On this page
- Overview
- What information we collect
- Where your information lives
- Uploaded medical records
- What goes on the blockchain
- How we use information
- Sharing and disclosure
- Third-party links and services
- Your rights and choices
- Legal frameworks we comply with
- Security
- Data retention and deletion
- Children's privacy
- International users
- Changes to this policy
- Contact us
1. Overview
TravelMedID ("TravelMedID," "we," "us," or "our") provides a digital travel medical card and related tools, including a passport-style card, emergency QR codes, insurance activation, phrasebook translation, trip advisory links, and optional medical record storage.
This Privacy Policy explains what information the TravelMedID application collects, how it is stored, what (if anything) leaves your device, and what rights you have. It applies to the TravelMedID web application and any associated card or QR features.
2. What information we collect
TravelMedID is designed to minimize what it collects. The categories of information involved in using the app are:
| Category | Examples |
|---|---|
| Identity & passport information | Full name, nationality, passport number, expiry date, photo |
| Medical information | Blood type, allergies, conditions, medications, organ donor status |
| Uploaded medical records | Files you choose to upload (images or PDFs) — entirely optional |
| Insurance information | Provider, policy number, coverage dates, uploaded insurance card |
| Emergency contact information | Contact name, relationship, phone number |
| Technical information | Browser type and basic device information needed to render the app |
We do not require you to create an account, and we do not collect this information through any external form, server-side database, or analytics pipeline beyond what's described in this policy.
3. Where your information lives
The information you enter — your card fields, photo, contacts, and insurance details — is stored locally on your own device using on-device storage. It is not transmitted to or held on TravelMedID servers as part of normal use.
If you choose to export a PDF, generate an emergency QR code, or print your card, that output leaves your device because you've directed it to — for example, to hand to a doctor. The emergency QR code itself only ever encodes blood type, critical allergies, and an emergency contact number; it does not encode your full medical record.
4. Uploaded medical records
TravelMedID lets you optionally upload a medical record — from the application form, or by tapping "manage records" on the back of your card. This feature is entirely optional and has no effect on the rest of your card if you choose not to use it.
Uploaded records are stored only on your device, the same way the rest of your card data is. TravelMedID does not upload these files to a server, does not view their contents, and cannot access them remotely.
Because medical records are sensitive by nature, the following applies regardless of how the information reached us:
- HIPAA: TravelMedID is not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA), because records are provided directly by you and not transmitted to us by a healthcare provider, health plan, or clearinghouse on our behalf. As a result, HIPAA does not govern our handling of this information.
- FTC Health Breach Notification Rule: We nonetheless treat uploaded records as sensitive health information and follow applicable requirements of the FTC's Health Breach Notification Rule, including notifying affected users and, where required, the FTC, in the event of a breach of unsecured identifiable health information.
- State health-privacy laws: Depending on where you live, additional state laws may apply to "consumer health data," including Washington's My Health My Data Act and California's Confidentiality of Medical Information Act and California Consumer Privacy Act. We do not sell consumer health data and do not share it with third parties for purposes unrelated to providing you the service.
- No secondary use: We do not use uploaded medical records for advertising, profiling, or any purpose other than displaying them back to you on your own device.
5. What goes on the blockchain
Public blockchains are permanent and world-readable, which makes them a poor place to store medical history — so we don't. The only blockchain interaction in TravelMedID is anchoring a cryptographic fingerprint (a SHA-256 hash) of your record on the XRP Ledger Testnet.
This fingerprint proves your record hasn't been silently altered, without revealing any of its contents. It cannot be reversed to reconstruct your name, passport number, medical history, or any other detail.
6. How we use information
Because the data described above is stored on your device rather than on our servers, our "use" of it is limited to enabling the features you directly interact with: rendering your card, generating QR codes, populating exports, and — if you opt in — connecting you to insurance activation or trip-advisory resources you select.
We do not use your personal or medical information for advertising, do not build behavioral profiles from it, and do not sell it.
7. Sharing and disclosure
We do not sell your personal or medical information. We do not share it with third parties except in the following limited circumstances:
- When you affirmatively choose to share it — for example, showing your card to a doctor, exporting a PDF, or clicking through to an insurance provider's website.
- To comply with a valid legal obligation, such as a court order or subpoena, where we are legally required to do so.
- To protect the rights, safety, or property of TravelMedID, our users, or the public, where permitted by law.
Because most of your data never reaches our servers in the first place, there is generally nothing for us to disclose even if requested — the data simply isn't held by us.
8. Third-party links and services
TravelMedID links out to a number of independent third-party services, including:
- Insurance activation through TW Global Protection (twglobalprotection.com)
- U.S. State Department travel advisories and embassy lookup tools (travel.state.gov, usembassy.gov, step.state.gov)
When you click through to these sites, you leave TravelMedID and their own privacy policies and terms govern your interaction with them. We do not transmit your TravelMedID card data to these services when you click through — any information you provide them is provided directly by you, on their site.
9. Your rights and choices
Because your information lives on your device, you are generally in direct control of it at all times:
- Access: You can view all stored information at any time by opening your card in the app.
- Correction: You can edit any field directly through the application form.
- Deletion: You can delete your card, contacts, insurance details, or any uploaded medical record at any time. Once deleted from your device, we hold no separate copy.
- Export/Portability: You can export your card as a PDF or printed document whenever you choose.
If you are a resident of a U.S. state with a consumer privacy law (such as California, Colorado, Connecticut, Virginia, or others), you may have additional statutory rights to access, delete, or restrict the use of your information. Because we do not hold your data on our servers in the ordinary course, many of these rights are already satisfied by the on-device design described above; where you believe we hold information about you, you may still contact us using the details in Section 16.
10. Legal frameworks we comply with
While most of TravelMedID's data handling falls outside traditional regulatory frameworks because of its on-device design, we take the following seriously and structure the product to comply with them where applicable:
- FTC Health Breach Notification Rule (15 U.S.C. § 6601 et seq., implementing regulations)
- Section 5 of the FTC Act (unfair or deceptive practices)
- Washington My Health My Data Act
- California Confidentiality of Medical Information Act (CMIA) and California Consumer Privacy Act (CCPA/CPRA)
- State data breach notification laws generally
TravelMedID is not currently designed or marketed as a HIPAA-covered product, and you should not rely on it as a substitute for records maintained by your healthcare provider.
11. Security
Because your information is stored on your own device rather than centrally, your device's own security (passcode, biometric lock, disk encryption) is a meaningful part of protecting it — we encourage you to keep your device secured.
Where any information is transmitted (for example, to render a QR code or anchor a hash on the XRP Ledger Testnet), we use industry-standard practices to protect it in transit. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
12. Data retention and deletion
We do not retain copies of your card data, contacts, insurance details, or uploaded medical records on our servers. Information persists only on your device, for as long as you choose to keep it there. Uninstalling the app, clearing site data, or using the in-app delete options removes it.
13. Children's privacy
TravelMedID is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information through the app, please contact us so we can assist with deletion.
14. International users
TravelMedID is designed for use by travelers worldwide. Because information is stored on your own device, it generally does not cross international borders through our servers. If you are located outside the United States, you remain responsible for complying with your own local data protection laws when using the app, and you may have additional rights under frameworks such as the GDPR or UK GDPR if applicable to you.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal or regulatory reasons. We will update the "Last updated" date above when we do. Material changes will be highlighted within the app where practical.
16. Contact us
If you have questions about this Privacy Policy or how TravelMedID handles information, contact us at: