This Privacy page explains what RedMed does and does not hold about you. Read it with Terms and Security.
1 Who we are
For any personal information we do control, RedMed is operated by an individual based in the State of New Jersey, United States (“RedMed”, “we”, “us”), not a registered company. There is no separate corporate entity behind RedMed at this time.
Contact: [email protected].
2 What RedMed is
RedMed is a consumer app for a local emergency medical ID: store self-reported details on your iPhone, optionally put them on a passive NFC band when write is available, call for help, and show on-device first-aid while waiting for professionals. Share Band URL and Preview pack a helper card; they do not write the chip. In-app Write returns when NFC Tag Reading is live and proven (Ships When Ready).
It is not a hospital portal, not an electronic health record, not insurance software, and not a promise that EMS will arrive or that anyone will get a particular medical result. Full limits are in Terms.
3 HIPAA — local only, not certified
HIPAA regulates covered entities and their business associates when they handle protected health information (“PHI”).
RedMed is not a covered entity and is not a business associate for your RedMed profile. We do not treat patients, process claims, or run an EHR. Your profile never lands on a RedMed server.
That local-only design means we never create, receive, maintain, or transmit your profile as PHI on our systems. It is not a “HIPAA certified” badge, not a claim that RedMed is “HIPAA-aligned,” and we do not market RedMed as a HIPAA-covered product.
If EMS or hospital staff tap the band and later enter what they see into their systems, that organization’s HIPAA rules may apply to its copy. RedMed does not push data into a hospital EHR and does not become their business associate for bracelet contents.
This page is not a HIPAA Notice of Privacy Practices.
4 What information exists
- Medical ID (self-reported): name, birth date, blood type, allergies, medications, conditions, notes — fields a responder may need fast.
- Emergency contacts: names, relationships, and phones you choose to list. Tell those people you listed them.
- Location: coordinates and heading shown only while Find Help is open, so you can read them to a dispatcher. Find Nearby Hospitals also uses GPS: Apple Maps in the iPhone app; OpenStreetMap Overpass on a band tap in a browser (see §7).
- Apple Health (optional, parked): when HealthKit import is restored, Fill From Apple Health would read birth date and blood type from HealthKit on this iPhone — read-only, never written back to Health, never sent to us. That control is not available in this build (HealthKit capability parked).
- Support email: if you write us, we see the address and message you send. Use it for app or band troubleshooting only — do not email your full medical ID. We delete support threads when resolved.
- Motion data (crash/impact alarm): for RedMed app users only, while the owner app is on screen (default thresholds), it can read your iPhone's motion sensors to detect a possible vehicle crash or severe impact, trigger a local alarm, and after the US Crash Detection delay (10s + 30s) open Phone to the emergency number unless you stop it. Face ID is not required for that monitor. It does not run when the phone is locked, you leave the app, or kill RedMed — even if RedMed was open moments before. Apple Crash Detection on supported devices is separate. See Terms §7. This processing happens only in memory on your device to evaluate the last few seconds of motion — it is never stored, logged, or sent to us.
Providing a profile is optional. Leaving fields blank is fine; an empty card is less useful in an emergency.
5 Where it lives
Your profile stays on your iPhone Keychain and, if you write one, on the band’s NFC chip. Those are two copies. Neither depends on the other — a dead or wiped phone does not blank the chip, and a rewrite does not need iCloud or an account. It is not uploaded, synced, or backed up to any RedMed server — we do not operate one for profiles.
On iOS we use the WhenPasscodeSetThisDeviceOnly Keychain class with no biometry ACL: readable while this iPhone is unlocked, and excluded from iCloud and encrypted backups. It does not sync to your other Apple devices. Face ID gates post-Agree (first launch / after Erase), returning cold re-entry (once per process), Edit, Save, Erase, and Load From Band — not viewing the YOU card, not 911, not Aid, not NFC write, not same-session resume, not tapper. Field-level Clear in Edit (blood type / birth date) does not prompt until you Save. Keychain restore loads the profile on Main without Face ID to view. The band is still the credential for tap-to-view — no Face ID on a passerby tap.
When someone taps the band, nothing is fetched from us. The card is built from what is on the chip (#d= in the URL fragment).
6 The band is readable by design
A RedMed band uses a passive NXP NTAG216 HF NFC chip (13.56 MHz, ISO 14443A Type 2). The bracelet comes complete. Just the chip is needed. No battery. No Bluetooth. The phone powers it only during a close write or tap. Blank chips may ship before in-app Write is proven — Share Band URL / Preview pack a #d= URL or Preview the card; that does not write the chip. Storefront “write from the app” stays off until NFC Tag Reading is live and Write The Band works on a blank NTAG216 (Ships When Ready).
Anyone who deliberately taps the band can open the card — no app, no account, no password. New writes use AES-GCM packing with a public client key shared by the app and the passerby page. That hides casual plaintext in the fragment; it is not confidentiality against a responder (or anyone else) who opens the URL.
Treat the band like a wallet medical ID. Do not put anything on it that you would not accept a stranger reading. Leave sensitive fields blank if you prefer.
Casual walk-by distance will not fire the band. A deliberate ~1–2″ antenna tap can. Separately, iOS Background Tag Reading can open the card on that kind of tap even when the phone is off or locked — Apple’s path, not RedMed. Payment terminals speak EMV and do not open the RedMed card. More detail: Security.
7 Location (Find Help)
Find Help shows coordinates only while that screen is open. GPS starts when Find Help needs it and stops when you leave or close the app. Location is not used for ads, profiling, or background tracking, and is never sent to us.
Location defaults on as part of Agree on the "Before You Continue" screen (first launch or after a policy update; later cold starts skip that page when the stored policy version still matches). There is no in-app Location toggle. iOS may show its When-In-Use Allow sheet the first time Find Help (or hospital search) needs GPS — Apple requires that tap; we cannot auto-accept it, and we do not interrupt cream drop / Face ID with it. GPS still starts only when Find Help needs it and stops when you leave or close the app. If you deny Location in iOS Settings, Find Help does not start GPS. RedMed does not show an in-app location gate.
The 911 coordinate readout stays on this iPhone. GPS is never attached to a tel: call. Find Nearby Hospitals has two paths: in the RedMed iPhone app, that search asks Apple Maps (MapKit) on this phone for ER POIs — Apple may see the query and region. On a band tap in a browser (tapper.html), that search sends this phone’s coordinates to OpenStreetMap’s Overpass API (overpass-api.de) because the browser has no MapKit. Overpass may see that location. Neither path is a RedMed upload, and RedMed does not receive the coordinates.
The Call button and SOS · Locate Me open the system Phone app to your regional emergency number only. SOS does that on the tap, with no in-app confirmation and no countdown. Crash detection waits the US Crash Detection delay (10-second alert + 30-second countdown) before the same tel: open, unless you tap Stop The Alarm. A band-tap auto-arm on a helper’s phone (no RedMed app) does not place a call. Phones with RedMed installed still open Safari or the tapper on a band tap first; the app claims that tap only after paid Program and Associated Domains are live. RedMed does not attach name, medical fields, contacts, GPS, or any other profile data to that call. iOS may still show its own Call sheet; RedMed cannot suppress that.
8 Who else can see data
- Anyone who taps your band (or opens a card link with your
#d=) can read the self-reported ID on it. That local handoff is the product. - Your phone’s OS apps — Phone, Messages, Maps, Share Sheet — when you use them. Apple’s rules apply there. Dispatchers hear or read what you say or type, not a RedMed server copy.
- Apple Maps may see a hospital search (query + region) when you use Find Nearby Hospitals in the RedMed iPhone app. That search is Apple’s, not a RedMed upload. The 911 GPS readout itself stays on-device.
- OpenStreetMap Overpass (
overpass-api.de) may see this phone’s coordinates when Find Nearby Hospitals is used on a band tap in a browser. That query is Overpass’s, not a RedMed upload. - No ad networks, no analytics IDs, no data brokers, no account signup. We do not sell personal information or share it for cross-context behavioral advertising.
9 How long it lasts
We keep none of your RedMed profile, because we receive none. It stays on your phone and band until you remove it.
On the phone: Help → Erase All User Data (Face ID), or delete the app. Edit has field-level Clear only (blood type / birth date) — there is no Clear-all. Clearing some fields and Save updates the stored ID; an empty Save does not write or wipe Keychain — use Erase. On the band: overwrite the chip or dispose of the band securely. We cannot wipe a band remotely — there is no link from us to the chip.
Support emails are kept only as long as needed to answer you, then deleted. Do not send your full medical profile to support.
10 Your rights (United States)
Most controls are on your device: edit to correct, erase or delete the app to remove, rewrite or discard the band. You do not need our permission.
For anything we do hold (for example a support email), write [email protected]. Requests are handled as required by the law that applies to you.
California (CCPA/CPRA). Residents may have rights to know, access, delete, correct, and opt out of “sale” or “sharing,” and to limit use of sensitive personal information, subject to exceptions. RedMed does not sell personal information and does not share it for cross-context advertising. There is no RedMed profile database to disclose. For limited records we may hold, email us with “California Privacy Request” in the subject line. We will not discriminate against you for exercising privacy rights.
Other state privacy laws may grant similar rights. Use the same address; we will handle requests as required.
11 Automated decisions
None. RedMed does not score, triage, or risk-rate you. The seizure stopwatch is a timer you start; it does not detect seizures.
12 Cookies and cache
The passerby card may keep its static shell in browser Cache Storage so a later tap opens offline. Medical fields stay in the URL #d= fragment and are not written into that cache. No advertising or analytics cookies. The owner profile lives in Keychain, not web localStorage.
13 Children and people you support
RedMed is not directed to children under 13, and we do not knowingly collect their information on RedMed servers. Only an adult who meets the eligibility rules in Terms §16 may create a profile for a child or an adult they support. That adult is responsible for accuracy and for what goes on the band. A child’s band is as readable as an adult’s.
14 Changes
We may update this page. The Effective date above shows the latest revision. Material changes require re-acceptance in the App before you can keep using it. Any public Privacy Policy URL (App Store Connect or the band host) must serve this same Privacy text — not a separate rewritten policy.