Privacy Policy

Effective: March 23, 2026

Our Core Principle

Patient data stays where it belongs — on your infrastructure. MedAgent is designed from the ground up for healthcare data privacy. Our self-hosted architecture means we never see, store, or process your patient data.

Data Collection by Deployment Type

Data TypeSelf-Hosted (Free)Cloud SaaS ($49)Enterprise ($500)
Patient data (PHI)Your servers onlyYour cloud tenant (encrypted)Your servers only
Account infoNoneEmail, name, orgEmail, name, org
Usage analyticsNoneAnonymous metricsNone (optional)
AI model dataLocal OllamaDedicated OllamaLocal Ollama
Payment infoNoneVia Stripe (PCI-DSS)Invoice

Self-Hosted Users

We collect zero data from self-hosted installations. The software runs entirely on your infrastructure. We have no telemetry, no phone-home, no usage tracking. Your patient data never touches our servers.

Cloud SaaS Users

For Cloud SaaS customers, we collect:

Data Security

AI & LLM Privacy

Data Retention

Your Rights

Depending on your jurisdiction, you have the right to:

Third-Party Services

ServicePurposeData Shared
StripePayment processingBilling info only (PCI-DSS compliant)
CloudflareCDN & DDoS protectionIP address, request metadata

We do not sell, share, or transfer patient data to any third party.

Compliance

MedAgent supports region-aware compliance for HIPAA (US), GDPR (EU), APPI (Japan), PIPA (Korea), and Vietnamese data protection laws. Compliance is configurable per tenant.

Changes

We will notify you of material changes via email at least 30 days in advance.

Contact

Data Protection Officer: privacy@medagent.dev