Transparency
Your health data is among the most sensitive information you own. This page explains, in plain language, how we store, encrypt, and protect it.
Our promise: you own your data. We protect it with medical-grade encryption, isolate it per user, and never share it without your explicit consent.
All health records are encrypted in transit using TLS 1.2+ and at rest using industry-standard AES-256 encryption. Files you upload are stored in private, access-controlled storage and are never served publicly.
Each account is isolated by Row-Level Security (RLS). You own your records — only you, and the people you explicitly share with, can view or download them. Admins can only access system metadata, never your clinical content.
Our data handling follows principles aligned with HIPAA (USA), GDPR (EU), and Singapore’s PDPA, including data minimization, purpose limitation, and least-privilege access.
Every access event — upload, preview, download, share, revoke — is recorded in a tamper-evident audit log you can review at any time from your records dashboard.
Sharing is always opt-in and revocable. Link shares can be password-protected, set to expire, or limited to a single download. You can revoke access instantly at any time.
You decide how long records are kept. Soft-deleted items can be restored, and permanent deletion removes the data from active storage. Retention expiry tags help you stay compliant.
You can export, correct, or delete your data at any time. We never sell health data, and we never use your clinical content to train third-party models.
If you have concerns about how your data is handled, want to exercise your data rights, or need a data export or deletion, contact our team and we will respond in accordance with applicable privacy law.