Privacy Policy

GMP — Global Medical Passport · Last updated: September 3, 2026

GMP is an application that allows you to save, organize and share your personal medical history. To function, the application processes personal data and health-related data, which the General Data Protection Regulation (GDPR) classifies as special categories of data. This policy describes, in concrete terms, what the application actually does with that data.

GMP does not replace medical advice, diagnosis or treatment and is not a medical device.

1. Data controller and contact details

The controller responsible for processing personal data through the GMP – Global Medical Passport application and website is MOMENTAOMINUTO, LDA, tax number 517905159, headquartered in Portugal (hereinafter "GMP", "we").

  • Contact for privacy matters and exercising rights: privacy@gmedicalpassport.com
  • Official websites: gmedicalpassport.com and www.gmedicalpassport.com

If applicable law requires the appointment of a Data Protection Officer (DPO) or an EU representative, their contact details will be published on this page.

2. Data we collect

We only collect the data that the user enters or uploads into the application, plus the minimal technical data necessary to authenticate the session and provide the service.

2.1 Account data (required)

  • Email address and password (or authentication via Google account).
  • Internal user identifier and GMP passport identifier generated by the system.
  • Account creation and update dates.

2.2 Profile data (optional)

All of the following fields are optional. The application works without them, albeit with fewer features:

  • Identification: full name, preferred name, photo/avatar, date of birth, biological sex, gender identity, nationality, country of residence.
  • Contacts: phone number, secondary email, address (address lines, city, state/province, postal code, country).
  • Emergency contact: name, phone number and relationship.
  • Preferences: interface language, primary and secondary clinical language, date format, unit system, time zone, currency, notification channel and language, theme.
  • Billing data, when provided: billing name, tax identification number, billing address, billing email and phone, company name and registration number, preferred currency, payment method, IBAN.
  • Country-specific fields (for example, fields applicable to Brazil or the United States) when the user selects that context.
  • Manually registered identification documents: document type, number, country and issuing authority, issue and expiry dates, notes.

We draw attention to the fact that tax identification numbers, identification document numbers and IBAN are sensitive data from a fraud perspective. They should only be entered if actually necessary for the user.

2.3 Technical data

  • Authentication session (token) stored on the device.
  • Technical error and operation logs generated by the infrastructure, which may include IP address and device/browser information.
  • A random device identifier generated in the browser of whoever views an emergency QR Code (see section 10).

We do not collect advertising identifiers, do not profile users, and do not sell data to third parties.

3. Health data and other sensitive data

The core of the service consists of health-related data, treated as a special category of data under Article 9 of the GDPR. Depending on what the user decides to record, GMP may store:

  • Blood type and date of birth.
  • Medical documents uploaded by the user (original files) and their metadata: file name, type, size, document type, date, institution, doctor, specialty and source language.
  • Automatic document summaries generated by artificial intelligence, in Portuguese and English.
  • Clinical facts extracted from documents: allergies, medication, vaccines, exams, reports, diagnoses, procedures and vital signs, with label, detail, date and severity.
  • Prescriptions: medication and active substance, dosage, form, quantity per dose, frequency, schedule, relation to meals, duration, start dates, notes and reminders.
  • Imaging exams: type, date, institution, doctor, report and associated files.
  • Vital signs: blood pressure, heart and respiratory rate, temperature, oxygen saturation, weight, height, body fat percentage, muscle mass, visceral fat, body water percentage, basal metabolism and notes.
  • Medical schedule events: appointments, exams and other events, with title, date, location, provider and notes.
  • Conversations with the GMP AI assistant, including the user's questions and the generated answers, stored in conversation threads.

None of this data is mandatory. The user chooses at each moment what to record and what to upload.

4. Purposes of processing

  • Create and maintain the account and authenticate access.
  • Store and organize the user's medical history and make it available across their devices.
  • Automatically analyze uploaded documents to extract summaries and structured clinical facts.
  • Generate and display the medical passport and the emergency access QR Code.
  • Manage prescriptions, dose reminders and the medical schedule.
  • Translate clinical information and teleconsultation captions into the chosen language.
  • Show nearby healthcare facilities when the user uses the medical map.
  • Ensure the security of the service, prevent abuse and diagnose technical errors.
  • Comply with applicable legal obligations.

5. Legal bases

  • Performance of a contract (art. 6(1)(b) GDPR) — creating and managing the account and providing the requested features.
  • Explicit consent (art. 9(2)(a) GDPR) — processing of health-related data. Consent is given when entering or uploading clinical information and can be withdrawn at any time by deleting the data or the account, without affecting the lawfulness of prior processing.
  • Vital interest (art. 9(2)(c) GDPR) — making clinical information available through emergency access, when activated by the user.
  • Legitimate interest (art. 6(1)(f) GDPR) — service security, abuse prevention and error correction.
  • Legal obligation (art. 6(1)(c) GDPR) — when the law requires us to retain or disclose information.

6. Storage and security

Data is stored in a managed PostgreSQL database and an associated file storage service, provided through the Lovable Cloud / Supabase infrastructure.

Measures actually implemented in the project:

  • Row Level Security (RLS) enabled on application tables, with policies restricting access to rows whose user identifier matches the authenticated user.
  • The medical documents storage bucket is private; file access is done via temporary signed links, valid for one hour.
  • Token-based authentication with server-side verification on all operations that access clinical data.
  • Schema validation (Zod) of input data in server functions.
  • Communications between the application and the server are done over HTTPS/TLS; the Android app is configured to not allow cleartext traffic.
  • External service keys are kept exclusively on the server and are never exposed to the browser or the mobile app.

For full transparency: we do not use end-to-end encryption — the content of documents and clinical records is readable by the server, since it needs to be processed in order to generate summaries and translations. We also do not claim HIPAA compliance, ISO 27001 certification or any other formal certification. No system is completely invulnerable; we cannot guarantee absolute security.

7. Service providers and subprocessors

We rely on the following third parties, each for a specific purpose. None of them receives data for their own advertising purposes.

  • Lovable Cloud / Supabase — authentication, database and file storage. Receives all account, profile and clinical data.
  • Google — only when the user chooses to sign in with a Google account (OAuth). In that case we receive the email address and name associated with the account.
  • Lovable AI Gateway (Google Gemini models) — document analysis, summary generation, GMP AI assistant and translations. Receives the content submitted for processing (see section 8).
  • OpenStreetMap / Nominatim / Overpass API — map tiles, location search and search for nearby healthcare facilities. Receive approximate coordinates or search text, without any account identifier.
  • Jitsi Meet (meet.jit.si) — public video call service used for the telemedicine feature. The video and audio call is established directly with that service and is subject to its operator's policies.
  • Browser speech recognition — caption transcription uses the browser's own speech recognition API. In Chromium-based browsers, audio may be processed on the browser vendor's servers.
  • Google Play — distribution of the Android application. Receives installation and Play account data managed by Google.

8. Artificial intelligence and translation

The application uses language models (Google Gemini family) accessed through the Lovable AI Gateway. We send for processing:

  • The content of uploaded documents (images, PDFs and audio are sent in their original format; text files are sent as text) to extract a summary, type, date and clinical facts.
  • Messages written by the user in the GMP AI assistant, along with the clinical context necessary to respond.
  • Clinical and interface texts to be translated on the emergency screen.
  • Captions transcribed during a teleconsultation, when real-time translation is active.

The generated responses are stored in your account (document summaries, clinical facts and conversation history). Files in formats the AI cannot read — such as DICOM, video or compressed archives — are only stored, without automatic analysis.

These responses are generated automatically and may contain errors. They should always be verified by a healthcare professional and never used in isolation for clinical decisions.

9. Document upload and processing

When the user uploads a document (report, lab test, prescription, imaging exam, photo or voice note):

  • The file is stored in a private storage bucket, associated with the user's identifier.
  • A database record is created with the file's metadata.
  • The content is sent to the AI service for analysis, and the extracted summary and clinical facts are saved.
  • The file is viewed through a temporary signed link, valid for one hour.
  • When a document is deleted in the application, the file is removed from storage and its record is deleted from the database.

10. QR Code and emergency access

Emergency access is optional and disabled by default. Before the first activation, the application shows exactly what data may become accessible and requires the user's explicit consent. The user can at any time disable access, choose which categories of data are shared (emergency contact and/or clinical facts) and revoke already authorized devices.

Each account has a passport identifier associated with a QR Code. Whoever scans the QR Code is directed to a public emergency page. The behavior depends on the mode chosen by the user in settings:

  • Approval mode — an access request is created and the information is only shown after the account holder approves it. The holder can choose to remember that device for future access.
  • Disabled — the QR Code returns no information.
  • Public mode — emergency information is shown immediately to anyone who scans the QR Code, without approval and without authentication.

When access is granted, the following becomes visible:

  • Full name, passport identifier, blood type and date of birth.
  • Emergency contact's name and phone number, only if the user has enabled that sharing.
  • Up to 50 clinical facts from the categories allergies, medication, diagnoses and conditions, only if the user has enabled that sharing. The full clinical history is never exposed.

Original files, full summaries, AI conversations, the schedule, billing data and vital signs are never exposed.

Whoever views the page receives a random device identifier stored in their own browser, used only to link the request to its approval. The account holder can revoke remembered devices and change the access mode at any time.

Note: public mode means that anyone with physical or visual access to the QR Code can view the emergency clinical information. It is a conscious choice by the user between speed in an emergency and privacy.

11. Location and medical map

Location is used exclusively for the medical map feature and only after the user expressly authorizes access on the device. Location is obtained on demand, at the time of use.

  • Coordinates are sent to the OpenStreetMap/Overpass services to search for nearby hospitals, pharmacies, clinics and doctors.
  • Location is not stored in our database nor associated with the account.
  • If the user declines location access, they can search manually by city and the feature still works.
  • There is no background location collection or continuous route tracking.

12. Telemedicine and captions

The teleconsultation and voice caption feature is disabled in this version of the application. No video call is established, the microphone is not activated for speech recognition, and no clinical data is sent to third-party video conferencing services.

If we reactivate this feature, this policy will be updated beforehand and the video conferencing service used will be identified on this page.

13. Cookies, local storage and analytics

  • We do not use advertising cookies, social media pixels or third-party analytics tools (there is no Google Analytics, Meta Pixel or equivalent integrated into the application).
  • We use strictly necessary browser local storage: authentication session, preferred interface language, and the device identifier for the emergency page.
  • The infrastructure hosting the service generates technical access logs, which may include IP address, for security and diagnostic purposes.

14. International transfers

The service is provided through cloud infrastructure and providers that may operate servers outside the European Economic Area, namely in the United States. Specifically, there is a transfer or possibility of international transfer to: the database and storage provider (Lovable Cloud / Supabase), the AI models provider (Lovable AI Gateway with Google models), Google when signing in with a Google account, the OpenStreetMap services, and the Jitsi Meet service.

These transfers rely on the mechanisms provided for in Chapter V of the GDPR, namely standard contractual clauses entered into by the respective providers. You can request additional information about storage locations through the privacy contact.

15. Data retention

  • Account, profile and clinical data: retained for as long as the account exists. There is no automatic deletion due to the passage of time.
  • Uploaded documents and files: retained until deleted by the user or until the account is deleted.
  • Conversations with GMP AI: retained until the user deletes the conversation thread or the account.
  • Emergency access requests: retained for as long as relevant to the access history; remembered devices are retained until revoked by the account holder.
  • Signed links to view files: expire after one hour.
  • Infrastructure technical logs: retained for the retention period defined by the hosting provider.

16. User rights

Under the GDPR, users have the right to:

  • Access their personal data.
  • Rectify incorrect or incomplete data.
  • Erase their data ('right to be forgotten').
  • Restrict processing in certain circumstances.
  • Data portability in a structured, machine-readable format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.
  • Lodge a complaint with the competent supervisory authority (in Portugal, the CNPD).

Most of these rights can be exercised directly within the application; for the remaining cases, simply contact us using the address indicated in section 21. We respond within a maximum of 30 days.

17. Data access and export

Within the application, the user can view and edit their profile, prescriptions, documents, exams, vital signs, schedule and conversations at any time, and can download each uploaded file.

Under Settings → Privacy and Data → Export my data the user can download, at any time, a structured copy (JSON file) of their profile, documents and extracted facts, exams, prescriptions and reminders, vital signs, schedule events, AI conversations, identification documents and emergency access records. Original files can be downloaded individually from the documents area.

18. Account and data deletion

Users can individually delete documents, exams, prescriptions, vital signs, schedule events and AI conversations within the application. Deleting a document also removes the file from storage.

Permanent account deletion can be done by the user under Settings → Account → Delete account, upon explicit confirmation. Deletion immediately erases the profile, all clinical records, identification documents, AI conversations, emergency access records, stored files and the authentication account itself. The operation is irreversible.

Alternatively, without needing to open the application, the request can be made through the /delete-account page or by email to privacy@gmedicalpassport.com from the email address associated with the account. After identity confirmation, we delete the account, profile, all clinical records and all stored files within a maximum of 30 days, unless we are legally required to retain information. Residual backups are deleted in the hosting provider's normal rotation cycles.

19. Privacy of minors

This version of GMP is intended exclusively for people aged 18 or older and does not support minors' accounts. We do not knowingly collect data from minors. If we become aware that an account was created by a minor, we delete the account and associated data.

20. Changes to this policy

We may update this policy to reflect changes in the service or applicable law. The last update date is shown at the top of the page. In case of substantial changes to the processing of health data, we will inform users through the application or by email before the change takes effect.

21. Privacy contacts

Questions about privacy, exercising rights, or requests for data export or account deletion: privacy@gmedicalpassport.com.

If you believe your rights have not been respected, you can lodge a complaint with the supervisory authority of your country of residence. In Portugal, the Comissão Nacional de Proteção de Dados (CNPD).

© 2026 GMP — Global Medical Passport.