Privacy Policy

medSOS · Version 1.0 · Effective 15 August 2026

medSOS is built on a simple principle: an emergency app should not ask you to trade your medical history for help. Everything you enter stays on your device. We operate no account system, no user database, and no analytics profile.

🔒Your medical data stays on YOUR device only

Never uploaded, sold, or shared. Permissions (location, contacts, notifications) are requested only when the feature that needs them is first used.

⚠️Important Disclaimer

This app may experience interruptions. www.medSOS.in shall not be liable for any claims or damages.

Always contact official emergency services (112, 911, 999) as the primary method. medSOS is supplementary only.

Contents
  1. Who we are
  2. The short version
  3. What data exists, and where it lives
  4. Location data
  5. Third parties and outbound links
  6. Legal basis for processing (GDPR / UK GDPR)
  7. Your rights
  8. India — DPDP Act 2023
  9. United States — CCPA/CPRA and health data
  10. A note on HIPAA
  11. Children
  12. Security
  13. Retention and deletion
  14. International transfers
  15. Changes to this policy
  16. Contact

1 · Who we are

medSOS is a product of the TokenKart Health AI Ecosystem ("medSOS", "we", "us"). Where applicable data-protection law requires a controller, medSOS is the controller for the limited processing described below. You can reach us through tokenkart.com/projects.

This policy covers the medSOS web application at medsos.in, the installable PWA Lite version, and the medSOS native applications for Android and iOS.

2 · The short version

3 · What data exists, and where it lives

DataWhere it is storedDoes it reach medSOS?
Medical profile — name, age, gender, blood group, blood sugar, diabetes status, allergies, past surgery, insurance policy, government ID Your device only (browser localStorage / app sandbox) No
Emergency contacts — names, country codes, phone numbers Your device only No
Language preference, acceptance of these terms, onboarding state Your device only No
GPS coordinates Held in memory while the app is open; last fix cached for the session No
Standard web server logs for medsos.in (IP address, user agent, requested file, timestamp) Our hosting provider, for security and abuse prevention Yes — see §6

Server logs

Like any website, medsos.in is served by a web host that records ordinary access logs. These are used to keep the site running and to investigate abuse. They are not combined with anything you type into the app, and they are not used to build a profile of you. Logs are retained for a short operational period and then discarded by the host in the ordinary course.

📶Offline does not mean without a SIM

medSOS opens and runs with no internet connection — the app, your medical profile, your contacts and the first-aid guidance are all stored on your device. Placing a call is different. Dialling an ambulance, the police, the fire service or an emergency contact requires an active SIM card and mobile network coverage. No application can place a call without one.

4 · Location data

Location is the one permission medSOS asks for, and it powers three things:

  1. Correct emergency numbers. 112, 911, 999, 102 and the rest differ by country. Knowing roughly where you are means the SOS button dials the right one.
  2. Nearby care. Finding the closest hospital, pharmacy, blood bank or specialist.
  3. Location sharing. Only when you actively choose to send it.

Your coordinates are read by your browser or operating system and handed to the app. They are processed on your device. medSOS does not receive, log or retain them.

When you tap Share Location, you choose the channel — WhatsApp, SMS, Telegram, email, your device's own share sheet. At that point your coordinates leave your device to the recipient you selected, through that third party's service, governed by their privacy policy and not ours. We have no copy of the message and no record that it was sent.

You can withdraw location access at any time in your browser or OS settings. The app continues to work; it simply falls back to a default country and cannot find nearby care.

5 · Third parties and outbound links

medSOS deliberately carries very few third-party dependencies. Those that exist are:

We do not embed advertising SDKs, social pixels, session recorders or cross-site trackers.

For users in the European Economic Area, the United Kingdom and Switzerland, where we process personal data at all, we rely on:

Because health data is a special category, we have designed the product so that it is never transmitted to us at all. That is the strongest safeguard available: data we do not hold cannot be breached, subpoenaed or misused.

7 · Your rights

Depending on where you live you may have rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decision-making. medSOS makes no automated decisions about you.

Because your data never leaves your device, you exercise most of these rights directly and immediately:

If you believe we hold data about you and wish to make a formal request, contact us via tokenkart.com/projects. EEA/UK users also have the right to lodge a complaint with their supervisory authority.

8 · India — Digital Personal Data Protection Act, 2023

For users in India, medSOS acts as a Data Fiduciary only in respect of the limited server-log processing described above. Personal data you enter into the app is not collected by us within the meaning of the Act, because it is neither transmitted to nor stored by us. You retain the rights of a Data Principal under the Act, including access, correction, erasure and grievance redressal, exercisable through the contact route above.

9 · United States — CCPA/CPRA and consumer health data

We do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA, and we do not process sensitive personal information for purposes requiring a right to limit. For residents of states with consumer health data statutes (including Washington's My Health My Data Act and Nevada SB 370), medSOS does not collect, store or disclose consumer health data on our systems. We do not discriminate against anyone for exercising a privacy right.

10 · A note on HIPAA

medSOS is a direct-to-consumer application. It is not a covered entity or a business associate under HIPAA, and the information you record in it is not protected health information under that statute. We mention this so you are not misled by the absence of HIPAA language: the reason your data is safe here is architectural, not regulatory.

11 · Children

medSOS is not directed at children under 13 (or under 16 where local law sets a higher age), and we do not knowingly collect data from them. A parent or guardian may set up a profile on a child's behalf; in doing so they accept responsibility for the accuracy of that information. If you believe a child has provided data to us, contact us and we will act promptly — though in practice, clearing the app's data on the device removes it entirely.

12 · Security

medsos.in is served exclusively over HTTPS. The installed app is sandboxed by your operating system. Because there is no central store of medical records, there is no single target whose compromise would expose users at scale.

The corollary is that the security of your data depends on the security of your device. A device without a screen lock, or shared with others, exposes what medSOS holds — by design, that information is meant to be readable in an emergency. Please secure your device accordingly.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13 · Retention and deletion

We retain nothing about you, so there is nothing for us to delete. Data on your device persists until you clear it or uninstall the app. Server logs are retained by our host for a short operational window.

14 · International transfers

Because your personal and medical data does not leave your device, there is no international transfer of it. Our website is served from infrastructure that may be located outside your country; where server logs are transferred, appropriate safeguards apply.

15 · Changes to this policy

We may update this policy as the product develops or the law changes. The version number and effective date at the top will change, and material changes will be surfaced in the app. Your continued use after an update constitutes acceptance of the revised policy.

16 · Contact

Questions, requests or complaints about privacy: tokenkart.com/projects.

See also our Terms of Use.