The fine print
Privacy Policy
<!-- Generated by scripts/sync-legal.mjs. Edit legal/privacy.md. -->
Privacy Policy
Version 2026-07-22. This policy describes what MedMatch collects, why, and what happens to it. MedMatch is built for pre-health students and is designed around a simple posture: collect little, and never hold patient information. It applies to the MedMatch website and the MedMatch iOS app.
1. What we collect
- Account and profile: name, email, school, graduation year, career interest,
experience interests, ZIP code, and travel radius. ZIP code is converted to approximate coordinates to rank opportunities by distance.
- Content you write: reviews, opportunity submissions, and outreach email
templates.
- CV / resume (optional): uploaded only if you choose, parsed to personalize
outreach emails. You can replace or remove it.
- Usage and safety data: search history, notification state, rate-limit
counters, and moderation records.
- Purchase history: when you buy credits, we record what was bought, when,
the credits granted or spent, and the store's transaction identifier. We keep this to maintain your balance and to stop a single purchase being redeemed twice. We do not receive or store your card number: on iOS the payment is handled by Apple, on the web by our payment processor.
- Location (optional, web only): on the website, if you grant your browser's
location permission, a search uses your live position instead of your home ZIP for distance ranking. It is used per search and is not stored as a location trail. The iOS app does not request device location; it converts the ZIP code you type into approximate coordinates on your device.
2. What we deliberately do not collect
MedMatch does not collect dates of birth (age is a one-time 18+ attestation, stored as a timestamp), government identifiers, or health information about you. Patient information has no place on the platform at all: automated screening blocks common identifier patterns (such as formats resembling Social Security numbers, medical record numbers, and patient names in clinical context) before content enters the database, and when a submission is blocked we log only the pattern category, never the matched text.
3. How we use data
- ranking and recommending opportunities against your profile
- drafting outreach emails you explicitly request
- moderation, abuse prevention, and rate limiting
- in-app notifications you can read and dismiss
- aggregate, non-identifying operational metrics for administrators
MedMatch does not sell personal data and does not use it for third-party advertising.
4. AI processing and third-party services
Some features send data to third-party processors: search queries and public web content go to AI providers (currently OpenAI and Anthropic) for search structuring and listing extraction; your profile summary and CV excerpts go to an AI provider when you ask for a personalized outreach draft; addresses and ZIP codes go to a geocoding provider to compute coordinates; payments are handled by Stripe, and MedMatch never sees your card number. These providers process data to deliver the feature, under their own security obligations.
5. Storage and security
Data is stored with our hosting and database providers in the United States. Access is controlled with row-level security so students can read only their own records, administrative actions are individually authorized, and transport is encrypted. No system is perfectly secure; we notify affected users of a breach as required by law.
6. Retention and deletion
Your data is kept while your account is active. Deleting your account removes your profile, saved items, tracking, notifications, CV, and search history, and forfeits any unspent credits. Published reviews may be retained in anonymized form so listing ratings stay honest. Records of completed purchases are kept as long as tax and accounting rules require. Operational logs age out on a fixed schedule.
7. Your choices
- edit your profile, interests, ZIP, and radius at any time in account settings
- remove your CV, or never upload one
- decline the browser location prompt on the website; ranking falls back to your
home ZIP
- delete your account from settings on web or iOS
8. Age requirement
MedMatch is for adults 18 and older. Accounts require an 18+ attestation at signup, and we do not knowingly collect data from anyone under 18. If we learn an account belongs to someone under 18, we delete it.
9. The iOS app
The iOS app collects the same categories of data as the website, with these platform-specific points:
- Sign-in: you can sign in with Sign in with Apple, with Google, or with an
emailed sign-in link. If you use Sign in with Apple and choose to hide your email, MedMatch receives Apple's private relay address and works normally with it.
- No device location: the app does not ask for, read, or store your device
location. Distance ranking uses the ZIP code you enter.
- No tracking: the app does not track you across other companies' apps or
websites, does not use the advertising identifier, and contains no advertising or third-party analytics SDKs.
- Session storage: your signed-in session is stored in the iOS Keychain.
- Purchases: credit packs are bought through the App Store. Apple bills you
and tells us the purchase happened; we verify Apple's signed receipt on our server before granting credits. Apple does not give us your payment details, and the app never sees them.
- Deletion in the app: you can delete your account and its data from the
account screen inside the app, without contacting support.
The app's privacy manifest (PrivacyInfo.xcprivacy) and its App Store privacy labels describe the same collection as this policy. If one changes, all three change together.
10. Changes
Material changes to this policy are announced in the app before they take effect.
11. Contact
Privacy questions go to <medmatch@cre8ivelabs.ai>, or to the support contact listed on your account page. MedMatch is operated by Cre8ive Labs AI.