Privacy

Privacy Policy

This Privacy Policy explains how iMed Care Coordination (“iMed”) accesses, collects, uses, shares, protects, retains, and deletes personal and sensitive information across its website, web app, mobile apps, APIs, and institution-managed device workflows.

Information iMed handles

  • Website contact requests submitted through the public contact form.
  • Account identifiers, institution membership, and role-based access state.
  • Care-operation content such as requests, notes, alerts, device assignments, and voice-session records.
  • Care requests, messages, staff notes, alerts, voice audio, transcripts, summaries, AI or translation outputs, and other content submitted or created while using enabled workflows.
  • Device and technical data such as app and browser version, operating system, language, network and IP information, diagnostic and security logs, notification tokens, and institution-managed device identifiers or assignments.

How information is used

  • To route each signed-in user to the workspaces and actions they are allowed to use.
  • To let authorized institution staff review, assign, forward, and audit care work.
  • To respond to website inquiries and improve product reliability, security, and support.
  • To operate enabled voice, transcription, translation, summarization, classification, and AI-assisted workflows. These tools support operations and are not used as autonomous medical decision-makers.
  • To deliver staff alerts and account, security, service, or support communications; troubleshoot performance; prevent fraud or abuse; and comply with law.

Sharing and retention

  • Institution data is scoped to the institution that owns the workflow.
  • Service providers are used only to operate infrastructure, authentication, messaging, analytics, translation, and AI-supported workflows.
  • Operational data is retained according to the configured institution and deployment requirements.
  • Information may be disclosed to the institution responsible for the workspace and to users authorized by its role and access controls. iMed also uses service providers for cloud hosting, databases, authentication, messaging and push delivery, diagnostics, support, translation, voice, transcription, and AI processing.
  • Information may be preserved or disclosed when reasonably necessary to comply with law or valid legal process, protect users or the service, investigate abuse, establish or defend legal claims, or complete a merger, financing, acquisition, or transfer with legally required notice and safeguards.
  • iMed does not sell personal or sensitive information and does not use it for third-party advertising or cross-context behavioral advertising.

Device permissions and sensitive access

  • iMed requests access only when a related feature is used: the microphone for realtime voice care sessions; the camera, where enabled, to scan setup codes or add visual context; and notifications for staff alerts. The current app does not request location, contacts, SMS, Health Connect, activity-recognition, or health-device sensor access. Operating-system permission prompts appear before access, and permission can be refused or withdrawn.

Your choices and privacy requests

  • Depending on role and applicable law, users may review or update account information in iMed or through their institution administrator, disable optional device permissions in operating-system settings, and request access, correction, or deletion through iMed or the responsible institution. The account-deletion process below is available both in-app and on the web.

Security and international processing

  • iMed uses HTTPS encryption in transit, role- and institution-based access controls, database security rules, audited service boundaries, and protected credential or notification-token storage. No system is completely secure. Information may be processed in countries where iMed or its service providers operate, subject to contractual, technical, and legal safeguards appropriate to the processing.

Scope, children, changes, and contact

  • Effective July 29, 2026. iMed is an institution-provisioned, invite-only service and is not directed to children to create independent accounts. A responsible institution, parent, or guardian must authorize use where applicable law requires it. iMed may update this Policy and will post the revised effective date on this page.
  • Contact iMed about privacy through the public inquiry form.

Account deletion

  • Open the secure deletion process with a 30-day undo period.
  • You must sign in before requesting account deletion.
  • Select “Request account deletion” to start the request.
  • Then select “Confirm account deletion” to submit the request.
  • This starts a 30-day period before the account is deleted.
  • You can sign in during the 30-day period and undo the deletion request.
  • After 30 days, iMed deletes or anonymizes account data that is not retained for legal, security, or operational records.