Privacy controls
The privacy policy is the authoritative statement. This page is the practical version.
Usage analytics — off unless you say yes
MedJot asks once, plainly, with "No thanks" offered exactly as prominently as "Allow". Until you answer, nothing is collected. Change your mind at any time in Settings → General → Usage analytics.
What analytics can record
Events from a fixed list — "a report was started", "the frailty scale was opened", "an export failed" — each carrying only pre-defined values: which presentation type, which tool, which error area.
There is no free-text field anywhere in the system. It is not that report content is filtered out; there is nowhere for it to go. The server re-checks every event against that fixed list and discards anything that does not match.
What analytics never records
- Any part of a report, note, or anything you typed
- Patient details of any kind
- Your name, email address or phone number
What events are tagged with
Whether you were on Premium, your role and sector from the fixed list, your region, whether you belong to an organisation, and whether you were on web, iOS or Android. The server adds these from your account — your browser never sends them, so they cannot be faked or inflated by anything on the device.
Google's part
If you opt in, the same events also go to Firebase Analytics for aggregate reporting. Advertising is switched off: no Google Signals, no ad personalisation, no advertising cookies, IP anonymised. No identifier for your account is ever sent to Google. If you do not opt in, the Google analytics code is never loaded at all.
Opting out
Collection stops immediately, and the detailed event history recorded against your account is deleted. Anonymous daily totals with no identifier in them — "180 reports were started on 14 July" — remain, because they are no longer connected to you or anyone.
Detailed events are kept for up to 90 days regardless.
Email preferences
Product updates and offers and news are separate permissions, asked as separate questions, changeable in Account → Profile. Every email sent on those bases carries an unsubscribe route.
Email about your account itself — security, billing, things you must be told — is not affected.
Making a privacy request
Access, correction, deletion, export, or an objection to how we use your data: use the request form on the privacy policy page. It works whether or not you can sign in, which matters if you have already left.
We may need to verify your identity first. You can also complain to the ICO at ico.org.uk.
What we hold about you
Broadly: your profile, when you created the account and last signed in, your Premium status and Stripe customer reference, your free-report count and date (a count and a date, never the reports), your saved templates, your consent answers, and a small set of hashed anti-fraud signals.
Not your reports. Those never reach us.
Anti-fraud signals
To catch disposable and fraudulent accounts we process a deliberately short list at sign-in: a random device identifier your browser generates (stored as a one-way hash), a salted one-way hash of your IP address — not the address itself — a normalised form of your email, and flags for automatically generated-looking addresses or names.
No browser fingerprinting, no tracking pixels, no third-party trackers. None of it is ever combined with clinical content, which does not reach us anyway. These hashes are kept for 12 months from your last sign-in.
Accounts are not suspended by an automated decision alone — a person reviews first, and you can appeal. See Suspension and appeals.
The standing request
Do not enter patient-identifiable information into MedJot. No names, dates of birth, addresses or NHS numbers. Initials, ages and de-identified descriptions are the way to work. Every privacy protection in the app is stronger when there is nothing identifying in it to begin with.