MedCross Privacy Policy

Last updated: July 11, 2026  ·  Effective: June 26, 2026

Plain-English summary. MedCross is designed to be privacy-friendly. We do not operate a backend server — your game progress, coins, friends list, library, and email-account credentials all stay on your device. We display ads through Google AdMob, offer optional sign-in via Apple or with an email + password (device-local), and process in-app purchases through Apple. We do not sell personal information. The sections below explain each data flow and your rights in detail.
Contents
  1. Who we are
  2. Information we collect
  3. How we use information
  4. Third-party services
  5. Legal basis for processing (EEA / UK)
  6. Your rights (GDPR / UK GDPR)
  7. California residents (CCPA / CPRA)
  8. Other countries — global privacy rights
  9. App Tracking Transparency
  10. Children's privacy & age requirement
  11. Data retention & deletion
  12. Data security
  13. International data transfers
  14. Data breach notification
  15. Friends feature, reporting & blocking
  16. Information we do NOT collect
  17. Changes to this policy
  18. How to contact us

1. Who we are

MedCross ("MedCross", "we", "us", or "our") is operated by Yoav Toren, an individual developer, acting as the data controller for the personal information described in this policy.

Contact: yoavtoren@gmail.com

This policy applies to the MedCross mobile application available through the Apple App Store. It does not apply to third-party websites or services we link to.

2. Information we collect

2.1 Information stored only on your device

The following information is generated by your use of MedCross and stored locally on your device using iOS application storage. We do not transmit, copy, or synchronize this information to any server we operate.

2.2 Sign-in options

MedCross offers three ways to use the app:

2.3 Information processed by advertising and purchase partners

When you view ads or make purchases inside the app, our third-party providers (Google AdMob and Apple) may collect information directly from your device under their own privacy policies. See Section 4 for details on what each provider collects.

2.4 Diagnostic information

If the app crashes, the iOS operating system may collect crash diagnostics that Apple makes available to us in aggregated, non-identifying form via App Store Connect. We do not use any third-party crash-reporting or analytics SDK. No personal information is included in the crash diagnostics we receive from Apple.

3. How we use information

We use the limited information described above only for the following purposes:

4. Third-party services

We use a small number of third-party services that may receive information directly from your device. We do not control their data practices once information reaches them — please consult their privacy policies for full details.

4.1 Apple App Store & StoreKit (in-app purchases)

In-app purchases (coin packs, World Pass, and any subscription products) are processed by Apple via StoreKit. Apple handles all payment information — we do not see or store your payment details. We receive only a transaction receipt confirming the purchase. See Apple's Privacy Policy.

4.2 Sign In with Apple

If you choose to sign in with Apple, Apple handles authentication and may share your name and email with us based on the choices you make in Apple's prompt. See Apple's Privacy Policy.

4.3 Google AdMob (advertising)

We display banner, interstitial, and rewarded ads through Google AdMob (a service operated by Google LLC). AdMob may collect and process the following information directly from your device:

If you grant permission through the iOS App Tracking Transparency prompt, AdMob may use these identifiers to deliver personalized ads. If you deny permission, AdMob will deliver non-personalized ads. See Google's Privacy Policy and how Google uses information from partner apps.

4.4 Notifee (local notifications)

We use the Notifee library to schedule daily reminder notifications. These notifications are scheduled and delivered locally on your device. No notification tokens or device identifiers are transmitted to any server, and we do not use remote push notifications.

5. Legal basis for processing (EEA / UK)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information under the following legal bases as set out in Article 6 of the GDPR (and equivalent provisions of the UK GDPR):

You may withdraw any consent at any time without affecting the lawfulness of processing already carried out. To withdraw consent to personalized ads, change your App Tracking Transparency setting in iOS Settings → Privacy & Security → Tracking. To withdraw consent to notifications, disable notifications in iOS Settings.

6. Your rights (GDPR / UK GDPR)

If you are in the EEA, UK, or Switzerland, you have the following rights regarding your personal information:

To exercise any of these rights, email us at yoavtoren@gmail.com. We will respond within 30 days as required by the GDPR.

7. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), gives you specific rights regarding your personal information.

7.1 Categories of personal information collected

In the 12 months prior to the effective date of this policy, we (and our advertising partner Google AdMob) may have collected the following categories of personal information as defined by the CCPA:

7.2 Sources, purposes, and recipients

We collect this information directly from your device through your interaction with the app, and through the Google AdMob SDK embedded in the app. We use the information for the operational and advertising purposes described in Section 3. Recipients are the third-party service providers described in Section 4.

7.3 Do Not Sell or Share My Personal Information

We do not sell personal information in the traditional sense of the word. However, the use of Google AdMob for personalized advertising may be considered "sharing" personal information for "cross-context behavioral advertising" under the CCPA.

To opt out, deny the App Tracking Transparency prompt the first time MedCross asks, or change your selection at any time in iOS Settings → Privacy & Security → Tracking → MedCross. When ATT is denied, AdMob serves only non-personalized ads and does not access your IDFA.

7.4 Your California rights

To exercise any of these rights, email yoavtoren@gmail.com. We may verify your identity by asking you to confirm details only the account holder would know (such as your 6-digit MedCross profile code).

8. Other countries — global privacy rights

MedCross is distributed worldwide. Wherever you live, we extend the same baseline privacy rights to you: access, correction, deletion, objection, and withdrawal of consent. This includes, without limitation, rights under Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act 1988, Israel's Privacy Protection Law, Japan's APPI, South Korea's PIPA, and any other national, state, or provincial privacy law that applies to you.

Because virtually all MedCross data is stored only on your own device and never reaches any server we operate, you can exercise most of these rights instantly and directly: edit your profile in the app, deny or revoke ad tracking in iOS Settings, or erase everything via Profile → Settings → Delete Account (or by deleting the app). For anything else, email yoavtoren@gmail.com and we will respond within 30 days, or sooner where your local law requires. Where your local law grants you rights beyond those described elsewhere in this policy, those rights apply to you in addition to, not instead of, the rights above.

9. App Tracking Transparency

iOS requires apps to obtain your permission before tracking you across other companies' apps and websites. MedCross presents the App Tracking Transparency prompt the first time you complete onboarding. Your response is stored on your device by iOS.

You can change this choice at any time in iOS Settings → Privacy & Security → Tracking → MedCross.

10. Children's privacy & age requirement

MedCross is intended for users aged 13 and older. During onboarding, you are required to confirm you are at least 13 years of age before continuing.

We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has provided information through MedCross, please contact us at yoavtoren@gmail.com and we will promptly delete the information.

MedCross does not include in-app chat, direct messaging, or other features that allow children to communicate with strangers.

11. Data retention & deletion

Because your MedCross data is stored on your device:

Third-party providers (Apple, Google) retain transaction records and advertising data under their own retention policies.

12. Data security

We take reasonable technical and organizational measures to protect your information against unauthorized access, disclosure, alteration, and destruction:

No security measure is perfect. If we become aware of a security incident affecting your personal information, we will notify you and the relevant authorities as required by applicable law (see Section 14).

13. International data transfers

We do not transfer your data internationally because we do not collect data on our own servers. However, our third-party providers may process your information in countries outside your country of residence:

These providers maintain appropriate data-transfer safeguards (such as Standard Contractual Clauses) for transfers from the EEA, UK, and Switzerland.

14. Data breach notification

If we become aware of an unauthorized acquisition or disclosure of personal information that we control, we will notify affected users and the relevant supervisory authorities without undue delay, and within 72 hours where required by the GDPR (Article 33).

15. Friends feature, reporting & blocking

The Friends feature allows you to add other MedCross players to your friends list using a 6-digit player code that you must obtain from the other person directly. There is no in-app contact discovery, no address-book access, no search by name or email, and no chat or messaging.

Friend additions, including any nickname you choose for a friend, are stored only on your device. The other person does not see the nickname you have chosen for them.

If you encounter a player who you believe is engaging in abusive behavior, you can long-press the friend card in the Friends list to access two options:

We review reports promptly and may take action including warning the reported player, restricting features, or, if we add a backend in the future, removing them from matchmaking.

16. Information we do NOT collect

17. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. For material changes, we will notify users through the app or by other reasonable means before the change takes effect. Continued use of MedCross after the effective date of a revised policy constitutes acceptance of the revised policy.

18. How to contact us

Questions about this policy, requests to exercise your rights, or other privacy concerns? Contact us at:

Email: yoavtoren@gmail.com
Operator: Yoav Toren
Subject line for privacy requests: "MedCross Privacy Request"

We will respond within 30 days of receiving a verifiable request, or as required by applicable law.