top of page

Privacy Policy

Last Updated: August 18, 2026 

This Privacy Policy explains how MediKarma, Inc. ("Company") collects, uses, shares, and protects your data. It applies when you use our websites, mobile apps, or other services we provide. We call these together our "Services." We may update this policy from time to time. If we make changes, we will post the new version on our site. We will also update the date at the top. Please check this page often to stay informed and protect your privacy. 

Our Commitment Regarding Your Health Data 

 

MediKarma does not sell your health data. We do not share your health data for cross-context behavioral advertising, we do not use it to build or target advertising audiences, and we do not permit third-party advertising partners to collect health data through our Services. For purposes of this Privacy Policy, health data means any information that identifies you, or that could reasonably be used to identify you, and that relates to your past, present, or future physical or mental health status. This includes conditions, diagnoses, symptoms, medications, treatments, test and lab results, health insurance information, biometric and behavioral inputs you provide to us, health-related location signals, and any inference we or others draw from that information. Any use or disclosure of your health data beyond delivering the Services you requested, meeting a legal obligation, or another purpose expressly described in this Privacy Policy requires your separate, affirmative, opt-in consent, which you may withdraw at any time without losing access to the Services. No other agreement between us, including our Terms of Use, grants us or any third party rights in your health data broader than those described in this Privacy Policy. 

Some of your medical data has special protections under federal law. These details are explained in our HIPAA Notice. If this Privacy Policy conflicts with the HIPAA Notice, the HIPAA Notice is the rule we will follow. Some health data we collect, including behavioral, self-reported, wellness, and coaching data you provide through our apps, may not be protected health information under HIPAA. That data is governed by this Privacy Policy and applicable state consumer health privacy laws. We apply the health data protections described in this Privacy Policy to all such data regardless of whether HIPAA applies to it. By accessing our websites or apps, you also agree to our standard rules. You can find these rules in our Terms of Use. 

We collect data that you type in or send to us. This happens when you email us, sign up for an account, or fill out forms. This data may include your name, phone number, email, home address, and mailing address. It also includes your sex, date of birth, payment details, and health insurance info. It includes any health issues you want us to help you with. 

We also gather technical details when you browse our site or use our mobile apps. We track details about the computer or phone you use. This includes your IP address, browser type, operating system, and country. We look at how you use our app. This means the pages you click, how long you stay, and any system errors. 

We collect location data about where you are. This includes general areas like your zip code. It can also include exact spots using your phone's GPS. We use this to provide location-dependent features of the Services. We do not use precise geolocation to select or deliver advertising, and we do not sell or share precise geolocation with advertising partners, data brokers, or analytics firms. For example, if your IP address shows you are in Los Angeles, you will see Los Angeles info. You can turn off GPS tracking in your phone's settings if you prefer. 

Cookies are small text files stored on your computer or phone. They remember your user ID, your choices, and the pages you visited. We use them so you do not have to log in every single time you visit our site. 

We use cookies to make your experience better, check how our site is performing, and stop fraud. We also use these tools for online ads. This means some of our business partners might use cookies to show you MediKarma ads on other websites. These ads are based on what you look at online. On our general marketing pages, our advertising partners may collect limited technical details such as IP address, device identifier, and browser type in order to estimate the general age range and browsing interests of our audience. We do not permit advertising or analytics tags, pixels, cookies, or software development kits that transmit data to third parties to operate on any screen or page where health data is entered, displayed, uploaded, or discussed. We do not disclose health data, health-derived audience segments, or health-related inferences to any advertising partner for any purpose, and we do not use health data to build, target, or suppress advertising audiences. 

Besides cookies, we use web beacons. These are tiny, invisible image files inside web pages or emails. They tell us how many people open our emails or click on our ads. This helps us improve our services. We use website analytics tools that track mouse clicks, scrolling, and typing on our site. This helps us make our website easier to use. These tools do not track you across other websites. 

 

Mobile phone IDs are data codes stored on your mobile device. They look at the apps you have installed and track traffic data. This helps us understand who is using our app. We may get info about you from other companies, like marketing firms or business partners. We might combine that new data with the info we already have about you. 

 

We may de-identify or aggregate data by removing personal identifiers and combining your information with information from other users. Where that data includes health data, we de-identify it in accordance with the standards at 45 C.F.R. 164.514(b), using either Expert Determination or the Safe Harbor method, before any use or disclosure beyond providing the Services. We publicly commit to maintaining that data in de-identified form, we do not attempt to re-identify it, and we contractually require every recipient to do the same and to impose the same obligation on any downstream recipient. We do not de-identify, aggregate, license, or sell health data to data brokers, advertising networks, or analytics firms for their own commercial purposes. 

 

We use your data to deliver the services you asked for. We also use it to show you products, events, and offers we think you will like. We do not use your health data to select, target, or personalize the products, events, or offers we show you unless you have given us separate, affirmative opt-in consent, which you may withdraw at any time. We use it to fix, maintain, and improve our apps and websites. We will contact you when you ask for help or when we must. We use your data to send you text alerts and emails. You can opt out of these at any time. 

We also use your data to spot and stop security breaches, fraud, or illegal acts. This protects our legal rights and property, and runs our business smoothly. We may use outside companies to store and handle your data in the United States. We require these companies by written contract to protect your data, to use it only to perform services for us, and not to sell, share, or retain it for their own purposes, applying safeguards at least as protective as those described in this Privacy Policy. Where a company handles protected health information on our behalf, we execute a HIPAA Business Associate Agreement before any data is disclosed. 

 

We may share your data with service providers who do work on our behalf. They help run and improve our services. We may share your name and contact information with affiliated companies or business partners so they can contact you about offers, but only where you have separately opted in to receive those communications. We do not share health data with affiliates, sister companies, or business partners for their own marketing purposes under any circumstances. If we sell our company, merge with another business, or file for bankruptcy, your data may be shared. Any successor will be bound by the commitments in this Privacy Policy with respect to health data collected before the transaction, and we will notify you before your health data becomes subject to a materially different privacy policy. This will only happen under strict, private rules. We will share your data if the law requires it. This includes responding to a court order, protecting public safety, or defending our legal agreements. 

 

When you give us your personal info, you can choose whether or not you want to receive marketing emails from us or our partners. If you want to stop receiving marketing emails, you can click the unsubscribe link at the bottom of our emails. You can also email us at info@Medikarma.com to change your settings. In your email, please tell us exactly what you want to stop. You can stop marketing emails from us, sharing your info with partners for marketing, or sharing your info with third parties for marketing. 

 

We will honor your request within 15 calendar days, and immediately where technically feasible. Requests submitted through in-app controls take effect immediately. Please note that even if you opt out of marketing, we will still send you important account updates. You will still get office emails. You cannot opt out of those. If we have already shared your info with a partner before you opted out, you must contact that partner directly to stop their emails. 

 

We only keep your data for as long as we need it to run our services. We also keep it to follow federal health laws like HIPAA. You can delete your account and data at any time. To do this inside our mobile app, go to your Profile, tap Profile Information, and select DELETE. We will delete your data within 30 days of your request, including from routine backup systems, and we will direct any service provider or third party that received your data to delete it as well. However, we may keep some records if the law requires it for audits, safety, or legal reasons. 

 

Our apps and websites may let you share info on social media sites like Facebook, Instagram, LinkedIn, or X (Twitter). We do not control these social media companies. Anything you post on their networks is governed by their privacy rules, not ours. We are not responsible for what happens to data you share on social media. 

 

Our services also contain links to other websites. These outside sites have their own privacy rules. We encourage you to read their policies. We use modern digital and physical security tools to protect your personal info from theft, loss, and unauthorized access. However, no internet connection is 100% secure. Because of this, we cannot guarantee total safety. You share your info at your own risk. If we experience a breach of unsecured health data that is not covered by the HIPAA Breach Notification Rule, we will notify affected individuals, the Federal Trade Commission, and, where required, the media, in accordance with the FTC Health Breach Notification Rule. 

 

Most web browsers accept cookies automatically. You can change your browser settings to reject or delete cookies. Doing so might cause our website to stop working properly. If you want to stop targeted ads from tracking your computer across the internet, you can visit the Network Advertising Initiative Consumer Opt-Out page, the Digital Advertising Alliance Consumer Opt-Out page, or the TRUSTe Advertising Choices Page to opt out. 

 

Even if you opt out of targeted ads, you will still see standard MediKarma ads. Ads shown to you before or after you opt out are never selected using health data or health-related inferences. We will also continue to track how you use our app to help improve our services. Some web browsers have a Do Not Track setting. We honor the Global Privacy Control (GPC) signal as a valid request to opt out of the sale or sharing of personal information. Legacy Do Not Track signals have never been standardized across the industry, and we do not process them separately; users who enable GPC receive the full opt-out. You can learn more about this at http://allaboutdnt.com

 

Our services are designed for people who are 13 years old or older. We do not knowingly collect info from children under 13. If you are under 13, please do not use our services. If we discover that a child under 13 has given us personal info without a parent's permission, we will delete it immediately. To report a child's account, email us at info@Medikarma.com

 

If you live in California, state law lets you request a free list once a year. This list shows any personal data we shared with other companies for marketing purposes during the past year. To ask for this list, email us at info@Medikarma.com

 

If you live in Washington, Nevada, Connecticut, or another state with a consumer health privacy law, you have additional rights regarding your health data. These include the right to confirm whether we collect, share, or sell your health data, the right to access the specific health data we hold and the list of third parties with whom we have shared it, the right to withdraw consent to the collection or sharing of your health data, and the right to have your health data deleted, including from our service providers and other third parties that received it. We will not deny you Services, charge you a different price, or provide a different level of quality because you exercised these rights. To exercise them, email us at info@Medikarma.com. We respond within 45 days and will tell you if we need a permitted extension. 

 

This Privacy Policy is a legal agreement between you and MediKarma. It does not create any legal rights for outside people. If you have any questions or concerns about your privacy, please reach out to us at MediKarma, Inc., 1900 N. California Blvd, 8th Floor, Suite 114, Walnut Creek, CA 94596 or by email at info@Medikarma.com or info@medikarma.ai

bottom of page