Last updated 31 July 2026
Medi-Chi is a clinical decision support tool for acupuncturists and TCM practitioners. The AI diagnosis and translation features are designed to work on de-identified clinical inputs only — symptoms, tongue and pulse findings, patterns, and points.
We do not ask for and do not want patient names, dates of birth, contact details, Medicare or insurance numbers, addresses, or any other direct identifiers in the diagnosis, reverse diagnosis, or study-tool inputs. Practitioners are asked to de-identify before pasting or typing anything into an AI prompt.
Optional patient profile records inside the practitioner dashboard (first name, notes, VAS scores) are stored in your own account and are never sent through the public AI prompts. They stay behind row-level security tied to your user ID.
user_roles table checked by a security-definer function — roles are never stored on the profile record.We keep account data and saved cases indefinitely while your account is active, so your history is there when you come back.
When you delete your account (or email support@medichi.online asking us to), we remove your account and associated user-owned rows within 30 days. Some records (Stripe payment history, minimal transaction logs required for tax and refund obligations) are retained by the relevant subprocessor per their own policies.
Full step-by-step instructions, what is deleted versus kept, and the retention timeline live on our account and data deletion page.
Cached AI responses tied to de-identified inputs expire on a rolling 7-day TTL.
Medi-Chi relies on a small set of vendors to run the service:
If you think you have found a security or privacy issue, please email support@medichi.online. Include steps to reproduce and, if possible, a proof of concept. We aim to acknowledge reports within two business days.
Please do not include real patient data in your report. If a reproduction needs sensitive input, use synthetic or clearly-fake data.
For our full response process and breach notification timelines, see the Security Incident & Breach Notification Policy.
Medi-Chi is built and operated in Australia. It is designed to align with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and with AHPRA advertising and record-keeping guidance for registered practitioners.
Medi-Chi is not HIPAA covered and is not intended for storing or transmitting identifiable US Protected Health Information (PHI). We do not currently sign Business Associate Agreements (BAAs), and several of our subprocessors are not engaged under BAAs on our current plan. Please do not paste identifiable US patient data into the app.
Medi-Chi is also not a certified medical device and has not been evaluated under the EU MDR, UK MHRA, FDA, or TGA medical-device frameworks. It is a clinical decision-support and education tool.
Note for US-based practitioners
If you practise in the United States and want to use Medi-Chi alongside identifiable patient care, you remain the covered entity. We suggest you:
We are happy to provide a plain-English description of Medi-Chi's data flows to support your own consent form — email support@medichi.online.
Before pasting or typing patient information into any Medi-Chi input (diagnosis, reverse diagnosis, tongue upload, study tools, saved cases), run through this checklist. It mirrors the HIPAA Safe Harbor method — remove all 18 identifiers so the input is no longer PHI.
Strip these before submitting
Safe to submit
Quick rewrite examples
A quick shortcut: if a colleague reading the input could plausibly guess which patient it is, it is not yet de-identified. When in doubt, generalise further. This checklist supports — but does not replace — your own HIPAA compliance program and patient authorisation process.
The Medi-Chi Android app is the same web application wrapped as a Trusted Web Activity, so it collects exactly what the website collects. The table below mirrors, word for word, the Data safety form we submitted in Google Play Console.
| Data type | Collected | Shared | Purpose | Required |
|---|---|---|---|---|
| Name, Email address, User IDs | Yes | No | Account management, App functionality | Required |
| User payment info, Purchase history | Yes | No | Purchases (handled by Stripe) | Optional |
| Health info | Yes | No | App functionality | Optional |
| Photos | Yes | No | App functionality (tongue images) | Optional |
| App interactions, In-app search history | Yes | Yes | Analytics | Optional |
| Other user-generated content | Yes | No | App functionality | Optional |
| Crash logs | Yes | Yes | Analytics | Optional |
| Diagnostics | Yes | Yes | Analytics | Optional |
| Device or other IDs | Yes | Yes | Analytics, Advertising or marketing | Optional |
Not collected
Sharing, in plain terms
The only data that leaves Medi-Chi's own systems is analytics: Google Analytics 4 and the Meta Pixel receive app interaction events, search terms entered in the site search, performance timings, and the browser or device identifiers those tools set. Because the Meta Pixel is used for marketing measurement, we declare Advertising or marketing as a purpose for device identifiers. Both tags are blocked until you accept the analytics choice in the consent banner, and neither receives your clinical inputs, tongue photos, saved cases, or patient profile records.
Security practices declared
Content rating note: Medi-Chi does not allow users to exchange content with each other, and does not promote or sell age-restricted products. Herb monographs are reference material, not products for sale.
Under applicable privacy law you can request a copy of your data, ask us to correct it, or ask us to delete it. Email support@medichi.online and we will respond within 30 days.
Medi-Chi provides the platform and its security controls. As the treating practitioner, you remain the data controller for your patients — including obtaining consent, keeping identifiable clinical records inside your own practice management system, and following AHPRA (or your equivalent regulator's) requirements. Medi-Chi is a decision-support tool and does not replace clinical judgement.