Privacy Policy
Last updated: September 2026
This policy explains what information Medic Media (“we,” “us”) collects through the Medic Media website and the Medic Media Admin and Client Portals (together, the “Platform”), how we use it, and the choices you have.
1. Who we are
Medic Media is a clinic marketing agency. This Platform is how we manage content, campaigns, billing, and social-media analytics for our clinic clients.
Medic Media is the trading name under which this Platform and our services are provided. For any question about this policy or your data, contact mms@medicmediastudios.com.
2. Account information we collect
To create and operate an Admin or Client Portal account, we collect the email address you sign in with (via Supabase Authentication, our identity provider) and a password, which Supabase stores hashed — we never see or store your password in plain text.
For a client account specifically, we also hold the clinic’s contact information entered by our team when setting up your workspace: clinic name, a contact name, an email address, and a phone number. If you submit our public contact/enquiry form as a prospective client, we collect the name, email, phone number, and message you provide there.
3. Connecting Instagram or Facebook (Meta OAuth)
If you ask us to connect your clinic’s Instagram or Facebook account so we can track its performance, we redirect you to Meta’s own login/consent screen — we never see or handle your Instagram or Facebook password. Meta asks you to approve a specific set of permissions before returning you to us:
- For Instagram (Instagram Login):
instagram_business_basic,instagram_business_content_publish,instagram_business_manage_messages,instagram_business_manage_comments, andinstagram_business_manage_insights. - For Facebook (Facebook Login):
pages_show_listandpages_read_engagement.
We only request the permissions each connected feature actually uses today — reading your account’s posts and their performance metrics, and (for Instagram) the ability to manage messages/comments as part of that permission set. We do not request, and this Platform does not currently use, permission to post on your behalf, run ads, or access any account beyond the one you explicitly connect.
4. How we store social-media account access
When you connect an account, we store the access and refresh tokens Meta issues for it, the account’s platform ID, and its display name (e.g. your Instagram username or Page name). Both tokens are encrypted (AES-256-GCM) before they are ever written to our database and are only decrypted, in memory, by the specific server-side process that performs a sync — never sent to, or readable by, any browser, including an admin’s own logged-in session.
Disconnecting an account immediately clears its stored tokens from our database. Reconnecting starts a fresh authorization with Meta.
5. Analytics and content data
Once an account is connected, we sync account-level metrics (reach, follower counts, and, where the connected platform currently supports it, impressions and follow activity) and content-level data for your posts (captions, thumbnails, publish dates, permalinks, and engagement such as likes, comments, shares, and saves) — automatically on a recurring schedule, on demand, or entered manually by our team. This data is used solely to power the analytics and reporting shown inside your own Client Portal and to our team.
6. Cookies and session data
The Platform uses a small number of strictly functional cookies — no advertising or cross-site tracking cookies. Specifically: a Supabase authentication session cookie (so you stay signed in), and, only while you are actively connecting a social account, a short-lived (10-minute) signed cookie that protects that connection flow against forgery. Neither cookie is readable by, or shared with, any third party other than Supabase, our authentication provider.
7. Data storage and security
Platform data is stored in a Supabase-managed Postgres database and served through our application hosted on Vercel. Access to every client’s data is enforced at the database level (Row Level Security) so that one client’s records — content, analytics, invoices, and connected accounts — are never readable by another client. Social-media access tokens are encrypted at rest, as described in Section 4, and administrative-level database access is limited to the specific automated processes that require it, such as our scheduled analytics sync.
8. Data retention and deletion
We retain your account and Platform data for as long as your clinic is an active client, so your historical analytics and content remain available to you. Disconnecting a social account deletes its stored tokens immediately, as described in Section 4. If you would like your account or clinic data deleted — in whole or in part — contact us at the email in Section 1 and we will action your request.
A specific automatic retention schedule for data after an account is closed is still being finalized and will be published here once decided.
9. Third parties who process data on our behalf
We rely on the following processors to operate the Platform. We do not sell your data, and we do not share it with anyone else for marketing purposes.
- Supabase — database hosting, authentication, and file storage.
- Vercel — application hosting and the scheduled job that syncs social-media analytics.
- Meta Platforms, Inc. — only if and when you connect an Instagram or Facebook account, as described in Sections 3–4.
10. Your rights and how to contact us
You can ask us to access, correct, or delete the personal data we hold about you, and you can withdraw a social-media connection at any time by disconnecting it inside the Client Portal. To exercise any of these rights, or if you have a question about this policy, contact mms@medicmediastudios.com.
The specific data-protection law(s) applicable to your data are being confirmed and will be stated here before this policy is treated as final.
11. Changes to this policy
If we make a material change to how we handle your data, we will update the date at the top of this page. Continuing to use the Platform after a change means you accept the updated policy.