Medule privacy notice

Who is responsible

The operator of this Medule instance is the data controller for the data the service stores: the operator decides how the service works, what it stores, for how long, and how it is secured. The family members and caregivers who use a care circle enter and share information as part of their own private, family care of one person — the law treats that personal use differently, but it never reduces the operator’s own responsibility for the platform.

Who this notice is about

Two kinds of people: the caregivers and family members with accounts, and the person being cared for— who usually has no account.

If you are the person being cared for

A care circle about you stores your name, date of birth, your medications and their schedules, notes about them, appointment and visit details (times, titles, locations), and a history of doses given. You did not enterthis data yourself — a family member or caregiver did, and it is possible to have a record about you that you have not seen. Medule asks the person who creates a circle to confirm that you agreed, or that they hold legal authority to decide for you (such as a power of attorney or guardianship) when you cannot consent, and records their answer. This public notice, and the expectation that your circle informs you or your representative, is how we make that transparent; we cannot contact you directly because the service holds no contact details for you. You or your representative can contact the operator (below) or any admin of the circle to see, correct, or erase the record.

Why we may hold this data

We rely on explicit consent: yours, if you are able to give it — or the documented decision of someone with legal authority to act for you if you are not. Consent can be withdrawn at any time, and withdrawal means the circle’s data can be erased (deleting a circle removes its data immediately). In a genuine emergency, the law also allows processing to protect a life; we never rely on that for day-to-day use.

Separately from the health information above, we rely on legitimate interests to keep basic figures about the service itself — how many accounts exist, how many were created recently, how many care circles there are, and totals such as how many doses were given or missed in the last day, how many appointments are coming up, and how many accounts are in a circle with an active medication. Alongside those instance-wide totals, the view lists one row per account — identified by a short reference rather than by an email address — showing the date the account was created, whether its address is verified, how many circles it belongs to, and the date it was last used. No medication name, dose note, appointment detail or patient name is shown. The operator also administers the server this service runs on, so this basis governs what the in-app view shows, not what the operator can technically reach.

If you have an account

We store your name, email, password (hashed), sign-in sessions (including IP addresses), notification settings, and a record of the actions you take in a circle. You can download all of it from your profile page, or at /api/me/export, and you can delete your account from the same page — see how Medule handles your data for exactly what deletion removes and what remains.

Where the data goes, and for how long

Everything runs on one EU server, with a short list of supporting services and defined retention periods — all stated plainly in how Medule handles your data. Nothing is sold, and there are no third-party analytics.

Your rights

Access, correction, erasure, portability, and withdrawal of consent — through the app where a control exists (export, account deletion, circle deletion), otherwise by contacting the operator. You also have the right to complain to your data-protection supervisory authority.

Contact

Reach the operator via the contact listed at /.well-known/security.txt.