Legal
App: MediLog24 · Version 2.1 · Effective: on publication · Contact: support@medilog24.com
MediLog24 is a personal medical document management app. We are not a healthcare provider, hospital, laboratory, insurer, or emergency service. We do not read, interpret, or act on the contents of your medical documents.
MediLog24 is operated by SAMTrek UG (haftungsbeschränkt), Lerchenstr. 7, 85630 Grasbrunn, Germany, registered at Amtsgericht München under HRB 309076, represented by Managing Director Dr. Shahidul Alam. SAMTrek UG (haftungsbeschränkt) is the controller of the personal data described in this policy. Contact: support@medilog24.com.
Your medical files are stored in your own Google Drive, not on our servers.
When you add a record, the file is uploaded directly into a folder named “MediLog24” inside your personal Google Drive. You own that storage, it counts against your Google account quota, and the files remain in your Drive even if you stop using MediLog24 or delete your account.
We keep a reference to each file, its Drive file ID, so the app can retrieve it for you. We do not keep a copy of the file contents.
To make the app work we hold the following in our own database:
Account: your email address, your display name, and account creation and last-login timestamps.
Google authorisation tokens: encrypted OAuth tokens that let the app reach your MediLog24 Drive folder on your behalf.
Patient profiles: the names, and optionally dates of birth and notes, that you enter for the people whose records you track.
Record metadata: record titles, categories (prescription, lab report, scan, other), dates, doctor and facility names, your notes, file names, file sizes, and the Google Drive file ID.
Sharing records: who you shared what with, share link tokens, and expiry times.
Technical and security data: IP address, device user-agent, login timestamps, and an activity log of actions taken on your account.
Please note: record titles, categories, and patient names can themselves reveal health information. This metadata is stored on our servers, so this policy, not only Google’s, governs it.
We do not sell your data. We do not share it with advertisers. We do not use your medical documents, metadata, or Google user data to train machine learning or AI models. We do not use your data for advertising or profiling of any kind. We do not read your files except as needed to transmit them at your request.
MediLog24’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
| Permission | Why we need it |
|---|---|
| See your primary Google Account email address | To identify your account and sign you in |
| See your personal info, including any personal info you’ve made publicly available | To show your name in the app |
See, edit, create, and delete only the specific Google Drive files you use with this app (drive.file) | To store and retrieve the medical files you add to MediLog24 |
The drive.file scope is deliberately narrow. It grants access only to files this app itself created. MediLog24 cannot see, list, or open any other file in your Google Drive, including files created by other apps, your own documents, or your photos.
You can revoke MediLog24’s access to your Google account at any time at myaccount.google.com/permissions. Doing so stops the app from reaching your files. It does not delete them, and it does not delete your MediLog24 account; use in-app account deletion for that.
You sign in with Google. We never receive or store your Google password, and there is no separate MediLog24 password. Sessions are maintained with access and refresh tokens held in your device’s secure storage.
Records stay private unless you choose to share them.
Sharing with another MediLog24 user grants that person access through the app. Public share links are accessible to anyone holding the link until the link expires or you revoke it; treat them as you would treat sending the document by email. You can see and revoke every active share from within the app.
We disclose data only: (a) to users or link-holders you explicitly share with, (b) to Google, as necessary to store your files in your own Drive, and (c) where required by law. We use no advertising networks and no third-party analytics on your medical data.
Traffic is encrypted with HTTPS. Google OAuth tokens are stored encrypted at rest. Access controls ensure records are reachable only by their owner and the people they were shared with. Sensitive actions are logged. No system can guarantee absolute security, and we will notify affected users of any breach that puts their data at risk.
Your account data is kept while your account is active. When you delete your account, our database records, profiles, metadata, share links, and stored Google tokens, are purged within 30 days.
Your files in Google Drive are not deleted by us. They are yours and stay in your Drive. If you want them gone, delete the “MediLog24” folder from your Google Drive yourself.
You can access and delete your records, patient profiles, and your entire account from within the app at any time, and revoke any share. If you are in the EU or UK, you additionally have the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR, and the right to complain to your local data protection authority. For any request we cannot serve in-app, contact support@medilog24.com.
Our servers are located in the European Union. Google may process your files in accordance with its own policies and infrastructure; see the Google Privacy Policy.
MediLog24 is not directed at anyone under 18. You must also meet Google’s minimum age requirement for your region to hold the Google account used to sign in.
When these policies change we bump the version number and ask you to review and accept them the next time you open the app.
Contact: support@medilog24.com · See also the Terms of Service and the Impressum.