Privacy Policy for MS Buddy

Effective Date: July 2024 · Last Updated: 2026-03

Your privacy is of utmost importance to us. This Privacy Policy outlines how SJB Digital Ventures LLC, doing business as MS Buddy ("MS Buddy," "we," "us," or "our"), collects, uses, discloses, and safeguards your personal information. By using MS Buddy ("the App"), you agree to the collection and use of information in accordance with this policy and our Terms of Use.

1. Data Collection and Use


a. Personal Data

Account Information: When you create an account, we collect your username and email address. Your password is securely hashed using industry-standard bcrypt and is never stored in plain text.

b. Profile and Health Data

User-Entered Data: We collect health-related information that you choose to provide, including symptoms, triggers, activities, journal entries, and optional profile details such as age, sex, year of diagnosis, type of MS, current medications, and other health information. If you use the Reminders feature, you may also provide doctor names, appointment locations, and questions for your doctor. This data is stored solely to power your reminders and is never shared with third parties.

Sensitive Health Data Consent: By entering health-related information into the App, you provide explicit consent for us to process this sensitive data for the purpose of delivering the App's wellness tracking features. You may withdraw this consent at any time by deleting your data or your account.

c. Apple HealthKit Data

  • We only access HealthKit data you specifically approve
  • We never share HealthKit data with third parties, including for advertising or marketing
  • HealthKit data is not stored in iCloud
  • You can revoke HealthKit access anytime in your iPhone Settings
  • HealthKit data is provided "as-is" from Apple and is not independently verified by MS Buddy for accuracy; it should not be relied upon for clinical or medical purposes

d. AI-Generated Content

Certain features of the App use artificial intelligence (AI) provided by third-party services (such as OpenAI) to generate summaries of research articles. When processing articles, we send the article text to the AI service; no personal user data is included in these requests. The AI-generated summaries are stored and displayed within the App. These summaries have not been reviewed by medical professionals and are provided for informational purposes only.

e. Device and Usage Data

Usage Information: We collect information about how you use the App, including page views, feature usage, device type, operating system, and timestamps. This data is collected through our internal logging system.

Approximate Location: We may use your IP address to determine a general geographic area for usage analytics. This is not precise location data and is not shared with third parties.

Local Storage: When accessed via a web browser, we use local storage (similar to cookies) to maintain your login session and retain user preferences. We do not use third-party tracking cookies.

2. Data Sharing and Disclosure


a. Third-Party Service Providers

Database: We use MongoDB Atlas for data storage. All data is encrypted in transit using TLS and at rest using AES-256 encryption. MongoDB Atlas maintains SOC 2 Type II and ISO 27001 certifications.

b. Legal Compliance

We may disclose your information when required to do so by law or in response to valid legal process (such as a court order, subpoena, or government request). We will notify you of such requests when legally permitted to do so.

c. No Sale of Personal Data

We do not sell, trade, or rent your personal information to third parties. We do not share your data with advertisers, data brokers, or any third parties for marketing purposes.

3. Data Security


We employ industry-standard security measures to protect your personal and health data:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security).
  • Encryption at rest: Data stored on our servers is encrypted using AES-256 encryption.
  • Secure data storage on protected servers with regular security updates.
  • Strict access controls to ensure only authorized personnel can access sensitive information.

While we implement strong security measures, no online service can guarantee absolute protection. We encourage users to use strong, unique passwords.

Biometric Authentication

MS Buddy supports Face ID and Touch ID for secure login. Biometric data is processed entirely within your device's secure enclave. MS Buddy does not store or access your biometric information.

4. Data Breach Protocol


In the event of a data breach affecting your personal information, we will:

  • Notify affected users as required by applicable law (and in no event later than 72 hours after discovery where required by law)
  • Provide details about the nature and scope of the breach
  • Outline steps taken to address the breach
  • Offer guidance on protecting your information
  • Provide dedicated support for affected users

5. Data Retention


We retain your personal data for as long as your account is active or as needed to provide you with the App's services:

  • Active Accounts: Your data is retained for the duration of your account's existence.
  • Account Deletion: Upon account deletion (whether voluntary or due to termination), we immediately and permanently delete your personal information (username, email, login credentials, and app settings). Your health data (symptoms, triggers, reminders, and other entries) is anonymized so it can no longer be linked to you, and is retained in de-identified form to help improve the App.
  • Full Deletion: If you would like all data deleted — including anonymized health records — contact us at support@mymsbuddy.com before deleting your account. We will process full deletion requests within 30 days.
  • Backups: Copies of your data may persist in encrypted backups for up to 90 days after deletion, after which they are permanently purged.

6. User Controls and Consent


a. Permissions Management

MS Buddy may request access to your HealthKit data and local notifications. You have full control over these permissions and can modify them at any time via your device settings.

b. Data Management

Editing and Deletion: You can view, edit, or delete your personal and health data within the App.

Account Deletion: You may delete your account at any time from your Profile page within the App. This will permanently remove your personal information and anonymize your health data so it can no longer be linked to you. For a complete deletion of all data including anonymized records, contact us at support@mymsbuddy.com before deleting your account.

Data Export: Before deleting your account, you can download all your data from your Profile page. Your data is exported as a JSON file containing your symptoms, triggers, health data, reminders, and other records.

c. Your Privacy Rights

You have the right to:

  • Access and export your personal data held by us
  • Request correction of inaccurate data
  • Delete your account and anonymize your data, or request full deletion by contacting support
  • Opt out of any data processing not essential to core App functions
  • Revoke previously granted permissions
  • Withdraw consent for health data processing at any time

7. Third-Party Access Restrictions


We commit to the following:

  • Never sell personal data to third parties
  • Never share your data with advertisers or data brokers
  • Never use your data for marketing purposes without explicit consent
  • Respond to government data requests only when compelled by valid legal process
  • Notify you of legally compelled disclosures when permitted by law

8. Notifications and Reminders


MS Buddy provides customizable local notifications for reminders about appointments, MRI and lab work, or other health-related activities. These notifications are processed locally on your device.

You can manage notification preferences within the App or through your device's notification settings.

9. Analytics and Usage Tracking


Internal Analytics: We collect anonymized usage data (such as page views and feature usage) through our internal logging system to improve App functionality.

Data Exclusion: No sensitive health or personal data is included in analytics. We do not use third-party analytics services that receive your data.


MS Buddy may contain links to external websites such as mymsbuddy.com. We are not responsible for the privacy practices of external websites. We encourage you to review their privacy policies.

The App utilizes third-party plugins for features such as secure data storage, biometric login, and local notifications. These plugins handle data in accordance with their own privacy policies and are used strictly within their intended functionalities.

11. California Privacy Rights (CCPA/CPRA)


If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions.
  • Right to Correct: You may request correction of inaccurate personal information we hold about you.
  • Right to Limit Use of Sensitive Personal Information: You may request that we limit the use of your sensitive personal information (including health data) to purposes necessary to provide the App's services.
  • Right to Opt-Out of Sale: We do not sell your personal information. No opt-out mechanism is needed because no sale occurs.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
  • Authorized Agent: You may designate an authorized agent to submit requests on your behalf. We may require verification of the agent's authorization.

Categories of Data Collected: Identifiers (username, email); health information (symptoms, medications, dosages, doctor information, diagnosis details you provide); and internet/electronic activity (page views, feature usage).

To exercise these rights, contact us at support@mymsbuddy.com. We will respond to verifiable consumer requests within 45 days, or within 30 days for non-CCPA requests.

12. State Health Data Privacy Laws


Certain states have enacted laws providing additional protections for consumer health data. If you reside in such a state, the following applies:

Washington (My Health My Data Act):

  • Categories of health data collected: Symptoms, triggers, medications, dosages, doctor names, appointment details, diagnosis information, journal entries, and HealthKit data (if authorized by you).
  • Purpose: Health data is collected solely to provide you with the App's wellness tracking features, including symptom logging, trend analysis, and personalized insights.
  • Third-party sharing: We do not share your health data with any third parties for advertising, marketing, or non-service purposes. Health data is stored by our database provider (MongoDB Atlas) under strict security controls.
  • We collect health data only with your consent, provided when you voluntarily enter it
  • You may delete your account (which anonymizes health data) or contact support for full deletion of all health data

Other states: Several states including Nevada, Colorado, Connecticut, and Virginia have enacted privacy laws granting consumer rights similar to those described in Section 11 above. If you reside in one of these states and wish to exercise your rights, contact us at support@mymsbuddy.com.

13. International Data Transfers


MS Buddy is operated from the United States and is primarily intended for users in the United States. Your information is transferred to and maintained on servers located in the United States, where data protection laws may differ from those in your jurisdiction.

EU/EEA Users: If you are located in the European Union or European Economic Area, please be aware that by using the App, your data will be transferred to the United States. We rely on your explicit consent (provided when you create an account and agree to this policy) as the legal basis for this transfer. If you do not consent to this transfer, please do not use the App.

By using MS Buddy, you acknowledge and consent to the transfer, processing, and storage of your information in the United States.

14. Do Not Track Signals


Some web browsers transmit "Do Not Track" (DNT) signals. Because there is no industry standard for how to respond to DNT signals, we do not currently respond to them. However, we do not engage in cross-site tracking of our users.

15. User Rights and Contact Information


a. Data Access and Correction

You have the right to access, correct, or delete your personal data. To exercise these rights, contact us at support@mymsbuddy.com. We will respond within 30 days (or 45 days for CCPA requests, as required by law).

b. Opt-Out Options

Communications: You may opt out of receiving promotional communications by following the unsubscribe instructions provided in emails.

Data Collection: You can limit data collection by adjusting App permissions in your device settings.

c. Contact Us

For any questions or concerns regarding this Privacy Policy, please contact us:

Email: support@mymsbuddy.com

16. Compliance with Laws


We comply with all applicable federal and state data protection and privacy laws. Users have the right to lodge a complaint with a data protection authority, state attorney general, or other regulatory body if they believe their rights have been violated.

17. Changes to This Privacy Policy


We may update this Privacy Policy from time to time. Any significant changes will be communicated via in-app notifications or email at least 30 days before they take effect. Your continued use of MS Buddy after the effective date indicates your acceptance of the updated policy.

Thank you for choosing MS Buddy to assist you in your wellness journey. We are committed to protecting your privacy and providing a secure, user-friendly experience.