MedCompanion is built local-first: your information lives on your phone, the AI is optional, and your clinician stays in charge. Here's exactly how it works โ and how to check it for yourself.
Your check-ins and records are saved only in your phone's local storage. They aren't uploaded when you open the app.
Nothing goes to the AI until you choose a feature. Then only the text for that one task is sent, to generate your answer.
The AI features are stateless โ they answer and forget. Your health content is not written to our database.
Your data is not used to train models, and never sold or used for advertising. Full stop.
MedCompanion helps you organize and understand your own health information so visits go further. It is not a medical device and does not provide diagnosis.
We publish our data policy as machine-readable, live facts.
This isn't a brochure โ it's the actual configuration of our running server. Anyone can read it, including your hospital's compliance team:
curl https://medcompanion-ai.up.railway.app/data-policy
The architecture above is real and live today: local-first, single-vendor for text AI (Anthropic), and no server-side storage of health content by default. That already removes most of the data-exposure surface teams worry about.
The formal assurances a hospital needs are a separate, in-progress track: signed Business Associate Agreements (BAAs) with each AI vendor, zero-data-retention configuration, a HIPAA compliance program, and a SOC 2 audit. We'd rather tell you exactly where that stands than overstate it. Reach out and we'll share our current data-flow documentation and roadmap.