MiniMedApp - Medtronic Mobile Healthcare Application
Effective Date: December 24, 2025 Last Updated: December 24, 2025 Version: 1.0.3
Introduction
MiniMedApp is a mobile healthcare application developed for Medtronic. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.
Information We Collect
Personal Information
We may collect the following personal information:
Device Information: Device ID, operating system, app version
Usage Data: App features accessed, video training progress, FAQ interactions
Technical Data: IP address, network connection type, error logs
Permissions Used
Android Permissions:
INTERNET (Required): Enables communication with our secure servers for authentication, content delivery, and data synchronization
CAMERA (Optional): May be used for future features such as document scanning or video consultations (currently not actively used)
iOS Permissions:
Network access for secure HTTPS communications
How We Use Your Information
We use collected information to:
Provide AI-powered chatbot assistance
Track training video progress for educational purposes
Deliver self-service support and FAQs
Process and respond to complaints and inquiries
Improve app functionality and user experience
Ensure HIPAA compliance and data security
Generate usage analytics (anonymized)
Data Security
Security Measures
We implement industry-standard security measures including:
Encryption: All data transmitted uses HTTPS with TLS 1.2+ encryption
JWT Authentication: Secure token-based authentication system
Secure Storage: Credentials stored using platform-specific secure storage (Keychain on iOS, EncryptedSharedPreferences on Android)
Memory Protection: Secure memory allocation to prevent data leaks
App Transport Security: HTTPS-only policy enforced on iOS
Minimum SDK Requirements: Android 11+ (API 30) for enhanced security
WebView Security: Remote debugging disabled in production builds
HIPAA Compliance
As a healthcare application, we maintain strict compliance with:
Health Insurance Portability and Accountability Act (HIPAA)
Protected Health Information (PHI) handling standards
Secure data transmission protocols
Access control and audit logging
Data Sharing and Disclosure
We Do NOT:
Sell your personal information to third parties
Share medical/health data without explicit consent
Use your data for advertising purposes
Track you across other apps or websites
We MAY Share Data:
With Medtronic: As the parent organization for service delivery
Healthcare Providers: Only with your explicit consent for medical purposes
Legal Requirements: When required by law, court order, or government regulation
Service Providers: Trusted third-party services that help operate our app (under strict confidentiality agreements)
Your Rights
You have the right to:
Access: Request a copy of your personal data
Correction: Update or correct inaccurate information
Deletion: Request deletion of your account and associated data
Portability: Receive your data in a machine-readable format
Opt-Out: Disable optional features like progress tracking
To exercise these rights, contact us at: privacy@medtronic.com
Children's Privacy (COPPA Compliance)
Important: MiniMedApp is NOT intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
Data Retention
We retain your information for as long as:
Your account remains active
Required for legal/regulatory compliance (typically 7 years for healthcare records)
Necessary for dispute resolution
You may request account deletion at any time, subject to legal retention requirements.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure adequate safeguards are in place for international transfers, including:
Standard Contractual Clauses (SCCs)
GDPR compliance for EU users
Adequate data protection frameworks
Cookies and Tracking Technologies
We use:
Session Tokens: For authentication (stored securely, automatically expire)
Local Storage: For offline functionality and app preferences
Analytics: Anonymized usage statistics (no personal identifiers)
Logging Services: For error monitoring and debugging
All third-party services are vetted for HIPAA compliance and data security.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. Changes will be effective upon posting the updated policy with a new "Last Updated" date. We encourage you to review this policy regularly.
Material changes will be notified via:
In-app notification
Email (if provided)
App store listing update
Contact Us
For questions, concerns, or requests regarding this Privacy Policy: