MedBooks

MedBooks

Privacy Policy

Policy version 2026-07-31-v1 · Last updated 1 August 2026

MedBooks is bookkeeping software for Canadian physicians. This policy explains what information we collect, where it is kept, who else touches it, and what you can ask us to do with it.

1. Who we are

MedBooks is bookkeeping software for Canadian physicians. It records your practice income and expenses so you and your accountant can file accurately. We are the organization responsible for the personal information described here.

Privacy Officer: Dr. Fahad Javed
Contact: admin@medbooks.ca

2. What we collect, and why

We collect only what the product needs to work.

Account information — your email address and authentication credentials. Needed to give you an account and to keep other people out of it.

Your books — income, expenses, categories, mileage, receipts, documents, and the notes you write. This is the service. You enter it or import it; we store it so it persists across your devices.

Your device keeps a complete copy too. MedBooks is not a website that holds your books hostage: everything you enter is written to your own device first and works with no connection at all, then copied to your account in the background. Two consequences worth stating plainly. The app keeps working on a hospital wifi dead spot or a plane. And if you clear your browser’s site data, the local copy goes with it — your account still has your books, and signing in again brings them back.

Bank transaction data — if you connect a bank account, transaction dates, amounts, merchant names and account balances, retrieved through Plaid (§5). We do not receive your banking username or password at any time. Connecting a bank is optional and requires separate, explicit consent that we record with a timestamp and the version of this policy you agreed to.

Technical information — IP address, browser type, and error diagnostics, used to keep the service running and secure. Not used to profile you and not sold.

What we deliberately do not collect: patient information of any kind. MedBooks reads the aggregate amounts that arrive in your bank account. It does not parse OHIP remittance advice and has no access to health numbers, fee codes or diagnostic codes. Do not put patient information into MedBooks — the service is not designed or permitted for it.

We do not sell your personal information. We do not use your books to train AI models. We do not serve advertising.

3. How your data is protected

All data is encrypted in transit (TLS) and at rest. Beyond that, MedBooks offers two protection levels, and the difference matters:

Standard Protection (default). Your data is encrypted with keys we manage. This means we can technically access your data — which is what allows us to help you when something goes wrong, and to restore your books if you lose access to your account. We restrict that access to staff who need it, and we log it.

Advanced Protection (optional). Your device generates an encryption key that never leaves it. We store only encrypted data that we cannot read — not for support, not for a backup restore, and not in response to a court order. If you turn this on, you alone can decrypt your books.

Read this before turning it on

If you enable Advanced Protection and lose both your password and your Recovery Key, your data is permanently unrecoverable. We cannot help you. No one can. Because the Canada Revenue Agency requires you to keep readable records for six years, please store your Recovery Key somewhere you will still have it years from now — and not only inside MedBooks.

Support access under Advanced Protection. We cannot read your data unless you explicitly grant access. If you do, you choose how long it lasts (24 hours or 7 days), you see a banner the entire time it is active, you can revoke it instantly, and it expires on its own. Every access is recorded in a log you can read. There is no master key and no standing access.

4. Where your data is processed — including the United States

Your books, receipts and documents are stored in Canada, in Google Cloud’s Toronto region (northamerica-northeast2). Our application servers and file storage run in the same region.

Your login credentials are processed in the United States. Firebase Authentication — the Google service that verifies your email and password and issues your login session — operates only in the United States. This location cannot be changed, and we are telling you rather than burying it. In practical terms:

  • The information involved is your email address, authentication metadata (when and from where you signed in), and multi-factor settings. Your books, receipts and financial records are not included and do not leave Canada.
  • While that information is in the United States it is subject to US law, including lawful access requests by US authorities such as those under the CLOUD Act. Canadian privacy law permits this transfer provided we remain accountable for the information and disclose it to you — which is what this section does.
  • Google Cloud is contractually bound to comparable protection standards, but no contract can fully override the laws of the country where data is processed.

If this is unacceptable to you, please do not create an account, and tell us — it is the kind of feedback that shapes what we build.

5. Third parties who process data for us

Every one of them, by name:

Third parties that process MedBooks data
WhoWhat they handleWhere
Google / Firebase Books, receipts, documents, application hosting Canada (Toronto)
Google / Firebase Authentication Login credentials and session metadata only United States (§4)
Plaid Bank connection and transaction retrieval, if you connect a bank United States
Cloudflare Inbound receipt email routing, if you use email-in receipts Global edge network
Anthropic Receipt images sent for automatic text extraction, if Cloud OCR is on United States

Plaid connects to your financial institution on your behalf. You authenticate directly with your bank; your banking credentials are never shared with us. Plaid’s own privacy policy governs what they do with the data they hold. You can disconnect a bank at any time from within MedBooks, which instructs Plaid to delete the connection.

Anthropic receives receipt images only if automatic text extraction (“Cloud OCR”) is enabled. This happens even under Advanced Protection, because your device decrypts the image before sending it. You can turn Cloud OCR off in Settings and enter receipts manually; nothing then leaves your device for this purpose.

Inbound receipt emails are encrypted before we can read them. Email forwarded to your MedBooks receipt address is encrypted to your personal public key at the edge, so the contents arrive already sealed.

6. How long we keep things

The short version

Nothing is ever deleted by a timer, and nothing is deleted without you asking. That is the whole policy in one sentence. We keep your records for as long as you keep your account.

Retention periods by data type
DataRetention
Books, receipts, documents Kept as long as you keep your account. Never removed automatically — and deleted whenever you ask us to.
Records you’ve marked “under CRA review” Deletion is blocked while that hold is on, because you turned it on. Remove the hold and deletion works normally again.
Closed account (default) Access ends immediately. We hold your data for 30 days and no longer, for one reason: so that a deletion you didn’t mean can be undone. At day 30 we purge it from every copy we hold — the database, the file storage, and the backup region.
Closed account (Delete immediately) If you’d rather not wait, you can choose immediate deletion instead. We purge every copy straight away, with no restore window. We’ll make you export first and confirm in writing, because this one genuinely cannot be undone.
Bank connection tokens Deleted when you disconnect the bank.
Authentication records Life of the account plus a short security window.
Breach records 24 months from the date of determination, as PIPEDA requires.

About the six-year rule. The Canada Revenue Agency requires you to keep your records for six years from the end of the tax year they relate to. That obligation is yours, not ours — MedBooks is the filing cabinet, not the record keeper of last resort. So we will not refuse to delete your own data on the CRA’s behalf. What we will do is make sure you’re not deleting something by accident: before we erase anything substantial we tell you plainly what it covers, which tax years are still inside the six-year window, and we give you a full export first.

We keep your records electronically readable, not just as a printed or PDF summary — the Income Tax Act requires the structured data itself to survive. You can export everything you have at any time, in machine-readable form, without asking us.

Every period above is a documented maximum, not an aspiration: the deletion runs on a schedule and covers copies and backups, not just the version you can see.

7. Your rights

You can access the personal information we hold about you, ask us to correct it, export it in an open format, withdraw consent for optional processing such as the bank connection or Cloud OCR, delete your data, and close your account.

Deletion means deletion. You can delete a single receipt, a whole tax year, or your entire account, and we carry it through to every copy we hold — the live database, the file storage, and the backup region. We don’t keep a quiet copy of something you told us to erase.

Closing your account gives you two choices. By default we hold everything for 30 days so you can change your mind. If you don’t want us holding it at all, choose Delete immediately and we purge it on the spot — you should not have to wait out our safety net if you’ve decided you’re done. Either way you get a full export first.

Two narrow exceptions, both stated up front rather than discovered later. We cannot destroy data that is subject to a legal preservation order or investigation served on us — if that ever happens we will tell you, unless the law forbids us from doing so. And records of our own business dealings with you, such as subscription invoices, are our records and follow ordinary business-record rules. Neither exception covers your books, your receipts or your documents.

Requests go to admin@medbooks.ca. We respond within 30 days.

8. If something goes wrong

If a breach creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, and tell you plainly what happened, what was affected, and what to do. We maintain an internal record of every breach — including minor ones that are not reportable — for 24 months, with the reasoning behind each decision about whether it was reportable. We wrote that process down before we needed it.

9. Quebec

MedBooks is not currently available to physicians practising in Quebec. We ask for your province when you create an account, and accounts cannot be created with Quebec selected.

We would rather tell you this plainly than take your money and work it out later. Quebec’s Act respecting the protection of personal information in the private sector (Law 25) sets requirements — including a formal assessment before any personal information leaves the province — that we have not completed. Since our login service and our bank connection both process data in the United States, those requirements apply to us in full from the very first Quebec user. Signing you up before that work is done would mean promising you protections we had not built.

If you are in Quebec and want MedBooks, tell us. There is a “let me know” option on the sign-up screen and we keep those requests. Demand from Quebec physicians is what will move this up the list — it is a matter of when, not whether.

If you move to Quebec after signing up, your books remain yours and remain fully exportable at any time. Changing your province to Quebec is treated as a deliberate step rather than an ordinary edit, so that neither of us drifts into a situation neither of us has planned for. Contact us and we will tell you exactly where things stand.

10. Changes

If we change this policy in a way that affects how your information is handled, we will tell you in the app and ask you to accept the new version before continuing. We keep a record of which version you accepted and when.

Last updated: 1 August 2026 · policy version 2026-07-31-v1