Skip to main content
Legal

PrivacyPolicy

Last updated: September 2026

1. Introduction

InstantMed ("we", "our", or "us") is committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we collect, use, disclose, and protect your personal and health information.

2. Information We Collect

We collect the following types of information:

  • Identity Information: Full name, date of birth, email address, phone number
  • Medicare Information: Medicare number, IRN, and expiry date (for eligible services)
  • Address Information: Residential address for delivery of prescriptions
  • Health Information: Medical history, current medications, symptoms, allergies, and other health-related information you provide
  • Usage Information: How you interact with our platform, including pages visited and features used

3. How We Use Your Information

We use your information to:

  • Provide telehealth consultations and medical services
  • Process prescriptions, medical certificates, and referrals
  • Communicate with you about your care
  • Comply with legal and regulatory requirements
  • Improve our services and user experience
  • Create aggregated, de-identified insights and reports about how our services are used (for example, anonymous trends in demand by day, season, or state)
  • Prevent fraud and ensure platform security

When we use information for research, reporting, or to promote our services, including any public reports, we use only aggregated, de-identified data that cannot reasonably be used to identify you. We never publish your individual health information, and small groups are suppressed so individuals cannot be re-identified.

4. AI-Assisted Services

InstantMed uses Anthropic (Claude) to assist with certain administrative tasks, including organising intake information and drafting clinical documentation. In the bounded medical-certificate pathway, AI uncertainty can only route a request to a doctor; it cannot widen the protocol or override a safety rule. AI-assisted prescribing documentation remains subject to individual doctor review before clinical use.

Your request is assessed for suitability. If more information is needed, a doctor may contact you. Every prescription requires a decision by an AHPRA-registered doctor. Health information shared during intake may be processed by Anthropic's systems in accordance with their data processing agreements with us.

Our phone message service uses Lena, an automated voice assistant, to speak with you and take one message for our Medical Director. The live call audio is processed to run the conversation. InstantMed stores the name, callback number if requested, and concise message that you confirm. We do not retain the raw call audio or a full transcript.

5. Third-Party Service Providers

We share your information with trusted third parties only where necessary to deliver our services:

  • Supabase: Database hosting and storage
  • Supabase Auth: Authentication and identity management
  • Stripe: Payment processing (no card data stored by InstantMed)
  • Resend: Transactional email delivery
  • Anthropic (Claude): AI-assisted documentation drafting
  • Twilio and OpenAI: Phone call routing and automated voice message processing. When the ElevenLabs voice option is used, Twilio also uses Google for speech recognition and ElevenLabs for voice synthesis, while OpenAI processes the conversation as text
  • Parchment: Electronic prescription generation
  • PostHog: Pseudonymous product analytics processed in the United States
  • Sentry: Error monitoring (no PHI in error reports)

We limit each provider to the information needed for its role and apply access, configuration, retention, and security controls appropriate to that service.

6. Health Information

Health information is sensitive personal information under the Privacy Act 1988 (Cth). We handle your health information with the highest level of care and in accordance with the Australian Privacy Principles. Your health information is:

  • Encrypted at rest using AES-256-GCM field-level encryption
  • Transmitted over TLS-encrypted connections only
  • Accessible only to treating clinicians and authorised staff
  • Never sold or shared for marketing purposes
  • Retained for a minimum of 7 years as required by law

For a source-backed checklist on telehealth health data, collection notices, access controls, disclosure limits, correction rights, and privacy complaints, see our telehealth privacy and health data checklist.

7. Data Security

We implement industry-standard technical and organisational measures to protect your information against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • AES-256-GCM field-level encryption for all health (PHI) data
  • TLS encryption for all data in transit
  • Role-based access controls - data is only accessible to authorised personnel
  • Row-level security enforced at the database layer
  • Regular security assessments and internal audits

8. Your Rights

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of your account (subject to legal retention requirements)
  • Opt out of non-essential communications
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)

To exercise any of these rights, contact us at privacy@instantmed.com.au. We will respond within 30 days.

9. Cookies and Analytics

We use cookies and similar tracking technologies to improve your experience and understand how our platform is used. This includes:

  • Essential cookies: Required for authentication and platform functionality
  • Analytics: PostHog uses a random browser identifier to measure page, form-step, checkout, and purchase events. We do not send names, email addresses, phone numbers, clinical answers, raw search terms, Google click identifiers, or production request IDs to PostHog. We do not create or update PostHog person profiles, and generic element autocapture and session recordings are disabled.
  • Error monitoring: Sentry captures technical error information (no health data included)

You can control cookie preferences through your browser settings. Disabling essential cookies may affect platform functionality.

10. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations:

  • Health records: minimum 7 years from last consultation (as required by law)
  • Account data: until you request deletion (subject to health record retention)
  • Payment records: 7 years (as required by Australian tax law)
  • Pseudonymous analytics events: retained for service improvement and deleted or aggregated when no longer required
  • Confirmed phone messages: deleted 30 days after our Medical Director resolves them. Any resulting clinical action that must be retained is recorded separately in the patient's health record

11. Children's Privacy

Our services accept patients aged 18 and over only. We do not knowingly collect patient information from individuals under 18. If you believe a minor has provided us with personal information, please contact us immediately so we can handle it appropriately.

12. Data Breach Notification

In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme within 30 days of becoming aware of the breach.

13. Contact Us

For questions, requests, or complaints about this Privacy Policy or how we handle your information, please contact our Privacy Officer:

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Questions about your privacy?

Your data belongs to you. If you have concerns, we want to hear about them.