Legal
Privacy policy
Last updated: 3 August 2026
- App name: Medical Records Vault (as listed on Google Play)
- Package name / Application ID:
com.medical.records.vault - Developer name (as shown on Google Play): FourTwos
- Legal entity: FOURTWOS INC., a Delaware corporation
- Registered address: 8 The Grn Ste B, Dover, DE 19901-3618, United States
- Contact: contact@fourtwos.com
- Website: https://fourtwos.com/
- Effective date: 3 August 2026
- Last updated: 3 August 2026
This policy covers the Medical Records Vault mobile app (com.medical.records.vault), published on Google Play by FourTwos and operated by FOURTWOS INC. ("we", "us"), along with our website at https://fourtwos.com/ and any related services.
This is the plain-English version of how we handle your data. We wrote it the way we'd want a privacy policy to read about a product our family uses: short sentences, no hedging, no surprises.
We never sell your data, and we never use it to train AI
Your records — every document, every chat message, every note — are not sold to anyone, ever, and are not used to train any AI model, ours or anyone else's. The AI providers we use (listed below) are contractually prohibited from training on the prompts and documents we send them. This is the single most important promise on this page. If it ever changes, you will hear it here first, in plain English, before it ships.
What we collect
Three categories of data, kept separate from each other:
- Account data — your email address, a hashed password, the date you signed up, and (if you join a family plan) which other accounts you're linked to.
- Health data you upload — the documents you give us (PDFs, images, scans), the structured fields we extract from them (medications, dates, lab values), the plain-English explanations we generate, and any chat messages you send about a document. This is sensitive personal data, and we treat it that way.
- Operational data — request timestamps, error reports, crash logs, and aggregate usage counts (e.g. "how many uploads happened today"). Operational data never contains document contents or personal identifiers in plain text.
We do not collect your precise or approximate location, your contacts, your device's advertising identifier, or any data for advertising purposes.
Device permissions the app asks for
- Camera — only when you choose to photograph a document. We never access the camera in the background.
- Photos / files — only to let you pick a document to upload. We read the specific files you select and nothing else.
- Notifications — only if you opt in, to tell you when a document has finished processing.
You can revoke any of these in your Android settings at any time; the rest of the app keeps working.
Why we collect it
- Account data: so you can log in, recover access, and share with family.
- Health data: because that's the product — we can't explain a document we don't have.
- Operational data: so we can keep the service running and fix bugs before you notice them.
We do not collect data for advertising, profiling, scoring, or any secondary commercial purpose. If we ever want to do something new with your data, we'll ask you first.
Our legal bases, where they apply: your consent for processing health data, performance of our contract with you for account data, and our legitimate interest in a working, secure service for operational data. You can withdraw consent at any time by deleting the relevant document or your account.
Who we share it with (nobody, except the subprocessors listed here)
We do not sell, rent, license, or share your data with any third party for their own purposes. The only entities that touch your data are the subprocessors that run the service for us, each scoped to a specific job:
- Amazon Web Services (AWS) — hosting and storage. Your encrypted database and uploaded files live on AWS infrastructure. Region: EU by default.
- OpenAI — AI inference for plain-English explanations and chat. Documents and chat messages are sent under a zero-retention agreement; OpenAI is contractually prohibited from training on our data.
- Anthropic — AI inference, used as a fallback and for specific tasks. Same zero-retention, no-training terms as above.
- Sentry — error reporting. Receives stack traces and request metadata (URL, status code, hashed user ID). Configured to scrub personal data before sending; never receives document contents.
We may add or change subprocessors over time. We'll publish the change here with at least 30 days' notice for any subprocessor that handles health data.
We will also disclose data if we are legally required to — a valid court order or equivalent legal process — and we will tell you when we're permitted to.
How we protect it
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to the people who need it, protected by multi-factor authentication, and logged. We don't run analytics SDKs or advertising SDKs inside the app.
No system is perfect. If a breach ever affects your data, we will notify you and the relevant regulators within the timeframes the law requires.
How long we keep it
- Account data — for as long as your account is open, plus 30 days after you delete the account (so we can recover it if you change your mind).
- Health data — for as long as you keep it. When you delete a document, it's removed from primary storage immediately and from backups within 7 days.
- Operational data — error reports retained for 30 days; aggregate usage counts kept indefinitely (they contain no personal data).
Deleting your account and your data
You can delete a single document from inside the app at any time.
To delete your entire account and all associated data:
Please email us on contact@fourtwos.com from your account's email address.
Deletion removes your account data, all uploaded documents, all extracted fields, and all generated explanations. It is permanent after the 30-day grace window. Aggregate usage counts, which contain no personal data, are retained.
Your rights
Regardless of where you live, Medical Records Vault applies the same baseline rights to everyone:
- Access — see everything we have on you, in one click.
- Export — download your data in standard formats (PDFs in original form, structured data as JSON/CSV).
- Correction — edit any structured field we've extracted.
- Deletion — delete a single document or your entire account, with the timelines above.
- Object / restrict — turn off optional processing (e.g. AI explanations) on a per-document basis.
EU/UK residents have these rights under the GDPR, and may complain to their local supervisory authority. Indian residents have these rights under the Digital Personal Data Protection Act, 2023.
To exercise any of them, email contact@fourtwos.com and we'll respond within 30 days (usually within a week).
Privacy and grievance contact: Ramanan Raj, FOURTWOS INC., 8 The Grn Ste B, Dover, DE 19901-3618, United States — contact@fourtwos.com
Children
Medical Records Vault is not intended for use by anyone under 16 as the primary account holder. A parent or legal guardian may store and manage records about their child as a profile under their own account. We do not knowingly collect data from children under 16 as account holders, and if we discover such an account we will delete it.
International transfers
FOURTWOS INC. is incorporated in the United States. We store data in the EU by default, and some subprocessors listed above may process data in other countries, including the United States. Where that happens, transfers are covered by Standard Contractual Clauses or an equivalent lawful transfer mechanism.
Changes to this policy
We will update this policy as the product evolves. For any material change — adding a subprocessor, expanding what we collect, or changing how we share data — we will email everyone with an active account at least 30 days before the change takes effect. The "Last updated" date at the top reflects the most recent change.
Contact
For privacy questions, data requests, or anything in this document you'd like clarified, email contact@fourtwos.com or write to FOURTWOS INC., 8 The Grn Ste B, Dover, DE 19901-3618, United States. A real human reads every message.