Last updated: June 21, 2026
Privacy policy
Medium helps physical therapists manage patient conversations and appointments over WhatsApp. This policy explains what data we process, why we process it, and how privacy requests are handled.
Roles
Each physical therapist or practice using Medium is the controller for their patient data. Medium acts as a processor and handles that data under instructions from the practice.
For account data about the practice owner, Medium acts as controller so we can provide, secure, and support the service.
Data we process
- Account data, such as email address, practice name, timezone, and product settings.
- WhatsApp connection data, such as phone number identifiers, WhatsApp Business account identifiers, encrypted access tokens, quality status, and template status.
- Patient and appointment data, such as names, phone numbers, conversations, messages, appointment times, appointment status, notes, and reminder responses.
- PWA and device data, such as push subscription endpoints, service worker state, and locally cached dashboard data used for offline access.
- Operational data, such as audit logs, security logs, idempotency records, delivery status, and aggregate product metrics.
How we use data
- To authenticate users and keep tenant data separated.
- To receive, send, and display WhatsApp conversations.
- To book, reschedule, cancel, remind, and confirm appointments.
- To let the practice review chats, take over conversations, and manage availability.
- To run AI-assisted scheduling and route conversations to a human when needed.
- To secure the service, detect failures, prevent duplicate processing, and maintain audit logs.
AI processing
Production AI requests are routed through OpenRouter to OpenAI for scheduling-related responses. The app sends only the conversation and scheduling context needed to answer the patient. The AI is instructed not to diagnose, provide medical advice, handle emergencies, or discuss legal, billing, or insurance matters.
Production requests use privacy controls that request zero data retention and deny provider data collection where supported. OpenRouter may retain request metadata, and AI processing may involve infrastructure outside the European Economic Area.
Subprocessors
Medium relies on a small set of service providers to operate the product:
- Supabase for Postgres, authentication, and realtime data.
- Vercel for hosting the Next.js app and server functions.
- Inngest for background jobs, retries, and scheduled reminders.
- Meta and WhatsApp for message delivery and WhatsApp Business account integration.
- OpenRouter and OpenAI for production AI inference.
We do not sell personal data.
Retention
Message retention is controlled per practice. The default retention period is 90 days, and older messages are purged by a scheduled job. Appointment, patient, account, and audit data are kept while needed to provide the service, meet legal obligations, resolve disputes, and maintain security. Aggregate anonymized metrics may be kept indefinitely.
Security
Medium uses tenant-scoped database rules, TLS in transit, encrypted WhatsApp access tokens, audit logging for patient-data access, and least-privilege application paths. Primary app data is hosted in EU-region infrastructure where available.
Your choices and rights
Practices can update account and retention settings in the dashboard. Patients should first contact their practice for access, correction, deletion, or objection requests because the practice controls the patient relationship.
Privacy requests can also be sent to klaididingu@gmail.com. During early access, export and deletion requests may be handled manually while product workflows are completed.
Cookies and local storage
Medium uses authentication cookies, service worker storage, IndexedDB, and browser storage needed to keep users signed in, support offline dashboard access, queue offline changes, and remember PWA state. The current MVP does not use third-party marketing analytics cookies on public pages before consent.