Privacy Policy
1. Information We Collect
When you use Medtech OS, we collect and process the following information:
- Workspace identifiers — your Notion workspace ID, used to associate your integration.
- Integration tokens — stored encrypted at rest and used only to communicate with the Notion API on your behalf.
- Document content — read from your Notion workspace during export. Generated documents are stored as archive copies indefinitely.
- Email addresses — from the People database in your workspace, used for approval workflow notifications.
2. How We Use Your Data
Your data is used solely to provide the Service: exporting documents, tracking revisions, and managing approval workflows. We do not sell, rent, or share your data with third parties for marketing purposes.
3. Data Storage and Security
Integration tokens are stored encrypted at rest. Generated documents are uploaded to your Notion workspace and stored in encrypted cloud storage (Amazon S3 with AES-256 server-side encryption). All database connections use TLS encryption in transit.
4. Security Practices
We employ the following security measures to protect your data:
- Encryption in transit — all connections to our database and third-party services use TLS.
- Encryption at rest — integration tokens and stored documents are encrypted using industry-standard algorithms.
- Network isolation — databases and backend services run in private subnets with no direct public access.
- CSRF protection — all form submissions are protected against cross-site request forgery.
- Input validation — user inputs are sanitized and validated to prevent injection attacks.
- Audit logging — key operations are logged with structured tracing, including who initiated each action and when.
- Error monitoring — automated monitoring detects and helps operators triage errors.
5. Third-Party Services
The Service interacts with the following third-party services:
- Notion API — to read workspace content and write revision data.
- Amazon Web Services — for compute, database, and encrypted file storage.
- Sentry — to collect operational error reports from deployed application components.
- OpenAI — in certain cases, limited pieces of information (such as error messages or template snippets) are sent to OpenAI to provide AI-assisted error correction and suggestions. Full documents are not sent.
- Anthropic — in certain cases, sanitized operational error metadata may be sent to Claude to help operators triage Sentry issues. Full documents are not sent.
6. Data Retention
Generated documents are retained indefinitely as archive copies. Integration tokens are retained as long as your integration is active. You may remove your integration at any time, after which your stored token will be deleted. You may request deletion of archived documents by contacting us.
7. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us. Removing the Notion integration from your workspace will stop all new data collection.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of the Service after changes are posted constitutes acceptance of the revised policy.
9. Contact
If you have questions about this Privacy Policy, contact us at support@medtechos.com.