MidLune
Back to MidLune

Privacy

Privacy policy

Effective 30 September 2026

MidLune exists to help save lives through early detection. That only works if you trust us with your health record, so we keep the rules simple: your health data stays yours, it is never sold, and you can take it or delete it at any time.

1. Our four promises

  • We never sell, rent or trade your health information to advertisers, data brokers, employers or insurers.
  • There are no third-party advertising trackers or behavioural profiling scripts in MidLune.
  • Your questions to the MidLune assistant are not used to train public AI models.
  • You can export everything, or permanently delete everything, from Settings without contacting us.

2. Who we are

MidLune provides a personal health companion available to people in Canada and the United States. In this policy, "we", "us" and "MidLune" refer to [LEGAL ENTITY NAME], [ADDRESS], and "you" refers to the account holder.

For privacy questions, corrections or data requests, write to info@midlune.com. We answer within 30 days.

3. What we collect

  • Account details: your email address, display name, language, time zone, and sign-in method.
  • Health information you enter: medicines, doses and schedules, adherence logs, lab results, vitals, symptom check-ins, screenings, vaccines, appointments, care team contacts and notes.
  • Photos and documents you upload, such as a medicine bottle label, a lab report or a meal photo, along with the text read from them.
  • Connected device data, only if you link a wearable or health platform: steps, sleep, heart rate and similar readings.
  • Subscription and billing status. Card numbers are handled by our payment processor and never stored by MidLune.
  • Technical and security records: sign-in times, device type, approximate region, and error diagnostics.

4. Why we use it

We use your information only to run the service you asked for and to keep it safe.

  • To show your schedule, send reminders and record what you have taken.
  • To run safety checks between medicines, supplements and your recorded conditions.
  • To surface screening and vaccine guidance appropriate to your age and history.
  • To turn lab reports and readings into trends and a one-page summary for your clinician.
  • To answer the questions you ask the MidLune assistant using your own record.
  • To handle billing, prevent fraud and abuse, and meet our legal obligations.

5. How the assistant handles your data

When you ask a clinical question, the relevant parts of your record are sent to a processing provider under contract to generate the answer, then discarded. Providers are contractually barred from using your content to train their models, and we do not use your record to train models of our own.

The assistant produces information, not diagnosis. Answers are labelled as such and always point back to your clinician.

6. When information leaves MidLune

We only disclose your information in these situations:

  • When you ask us to: a share link you create, a report you export, or a care-team member you invite. You choose what is included and can revoke access at any time.
  • To service providers who host, secure, process payments for, deliver email for, or provide AI processing to MidLune, each bound by contract to protect it and use it only for us.
  • When required by law, a valid court order, or to prevent serious and imminent harm to someone's safety.
  • In a business transfer, in which case the buyer is bound by this policy and you are notified in advance.

7. Service providers

We work with a small number of providers, each bound by contract to protect your information and use it only to run MidLune:

  • Hosting and security: Cloudflare, which runs the service and sets one strictly necessary security cookie to block abuse.
  • Database and sign-in: Supabase, which stores your record and handles authentication.
  • Payments: Stripe, which processes your card. MidLune never sees or stores full card numbers.
  • AI processing: Google and OpenAI models, reached through a secure gateway, read medicine labels, lab reports and the questions you ask. They may not use your content to train their models.
  • Site analytics: Lovable analytics, which counts visits and page views. It is never used for advertising.

8. How we protect it

  • Encrypted in transit with TLS 1.3 and at rest with AES-256.
  • Access controls that scope every record to its owner, so no other account can reach your data.
  • Optional device lock (Face ID, Touch ID or passcode) for sensitive sections such as women's and men's health.
  • Staff access is restricted, logged and used only when needed to operate or repair the service. Administrators see aggregate and account-level metadata, never your health records.
  • If a breach ever creates a real risk of significant harm, we notify you and the appropriate regulator without undue delay.

9. How long we keep it

We keep your record while your account is open. If you delete your account, your health records are erased from active systems immediately and from encrypted backups within 30 days. Limited billing and security records are retained where tax or fraud-prevention law requires it.

If your account stays inactive for 24 months, we contact you before removing it.

10. Your rights and controls

  • Access and portability: download your full record in one tap from Settings.
  • Correction: edit or remove any entry yourself, at any time.
  • Deletion: erase a single record, a whole module, or your entire account.
  • Withdraw consent: disconnect a device, turn off a module, or close your account.
  • Complain: contact info@midlune.com first. You may also contact the Office of the Privacy Commissioner of Canada, your provincial commissioner, or your state attorney general.

11. Canada and the United States

For Canadian residents, we handle personal health information in line with PIPEDA and applicable provincial law, including Ontario's PHIPA, Quebec's Law 25, and the Alberta and British Columbia PIPAs.

For United States residents, we apply HIPAA-level safeguards to your data and honour the access, deletion and opt-out rights given by state privacy laws such as the CCPA/CPRA. MidLune does not sell or share personal information for cross-context behavioural advertising.

Data may be processed on servers in Canada and the United States. Wherever it is processed, it remains protected by this policy.

12. Children

MidLune is for adults. You must be 18 or older, or the age of majority where you live, to hold an account. We do not knowingly collect information from children, and we delete it promptly if we learn we have.

13. Changes to this policy

If we make a change that meaningfully affects your privacy, we tell you in the app and by email before it takes effect, and the date at the top of this page changes.

Questions about your privacy? Write to info@midlune.com.

Other documents