Back to Trust & Security

    Security Incident & Breach Notification Policy

    Last updated: 18 July 2026

    This page is maintained by Derek Doran (Medi-Chi) to describe how we respond to security incidents affecting Medi-Chi, and how we notify people who may be impacted. It sits alongside our Trust & Security page and Privacy Policy.

    What counts as a security incident

    A security incident is any event that may compromise the confidentiality, integrity, or availability of Medi-Chi accounts or data. Examples include unauthorised access to accounts, exposure of account data (email, hashed credentials, subscription status), a confirmed vulnerability in a subprocessor that touches our data, or extended service outages caused by attack.

    A personal data breach is an incident that we have reason to believe resulted in unauthorised access to, loss of, or disclosure of personal information belonging to identifiable users. Not every incident is a breach — we investigate first, then classify.

    Response timeline

    Once an incident is reported or detected, we work to the following targets:

    • Within 1 hour — acknowledge the report internally and begin triage.
    • Within 24 hours — contain the issue (revoke keys, disable affected functions, roll credentials, block abusive traffic) and preserve logs for investigation.
    • Within 72 hours of establishing that a personal data breach has occurred and is likely to result in risk to affected individuals, notify those individuals and, where required, the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.
    • Within 14 days — publish a post-incident summary on this page describing what happened, what data was involved, what we did, and what changes we've made to prevent recurrence.

    Timelines start when Medi-Chi becomes aware of the incident. Contained incidents with no user impact may be handled internally without public notification.

    Who gets notified

    • Affected users — anyone whose account or personal information was, or is reasonably believed to have been, involved in the incident.
    • OAIC — when the incident meets the threshold of an eligible data breach under the Privacy Act 1988 (Cth).
    • Payment provider (Stripe) — if the incident could touch billing data, even though card details are handled entirely by Stripe and never stored by Medi-Chi.
    • Subprocessors — Lovable Cloud, Cloudflare, or Google (Gemini via Lovable AI Gateway) where relevant to containment.
    • All users — via this page and a banner in the app, when an incident affects platform availability or security posture broadly, even if no personal data was exposed.

    How we contact affected users

    Notifications are sent using the channels below, in order of priority:

    1. Direct email to the address on your Medi-Chi account, sent fromnotify@medichi.online. The subject line will begin with "Security notice —" so it's easy to identify.
    2. In-app banner shown on sign-in for affected accounts, linking to the full incident summary.
    3. Public post-incident summary on this page, listing the date, scope, data involved, remediation, and any action required from users.

    Each notification will describe, in plain language: what happened, when it happened, what data was involved, what we've done, what you should do (e.g. rotate a password), and how to reach us with questions.

    We will never ask you to send us your password, credit-card number, or a copy of your ID by email as part of an incident response. If a message claims to be from Medi-Chi and asks for these, treat it as suspicious and email us at the address below to verify.

    What we do after an incident

    • Root-cause analysis and a written post-incident review.
    • Fixes applied to code, configuration, or process to prevent recurrence.
    • Updates to the Trust & Security page if our controls or subprocessors change.
    • Where relevant, disclosure to the reporter and public credit for responsible reports.

    Reporting a vulnerability or suspected incident

    If you believe you've found a security issue in Medi-Chi, or you think your account has been compromised, please email support@medichi.online with the subject line "Security report". Include steps to reproduce, the URL or feature involved, and any relevant screenshots or logs. Please do not publicly disclose the issue until we've had a reasonable opportunity to fix it.

    We aim to acknowledge security reports within 1 business day and to keep reporters updated as we investigate.

    This policy describes Medi-Chi's own practices as the app owner. It is not a certification or a legal guarantee, and it does not replace the obligations set out in our Privacy Policy and Terms.