MedMatch
Baseline template delivered under SOW §6 for the operator's own counsel to review, finalize, and adopt. Not legal advice.

Privacy Policy

Version 2026-07-25. This policy describes what MedMatch collects, why, and what happens to it. MedMatch is built for pre-health students and is designed around a simple posture: collect little, and never hold patient information. It applies to the MedMatch website and the MedMatch iOS app.

1. What we collect

  • Account and profile: name, email, school, graduation year, career interest, experience interests, ZIP code, and travel radius. ZIP code is converted to approximate coordinates to rank opportunities by distance.
  • Content you write: reviews, opportunity submissions, and outreach email templates.
  • CV / resume (optional): uploaded only if you choose, parsed to personalize outreach emails. You can replace or remove it.
  • Usage and safety data: search history, notification state, rate-limit counters, and moderation records. This includes the IP address our servers see when your app or browser makes a request. We use it only to enforce rate limits and to investigate abuse, never for advertising and never combined with data from other companies. It is erased from our abuse records after 30 days.
  • Purchase history: when you buy credits, we record what was bought, when, the credits granted or spent, and the store's transaction identifier. We keep this to maintain your balance and to stop a single purchase being redeemed twice. We do not receive or store your card number: on iOS the payment is handled by Apple, on the web by our payment processor.
  • Location (optional, web only): on the website, if you grant your browser's location permission, a search uses your live position instead of your home ZIP for distance ranking. It is used per search and is not stored as a location trail. The iOS app does not request device location; it converts the ZIP code you type into approximate coordinates on your device.

2. What we deliberately do not collect

MedMatch does not collect dates of birth (age is a one-time 18+ attestation, stored as a timestamp), government identifiers, or health information about you. Patient information has no place on the platform at all: automated screening blocks common identifier patterns (such as formats resembling Social Security numbers, medical record numbers, and patient names in clinical context) before content enters the database, and when a submission is blocked we log only the pattern category, never the matched text.

3. How we use data

  • ranking and recommending opportunities against your profile
  • drafting outreach emails you explicitly request
  • moderation, abuse prevention, and rate limiting
  • in-app notifications you can read and dismiss
  • aggregate, non-identifying operational metrics for administrators

MedMatch does not sell personal data and does not use it for third-party advertising.

4. AI processing and third-party services

Some features send data to third-party processors: search queries and public web content go to AI providers (currently OpenAI and Anthropic) for search structuring and listing extraction; your profile summary and CV excerpts go to an AI provider when you ask for a personalized outreach draft; addresses and ZIP codes go to a geocoding provider to compute coordinates; payments are handled by Stripe, and MedMatch never sees your card number. These providers process data to deliver the feature, under their own security obligations.

5. Storage and security

Data is stored with our hosting and database providers in the United States. Access is controlled with row-level security so students can read only their own records, administrative actions are individually authorized, and transport is encrypted. No system is perfectly secure; we notify affected users of a breach as required by law.

6. Retention and deletion

Your data is kept while your account is active. Deleting your account removes your profile, saved items, tracking, notifications, CV, and search history, and forfeits any unspent credits. Published reviews may be retained in anonymized form so listing ratings stay honest. Our copy of your purchase and credit history is deleted along with the account; Apple and our payment processors retain their own transaction records under their own policies, as tax and accounting rules require of them. Operational logs age out on a fixed schedule.

7. Your choices

  • edit your profile, interests, ZIP, and radius at any time in account settings
  • remove your CV, or never upload one
  • decline the browser location prompt on the website; ranking falls back to your home ZIP
  • delete your account from settings on web or iOS

8. Age requirement

MedMatch is for adults 18 and older. Accounts require an 18+ attestation at signup, and we do not knowingly collect data from anyone under 18. If we learn an account belongs to someone under 18, we delete it.

9. The iOS app

The iOS app collects the same categories of data as the website, with these platform-specific points:

  • Sign-in: you can sign in with Sign in with Apple, with Google, or with an emailed sign-in link. If you use Sign in with Apple and choose to hide your email, MedMatch receives Apple's private relay address and works normally with it.
  • No device location: the app does not ask for, read, or store your device location. Distance ranking uses the ZIP code you enter.
  • No tracking: the app does not track you across other companies' apps or websites, does not use the advertising identifier, and contains no advertising or third-party analytics SDKs.
  • Session storage: your signed-in session is stored in the iOS Keychain.
  • Purchases: credit packs are bought through the App Store. Apple bills you and tells us the purchase happened; we verify Apple's signed receipt on our server before granting credits. Apple does not give us your payment details, and the app never sees them.
  • Deletion in the app: you can delete your account and its data from the account screen inside the app, without contacting support.

The app's privacy manifest (`PrivacyInfo.xcprivacy`) and its App Store privacy labels describe the same collection as this policy. If one changes, all three change together.

10. Changes

Material changes to this policy are announced in the app before they take effect.

11. Contact

Privacy questions go to medmatch@cre8ivelabs.ai, or to the support contact listed on your account page. MedMatch is operated by Cre8ive Labs AI.