MedStory is built so that your health records belong to you, not to us. Your data is encrypted in transit and at rest, access to it is restricted by design, and we never sell or share it for advertising or any other secondary purpose. You control who can see what, and you can revoke that access at any time. This page explains how, in plain language — for policy and consent details, see our Privacy Policy.
This page describes the technical safeguards behind the MedStory product — the vault where your reports, prescriptions, and records actually live. This marketing website is a separate, static site: it doesn't store or process health data at all. A short waitlist signup form is relayed directly to our email provider and nothing typed into it is retained here.
The vault itself lives on our secured application, kept deliberately separate from this public site. MedStory is operated by Ashwin Zachariah.
Every connection to MedStory is encrypted using industry-standard transport encryption (TLS). Uploaded documents are encrypted at rest (AES-256) in our storage provider, and structured health data in our database is encrypted at rest using our database provider's built-in encryption.
Your records are restricted at the database level — row-level security ensures only your own account can read your records and those of family members you've added; no other MedStory user can query your data. As a single-operator project today, there's no separate administrative team or staff-access-logging system to describe — that's something we'll build out as MedStory grows.
MedStory's marketing website runs on Cloudflare's global network (encrypted connections, DDoS protection by default). The product itself — where your records live — runs on Vercel, with Supabase for the database and Cloudflare R2 for document storage, primarily hosted in India.
India's DPDP Act, 2023 governs how organizations like MedStory handle personal data, putting you — the "data principal" — at the center. Before we process your health information, we ask for consent that is free, specific, informed, unconditional, and unambiguous. You can see what you've consented to, withdraw it, and request correction or erasure.
MedStory aims to act as a responsible "data fiduciary" under this framework, designing our consent model around revocable, purpose-specific control rather than an all-or-nothing permission granted once and forgotten.
India's DPDP Rules 2025, notified on November 13, 2025, confirmed the Act does not create a separate "sensitive personal data" category — a tier that was proposed in an earlier draft was dropped from the final law. So health data isn't singled out for a distinct statutory tier the way it is under some other countries' data protection regimes; MedStory applies elevated care to health data as a matter of our own policy, not because the law mandates a separate category for it. The Act's procedural rollout — Consent Manager registration, the Data Protection Board — is a separate, genuinely ongoing timeline that continues to phase in through 2027.
These are foundational commitments MedStory is built around today.
Not to anyone.
No ad networks, no data brokers, no targeting profiles built from your health information.
Your health records aren't used to train outside AI models without your explicit, separate consent.
We do not currently hold formal third-party certifications such as SOC 2 or ISO 27001, and pursuing them isn't an active roadmap commitment at this stage.
Found a vulnerability or have a security concern? We want to hear about it directly, before it becomes a public issue. Email security@themedstory.com with details.
You've seen how MedStory protects your data — encrypted, access-controlled, and never sold. Join the waitlist to be among the first to bring your family's health records into a vault built around consent, not convenience.
MedStory is currently in closed beta. We'll only use your email to notify you about access. See our Privacy Policy.