MERIDIAN
GI AND METABOLIC HEALTH

Privacy Policy

How the MERIDIAN patient app and staff portal handle your information.

What we collect

The MERIDIAN app is designed to help you track your bariatric and metabolic care between visits. The information stored against your account is limited to what is needed for that purpose:

What we don’t collect

The app does not ask for your full name, date of birth, address, phone number, Medicare number, or any other identifying information. We identify you only by the Patient ID issued to you by the practice. We do not use third-party advertising trackers, and we do not sell or share your data with any party for marketing purposes.

Where it is stored

Your entries and account data are stored in a PostgreSQL database hosted on Replit’s cloud infrastructure, with servers located in the United States. We use this hosting provider to run the app reliably and securely; it stores data on our behalf and is not permitted to use it for its own purposes. Connections are made over TLS. Staff portal sessions are stored server-side and protected by HTTP-only, same-site cookies and CSRF tokens.

Who can see it

Your treating team at MERIDIAN GI and Metabolic Health can access your tracked data through the staff portal in order to support your care. Each staff member has their own login. We do not share your data with anyone outside the practice except where required to provide the service (for example, sending the consent PDF to the practice’s administration email, or sending anniversary blood-test reminders to the email address you supplied).

Overseas disclosure and AI features

Two optional features in the calorie tracker use artificial intelligence: scanning a nutrition label from a photo, and estimating nutrition from a food description. When you use them, the photo or text you submit is sent to OpenAI, a service provider located in the United States. This is the only situation in which information you enter in the app is disclosed overseas.

Your name, Patient ID, and account details are never sent with the request. The OpenAI key is held only on the server and is never exposed to the app. Submissions are subject to OpenAI’s data use policy. Before the first use, the app asks for your consent to this overseas disclosure; the features do not run without it, and you can withdraw consent at any time from the app’s Privacy screen.

How long it is kept

Health information is kept for as long as the law requires: at least 7 years from your last visit or entry, or if you were under 18 at the time, until you turn 25 (whichever is later), in line with the Health Records Act 2001 (Vic). Everyday tracker entries that are not part of your health record can be deleted sooner on request. When a record is no longer required it is securely destroyed, and a record of that destruction is kept.

If you would like your app data deleted, contact the practice on the details below and we will action your request.

Security

Staff passwords are stored as bcrypt hashes. Login attempts are rate-limited per IP address and per account. Sensitive details (request bodies, prompts, photos, session IDs) are not written to server logs. Patient-facing endpoints accept only the data shapes the app is designed to send.

Questions and complaints

If you have a question about your privacy, or you believe we have mishandled your information, please contact the practice first using the details below. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.

If you are not satisfied with our response, you can escalate your complaint to:

Contact

Meridian Health
Suite 2, Level 3, Brenan Place Building, 31-35 Victoria Parade, Fitzroy VIC 3065
Phone: (03) 9416 4418
Email: reception@meridianhealth.com.au

Last updated July 2026 · v2