Privacy Policy

We take privacy seriously because we're a health-adjacent platform. This policy explains exactly what we collect, why, and who sees it.

Last updated: April 2026 · Version 1.0

Contents

  1. Who we are
  2. What information we collect
  3. Why we collect it
  4. Who sees your information
  5. How we handle Protected Health Information
  6. How long we keep your data
  7. Your rights
  8. How we protect your data
  9. Cookies and tracking
  10. Children's privacy
  11. State-specific rights (CA, VA, CO)
  12. Changes to this policy
  13. Contact us
The short version: Medicin.io LLC is a technology platform. We collect only what's necessary to connect patients with independent healthcare providers. We don't store clinical records, don't sell your data, don't run ads on your information, and don't share with third parties except as needed to run the platform (like Stripe for payments, Twilio for calls).

1. Who We Are

This Privacy Policy applies to Medicin.io LLC, a Delaware limited liability company ("Medicin," "we," "our," or "us") and the Medicin™ platform accessible at medicin.io and associated applications.

Medicin is a technology infrastructure platform. We are not a healthcare provider, medical practice, or clinical entity. We connect users to independent, licensed healthcare providers ("Providers") who operate under their own professional licenses and insurance.

2. What Information We Collect

We collect only information necessary to operate the platform. Specifically:

Information you provide:

Information we generate:

What we deliberately do NOT collect or store:

3. Why We Collect It

Every category of data above is collected for one or more of the following purposes:

We do not sell your information. We do not rent it. We do not use it for advertising.

4. Who Sees Your Information

Your Provider: The independent healthcare provider matched to your session sees your name, phone number, state, age, relationship context, and your written description of your concern. They use this to provide you with clinical care.

Our service providers (subprocessors): We use a small number of trusted third parties to operate the platform. Each has a signed Business Associate Agreement (BAA) where applicable or a Data Processing Addendum:

These subprocessors are contractually prohibited from using your data for their own purposes.

Legal compliance: We may disclose information if compelled by valid legal process (subpoena, court order, warrant) or if we believe in good faith that disclosure is necessary to prevent imminent harm, fraud, or violation of our Terms of Service. When lawfully permitted, we will notify you of such requests.

Business transfers: If Medicin is acquired, merges, or sells its assets, your information may transfer to the successor entity, subject to the protections of this Privacy Policy.

5. How We Handle Protected Health Information (PHI)

When you use Medicin, certain information you provide may constitute Protected Health Information under HIPAA. Medicin operates as a Business Associate under HIPAA with respect to the Providers on our platform.

Our data architecture is designed around a minimization principle: we capture the least amount of PHI necessary to facilitate your connection. Clinical observations, diagnoses, treatment plans, and prescriptions are recorded by your Provider in their own independent records system — not on Medicin servers.

The written "concern" you submit in the intake form is routed to your Provider and stored on our platform to generate a receipt and administrative record. It is encrypted at rest and in transit.

For a detailed discussion of PHI handling, see our HIPAA Business Associate Agreement.

6. How Long We Keep Your Data

You may request earlier deletion by contacting us (see Section 13). We will honor such requests except where we are legally required to retain specific records.

7. Your Rights

Regardless of where you live in the United States, you have the right to:

To exercise any of these rights, email us at privacy@medicin.io. We verify identity before fulfilling requests. We will respond within 30 days.

8. How We Protect Your Data

No system is perfectly secure. If we discover a data breach affecting your information, we will notify you within 60 days as required by HIPAA and applicable state laws.

9. Cookies and Tracking

Medicin uses a minimal set of cookies and browser storage, limited to:

We do not use third-party advertising cookies, social media tracking pixels, or behavioral retargeting. We do not sell cookie data.

10. Children's Privacy

Medicin is not directed to children under 13 and we do not knowingly collect information from children under 13. A parent or legal guardian may use the Medicin platform on behalf of a minor; in such cases, the parent/guardian is the account holder and is responsible for the information provided.

If we learn that we have collected information from a child under 13 without parental consent, we will delete it promptly. Parents may contact us at privacy@medicin.io with concerns.

11. State-Specific Rights

California residents (CCPA / CPRA): In addition to the rights listed in Section 7, you have the right to know what categories of personal information we collect, the right to opt out of "sale" or "sharing" of personal information (we do neither), and the right to non-discrimination for exercising your privacy rights. You may designate an authorized agent to submit requests on your behalf.

Virginia residents (VCDPA): You have the right to access, correct, delete, and obtain a copy of your personal information. You may also appeal our response to your privacy request.

Colorado residents (CPA): You have the same rights as Virginia residents and may opt out of profiling that produces legal or similarly significant effects.

To exercise any state-specific right, email privacy@medicin.io and identify the state where you reside.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, legal requirements, or services. When we make material changes, we will:

13. Contact Us

For any privacy-related question, concern, or request:

We respond to privacy requests within 30 days. For urgent security issues, use the subject line "URGENT SECURITY" for expedited handling.

A note on what this policy doesn't cover: This policy covers information collected by Medicin. It does not cover information your independent Provider collects, records, or maintains in their own clinical records system. Your Provider has their own obligations under HIPAA and state law regarding your clinical records. Ask your Provider directly about their privacy practices.