Privacy Policy
medSOS is built on a simple principle: an emergency app should not ask you to trade your medical history for help. Everything you enter stays on your device. We operate no account system, no user database, and no analytics profile.
Never uploaded, sold, or shared. Permissions (location, contacts, notifications) are requested only when the feature that needs them is first used.
This app may experience interruptions. www.medSOS.in shall not be liable for any claims or damages.
Always contact official emergency services (112, 911, 999) as the primary method. medSOS is supplementary only.
- Who we are
- The short version
- What data exists, and where it lives
- Location data
- Third parties and outbound links
- Legal basis for processing (GDPR / UK GDPR)
- Your rights
- India — DPDP Act 2023
- United States — CCPA/CPRA and health data
- A note on HIPAA
- Children
- Security
- Retention and deletion
- International transfers
- Changes to this policy
- Contact
1 · Who we are
medSOS is a product of the TokenKart Health AI Ecosystem ("medSOS", "we", "us"). Where applicable data-protection law requires a controller, medSOS is the controller for the limited processing described below. You can reach us through tokenkart.com/projects.
This policy covers the medSOS web application at medsos.in, the installable PWA Lite version, and the medSOS native applications for Android and iOS.
2 · The short version
- We do not operate user accounts. There is nothing to sign up for.
- We do not have a server that stores your medical information.
- Your name, blood group, allergies, conditions, medication, insurance details, government ID and emergency contacts are written to your device's local storage and stay there.
- Your location is used on your device to select the correct emergency numbers and to find nearby care. It is not transmitted to us.
- We do not sell, rent, licence or share personal data with data brokers or advertisers. We do not run behavioural advertising.
- Uninstalling the app, or clearing site data, erases everything.
3 · What data exists, and where it lives
| Data | Where it is stored | Does it reach medSOS? |
|---|---|---|
| Medical profile — name, age, gender, blood group, blood sugar, diabetes status, allergies, past surgery, insurance policy, government ID | Your device only (browser localStorage / app sandbox) |
No |
| Emergency contacts — names, country codes, phone numbers | Your device only | No |
| Language preference, acceptance of these terms, onboarding state | Your device only | No |
| GPS coordinates | Held in memory while the app is open; last fix cached for the session | No |
| Standard web server logs for medsos.in (IP address, user agent, requested file, timestamp) | Our hosting provider, for security and abuse prevention | Yes — see §6 |
Server logs
Like any website, medsos.in is served by a web host that records ordinary access logs. These are used to keep the site running and to investigate abuse. They are not combined with anything you type into the app, and they are not used to build a profile of you. Logs are retained for a short operational period and then discarded by the host in the ordinary course.
medSOS opens and runs with no internet connection — the app, your medical profile, your contacts and the first-aid guidance are all stored on your device. Placing a call is different. Dialling an ambulance, the police, the fire service or an emergency contact requires an active SIM card and mobile network coverage. No application can place a call without one.
4 · Location data
Location is the one permission medSOS asks for, and it powers three things:
- Correct emergency numbers. 112, 911, 999, 102 and the rest differ by country. Knowing roughly where you are means the SOS button dials the right one.
- Nearby care. Finding the closest hospital, pharmacy, blood bank or specialist.
- Location sharing. Only when you actively choose to send it.
Your coordinates are read by your browser or operating system and handed to the app. They are processed on your device. medSOS does not receive, log or retain them.
When you tap Share Location, you choose the channel — WhatsApp, SMS, Telegram, email, your device's own share sheet. At that point your coordinates leave your device to the recipient you selected, through that third party's service, governed by their privacy policy and not ours. We have no copy of the message and no record that it was sent.
You can withdraw location access at any time in your browser or OS settings. The app continues to work; it simply falls back to a default country and cannot find nearby care.
5 · Third parties and outbound links
medSOS deliberately carries very few third-party dependencies. Those that exist are:
- Google Maps — opened in a new tab or the Maps app when you tap "Near Me" or a map link. Google receives that request under Google's privacy policy.
- Your telephone dialler and messaging apps — invoked via standard
tel:,sms:andmailto:links. We do not place calls or send messages; your device does, after you confirm. - Web fonts and a weather lookup on some screens, served from public CDNs and APIs which will see your IP address as a normal consequence of your browser making the request.
- Third-party emergency and healthcare services you reach through the app. Once you are connected to them, their terms and privacy practices apply.
We do not embed advertising SDKs, social pixels, session recorders or cross-site trackers.
6 · Legal basis for processing (GDPR / UK GDPR)
For users in the European Economic Area, the United Kingdom and Switzerland, where we process personal data at all, we rely on:
- Consent (Art. 6(1)(a), and Art. 9(2)(a) for health data) — you choose to enter medical information and to grant location access. Consent can be withdrawn by revoking the permission or clearing the app's data.
- Legitimate interests (Art. 6(1)(f)) — minimal server logs, to keep the service secure and available.
- Vital interests (Art. 6(1)(d), Art. 9(2)(c)) — where information is surfaced to protect your life or that of another person in an emergency.
Because health data is a special category, we have designed the product so that it is never transmitted to us at all. That is the strongest safeguard available: data we do not hold cannot be breached, subpoenaed or misused.
7 · Your rights
Depending on where you live you may have rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decision-making. medSOS makes no automated decisions about you.
Because your data never leaves your device, you exercise most of these rights directly and immediately:
- Access and portability — open Medical Info or Emergency Contacts; what you see is the entirety of what exists.
- Rectification — tap Edit and change it.
- Erasure — clear the app's site data, or uninstall it. Nothing survives.
If you believe we hold data about you and wish to make a formal request, contact us via tokenkart.com/projects. EEA/UK users also have the right to lodge a complaint with their supervisory authority.
8 · India — Digital Personal Data Protection Act, 2023
For users in India, medSOS acts as a Data Fiduciary only in respect of the limited server-log processing described above. Personal data you enter into the app is not collected by us within the meaning of the Act, because it is neither transmitted to nor stored by us. You retain the rights of a Data Principal under the Act, including access, correction, erasure and grievance redressal, exercisable through the contact route above.
9 · United States — CCPA/CPRA and consumer health data
We do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA, and we do not process sensitive personal information for purposes requiring a right to limit. For residents of states with consumer health data statutes (including Washington's My Health My Data Act and Nevada SB 370), medSOS does not collect, store or disclose consumer health data on our systems. We do not discriminate against anyone for exercising a privacy right.
10 · A note on HIPAA
medSOS is a direct-to-consumer application. It is not a covered entity or a business associate under HIPAA, and the information you record in it is not protected health information under that statute. We mention this so you are not misled by the absence of HIPAA language: the reason your data is safe here is architectural, not regulatory.
11 · Children
medSOS is not directed at children under 13 (or under 16 where local law sets a higher age), and we do not knowingly collect data from them. A parent or guardian may set up a profile on a child's behalf; in doing so they accept responsibility for the accuracy of that information. If you believe a child has provided data to us, contact us and we will act promptly — though in practice, clearing the app's data on the device removes it entirely.
12 · Security
medsos.in is served exclusively over HTTPS. The installed app is sandboxed by your operating system. Because there is no central store of medical records, there is no single target whose compromise would expose users at scale.
The corollary is that the security of your data depends on the security of your device. A device without a screen lock, or shared with others, exposes what medSOS holds — by design, that information is meant to be readable in an emergency. Please secure your device accordingly.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13 · Retention and deletion
We retain nothing about you, so there is nothing for us to delete. Data on your device persists until you clear it or uninstall the app. Server logs are retained by our host for a short operational window.
14 · International transfers
Because your personal and medical data does not leave your device, there is no international transfer of it. Our website is served from infrastructure that may be located outside your country; where server logs are transferred, appropriate safeguards apply.
15 · Changes to this policy
We may update this policy as the product develops or the law changes. The version number and effective date at the top will change, and material changes will be surfaced in the app. Your continued use after an update constitutes acceptance of the revised policy.
16 · Contact
Questions, requests or complaints about privacy: tokenkart.com/projects.
See also our Terms of Use.