Contact RobotMD®
Service Areas
The U.S. and Canada
Email
info@robotmd.com
RobotMD® Card App
Privacy Policy
Effective Date: July 3, 2026
Introduction
RobotMD, LLC (“RobotMD,” “we,” “us,” or “our”) operates the RobotMD Card mobile application (the “App”), available on Apple iOS and Google Android. This Privacy Policy explains how we handle information in connection with your use of the App.
RobotMD Card is intended for licensed healthcare providers, their authorized staff, and adult patients. It is designed from the ground up with your privacy as the highest priority. The App uses a zero-PHI (Protected Health Information) architecture, meaning that no patient health information is ever transmitted to our servers or to any third party.
Information We Collect
Information you Enter -- Patients
If you use the App as a patient, you may enter the following information on your own device:
- Your name
- Date of procedure
- Procedure type and laterality (side)
This information is stored exclusively on your personal device, encrypted at rest using platform-standard device encryption (AES-256), accessible only when your device is unlocked. On iOS this uses Apple’s Data Protection; on Android this uses Android Jetpack Security (EncryptedFile / EncryptedSharedPreferences). It is never transmitted to RobotMD’s servers, your surgeon’s device, or any third party. Because this data is stored only on your device, it may be included in your own personal device backup — for example, your Apple iCloud backup on iOS, or your Google account device backup on Android — if you have backups enabled. Any such backup is your own, controlled by your Apple or Google account; RobotMD never receives or accesses it. We recommend keeping a screenshot of your completed implant card for your records.
Information Entered by Healthcare Providers
If you are a healthcare provider (surgeon or physician), you enter the following implant and practice information:
- Implant manufacturer, model, and robotic system used
- Surgeon name, credentials, phone number, email, address, and website
- National Provider Identifier (NPI) — optional
- Facility name
This information does not include any patient identifiers. It is stored on your device and, on iOS, may be synced across your own devices via Apple iCloud Key-Value Store; on Android, it is stored in the App’s on-device storage and may be included in your own Google account device backup if you have backups enabled. QR codes are generated entirely on-device using platform-standard image frameworks. No implant or patient data is transmitted to RobotMD servers at any point during QR code generation.
When healthcare providers subscribe, we create a provider account on RobotMD servers. This account stores the provider’s professional profile — name, credentials, specialty, practice address, phone, email, and website — along with a generated provider code used to link authorized staff and to display implant card information. None of this is patient information. Providers may optionally enter their National Provider Identifier (NPI); if provided, it may be used to include the provider in RobotMD’s planned verified provider directory. Providers can edit their profile information at any time; profile changes take effect immediately and are recorded in a server-side activity log used for account security and fraud prevention.
Information Entered by Staff
Authorized staff members (for example, a provider’s office or clinical staff) may use the App under a provider’s account. Staff link to a provider using the provider code and are periodically re-verified against the provider’s active subscription status. For staff, we store on RobotMD servers only the information needed to establish and maintain this association — such as the provider’s name and the linked provider code. Staff accounts do not involve patient identifiers or PHI, and follow the same zero-PHI model described throughout this policy.
Subscription and Account Data
For provider subscriptions, RobotMD’s servers store subscription-management information necessary to operate the service: the provider’s subscription status (active/inactive), and the transaction and order identifiers provided by the app store (for example, an Apple original transaction ID or a Google Play purchase token/order ID). These identifiers are used solely to verify entitlement, match subscription lifecycle events (such as renewal, cancellation, expiration, or refund) to the correct provider account, and manage access. RobotMD does not receive or store your payment card information; all payment processing is handled by Apple or Google (see Third-Party Services below).
Information We Do Not Collect
We do not collect, receive, store, or transmit:
- Patient names, dates of procedure, or procedure information — this data is entered by patients directly on their own device and stored locally only. It is never collected by, transmitted to, or stored on RobotMD servers.
- Medical record numbers or patient identifiers of any kind
- Device location data
- Contacts, photos, or other device content
- Usage analytics or behavioral tracking data
- Payment card or bank account information
How the QR Code Transfer Works
RobotMD Card uses a proprietary QR code system to transfer implant data from a provider’s device to a patient’s device. The QR code contains only implant and provider information — it never contains patient names, dates, or any PHI.
When a patient scans a provider's QR code:
- The implant data is transferred directly from the provider’s screen to the patient’s camera — no server is involved.
- The patient then enters their own name, date of procedure, and procedure on their personal device.
- The combined implant card is stored locally on the patient’s device only.
This architecture ensures that the provider device never receives, stores, or transmits any patient PHI at any point in the workflow.
Third-Party Services
App Stores and In-App Purchases
In-app purchases are processed by the platform’s app store — Apple through StoreKit on iOS, and Google through Google Play Billing on Android. RobotMD does not receive or store your payment information. The privacy policy of Apple (iOS) or Google (Android) applies to all purchase transactions.
Device Cloud Services (Apple iCloud / Google)
On iOS, provider implant card data (non-PHI) may be synced across a provider’s own devices using Apple’s iCloud Key-Value Store. On both iOS and Android, on-device data may be included in your own personal device backup (Apple iCloud on iOS, or your Google account on Android) if you have backups enabled. The App does not sync patient data to RobotMD servers through any mechanism. Patient data resides only in the App’s on-device storage; as noted above, it may be captured in a user’s own personal device backup if backups are enabled, but it is never synced to RobotMD or transmitted to any third party by the App. Apple’s and Google’s respective privacy policies govern data handled by their cloud services.
NPI Registry
Healthcare providers may optionally enter their National Provider Identifier (NPI), which, if provided, may be used to include them in RobotMD’s planned verified provider directory. NPI numbers are public registry data maintained by the U.S. Department of Health and Human Services and do not constitute PHI.
HIPAA Considerations
RobotMD Card is architected to avoid HIPAA applicability by ensuring that Protected Health Information (PHI) is never collected, transmitted, or stored on provider devices or servers. Patient health data entered in the App remains exclusively on the patient’s own personal device.
RobotMD, LLC does not function as a Business Associate under HIPAA because the App does not handle PHI on behalf of any Covered Entity. However, healthcare providers should consult their own compliance counsel regarding their use of any technology in their practice.
This statement is informational and does not constitute legal advice.
Data Security
We take the security of your information seriously. The following measures protect your data:
- Patient implant information is encrypted at rest on the patient’s device (Apple Data Protection on iOS; Android Jetpack Security on Android) and is never transmitted to RobotMD servers.
- Provider implant card data is stored on the provider’s device and, where applicable, synced across the provider’s own devices through the platform’s encrypted cloud infrastructure.
- RobotMD servers store provider and staff account and profile information (non-PHI) but never store patient health information or any patient identifiers.
- Communication between the App and RobotMD servers occurs over encrypted connections (HTTPS/TLS).
- In-app purchases are handled entirely by Apple’s or Google’s secure payment infrastructure.
- While we strive to protect your information, no method of electronic storage is 100% secure. We encourage you to use a device passcode and enable your device’s built-in encryption (enabled by default on modern iPhones and Android devices).
Data Retention and Deletion
We retain provider and staff account information for as long as the account is active and as needed to provide the service. Provider subscription status and store-provided transaction identifiers are retained while the subscription is active and for a reasonable period afterward as needed for account security, fraud prevention, and recordkeeping.
You may request deletion of your provider or staff account and associated server-stored profile data at any time by contacting us at info@robotmd.com. Upon verifying your request, we will delete the associated account data from our servers within 30 days, except where retention is required to comply with legal obligations or to resolve disputes. Patient data is stored only on the patient’s own device; you can delete it at any time by deleting the entry within the App or uninstalling the App from your device.
Children's Privacy
RobotMD Card is intended for licensed healthcare providers, their authorized staff, and adult patients, and is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information through the App, please contact us and we will take steps to remove that information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Continued use of the App after changes constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
Contact Us
If you have questions about this Privacy Policy or your data, or to request account deletion, please contact us:
RobotMD, LLC
Website: www.robotmd.com
Email: info@robotmd.com
© 2026 RobotMD, LLC. All rights reserved.
RobotMD® Card App Data Deletion Request
Effective Date: July 3, 2026
This section explains how to request deletion of data associated with the RobotMD Card app (developer: RobotMD, LLC).
What Data We Store
RobotMD Card uses a zero-PHI architecture. Patient health information (name, date of procedure, procedure, and implant details) is stored only on the patient’s own device and is never transmitted to or stored on RobotMD servers — there is nothing for RobotMD to delete on the server side for patients.
On RobotMD servers, we store only provider and staff account information: the provider’s professional profile (name, credentials, specialty, practice address, phone, email, website), the generated provider code, subscription status, and store-provided transaction identifiers used to manage the subscription. We do not store patient identifiers or payment card information.
How to Request Deletion
To request deletion of your provider or staff account and its associated server-stored data:
- Email info@robotmd.com from the email address associated with your account.
- Include your name and, if available, your provider code, so we can locate your account.
- State that you are requesting deletion of your RobotMD Card account data.
Upon verifying your request, we will delete your associated account data from our servers within 30 days, except where limited retention is required to comply with legal obligations, resolve disputes, or prevent fraud.
Deleting Patient Data on Your Device
Because patient data is stored only on your device, you can delete it at any time by deleting the entry within the app or by uninstalling the RobotMD Card app from your device. Uninstalling removes the app’s locally stored data from that device.
Contact
RobotMD, LLC Website: www.robotmd.com
Email: info@robotmd.com
