Privacy

Where your records actually are.

Your health. Your data. Your control.

This page explains where your data lives, what leaves your phone when you share, who else touches any of it, and what happens when you revoke.

On your phone: everything

Every record you enter is written to your iPhone's own encrypted store and stays there. There is no account holding a copy, and no sync that runs on its own. Signing in to the app unlocks the data already on that device — it does not fetch anything from us.

If you have iCloud Backup turned on, Apple backs this up the same way it backs up the rest of your phone. That's Apple's backup, under Apple's own privacy terms — restoring your phone restores the app, and we never receive a copy of it ourselves.

On our server: only what a share needs

When you create a share, the app sends a copy of the categories you ticked — and nothing outside them. That copy is attached to that one share, readable only by the clinician who redeemed its code.

  • The entries in the categories you chose
  • Prescriptions, only if you included them
  • The name of the doctor attached to an entry, where you recorded one
  • The recipient doctor's name, specialty and email if you gave one, plus any note you typed while setting the share up

Creating your first share also opens one small record keyed to your device's account — whatever display name, email or date of birth the app has on file for you. It exists so a doctor's patient list shows a name instead of a string of characters, and it's the one thing on our server that doesn't come and go with a single share. See "Your choices" below for how to have it removed.

If you keep records for somebody else — a child, a parent — each profile you share from opens its own record of that kind, under that person's name, and how they're related to you so the chart can say who is keeping it. Profiles are kept apart the whole way through: separate shares, separate copies, separate access logs. A doctor holding a code for one of them sees that person's chart and has no way to reach any of the others, and nothing on our server ever puts two profiles' entries in the same place. Profiles you never share stay on your phone and reach us not at all.

Billing: separate, and smaller

The billing server knows your subscription state, your account key, and the email you paid with. It has never held a health record and does not join to the one that does — sharing and billing are two different apps, deliberately not linked by anything but that key.

Your card number never reaches us. Stripe collects it, runs the charge, and hands back a status and an ID — that's all the billing server ever sees. What Stripe does with a card is covered by Stripe's own privacy policy, not this one.

When you revoke: what actually goes

Revoking a share deletes the shared copy from the server in the same transaction that turns the share off. It is not marked inactive and kept around — the doctor's next click is a 404, immediately.

A share you gave an end date to stops being readable the moment that date passes, and a sweep that runs every night deletes the copy. So the door closes on the hour and the copy is gone within the day, whether or not you remember it was there.

What that doesn't reach: the share itself stays on as an empty entry in your own history — which doctor, which categories, when it opened and closed — and the access log stays with it, listing who opened it and when. Erasing those alongside the records they describe would erase your own account of who's had your data, which is the opposite of the point.

Who can see a share

Exactly one clinician account: the one that redeemed the code. Codes work once. An unredeemed code expires after two weeks. A clinician with three of your codes over three years still sees only what each of those shares covers, and each one can be revoked on its own.

Getting into the doctor portal at all

A clinician gets in one of two ways. Redeeming a code you handed them is approved on the spot — you vouched for them, so we don't second-guess it. Registering directly on the site sits pending until we approve it by hand, usually the same day.

Either way, we collect what they give us at registration: name, credentials, specialty, practice, phone, and an NPI. That NPI is not checked against the federal registry — it's there so you can confirm the name in front of you matches the name on the screen, not to vet anyone on our end.

An account we haven't approved yet can sign in and look at its own profile, and nothing else. Once approved, a doctor's authority is scoped to the one grant they redeemed — there is no patient directory, no search box, and no route into a share that isn't theirs.

Security, plainly

  • Every connection is TLS, enforced by the server, with HSTS turned on
  • A doctor's session expires after two hours and is marked secure, same-site only
  • Sign-in attempts and invite-code guesses are rate-limited
  • The one call that can mark an account paid — Stripe's webhook — is signature-verified; nothing else can flip that switch
  • Every view, sync and revoke against a share writes to that share's access log, tagged with the IP address behind it — the same log you can read back in the app

Who else touches this

Two outside services see anything at all. Stripe processes the charge and reports back a status — never a health record. An email-delivery service we configure sends four kinds of message on our behalf: a doctor's invite, a new registration for us to review, an approval, and a password reset. None of the four carries a health record either.

Neither is paid to look at what passes through it beyond doing its job, and neither is an ad network.

What we don't do

  • No advertising, and no ad identifiers
  • No selling or brokering of health data, at any price
  • No training models on your records
  • No third-party analytics or trackers built into the app

The revenue is the $5 a month. That is the whole business model, which is what lets the rest of this list stay short.

Your choices

Revoke a share yourself, any time, from the app — nobody has to act on your behalf, and revoking never depends on your subscription being paid up. Change your card or cancel the subscription from Settings, which opens Stripe's own billing portal, not a page we run.

Cancelling the subscription ends every share that is still open and deletes the copies behind them, the same as revoking each one by hand. Your own records are not affected: they are on your phone, the app goes on opening them, and you can keep adding to them after you stop paying. What ends is sharing.

To have the account-level record described above erased outright — the name, email or birthdate a share may have put on file, and the billing record tied to your key — write to [email protected] and we'll do it by hand. There's no self-serve delete-account button for that yet, and we'd rather say so than pretend otherwise.

Not for children

HealthKeystone doesn't ask your age and isn't directed at children. It's built for an adult keeping their own record. If you're the one typing in history on behalf of someone who can't — a parent, a caregiver — that's your call to make, the same way it would be with a paper folder.

Changes to this page

When what the app or server actually does changes, this page changes with it — that's the deal the opening line makes. Nothing here is a placeholder for a future rewrite; if it stops matching the code, it's wrong, and you should tell us.

Last updated August 26, 2026.

Questions

Write to [email protected] — the same address handles an access or deletion request. HealthKeystone is built and operated by Noii Consulting LLC.