Medlens AI — Privacy Policy
Effective date: October 17, 2025
1. Introduction
Medlens AI (“Medlens AI”, “the App”, “the Service”) is committed to protecting the privacy and confidentiality of personal and health information. This Privacy Policy explains what information is collected, how it is used, how it is stored and protected, and the rights available to users.
2. Information Collected
Uploaded Medical Reports: PDFs, images, scans, and other files containing medical or health information provided by the user.
User Account Information: name, email address, specialty (e.g., pulmonologist, sleep specialist), and account credentials.
Device & Usage Data: IP address, device identifiers, operating system, app version, crash logs, usage telemetry and analytics to improve the Service.
Derived Data: AI-generated summaries, analyses, and risk scores produced from uploaded content.
3. How Information Is Used
Provide core services: analyze and interpret medical documents, generate clinical summaries and risk scores, and present results to the user.
Improve Models & Service Quality: training, evaluation, and improvement of algorithms and software (de-identified/aggregated where feasible).
Support & Communication: respond to user inquiries, send account-related notices and updates.
Security & Fraud Prevention: detect, investigate and prevent malicious activity or misuse.
4. Legal Basis and Consent
Where applicable, processing is based on user consent and legitimate interests in providing and improving the Service. Users must obtain any required consents and authorizations to upload protected health information.
5. Data Sharing and Third Parties
Medlens AI may share information with:
Service providers required to operate the App (secure, contractually bound third parties such as cloud hosts, OCR/NLP providers, analytics, and identity providers).
Legal and regulatory authorities when required by law or to protect rights and safety.
Third parties are required to implement appropriate safeguards and are limited to processing data on Medlens AI’s behalf.
6. Data Retention and Deletion
Uploaded reports are retained only as long as necessary for processing and for the retention period stated to users (e.g., 30 days) unless the user explicitly saves or requests longer storage. Users may request correction or deletion of their data; deletion requests will be processed within a reasonable timeframe, subject to legal and operational constraints.
7. Security Measures
Encryption in transit (TLS) and at rest for stored data.
Access controls, authentication, and role-based permissions to limit access to authorized personnel.
Regular security assessments, employee training, and incident response procedures.
Measures to support compliance with applicable data protection laws (e.g., HIPAA, GDPR) where claimed.
8. User Rights
Depending on jurisdiction, users may have rights including:
Access: obtain a copy of personal data held by Medlens AI; Correction: request correction of inaccurate or incomplete data; Deletion: request deletion of personal data; Restriction/Objection: restrict or object to certain processing activities; Portability: request a machine-readable copy of data.
To exercise rights or for privacy-related inquiries, contact: support@mdlens.ai.
9. Children’s Privacy
The Service is not intended for children under 13 (or higher age where required). Do not upload information for children without parental authorization.
10. International Transfers
Data may be processed or stored in jurisdictions outside the user’s country. Medlens AI will implement appropriate safeguards for international transfers as required by applicable law.
11. Changes to This Policy
This policy may be updated to reflect changes in practices, services, or legal requirements. Continued use of the App after updates indicates acceptance of the revised policy. Material changes will be communicated via the App or email when feasible.
12. Contact Information
For questions, requests, or privacy concerns: support@mdlens.ai