Privacy Policy
Last updated 8 October 2026
This policy explains what MedProfile – Health Monitoring (“MedProfile”) collects, where your health records are kept and what you can ask us to do about it. Health data is the most sensitive data there is, so MedProfile stores it on your device by default and sends it to our servers only when you turn on cloud backup or a family account.
1.Who we are
MedProfile – Health Monitoring is operated by Highglossy FZE, a company registered in the United Arab Emirates, with its registered office at Al Shmookh Business Center, One UAQ, UAQ Free Trade Zone, Umm Al Quwain, U.A.E. (“we”, “us”). For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the personal data described here.
Questions, requests and complaints: privacy@highglossy.com.
2.The short version
- Your records stay on your device unless you say otherwise. Diagnoses, photos, test results, medication and pain logs are stored locally. Cloud backup and the family account send them, encrypted, to our servers and only after you turn those on.
- Health data is processed only with your explicit consent, which you give when you enable cloud features and can withdraw by turning them off or deleting the account.
- We do not use health data for advertising, profiling or research, and we never sell it.
- We do see: your account email, subscription status, notification tokens and crash reports.
3.What stays on your device
- Health records without cloud backup. Everything you log stays in the app's local storage; uninstalling the app deletes it.
- Photos and documents. Read from your library or camera only when you attach them to a record.
- Reminders. Pill and appointment reminders are scheduled by the operating system on the device.
4.What we collect, and why
Every category we hold, why we hold it, the lawful basis and how long we keep it:
- Account: email address or sign-in provider identifier, display name — To sign you in, restore your data on a new device and share a family account. Basis: Contract (Art. 6(1)(b) GDPR). Kept: until you delete the account.
- Health records (only with cloud backup or a family account): body-map entries, diagnoses, examination history, photos and documents, medication schedule, appointment calendar, pain log — To back up your records and show them to the family members you choose. Basis: Explicit consent (Art. 9(2)(a) GDPR). Kept: until you delete the record, turn cloud features off or delete the account.
- Family profiles: names and records of family members you add — To let one subscriber keep records for several people. You confirm you have their permission. Basis: Explicit consent (Art. 9(2)(a) GDPR). Kept: until you delete the profile or the account.
- AI avatar inputs: the photo you submit for an avatar — To generate the avatar with our AI processor; the input is deleted once the avatar is rendered. Basis: Consent (Art. 6(1)(a) GDPR). Kept: until the avatar is generated.
- Push tokens (only if you allow notifications) — To deliver reminders that the device cannot schedule itself, such as family updates. Basis: Consent (Art. 6(1)(a) GDPR). Kept: until the token is revoked or goes stale.
- Subscription records: plan, status, expiry, store product and transaction identifiers, a random Adapty profile ID — To give you the PRO features you paid for and restore them on a new device. Basis: Contract (Art. 6(1)(b) GDPR). Kept: life of the account, then 7 years where tax law requires.
- Crash and error reports: stack traces, device model, OS version, app version; never the content of a record — To find and fix defects. Basis: Legitimate interests (Art. 6(1)(f) GDPR). Kept: 90 days.
- Support correspondence: your email address and what you write to us — To answer you. Basis: Legitimate interests (Art. 6(1)(f) GDPR). Kept: 24 months.
We do not collect an advertising identifier, we do not track you across other apps or websites, and we run no advertising SDK. Health records are encrypted in transit and at rest; our staff do not read them except when you ask us to help with a specific record.
5.Who we share it with
We use a small number of processors. Each is bound by a data processing agreement and may use the data only to provide the service to us.
- Adapty — subscription management. Receives a random account identifier and purchase events so your plan can be applied and restored.
- Apple and Google — payment processing for in-app purchases. They take the payment; we never see your card number or billing address. Your relationship for the payment itself is with the store, under its own privacy policy.
- Google Firebase Cloud Messaging — delivery of push notifications. Receives the notification token and the notification text, which never contains a diagnosis or a record.
- AI image provider — generates avatars from the photo you submit. Receives only that photo; it is contractually barred from keeping it or training on it.
- Crash reporting (Sentry, hosted in the European Union) — receives stack traces, device model, OS and app version. Crash reports carry no IP address and no user identifier.
- Our hosting provider — runs the servers and encrypted storage holding accounts and backed-up records.
We also disclose data where we are legally compelled to: to comply with a legal obligation, to protect our rights or property, to investigate possible wrongdoing in connection with the app, or to protect the safety of users or the public.
Within a family account, the members you invite see the profiles and records you share with them. We never share health records with insurers, employers, advertisers or anyone else.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6.How long we keep things
The section above gives the retention period for each category. Turning cloud backup off deletes the backed-up records from our servers within 30 days; deleting the account deletes everything that references it. Backups are purged on a rolling 30-day cycle. We retain subscription records where tax or accounting law obliges us to.
7.Where your data is processed
Our servers and those of our processors may be located outside your country, including in the United Arab Emirates and the European Union. Where personal data leaves the UK or the EEA, the transfer relies on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or an adequacy decision, as applicable.
8.Your rights
Wherever you live, you can ask us to:
- Give you a copy of the personal data we hold about you, in a portable format.
- Correct anything inaccurate.
- Delete your data. You can do this yourself in the app; we will also do it on request.
- Restrict or object to processing we carry out on the basis of legitimate interests.
- Withdraw consent, for example for notifications by turning them off in your device settings, without affecting what we did before you withdrew it.
Write to privacy@highglossy.com. We respond within 30 days.
If you are in the UK or the EEA, you may also complain to your data protection authority: in the UK the Information Commissioner's Office, in the EEA the supervisory authority where you live.
9.California residents
Under the CCPA as amended by the CPRA, in the last 12 months we collected the categories described above for the business purposes stated there, from you and from your device. We have not sold personal information and we have not shared it for cross-context behavioural advertising. We have no actual knowledge of selling the personal information of consumers under 16.
You have the right to know, delete, correct, and to be free from discrimination for exercising those rights. Exercise them at privacy@highglossy.com.
10.Children
MedProfile – Health Monitoring is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with data, write to privacy@highglossy.com and we will delete it.
11.Security
Health records are encrypted in transit with TLS and at rest on our servers. Access to production systems is limited to the engineers who run them and is logged. On the device, the app can be locked behind the device passcode or biometrics. No system is perfectly secure, and we will not claim otherwise; if a breach affects your personal data, we will notify you and the competent authority as the law requires.
12.Changes
We will update this policy when what we do changes. The date at the top always reflects the current version. If a change materially reduces your rights or widens what we collect, we will tell you in the app before it takes effect.
13.Contact
Highglossy FZE, Al Shmookh Business Center, One UAQ, UAQ Free Trade Zone, Umm Al Quwain, U.A.E.
Support: support@highglossy.com · Privacy: privacy@highglossy.com