TRAVELMEDID

Privacy policy

Updated 16 September 2026

On this page

Privacy policy

TravelMedID helps you keep a personal medical record and choose what to share in an emergency. This policy covers the TravelMedID app. Features depend on your device and the app version available to you. Contact: traveler@travelmedid.com.

Your records and security

Names, contact details, health information, nationality, travel choices, photos and documents you enter are stored in an encrypted vault on this device. The app does not upload your private vault to a TravelMedID account or cloud database. Your card password protects the vault. Optional phone authentication uses your device authentication and device-protected keys; the app does not receive your fingerprint or phone PIN. There is no email password reset.

Emergency sharing and QR codes

Emergency sharing is optional. You choose the fields, photo and documents available in a separate read-only snapshot without your card password. Anyone with access to that emergency screen can read the selected information. The optional home-screen widget can show selected identity and contact details. QR codes contain only the supported selected text summary and open the TravelMedID website; photos, documents and wallet keys are not included. The summary is in the link fragment, which is not part of the ordinary HTTP request to the website server. Scanning still connects to the website, whose host receives ordinary connection information such as IP address. Anyone who copies the QR/link can read its summary. Printed and copied codes are snapshots and cannot be recalled.

Optional lock-screen banner

On supported devices, with your explicit permission, the AccessibilityService detects window-state changes and checks whether the screen is locked and awake to display an emergency shortcut. It does not inspect other apps, read screen content, record gestures or transmit accessibility events. Double-tapping opens only your selected emergency snapshot; it does not unlock your phone or private vault. Disable the banner in the app or revoke the service in your device settings. Availability varies by device and may require the first device unlock after a restart.

Wallet and external services

The optional self-custody XRP wallet generates and signs with keys locally. The seed is encrypted in your vault and is included in encrypted app backups; it is not sent to the ledger server. Wallet checks send public addresses to Ripple-operated XRPL endpoints. Transactions send signed transaction data, including addresses, amounts, optional destination tags and, for anchoring, a card fingerprint. These providers receive network information such as your IP address. Ledger transactions and fingerprints are public and generally permanent. A fingerprint is not your medical record, but may be linkable to information someone already knows. Verification proves a matching successful ledger transaction, not personal identity or medical accuracy. MoonPay purchases and Allianz quotes open external websites, which handle the information you enter under their own policies. The insurance link includes the partner agency tracking code. No card data or seed is automatically supplied to those purchase pages.

Device services and exports

The system file picker gives access only to files you select. Your chosen storage provider may receive exported backups or PDFs. Backups use a separate password and include sensitive records, attachments and any wallet seed. PDFs and printed cards are not encrypted. Delete unwanted exports separately. Emergency phrases use the device’s selected text-to-speech service, which may require an online voice service; the app supplies the selected phrase, not your medical record. Destination selection is manual, without GPS access.

Retention, deletion and choices

Records remain on this device until you delete them, clear app storage or uninstall. Profile > Delete records from this device removes the local vault and emergency snapshot. Disable emergency sharing to withdraw access to the current local snapshot. Keep wallet recovery material safe before deleting records: deletion does not move or recover XRP. Device deletion cannot erase exported files, copies held by other people, provider records or public ledger transactions. TravelMedID cannot retrieve a forgotten card password or seed. Contact the relevant external provider about information held by that provider.

Other data and policy updates

The app includes no advertising or analytics SDK and does not sell your medical records. Emailing support shares the information you send and your email address with TravelMedID and its email provider; do not send passwords, seeds or unnecessary medical documents. Support correspondence may be retained while handling your request; contact us to request its deletion, subject to applicable recordkeeping obligations. This policy will be updated if app data practices change.

Questions? traveler@travelmedid.com