Privacy Policy
Effective September 1, 2026
MedSmartIQ (“MedSmartIQ,” “we,” “us”) is a mobile app, made by LumaSeer, that helps you keep track of your medications and understand medication-related information. This policy describes what information the app actually collects, how it’s used, who it’s shared with, and how you can delete it — nothing here describes a hypothetical future version of the app.
Information we collect
Account information
When you create an account, we collect your email address, a password (which we never see or store ourselves — it’s handled by our authentication provider, Amazon Cognito), and the display name you choose.
Health profile
Your name, date of birth, preferred language, accessibility preferences, and preferred pharmacy, if you choose to add one.
Medication and clinical information
The medications you add, changes you make to them over time, your reported allergies and intolerances, medical conditions you record, and any lab or observation values you choose to enter. If you connect an external health record source, information from that source is imported the same way.
Medication safety findings and reviews
When MedSmartIQ evaluates your medications for possible interactions or other safety considerations, we store the findings it generates and a record of scheduled medication reviews, so you can revisit them later.
Camera and photos
MedSmartIQ uses your device’s camera to scan medication barcodes and capture photos of medication labels to help identify a medication, and lets you choose an existing photo instead if you prefer. This is handled entirely on your device: photo recognition runs locally on your phone, and only the text it recognizes from a label — never the photo itself — is ever sent to our servers. We do not store, upload, or retain the photo.
AI-assisted explanations
MedSmartIQ uses Anthropic’s Claude AI to generate plain-language explanations of medication safety findings and to answer questions you ask about your medications. What we send Anthropic is limited to the clinical facts needed to answer — medication names, the finding being explained, and relevant evidence — and does not include your name, email, date of birth, or any other account or profile information. Under Anthropic’s API terms, this content is not used to train Anthropic’s models. We keep a record that an AI request was made (for support and quality purposes) but not the actual question or answer text — we store a one-way cryptographic hash of the input, not the input itself.
Care team, emergency contacts, and sharing
The name, relationship, and contact details of care-team members or emergency contacts you choose to add — we never access your device’s own address book. If you use your device’s share feature to send information from the app to someone else, we keep a record that a share happened, not the shared content itself.
Notifications and device information
If you enable notifications, we store a push-notification token for your device (via Apple’s and Google’s standard push services) and a randomly generated installation identifier, so we know where to deliver a notification and can stop sending to a device you’ve signed out of.
What we don’t collect
MedSmartIQ does not access your device’s location, microphone, or contacts, and it contains no advertising or third-party analytics/tracking software of any kind.
How we use this information
To provide the app’s core features: maintaining your medication list, generating safety findings and explanations, scheduling medication reviews, sending the notifications you’ve enabled, and providing customer support. We do not use your health information for advertising, and we do not sell it.
Who we share it with
We use a small number of service providers to operate MedSmartIQ, each only for the specific purpose described:
- Amazon Web Services (AWS) — hosts our servers, database, and authentication.
- Anthropic — generates AI explanations from the limited, de-identified clinical information described above.
- Apple and Google’s push notification services — deliver notifications you have enabled.
We do not sell your information, and we do not share it with advertisers or data brokers.
Security
Information is encrypted in transit (HTTPS) and encrypted at rest in our database. We follow least-privilege practices internally, limiting access to what a system actually needs to function.
Retention and deletion
You can permanently delete your account and all associated data at any time, directly in the app, under Settings → Delete Account. Deletion is immediate and permanent — we do not retain a copy of your data afterward, and it is not recoverable once deleted. Deleting your account also deletes your MedSmartIQ sign-in identity itself.
Children
MedSmartIQ is not directed to children and is not intended for use by anyone under 18.
Changes to this policy
If we make a material change to this policy, we’ll update the effective date above and, where appropriate, notify you in the app.
Contact us
Questions about this policy or your data can be sent through the in-app Support screen, or our Support page.