Local records, optional cloud scanning. Medication records are stored on your device. When you choose AI scanning, the label photo leaves your device for processing by Google. A photo may contain identifying and health information.
This notice explains how Varaporn Suwanthevarat, operating as MedAi in Thailand, processes data in the MedAi app and at meetmedai.com. Reading this notice is not consent to optional AI processing.
1. Controller and contact
Controller: Varaporn Suwanthevarat (MedAi). Contact address: 39/642 Nichada-Thani, Raveevan, Samakee Road, Bang Talat, Pak Kret, Nonthaburi 11120, Thailand. Email: support@meetmedai.com.
Data protection officer. We have assessed section 41 of the PDPA and have not appointed a DPO, on the basis that MedAi is operated by one person and does not process sensitive personal data on a large scale. We review this as the service grows, and will appoint and publish a DPO if that assessment changes. Privacy questions reach the controller at the address above.
2. Information and purposes
- Local health records: medicine names, doses, schedules, course changes, allergies, notes, photos, stock and dose history support your chosen reminder and recordkeeping functions. Core records use AES-256-GCM encryption; saved medicine photos use ChaCha20-Poly1305 with a key derived from the local storage key. Keys are managed through the operating system’s secure storage. Settings and system alarm/display information are not all covered by this application-level encryption. Names and doses may appear in notifications and on the lock screen; manage their visibility in device settings.
- AI label photos: after separate consent, the entire selected or captured label image and language are sent through Firebase Cloud Functions in the United States (us-central1) to Google’s Gemini API. The image itself may reveal your name, prescription, pharmacy, birth date or other identifiers. We do not automatically redact it. Cover unnecessary personal details before capture while keeping medicine instructions readable. We do not upload your saved medication list as part of a scan. Photos attached to saved records remain on your device until removed.
- Account and security: Firebase Authentication creates a pseudonymous installation account. Its UID, App Check attestation and technical request information support access control, fraud prevention and scan quotas. A random UID does not make all associated data anonymous. These services can start before you use AI.
- Purchases: Apple or Google handles payments. RevenueCat processes app-user identifiers, purchase and entitlement information; Firebase stores subscription status and scan counters. We do not receive your card number. Store and provider records have their own retention obligations.
- Updates and operations: Shorebird distributes app patches. Providers may process app/build versions, operating-system information, device identifiers, IP addresses, timestamps and diagnostic information to deliver and secure their services. We do not promise that IP addresses are masked.
- Support and website: if you email us, we receive your address and message. Avoid sending unnecessary medical information. Hosting and external font services may receive IP addresses and browser/request information. The website uses local storage for language and text-size preferences and session storage for navigation.
- Consent records: the app stores the AI notice version, choice, language, time and age/guardian confirmation locally. A scan request includes the consent version. This is self-attestation, not identity verification.
- No analytics or advertising: MedAi contains no advertising network, no analytics or attribution SDK and no behavioural tracking, and we do not sell or share personal data for advertising. The website sets no advertising or analytics cookies. The AI reads a label and returns a transcription for you to check; it is not used to profile you, score you, or make any decision about you.
3. Legal bases and your choices
Optional cloud processing of health-related photos uses explicit consent under PDPA sections 19 and 26. Declining does not prevent manual medication entry or local reminders. Withdraw consent for future uploads in Settings > Privacy > Withdraw AI photo consent. This cannot recall requests already sent. Other processing necessary to provide requested services relies, where applicable, on contract performance; service security relies on legitimate interests, and required records on legal obligations. These bases do not replace the additional requirements for sensitive health data.
4. Providers and overseas processing
Firebase/Google Cloud, Google Gemini, RevenueCat, Apple/Google stores, Shorebird and Zoho (which hosts our support mailbox) process the categories above. Cloud processing can take place outside Thailand, including the United States and other countries where providers operate. Their protections may differ from Thailand’s. The AI consent notice explains overseas processing; where transfer consent is relied upon, PDPA section 28(2) applies. Applicable processor agreements and other lawful safeguards must also be maintained; encryption alone is not a transfer mechanism.
Provider information: Google privacy, Gemini terms, RevenueCat privacy, Shorebird privacy, Zoho privacy.
5. Retention and deletion
Our scan function does not save image payloads or AI responses in a database, and prompt storage is switched off in our Google project for the API method the app calls, so no copy of your scan is kept there. This is separate from provider retention: Google documents 55-day retention of prompts, context and outputs for abuse monitoring, with authorized review of flagged content. We use the paid tier, whose terms state that Google does not use prompts or responses to improve its products. See Google’s abuse-monitoring policy. We do not promise immediate erasure at every provider.
Local records remain until you remove them. Settings > Delete All Data first attempts cloud account-data deletion and requires connectivity. If that fails, local records remain so you can retry. The app then removes reminders, photos, encryption keys and preferences and attempts Firebase account deletion. Partial failures are reported. Continuing to use the app may create a new pseudonymous account. Deletion does not cancel a store subscription or automatically erase provider security logs, purchase records, emails, or copies you saved elsewhere. Contact us for assistance with these records.
Lawful retention beyond the periods in the table may continue only where a dispute or a statutory duty requires it, and only for as long as that reason lasts. Device backups and copies outside the app are controlled by the device owner and their provider; we cannot promise their removal through the app.
The periods below apply. Where a period depends on a provider rather than on us, that is stated rather than implied.
- Data — Retention period
- Medication records, schedules, dose history, allergies, photos, stock and your AI consent record — Held on your device until you delete them or use Settings > Delete All Data. No automatic expiry. Finished courses move to History and remain until deleted from there.
- AI label image and the model’s response — Not stored by us — prompt storage is disabled in our Google project. Google documents up to 55 days’ retention for its own abuse monitoring.
- Account record (pseudonymous UID, plan, monthly scan counter, subscription status) — While the installation account exists; deleted when you use Delete All Data.
- Cloud Functions operational logs (timestamps, status codes, UID, IP) — 30 days, the configured Google Cloud Logging period.
- Support email — Held in our Zoho mailbox for as long as that mailbox exists. We do not run an automatic deletion schedule for support mail, so a message you send us stays until it is deleted by hand. You can ask us to delete your correspondence at any time under section 7, and we will do so within 30 days unless a legal obligation or an active dispute requires us to keep it. A deleted message may remain recoverable at Zoho for a short period set by that provider.
- Purchase and entitlement records at Apple, Google and RevenueCat — Set by those providers under their own terms and accounting obligations; deleting your MedAi data does not remove them.
Change of operator. If MedAi is transferred to a company or another operator, this notice and your choices transfer with it, and we will tell you before any change of controller takes effect. Where the law requires fresh consent, we must obtain it.
6. Security and incidents
Organisational measures. MedAi is operated by one person, who is the only individual with access to the backend console and provider accounts. Those accounts use multi-factor authentication. No employee, contractor or support agent has access to your records, and we do not have any means of reading the medication data held on your device. Provider access is reviewed when the set of providers changes.
We use encrypted core local storage, HTTPS transport, access controls and backend attestation. HTTPS is not end-to-end encryption against the processing provider: Google must process readable images. No system is risk-free. We assess suspected breaches and make required notifications to the PDPC and affected people under applicable law, including the applicable 72-hour regulatory notification requirement.
7. Your rights
Subject to the PDPA’s conditions and exceptions, you may request access, correction, erasure, restriction, objection and portability, withdraw consent, or complain to the PDPC. You can view and edit local records in the app. Email support for other requests; we may request proportionate verification and will respond within 30 days, as section 30 of the PDPA requires, telling you if a permitted extension applies. We cannot retrieve local records that you have deleted. Privacy contact: Varaporn Suwanthevarat at the address and email above.
You may also complain to the Office of the Personal Data Protection Committee (PDPC), 7th Floor, The Government Complex, Chaeng Watthana Road, Thung Song Hong, Lak Si, Bangkok 10210, Thailand — pdpc.or.th.
8. Age and updates
Users under 20 who are not sui juris need the consent of the holder of parental power, as section 20 of the PDPA requires, together with their supervision in using the app. AI scanning is restricted to users who confirm they are at least 18; those aged 18–19 must also confirm guardian consent. This does not verify age. We do not intend AI scanning for children. If a child’s data has been submitted without appropriate authorization, contact us. When AI processing materially changes, the consent notice version will change and the app will ask again before uploading. Check this page for other notice updates.