MedEasy
Legal

Privacy Policy

Last updated: June 29, 2026

Welcome to MedEasy. We provide a digital platform that helps Canadian users log, track, and organize their medical travel mileage and related health-travel expenses for tax-deduction and financial-tracking purposes. MedEasy is operated by 10203786 Manitoba Ltd. (“we,” “us,” “our”).

Because MedEasy handles information related to your medical travel, we take your privacy and data security seriously. This policy explains what we collect, how we use it, who we share it with, and the rights you have under Canadian privacy law (PIPEDA, and Quebec's Law 25 where applicable).

1. Information We Collect

  • Account information: name, email address, and password. Passwords are obfuscated using industry-standard bcrypt hashing — we never store or see your plaintext password.
  • Profile & configuration: your home address (used as the baseline for mileage calculations), province (used for the CRA simplified mileage rate), and optional net-income estimate if you provide one for the tax-credit calculator.
  • Trip & expense data: appointment date and time, provider (doctor) name, clinic or destination address, purpose of visit, distance, parking / fuel / meal / lodging / taxi / rental / other costs, and any notes you choose to add. We also store related calendar metadata when you opt to sync a trip to your phone's calendar.
  • Prescription & service data: medication or service name, Drug Identification Number (DIN), pharmacy or clinic name, total amount billed, amount covered by insurance, and out-of-pocket cost. These are the fields the CRA expects to see when you claim a medical expense.
  • Uploaded documents & receipts: photos or PDFs of parking, fuel, restaurant, pharmacy, dental, or other medical receipts, plus appointment letters and statements you choose to upload.
  • Payment data: Stripe customer and invoice identifiers needed to manage your subscription. We never see or store your credit-card number, CVV, or banking credentials — Stripe handles all of that in their own PCI-compliant environment.
  • Local-device data: some non-sensitive preferences and the optional Family & Dependents name list are stored in your browser's local storage on your device and are never transmitted to our servers.

2. How We Process Your Data (Our “Magic” Features)

A. AI Document Scanning (OCR)

When you snap or upload an appointment letter, prescription receipt, or expense receipt, the image is transmitted via an encrypted (HTTPS) pipeline through our LLM integration provider (Emergent) to a third-party vision-model provider (OpenAI). The AI reads the document solely to extract the relevant fields — date, vendor, address, total, insurance coverage, out-of-pocket amount, DIN, and so on — so MedEasy can pre-fill your trip form.

  • No model training: under OpenAI's current API terms, customer API data is not used to train OpenAI's models. We do not control changes to those terms but will notify you of any material change.
  • Transient processing: documents are processed transiently by the vision model. The original image stays in our private object storage; OpenAI does not retain a copy after responding.
  • You stay in control: every extracted field is presented to you for review. You can edit, delete, or override anything before saving. You can also turn the feature off and enter everything manually.

B. Payment Processing

All subscriptions, one-time charges, and refunds are handled by Stripe, Inc. MedEasy never sees or stores your credit-card number or financial credentials. We retain only the Stripe customer ID and invoice IDs we need to manage your subscription status and provide our Refund Guarantee.

C. Email Notifications

Transactional emails — calendar invites for appointments, comp-code redemption confirmations, refund-request acknowledgements — are sent through Resend (a US-based email provider). Only the recipient address, subject, and message body are shared with Resend; no expense or document data is included in routine emails.

3. How We Store and Protect Your Information

  • Where it lives: account, trip, and expense data is stored in a managed MongoDB cluster. Receipt and document uploads are stored in private object storage with strict per-user access controls. We use reputable cloud infrastructure providers and are working toward full Canadian data-residency for all customer data.
  • Access gating: every receipt download is authenticated against your user identity before the file is streamed — there is no public URL on any document you upload.
  • In transit: all traffic between your device and our servers is TLS-encrypted (HTTPS).
  • Sessions: we authenticate using JSON Web Tokens (JWTs) delivered in an httpOnly, Secure cookie, so JavaScript on your device cannot read or steal them.
  • Brute-force defence: repeated failed logins from the same IP are rate-limited and temporarily locked out.

4. A Note on Personal Health Information (PHI)

MedEasy is an administrative and tax-optimization utility, not an Electronic Health Record system or a medical provider. We do not solicit clinical diagnoses, lab results, treatment plans, or other clinical records.

To calculate your eligible CRA medical expenses accurately, we do intentionally collect health-adjacent administrative data — medication names, DINs, doctor names, clinic names, appointment dates, and purposes of visit — because the CRA requires this information to substantiate a medical-expense claim. We treat this data with the same standard SaaS-grade security as the rest of your account.

Because you may write free-form notes (e.g. “follow-up for a specific condition”) or upload letters that include clinical details, you may inadvertently introduce sensitive information into the app. We strongly encourage you to review and edit your trip notes to omit specific diagnostic or sensitive clinical details that are not required for tax filing.

4a. Security-Incident Notification (PIPEDA & Law 25)

If MedEasy ever discovers a security breach that creates a real risk of significant harm to you — unauthorized access to your medical-expense records, receipts, or account credentials — we will notify you directly by email to the address on your account as soon as feasible, and in any event within 72 hours of confirming the incident, in line with PIPEDA's Breach of Security Safeguards Regulations and Quebec's Law 25 reporting standards. Our notice will include:

  • The date and nature of the incident, in plain language.
  • Which categories of your data were affected.
  • The concrete steps we are taking to contain the breach and prevent recurrence.
  • Recommended actions you should take (rotate your password, alert your financial institution, etc.).
  • Direct contact details for the MedEasy operator handling the incident.

We will also report qualifying breaches to the Office of the Privacy Commissioner of Canada and maintain a breach register for at least 24 months as required by law.

Belt-and-suspenders for your peace of mind: in Settings → Download all my receipts, you can generate an AES-256 password-protected ZIP of every receipt. Because we never store the password you choose, that archive remains unreadable to anyone — including a hypothetical attacker who exfiltrates our object storage.

5. Data Disclosure & Sharing

We do not sell, rent, or trade your personal information to third parties. We share information only with trusted service providers, strictly to the extent necessary to run the app:

  • Stripe, Inc. — subscription billing and payment processing.
  • Emergent + OpenAI — AI receipt and document parsing (the “Magic” OCR features).
  • Resend — transactional email delivery (appointment invites, refund acknowledgements).
  • MongoDB Atlas / cloud infrastructure host — encrypted database and object storage.

All such providers are contractually bound to keep your data secure and to process it only for the purposes we've described.

6. Retention & Deletion

We retain your records as long as your account is active or as needed to support your tax filings. The CRA generally requires Canadians to keep tax records for six years, so we keep your data available to you for at least that long unless you ask us to delete it sooner.

You can delete individual trips, expenses, or uploaded documents at any time from inside the app. To delete your entire account and all associated records, email us at the address below; we will purge active-system data within 30 days, and encrypted backups will roll off within 90 days.

7. Your Privacy Rights (PIPEDA)

As a Canadian resident, you have the right to:

  • Access the personal information we hold about you.
  • Request corrections to any inaccurate information.
  • Withdraw consent for optional processing (for example, you can stop using AI receipt scanning at any time).
  • Request the permanent deletion of your account and all associated records.
  • File a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) if you are not satisfied with our response.

To exercise any of these rights, contact us at the email or postal address in §9 below.

8. Children

MedEasy is not directed at children under 13 and we do not knowingly collect their information. If you are a caregiver tracking trips on behalf of a child or other dependent, you are entering that information yourself as a permitted adult user; it is treated under your own account.

9. Contact Information & Privacy Officer

In accordance with PIPEDA §5(1) & Principle 1 (Accountability), MedEasy has designated a Privacy Officer responsible for compliance with this policy and for responding to privacy inquiries, data-access requests, or complaints. All requests are logged and answered in writing within 30 days.

You also have the right to file a complaint directly with the Office of the Privacy Commissioner of Canada at any time.

© 2026 10203786 Manitoba Ltd., operating as MedEasy · Built in Canada · 10% of every payment supports Hope Air