Privacy Policy
Last updated: 6 August 2026
MedTrack ("we", "us", "our") is operated from Sweden and is subject to the GDPR. This Privacy Policy explains what personal data we process, why, and your rights.
1. Data Controller
Controller: Abdullah Gültepe (individual), Sweden. Contact: [email protected]
2. What We Process
- Local app data (default): medications, schedules, dose logs, profiles, preferences — stored in your browser/device (e.g. localStorage) unless you enable sync
- Sync account (optional): opaque user id, device ids/tokens, recovery code hash, encrypted or structured payload of the data you choose to sync
- Push notifications (optional): browser push subscription endpoints needed to deliver reminders you enable
- Technical logs: basic server logs (IP, user-agent, timestamps) for security and reliability — short retention
- Payments (when Premium is live): handled by Paddle as Merchant of Record; we receive subscription status linked to your user id, not full card numbers
3. Special category / health-related data
Medication names and dose history can reveal health-related information. We process this only to provide the tracking Service you request. Default storage is on your device. Cloud sync is optional and under your control. We do not use this data for advertising or sell it.
4. Legal bases (GDPR)
- Contract / requested service: providing local tracking, optional sync, and reminders you enable
- Legitimate interests: securing the Service, preventing abuse, basic reliability logging
- Legal obligation: where tax/accounting rules apply to paid subscriptions
- Consent: optional browser notifications and similar device permissions
5. How We Use Data
We use data only to run and improve MedTrack (schedules, sync across your devices, reminders, support). We do not sell personal data or use it for third-party marketing.
6. Infrastructure & processors
Depending on features you use:
- Hosting (VPS / EU-oriented infrastructure) — application and optional sync database under our control
- Web Push — browser push services when you enable notifications
- Paddle — payments/MoR when Premium checkout is enabled
7. Retention
Local data remains until you clear browser storage or uninstall. Sync account data is kept while the account is active. If you delete the cloud account (or admin trash/purge), server-side sync data is removed or moved to a short-lived recoverable trash then permanently deleted on purge. Technical logs are kept briefly for security.
8. Cookies & local storage
MedTrack uses localStorage/sessionStorage for app state, preferences, sync identity, and landing session flags. We do not use third-party advertising cookies or analytics trackers. No non-essential marketing cookie banner is required for that reason.
9. Your GDPR rights
If you are in the EEA/UK you may have rights to access, rectify, erase, port, restrict, or object. You can export JSON from Settings and delete local or cloud data from the app. For other requests: [email protected]. You may lodge a complaint with your authority (Sweden: IMY — Integritetsskyddsmyndigheten).
10. Security
Traffic uses HTTPS. Sync uses device tokens; recovery codes are stored hashed where applicable. Access to server data is limited to operating the Service. No method is 100% secure — keep your device locked and recovery codes private.
11. International transfers
We aim to host primary Service infrastructure in the EU/EEA. Some subprocessors (e.g. global push or payment networks) may process data outside the EEA with appropriate safeguards where required.
12. Children
The Service is not directed at children under 16. Do not use MedTrack if you are under 16.
13. Changes
We may update this policy. The date at the top will change; significant updates may also be noted in the app.
14. Contact
Privacy questions or data requests: [email protected]