Controller
Alivency, a French single-member limited liability company (EURL) with share capital of €1,000, registered with the Paris Trade and Companies Register under number 107 165 458, VAT number FR71107165458, whose registered office is at 14 Rue Bausset, 75015 Paris, France.
Privacy contact: Franck Perthuis, hello@alivency.com.
Scope and regions
This policy applies to the MyMediBox website and iPhone app, including users in France and the United States where the app is available. GDPR applies where relevant; applicable U.S. federal and state privacy protections may also apply based on residence.
Website data and PostHog analytics
- Technical HTTP and security logs processed by o2switch to host and protect the website.
- Messages sent voluntarily by email; their content is never sent to analytics.
- Before consent, no PostHog script is loaded and no analytics request is sent. If analytics is accepted, the website loads the PostHog JavaScript snippet from its European infrastructure and records page views, visible sections, selected useful clicks, page exits, visit duration, bounce rate, scroll depth and technical Web Vitals (FCP, LCP, CLS and INP).
- Autocapture, session replay and identification are disabled. The website does not send health data, email contents, free-form entries or form fields to PostHog. Custom events contain only fixed labels and destinations, the language, the page path without query parameters and the relevant section. System events may also include the page and referrer without query parameters or fragments, general browser and display characteristics, random session/page identifiers, duration, scroll and Web Vitals values. A random technical identifier supports pseudonymous measurement without creating an identified profile.
- The project is configured to anonymize IP data. An IP address may be processed technically while the HTTPS request is routed, but the raw value is not retained in PostHog events.
- The user may refuse analytics or withdraw consent at any time through “Manage analytics” in the footer. The website remains fully accessible without analytics.
App data and PostHog analytics
- Medication, prescription, schedule, stock, intake and saved doctor or pharmacy details are stored locally first on the device.
- When iCloud/CloudKit sync is enabled and available, this user data may synchronize within the user’s Apple environment.
- Nearby doctor and pharmacy search uses Apple Maps. When the user opens this feature, MyMediBox may request When In Use location access to center nearby results. The location is used only for the requested search; there is no background location tracking. If access is denied, the user can still move the map, enter a search, or add doctor and pharmacy details manually.
- Location authorization and analytics consent are separate. Granting location access does not enable PostHog analytics.
- StoreKit provides subscription status and transaction management; Alivency does not receive full payment-card details.
- PostHog analytics is disabled until the user explicitly accepts it. Through AlivencyAnalytics and a European endpoint, selected events may then describe screens opened, navigation, feature outcomes, technical failures and crash diagnostics. They are linked to a random pseudonymous identifier and never to the user’s name.
- The IP address is processed briefly and then discarded to infer country, region, city and approximate coordinates for geographic analytics. This processing does not use GPS or the app’s Core Location permission. The device location used for nearby search is not sent to PostHog.
- Medication names, OCR text, scanned prescriptions, stock levels, appointments, saved doctor or pharmacy details, business identifiers and quantities are never sent to PostHog analytics.
- The user may continue without sharing analytics and may withdraw consent at any time in Settings, which prevents subsequent analytics events without disabling core app features.
- Notification permissions and reminders are managed through Apple system services and device settings.
Purposes and legal bases
- Provide requested app features and subscriptions: performance of the user agreement.
- Find nearby doctors and pharmacies at the user’s request and save selected contact or place details: performance of the user agreement; device location is accessed only after When In Use authorization.
- Optional website analytics and optional app analytics and crash diagnostics: consent, which can be withdrawn at any time.
- Website and service security, fraud prevention and technical operations: legitimate interests.
- Respond to privacy requests and legal obligations: legal obligation or legitimate interests, as applicable.
Recipients, processors and transfers
Data is limited to authorized Alivency personnel and service providers that need it: o2switch for website hosting, Apple for Maps searches, CloudKit and StoreKit, and PostHog for consented website analytics or consented app telemetry through AlivencyAnalytics. PostHog ingestion and interface hosts are configured in Europe. Providers may otherwise process data outside the user’s country under applicable safeguards. Apple data remains subject to the user’s Apple account settings and Apple’s terms.
Retention
- Local app data, including saved doctor and pharmacy details: until the user deletes it through available controls or removes the app. Synced copies are governed separately by iCloud controls and Apple retention rules.
- The device location used to center nearby results is held only for the current search flow and is not retained by MyMediBox as a location history.
- iCloud data: according to user controls and Apple retention rules.
- Website technical logs: for the limited period applied by o2switch for security and operations.
- The website stores the analytics choice, its version and its date in the browser for six months; after that period, consent is requested again.
- Consented PostHog analytics and app crash diagnostics: for the limited retention period configured in the PostHog project and necessary for product measurement, subject to applicable deletion or objection rights.
- Privacy requests and legal records: for the period required to handle the request and establish compliance.
Cookies and consent
Website and app consent are separate. On the website, no PostHog script or analytics storage is activated before an explicit choice. Acceptance and refusal have the same six-month validity. Refusal does not limit the website, and withdrawal is available at any time through “Manage analytics” in the footer; it stops subsequent events and clears PostHog persistence when it has been loaded.
In the app, a separate explicit choice controls pseudonymous usage analytics and crash diagnostics. Refusing does not prevent core app use, consent can be withdrawn in Settings, and the app may request a renewed choice when its consent period expires or the policy changes.
No advertising tracker or marketing cookie is used by MyMediBox.
Security
Alivency applies measures appropriate to the nature of the data, including local-first storage, access restrictions, secure transport for enabled services and data minimization. No system can guarantee absolute security.
Your rights
Depending on applicable law, users may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting prior lawful processing. Requests can be sent to hello@alivency.com. Identity may be verified proportionately. EU/EEA users may complain to the CNIL or their local authority. U.S. residents may have additional state-law rights, including appeal or non-discrimination rights where applicable. MyMediBox does not sell personal data or use it for cross-context behavioral advertising.
Children
MyMediBox is not directed to children under 13. Where consent or parental authorization is legally required for a minor, the app must be used only with the required authorization.
Changes and contact
This policy may be updated as the product, countries served or providers change. Material changes will be communicated where required. Contact: hello@alivency.com, Alivency, 14 Rue Bausset, 75015 Paris, France.
Launch notification
If you register for launch news, Alivency stores your email address, the selected language, the registration date, the version of your consent and a random unsubscribe token in a private database hosted by o2switch in France. Registration is optional and based on your explicit consent, independently of analytics consent. These details are used only to notify you of the MyMediBox launch and are never sent to PostHog.
You can unsubscribe using the link in each launch email and confirming on the page. Confirmation deletes your email, consent details, token and associated anti-abuse hash from the active database. You can also request deletion at hello@alivency.com. The launch list is deleted after the launch notification has been sent and, in any event, registrations expire after 365 days and are deleted by the next scheduled cleanup, which runs every minute. To limit abuse, a temporary keyed hash of the email expires after at most one hour and is deleted by the next scheduled cleanup; the signup database does not store IP addresses.