personnel.

Consent & privacy controls

Users can review and manage MedVault permissions through the app’s Profile → Consent & privacy area.

Account and data deletion

The current policy says active records are removed when an account is deleted and encrypted backups are purged within 30 days, subject to legal retention requirements.

Trust architecture

Privacy should be visible in the product flow.

Protection and control stay visible at the moments that matter most: upload, storage, AI-assisted processing and deletion.

01 · Upload

Encrypted in transit

HTTPS/TLS protects document transmission according to the published policy.

02 · Storage

Access controlled

Uploaded documents are described as access-controlled at rest with restricted production access.

03 · Control

Delete when needed

The published policy describes active-record deletion plus a backup purge window subject to legal requirements.

No sale of personal informationHealth information not shared with advertisersConsent controls in productAccount deletion path
Trust is part of the interface

A health product should earn confidence before asking for data.