Skip to main content

Privacy controls

The privacy policy is the authoritative statement. This page is the practical version.

Usage analytics — off unless you say yes​

MedJot asks once, plainly, with "No thanks" offered exactly as prominently as "Allow". Until you answer, nothing is collected. Change your mind at any time in Settings → General → Usage analytics.

What analytics can record​

Events from a fixed list — "a report was started", "the frailty scale was opened", "an export failed" — each carrying only pre-defined values: which presentation type, which tool, which error area.

There is no free-text field anywhere in the system. It is not that report content is filtered out; there is nowhere for it to go. The server re-checks every event against that fixed list and discards anything that does not match.

What analytics never records​

  • Any part of a report, note, or anything you typed
  • Patient details of any kind
  • Your name, email address or phone number

What events are tagged with​

Whether you were on Premium, your role and sector from the fixed list, your region, whether you belong to an organisation, and whether you were on web, iOS or Android. The server adds these from your account — your browser never sends them, so they cannot be faked or inflated by anything on the device.

Google's part​

If you opt in, the same events also go to Firebase Analytics for aggregate reporting. Advertising is switched off: no Google Signals, no ad personalisation, no advertising cookies, IP anonymised. No identifier for your account is ever sent to Google. If you do not opt in, the Google analytics code is never loaded at all.

Opting out​

Collection stops immediately, and the detailed event history recorded against your account is deleted. Anonymous daily totals with no identifier in them — "180 reports were started on 14 July" — remain, because they are no longer connected to you or anyone.

Detailed events are kept for up to 90 days regardless.

The AI tools, and what is stripped​

The AI features are the only route by which anything from a report leaves your device, and only when you press the button on one.

When you do, identifiers are removed twice — once in the browser before the request is sent, and again on our server before the prompt is built:

  • email addresses, UK phone numbers, NHS numbers and postcodes
  • dates of birth, written or numeric
  • names introduced by a title (Mrs Margaret Ellis) or a relationship word (her son Michael), reduced to initials

Your observations and clinical terminology are deliberately left intact — a redactor that mangles Sinus Tachycardia is one nobody would use. The patient is referred to only as "Pt".

Nothing you sent and nothing that came back is stored. See What gets sent, and what doesn't for the rule-by-rule account.

Email preferences​

Product updates and offers and news are separate permissions, asked as separate questions, changeable in Account → Profile. Every email sent on those bases carries an unsubscribe route.

Email about your account itself — security, billing, things you must be told — is not affected.

Making a privacy request​

Access, correction, deletion, export, or an objection to how we use your data: use the request form on the privacy policy page. It works whether or not you can sign in, which matters if you have already left.

We may need to verify your identity first. You can also complain to the ICO at ico.org.uk.

What we hold about you​

Broadly: your profile, when you created the account and last signed in, your Premium status and Stripe customer reference, your free-report count and date (a count and a date, never the reports), your saved templates, your consent answers, and a small set of hashed anti-fraud signals.

Not your reports. Those never reach us.

Anti-fraud signals​

To catch disposable and fraudulent accounts we process a deliberately short list at sign-in: a random device identifier your browser generates (stored as a one-way hash), a salted one-way hash of your IP address — not the address itself — a normalised form of your email, and flags for automatically generated-looking addresses or names.

No browser fingerprinting, no tracking pixels, no third-party trackers. None of it is ever combined with clinical content, which does not reach us anyway. These hashes are kept for 12 months from your last sign-in.

Accounts are not suspended by an automated decision alone — a person reviews first, and you can appeal. See Suspension and appeals.

The standing request​

warning

Do not enter patient-identifiable information into MedJot. No names, dates of birth, addresses or NHS numbers. Initials, ages and de-identified descriptions are the way to work. Every privacy protection in the app is stronger when there is nothing identifying in it to begin with.