Privacy policy
My Medicine Cabinet stores health information, so we keep the data set small, keep it tied to your account, and give you a way to export or delete it.
Last updated 30 July 2026. This page is maintained by Bernard Piccione and describes how My Medicine Cabinet works. It is not an independent certification or legal advice.
Who is responsible
Bernard Piccione, established in Europe (EU/EEA) and the United States, is the data controller for personal data processed in My Medicine Cabinet. Privacy contact: privacy@bernardpiccione.com.
What we collect
- Account data: email address, and the name and avatar supplied by Google or Apple if you sign in that way.
- Health data you enter: medicines, strengths, dose schedules, pill counts, scanned pack details (GTIN, batch, serial, expiry) and run-out dates.
- Care contacts you add: your doctor's and pharmacy's name, address, phone and email.
- Refill requests: the message content and the date it was emailed to your doctor.
- Costs and claims: amounts in euro, claim status and any receipt files you upload.
- Reminders and check-ins: your reminder times, chosen channels (email, text or browser), and your answers about whether a dose was taken.
- Caregiver data: who you granted access to, what they may see, and an activity log of actions taken on a patient record.
- Technical data needed to run the service: authentication tokens, and standard server logs.
Why we process it, and on what legal basis
- Health data (Art. 9 GDPR special category) is processed only on your explicit consent, given when you create an account and add medicines. You can withdraw consent at any time by deleting the data or your account.
- Account and authentication data is processed to perform the contract with you (Art. 6(1)(b)).
- Refill emails to your doctor are sent only when you press send, on your instruction.
- Reminder emails and text messages are sent only after you switch reminders on and pick a channel.
- Security logging and abuse prevention rests on our legitimate interest in a safe service (Art. 6(1)(f)).
Who can see your data
- You, and any caregiver you explicitly grant access to for a specific patient record. You can revoke that access at any time.
- Database access rules restrict every record to the account that owns it or has been granted access.
- Doctors and pharmacies only receive what you choose to send them in a refill email.
- We do not sell personal data and do not use it for advertising or profiling.
Processors and third parties
- Hosting, database, authentication and file storage run on the Lovable Cloud platform (Supabase infrastructure).
- Outbound refill, reminder and check-in emails are sent through Lovable's managed email service from notify.bernardpiccione.com.
- Text-message reminders are sent through GatewayAPI, which receives your mobile number and the message text.
- Sign-in with Google or Apple, only if you use those buttons.
- Care contact lookup uses OpenStreetMap Nominatim; only the search text you type is sent, never your medicine list.
- Interaction checks run against a curated open dataset inside the app; your medicine names are not sent to a third-party interaction service.
- Optional label reading uses the Lovable AI Gateway on the photo you scan.
Storage location and transfers
Data is stored on the Lovable Cloud platform. Where a processor operates outside the EU/EEA, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
How long we keep it
- Medicines, packs, refills, costs and receipts are kept until you delete them or delete your account.
- Caregiver activity logs are kept for the life of the patient record, so there is an audit trail of who changed what.
- When you delete your account, associated records are removed; short-lived backups may persist for a limited period before rotating out.
Security
- Traffic is encrypted in transit (HTTPS) and data is encrypted at rest by the hosting platform.
- Every table enforces row-level access rules tied to your authenticated account.
- Receipt files are stored in a private bucket that is not publicly readable.
- Sign-in supports email/password plus Google and Apple, and multiple sign-in methods can be linked to one profile.
Cookies and local storage
We use only what is needed to keep you signed in and remember your settings. See the cookie notice for the full list.
Your choices
You can edit or delete any medicine, pack, contact, receipt or claim from within the app, revoke caregiver access at any time, and request an export or full deletion by email. See the GDPR page for your full rights and how to exercise them.
Children
The app is intended for adults. A parent or legal guardian may maintain a child's medication record as a caregiver, and is responsible for that data.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how health data is used, ask for your consent again.