Privacy Policy
Last updated 6 September 2026
This policy covers mednais.com and the MedNAIS™ product — the web console at sop.mednais.com and the iPhone, Android and watch apps. Questions, or a request about your own data, to mednais@samplify.org.
MedNAIS is operated by Samplify FZCO, a company registered in Dubai, United Arab Emirates, at DDP, Building A2, office 101. In this policy “we” means Samplify FZCO.
The short version
- We do not sell personal data, and we do not use it for advertising.
- The apps contain no advertising network, no attribution SDK and no cross-app or cross-site tracking. There is no tracking prompt because there is nothing to prompt about.
- Nothing you write or upload is used to train any language model, ours or anyone else's.
- You can delete your account yourself, at once, without asking us — in the apps, in the console, or from mednais.com/delete-account.
- MedNAIS is not designed to hold data about the people your work concerns — a patient, a customer, a member of the public — and should not be used to hold it.
1. What we collect, and when
If you only visit this website
- Analytics, only if you agree to it. We ask on your first visit. Until you answer yes, Google Analytics is not loaded at all — no request to Google, no script, no cookie. If you agree, it records the pages visited, an approximate location derived from the network address, and the kind of device and browser, and we use it to see which pages are read. If you decline, nothing loads and we do not ask again. Either answer can be changed later from “Cookie choice” in the footer, and declining after having agreed deletes the cookies Analytics has already set. Nothing on this site is withheld from you either way.
- The contact form. The name, e-mail address, country and message you type. It is sent to our own inbox as an e-mail and is not published or passed to anyone else. The form is protected by Google reCAPTCHA, which assesses whether the request came from a person and which sets cookies of its own. It loads when you start typing in the form and not before, so opening the page to read our address involves no request to Google. We treat it as necessary to the message you have chosen to send rather than as something to be agreed to separately; if you would rather not involve it, write to us directly instead of using the form.
- Server logs. Our host records requests, including network addresses, for security and reliability.
The demonstration at sop.mednais.com/demo needs no account. Nothing done in it is recorded or sent anywhere.
If you use MedNAIS with an account
- Your account. Your e-mail address; your name and picture if your Google or Apple account supplies them; a password, held in the customary irreversible form, if you chose to set one; the language and theme you selected. If you sign in with a one-time code, we hold the address the code went to.
- Your place in an organisation. Which organisations you belong to, your role in each, who invited you, and the fact and date of your having accepted the terms of use.
- What you write and upload. Procedures, their versions and steps; the documents and files your organisation uploads and the text extracted from them; what you stated about the basis on which your organisation holds a third party's document.
- What happens when a procedure is run. Which version was performed and by whom, when each step was started and finished, steps skipped, steps returned to, answers given to a step, notes typed at a step, and codes entered — together with whether a code was scanned or typed by hand. That record is the point of the product: it is what an inspection or an incident review asks for.
- Devices. Which watch you paired, and technical logs from the application.
What we do not collect
- No location. The apps use no location interface and hold no location entitlement.
- No photographs. On Android the camera is used only as a barcode detector: frames are analysed on the device and discarded, never stored and never uploaded. On iPhone the camera is not opened at all, and a code is typed in.
- No health or fitness data, no contacts, no financial data, no advertising identifier.
- One exception, on Android only. The barcode scanner uses Google's ML Kit. Image data stays on the device, but the library itself sends Google diagnostic and usage data — device information, app version, performance metrics, error codes — and there is no supported way to switch that off. We disclose it because it is Google's collection through a library we ship, not ours. The iPhone app contains no ML Kit and none of this applies to it.
2. Why we hold it
To let you sign in and keep you signed in; to show your organisation its procedures and let people run them; to produce the record of what was done and the timing figures calculated from it; to send the one-time codes and invitation mail the product depends on; to keep the service secure and working; and to answer you when you write to us. For the personal data your organisation puts into MedNAIS — your colleagues' accounts, and whatever appears in the procedures and records they create — your organisation decides what is collected and why, and we process it on its instructions.
3. Who processes it on our behalf
This is everyone. We will give notice before adding or replacing any of them. We do not otherwise disclose personal data, except where the law requires it of us.
| Who | What they receive | Where |
|---|---|---|
| Supabase, Inc. | All customer data at rest: accounts, procedures, uploaded files, extracted text, execution records. Also handles sign-in. | Managed PostgreSQL in the European Union (Stockholm, eu-north-1) |
| Vercel Inc. | Hosting and request handling for this website and for the MedNAIS console, plus application logs. Document text passes through the application; it is not stored there. | United States and Vercel’s global edge network |
| Anthropic PBC | The extracted text of a document you upload, or the passages selected as relevant, and the topic you typed — sent when you ask MedNAIS to draft a procedure. | United States |
| OpenAI OpCo, LLC | The same text, to compute the numerical representations (embeddings) that make your own documents searchable. | United States |
| Google LLC | Sign-in with Google, if you use it. On this website: analytics, but only if you agreed to it, and reCAPTCHA, but only once you start filling in the contact form; also delivery of contact-form mail to our inbox. In the Android app: diagnostic and usage data sent by Google’s on-device barcode-scanning library. | United States and Google’s global infrastructure |
| Apple Inc. | Sign in with Apple, if you use it. Apple tells us the identifier and the address you chose to share, which may be a relay address. | United States |
4. What happens when you ask MedNAIS to draft a procedure
MedNAIS can write a first draft of a procedure from a document your organisation uploaded, or from a description you typed. To do that we send the extracted text of the document — or the passages of it selected as relevant — and the topic you entered to Anthropic, which produces the steps, and to OpenAI, which computes the search embeddings. The files themselves are not sent; images and formatting are not sent. Both providers are engaged under terms that forbid the use of content submitted through their programming interfaces to train their models.
This matters if you upload a standard you have licensed: many are sold under single-user or single-site licences that forbid disclosure of the document to anyone outside the licensed entity, and transmission to a processor may fall within such a prohibition. Check the licence before uploading. A procedure can refer to a document by name without our ever receiving its text.
A drafted procedure is a draft. Nobody may perform it until a person qualified in that work has read it in full and published it. MedNAIS will not publish a version by itself.
Checking a document name against its register. When MedNAIS names a standard or a regulation that ordinarily governs a piece of work, our server queries the public catalogue of the body that issues it — among them the Estonian Centre for Standardisation, the United States Electronic Code of Federal Regulations, the National Institute for Health and Care Excellence, the WHO institutional repository and Crossref — to confirm the designation, title and edition. What travels is the designation or title being checked. No personal data is sent, and the request comes from us rather than from your device, so your network address is not disclosed to those bodies.
5. Data about the people your work concerns
The execution part of MedNAIS is built to store nothing about the subject of the work: no patient identifier, no diagnosis, no observation, and equally no customer, no vehicle registration and no name of whoever the work was done for. A procedure describes how work is done; it does not need anybody's name. The free-text and code fields at the point of work are the likeliest place for such data to arrive anyway, and the app says so where you type: please do not put personal data in them.
6. Where it is stored, and transfers
Customer data at rest is held in a managed PostgreSQL database in the European Union (Stockholm). The application runs on infrastructure in the United States and on a global edge network, and the model providers named above are in the United States. So using MedNAIS involves transferring personal data outside the European Economic Area and outside the United Arab Emirates. We rely on the contractual protections in our agreements with those providers. If your organisation needs those transfers documented for its own compliance file, or needs a separate data processing agreement, write to us and we will deal with it individually.
7. How long we keep it, and deleting your account
We keep your account and your organisation's data for as long as the organisation uses MedNAIS. An owner can delete an organisation from its settings, which removes that organisation's procedures, documents, uploaded files and execution records.
You can delete your own account yourself. In the iPhone and Android apps, on your account screen; in the web console under “Sign-in and security”; and there is a page open to anybody at mednais.com/delete-account that says what deletion does and takes you to it. You do not have to ask us and we do not have to agree. It takes effect at once and cannot be undone.
Deletion removes the account and every way of signing in to it — the e-mail address, any password, any Google or Apple identity — along with your name, your picture, any watch you paired, any pending request to join an organisation, and the record of your having accepted the terms. Every session on every device ends. An organisation you own that has nobody else in it is deleted with your account, together with its procedures, runs, documents and files.
What your organisation keeps. The record of procedures you carried out stays with the organisation you carried them out for — which version, when, in what order, how long each step took — along with its audit entries for administrative actions you took and the record that you wrote or published a particular procedure. Documents and files you uploaded for an organisation likewise stay with it. That record is the organisation's evidence of its own work rather than a personal file, and its timing figures are calculated from it, so removing it would alter, retroactively, numbers other people rely on. None of what stays names you: what is left of your profile is an identifier those records point at, with nothing in it, and screens and exports say “Deleted account” where your name used to be.
Files belonging to a deleted organisation are removed from storage within a day. Backups are cycled out rather than edited, so a copy can persist in backup for a short period after deletion.
A message you send through the contact form on this website is ordinary e-mail in our inbox: it is kept while the conversation is useful, and no longer than two years after the last reply. Ask us to delete it sooner and we will. Server and security logs are kept for a matter of weeks.
8. Your rights
Subject to applicable law you may ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to our holding it. Deletion of your own account needs no request at all — see section 7. Ask us and we will export your organisation's procedures and records in a machine-readable form. Write to mednais@samplify.org. Where your data sits inside an organisation's account, we may need to involve that organisation, because it decided what was collected.
9. Children
MedNAIS is a tool for people at work. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has an account, write to us and we will remove it.
10. Security
Connections are encrypted in transit. Each organisation's data is separated at the database level rather than by application code alone, and what a person may read or write is decided by their role. What we do and do not claim is set out on our security page, which is deliberately explicit that we hold no security certification.
11. Changes
When we change this policy we publish the new text here and change the date at the top. Where the product's own terms of use and this policy differ about the product, the terms — section 7 of them — are the more specific of the two.
12. Contact
Samplify FZCO, DDP, Building A2, office 101, Dubai, United Arab Emirates. mednais@samplify.org.