Experimental research prototype. AI-generated, not reviewed by a clinician. Not medical advice. Read the full disclaimer
Security

We keep as little as possible. What we keep is encrypted.

Health data is special category data. We treat it that way, in the defaults and in the code.

256bit
AES encryption
≤ 1hr
Temp file lifetime
0
Tracking cookies
30days
Log retention

The four promises that matter

Lifted from the code, not from marketing slides.

01

Files deleted immediately

Your original files are deleted as soon as the brief is built. There is no step at which we keep them. An hourly sweep cleans up if the primary path is delayed.

02

Encrypted at rest

When you save a brief, its contents sit AES-256 encrypted in the database. No one on our team can read them without the application key.

03

No account required

You can build a brief without registering. If you do not save it, we keep nothing.

04

GDPR followed

We follow the GDPR as data controller, with processor agreements in place for AI inference. Full statement in our privacy policy.

What we do, what we do not

What we do

  • Delete originals right after processing.
  • Encrypt brief contents at rest with AES-256.
  • Check passwords against public breach lists.
  • Log every caregiver read for audit.
  • Send CSP, HSTS and frame-ancestors none.

What we do not do

  • Sell your data to ad networks.
  • Train AI models on your documents.
  • Set tracking cookies or pixels.
  • Log the contents of your files.
  • Diagnose or recommend treatment.

How the upload path looks

  1. You upload a file. It is written to a temporary directory that only this session knows about.
  2. Continuum sends the file to Anthropic for processing over a TLS-encrypted connection.
  3. As soon as the response comes back, the file is deleted on our side.
  4. The finished PDF sits at a random link for up to one hour, after which that path is also removed.
  5. If the scheduled cleanup is delayed, an hourly sweep returns and removes anything older than an hour.

Vendors we use

Anthropic
AI inference. Contractually prohibited from training on or retaining your data. Processing in the US, covered by SCCs and the EU-US Data Privacy Framework.
Google
Only if you choose to sign in with Google. We exchange your email and an anonymous identifier.
Our hosting provider
Servers in the EU, with a signed data processing agreement.

What we do not log

We never log the contents of your files. We log file counts, sizes, and technical error classes if something fails. We log which IP starts an upload so we can spot abuse, and we delete those logs after 30 days.

What we do log

When a family member opens a brief shared with them, we record the date, the caregiver id, the owner id, and the brief id. You can see these records in your data export.

Your rights

  • Access: you can export all your data as JSON at any time.
  • Erasure: you can delete your account in one step, fully.
  • Rectification: you can change the title of a brief. The content is intentionally read-only so it stays aligned with your sources.
  • Portability: the same JSON export satisfies this.

Report a vulnerability

If you have found a security issue, write to [email protected]. We acknowledge within two business days and work toward a fix within thirty days.

See it in a minute.

No account. No risk. You can walk away with nothing left behind.

Prepare for my next visit