Privacy Policy
Last updated 28 July 2026
MyGabrielAI holds medical records, which are among the most sensitive categories of personal data. This page describes exactly what is collected, where it goes, and what is never sent anywhere.
This policy is a good-faith description of how the service works. It has not been reviewed by a lawyer, and it is not a substitute for advice from one. Sections marked like this must be completed before relying on it.
Who is responsible
The controller of your data is [legal entity name], [registered address]. Questions and requests: [contact email].
What is collected
- Identity. An email address or mobile number, used only to sign you in and to match invitations. Authentication is handled by Google Firebase; MyGabrielAI never sees or stores a password.
- Documents you upload. The original files, and the text extracted from them.
- Derived data. AI-generated summaries, categories, findings, extracted lab values, and numeric embeddings used for search.
- Anything you write yourself, such as the free-text profile of your symptoms and history.
There is no advertising, no analytics profiling, and no third-party tracking. Your records are not used to train any AI model.
How documents are processed
Every document goes through the same sequence: it is converted to text, identifiers are removed from that text, and only then is anything sent to an AI provider.
The de-identification step removes names you have registered, national identity numbers (validated by check digit, so lab values and accession numbers are left intact), and similar direct identifiers. If a validated identifier survives the process, the document is held back and never reaches the AI provider at all.
The original, un-redacted text is stored so that you and the doctors you choose can read your records as they were written. It is never sent to an AI provider. Only the de-identified version leaves the system.
Text recognition for scanned documents runs on our own infrastructure rather than through an external vision model, because an image cannot be de-identified before it has been read.
Who processes data on our behalf
- Google Firebase — authentication only. Receives your email address or phone number. It does not receive any medical data.
- Supabase — database and file storage. Holds your documents and all derived data. The storage bucket is private; files are reachable only through short-lived links issued after an access check.
- OpenAI — summarisation, categorisation, second opinions and search. Receives de-identified text only, never original files and never un-redacted text.
- Vercel — application hosting.
These providers may process data outside your country, including in the United States.[Confirm the transfer mechanism you rely on — e.g. Standard Contractual Clauses.]
Who else can see your records
Nobody, unless you invite them. Sharing is always started by you: you enter a doctor's email address or mobile number, and access begins the first time that person signs in with that verified identity.
- A doctor you invite can read everything in your chart and change nothing.
- A doctor cannot request access, and cannot see who else you have shared with.
- You can revoke access at any time, and it stops immediately.
- A record of who had access, and when, is kept so you can review it.
Security
Data is encrypted in transit. Files live in a private store and are served only through links that expire within minutes and are issued after checking that the requester is entitled to that specific record. Every request to the application is authorised against the signed-in account before any record is returned.
No system is perfectly secure, and we do not claim otherwise. [State your breach-notification commitment and timeframe.]
How long data is kept
Your records are kept until you delete them or close your account. Deleting a record removes the stored file and everything derived from it. [State your backup retention window, after which deleted data is fully purged.]
Your rights
You can ask for a copy of your data, correction of anything inaccurate, deletion, or restriction of processing, and you can object to processing. Write to [contact email]. [Name the supervisory authority users may complain to.]
Children
The service is not intended for people under [age]. If a chart is managed on behalf of a child, the account holder is responsible for having the authority to do so.
Changes
Material changes will be announced in the application before they take effect. The date at the top of this page always reflects the current version.