Terms of Service
Last updated: February 2026
⚠️ Important Medical Disclaimer: MedAssist AI provides general health information only. It is not a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of your GP or other qualified health provider with any questions you may have regarding a medical condition.
1. Acceptance of Terms
By accessing or using MedAssist AI ("the Service"), you agree to be bound by these Terms of Service. If you do not agree to these terms, please do not use the Service.
2. Description of Service
MedAssist AI is an AI-powered health information assistant that provides general medical information based on publicly available, verified medical databases including WHO ICD-11, NICE Guidelines, and the European Medicines Agency. The Service is intended for informational purposes only.
3. Medical Disclaimer
The Service does not provide medical advice, diagnosis, or treatment. The information provided:
- Is for general informational purposes only
- Is not a substitute for professional medical advice
- Should not be used to diagnose or treat a health problem or disease
- Should not replace consultation with a qualified healthcare provider
If you think you may have a medical emergency, call 999 (UK) or your local emergency services immediately.
4. Eligibility
You must be at least 18 years of age to use this Service. By using the Service, you represent and warrant that you are 18 years of age or older.
5. User Account
To access certain features, you must register for an account. You agree to:
- Provide accurate and complete registration information
- Maintain the security of your password
- Notify us immediately of any unauthorised use of your account
- Take responsibility for all activities that occur under your account
6. Subscription and Payments
MedAssist AI offers a 7-day free trial followed by a paid subscription (Pro plan at £9.99/month). Billing is handled securely through Stripe. You may cancel your subscription at any time. No refunds are provided for partial billing periods.
7. Acceptable Use
You agree not to:
- Use the Service for any unlawful purpose
- Attempt to gain unauthorised access to any part of the Service
- Transmit any harmful, offensive, or disruptive content
- Use the Service to provide medical advice to third parties
- Reverse engineer or attempt to extract the underlying AI models
8. Intellectual Property
All content, features, and functionality of the Service are owned by MedAssist AI and are protected by UK and international copyright, trademark, and other intellectual property laws.
9. Limitation of Liability
To the fullest extent permitted by law, MedAssist AI shall not be liable for any indirect, incidental, special, consequential, or punitive damages resulting from your use of the Service. Our total liability shall not exceed the amount you paid for the Service in the 12 months preceding the claim.
10. Changes to Terms
We reserve the right to modify these terms at any time. We will notify users of significant changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the new terms.
11. Governing Law
These Terms are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
12. Contact
Privacy Policy
Last updated: February 2026
MedAssist AI ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
MedAssist AI is the data controller for personal data collected through this Service. For any data protection queries, contact us at privacy@medassistai.co.uk.
2. Data We Collect
We collect the following categories of personal data:
- Account data: Email address, password (hashed and encrypted)
- Health profile data: Age, sex, chronic conditions, allergies, medications (provided voluntarily)
- Usage data: Symptom queries, chat history, session identifiers
- Technical data: IP address, browser type, device information, access times
- Payment data: Billing information processed by Stripe (we do not store card details)
3. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract performance: To provide the Service you have signed up for
- Legitimate interests: To improve the Service and ensure security
- Consent: For optional health profile data and marketing communications
- Legal obligation: To comply with applicable laws and regulations
4. How We Use Your Data
We use your personal data to:
- Provide and personalise the Service
- Process your symptom queries through our AI pipeline
- Manage your account and subscription
- Send service-related communications
- Improve our AI models and Service quality (anonymised data only)
- Comply with legal obligations
5. Special Category Data (Health Data)
Health information you provide (symptoms, conditions, medications) is considered special category data under UK GDPR. We process this data only to provide the Service you have explicitly requested. This data is:
- Stored securely with encryption at rest and in transit
- Never sold or shared with third parties for marketing
- Retained for a maximum of 2 years or until account deletion
6. Data Sharing
We share your data only with:
- Anthropic (Claude AI): Symptom queries are processed by Claude AI to generate responses. Anthropic does not use your data to train their models.
- OpenAI: Used for generating text embeddings. Subject to OpenAI's data processing agreement.
- Railway.app: Cloud infrastructure provider hosting our servers and database.
- Stripe: Payment processing. Subject to Stripe's privacy policy.
- Netlify: Frontend hosting provider.
We do not sell your personal data to any third parties.
7. Data Retention
We retain your personal data for as long as necessary to provide the Service:
- Account data: Until account deletion + 30 days
- Query history: 2 years or until account deletion
- Payment records: 7 years (legal requirement)
- Technical logs: 90 days
8. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restriction: Request restriction of processing
- Portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw consent: At any time where processing is based on consent
To exercise any of these rights, email privacy@medassistai.co.uk. We will respond within 30 days.
9. Cookies
We use the following types of cookies:
- Essential cookies: Required for the Service to function (authentication, session management)
- Analytics cookies: Help us understand how users interact with the Service (with consent only)
You can manage cookie preferences through our cookie banner or your browser settings.
10. Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- TLS encryption for all data in transit
- AES-256 encryption for data at rest
- Bcrypt password hashing
- Regular security assessments
- Access controls and audit logging
11. International Transfers
Some of our service providers are based outside the UK. Where we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the ICO.
12. Children's Privacy
Our Service is not directed at children under 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email. The latest version will always be available at this page.
14. Complaints
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
15. Contact
Data Protection Contact — MedAssist AI
Email: privacy@medassistai.co.uk
Response time: Within 30 days