Health data is special category data. We treat it that way, in the defaults and in the code.
Lifted from the code, not from marketing slides.
Your original files are deleted as soon as the brief is built. There is no step at which we keep them. An hourly sweep cleans up if the primary path is delayed.
When you save a brief, its contents sit AES-256 encrypted in the database. No one on our team can read them without the application key.
You can build a brief without registering. If you do not save it, we keep nothing.
We follow the GDPR as data controller, with processor agreements in place for AI inference. Full statement in our privacy policy.
We never log the contents of your files. We log file counts, sizes, and technical error classes if something fails. We log which IP starts an upload so we can spot abuse, and we delete those logs after 30 days.
When a family member opens a brief shared with them, we record the date, the caregiver id, the owner id, and the brief id. You can see these records in your data export.
If you have found a security issue, write to [email protected]. We acknowledge within two business days and work toward a fix within thirty days.
No account. No risk. You can walk away with nothing left behind.
Prepare for my next visit