MedTime Privacy Policy
MedTime is operated by Sonic Wall LLC. This Privacy Policy explains what information may be processed when you use MedTime, how it is used, when it may be disclosed, and the choices available to you.
Effective date: September 4, 2026
Last updated: September 8, 2026
Contact: support@medtime.app
What this policy covers
This policy applies to information processed through:
- The MedTime iOS and iPadOS app
- MedTime's optional SMS alert-delivery service
- MedTime support and help pages
- Communications you send to MedTime support
Information processed by MedTime
Profile and care information you enter
MedTime can store names, birthdays, medications, dosage history, reminder schedules and status, doctors, pharmacies, insurance details, medical-history entries, notes, and other information you choose to enter.
Optional images, files, and imported information
MedTime can store photos, insurance-card images, PDFs, or other supported files you choose to attach. If you grant permission, MedTime can also import contact details you select. MedTime does not access your contacts or photos without your action and the applicable device permission.
The current MedTime app does not provide an appointment scheduler, import appointments from your device calendar, or request calendar access. A legacy appointment saved in an earlier MedTime version may be converted on-device into a medical-history event during migration.
Optional alert-contact and delivery information
If you configure or use MedTime's optional external SMS alerts, the alert-delivery service processes the alert contact's name, mobile number, verification status, a pseudonymous installation identifier, reminder timing and time-zone information, and limited delivery and security records. Security records can include an Apple App Attest key identifier, public key, attestation receipt, assertion counter, app bundle version, and Apple validation category. The App Attest private key remains protected on the device. MedTime does not contact the alert-delivery service merely because you launch the app; App Attest and related service requests occur when you configure or use the optional SMS-alert feature or when previously requested cleanup must be retried.
The alert-delivery service does not receive medication names, dosages, notes, attachments, insurance information, medical-history details, or exported health records. An external missed-reminder message states only that a MedTime medication reminder has not been marked as taken.
MedTime does not provide external alert delivery by email.
Purchase information
Apple provides StoreKit transaction and entitlement information used to verify activation of the free 30-day trial, unlock purchased features, recognize eligible previous customers, and restore access. MedTime does not receive your full payment-card information.
Diagnostics and support information
MedTime may process error details, logs, diagnostic exports, and other information you choose to send when requesting support. Do not include information you do not want support personnel to review.
How information is collected
Information is collected:
- Directly from you when you enter or import it
- From device permissions you choose to grant
- From Apple services you use with the app
- From an alert recipient when they verify control of a mobile number
- From routine service requests needed to verify recipients, schedule alerts, prevent abuse, and record delivery status
How information is used
Information is used to:
- Provide medication reminders, dose history, medical records, and profile management
- Sync your private app data through iCloud when enabled
- Deliver local notifications and optional verified SMS alerts
- Process, unlock, and restore app purchases
- Maintain service security, rate-limit abusive requests, and troubleshoot reliability
- Respond to support requests
- Comply with applicable legal obligations
MedTime does not use health information to provide medical advice, diagnosis, treatment, or clinical monitoring.
Storage, synchronization, and service providers
MedTime is local-first. Records open from the app's local store. If iCloud is available, supported records sync in the background through your private CloudKit database so they can remain available on devices signed in to your Apple Account. MedTime does not offer profile sharing with other MedTime users.
Limited information may be disclosed to service providers only as needed to operate features you request. These providers may include:
- Apple, for iCloud, CloudKit, StoreKit, App Attest, and platform services
- Cloudflare, which hosts the optional alert-delivery service and its operational database
- Telnyx, which delivers requested SMS messages
Service providers process information under their own terms and privacy policies. MedTime does not authorize them to use alert-contact information for advertising or unrelated marketing.
SMS privacy and consent data
Mobile information and text-messaging originator opt-in data and consent are used only to provide MedTime messages requested by the user and alert recipient. This information is not sold or shared with third parties or affiliates for marketing or promotional purposes. It may be disclosed to communications and infrastructure providers solely as necessary to verify recipients, deliver requested messages, prevent abuse, and operate the alert service.
SMS alerts are optional and are not a condition of purchasing or using MedTime. A mobile number must be verified before it can receive recurring missed-reminder alerts. Message frequency varies based on the reminders for which alerts are enabled. Message and data rates may apply. Reply STOP to opt out or HELP for help. You can also disable an alert, remove the alert contact in MedTime, or contact support@medtime.app.
Sharing and disclosure
MedTime may disclose information:
- To the service providers described above, solely to provide requested app functionality
- When you deliberately export or send information using an Apple share sheet or another destination you select
- When required to comply with law, legal process, safety obligations, or fraud and abuse prevention
- In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable legal protections
MedTime does not sell personal information and does not include third-party advertising SDKs or behavioral-advertising tracking.
Retention and deletion
App records remain on your device and, when enabled, in your private iCloud storage until you delete them, subject to recently-deleted recovery periods and Apple's iCloud behavior. Deleting the app does not necessarily delete iCloud-synced data.
Alert-contact and scheduling records remain in the alert-delivery service while the feature is configured. Removing an alert contact or disabling the associated service requests removal or deactivation of the corresponding delivery configuration. If the service is unavailable, MedTime keeps an opaque cleanup identifier in durable device and private iCloud key-value storage and retries automatically; it does not retain the contact's name, mobile number, medication information, or other health details in that cleanup queue. Limited security, delivery, and diagnostic records may be retained as reasonably necessary to operate, secure, and document the service or comply with law.
Security
MedTime uses reasonable administrative, technical, and organizational safeguards. Alert destinations are encrypted at rest in the delivery service, verification codes are stored in non-reversible form, and supported physical devices use Apple App Attest assertions to help the service reject modified clients and replayed requests. No method of storage or transmission can be guaranteed to be completely secure.
Your choices and rights
You can:
- Edit, archive, export, or delete records using available in-app controls
- Control permissions for notifications, photos, contacts, and related device services
- Control iCloud availability through your Apple Account and device settings
- Decline or disable optional external alerts without losing access to MedTime's primary features
- Remove an alert contact or reply STOP to SMS messages
- Request access, correction, or deletion where applicable law provides that right
For privacy requests, contact support@medtime.app.
Related notices
For U.S. state consumer health data rights, review the MedTime Consumer Health Data Policy.
Children's privacy
MedTime is not directed to children as standalone users. An adult may choose to organize information for a dependent. If you believe personal information was submitted improperly, contact support@medtime.app.
Changes to this policy
This policy may be updated to reflect changes to MedTime, service providers, or legal requirements. The current version and its effective date will remain available on this page.
Contact
Sonic Wall LLC
Attn: Privacy
support@medtime.app