We do not sell your health data
Not to advertisers, not to insurers, not to data brokers, not in aggregate, not ever. Our revenue comes from services people choose to pay for.
Plain-English answers to the questions that actually matter: what we collect, who can see it, how long we keep it, and how to get rid of it. No legal fog.
These aren’t aspirations. They’re the constraints our engineering works within.
Not to advertisers, not to insurers, not to data brokers, not in aggregate, not ever. Our revenue comes from services people choose to pay for.
If a feature works without a piece of data, we don’t ask for it. Location is used to find pharmacies and is not stored as a history.
TLS 1.2+ on every connection, AES-256 on every stored record, with strict internal access controls and full audit logging.
Export, correct or delete everything we hold, from the app or by email, without having to explain why you want to.
Every share is deliberate, scoped and time-limited. You choose which items go out, who receives them and when access ends — and you can see exactly who opened what.
What you type or say is processed to generate guidance for you, in that session. That is its primary and default use.
Your health conversations are not used to train models unless you explicitly turn that on in settings. It is off by default.
A small number of conversations may be reviewed for safety. Where that happens, content is de-identified and access is logged.
Records are kept while your account is active and deleted on request. Backups roll off within 90 days.
Consumer health apps are usually not HIPAA-covered. Here is exactly where the line sits for us.
To records created during a consultation with a licensed clinician. The clinician is the covered entity; we act as their business associate under a signed Business Associate Agreement, and those records follow the Notice of Privacy Practices.
To AI conversations, symptom checks, wallet items you upload yourself and wearable data. We protect those under our Privacy Policy, state health-privacy laws such as Washington’s My Health My Data Act, and the FTC Health Breach Notification Rule — to the same standard.
Get a machine-readable copy of everything associated with your account, usually within 30 days and often much sooner.
Fix anything inaccurate in your profile or records directly in the app, or ask us to do it.
Delete your account and associated data. We confirm when it’s done and tell you what, if anything, we’re legally required to retain.
Withdraw consent for optional processing at any time without losing access to core features.
Write to our privacy team directly. A person reads it, and you’ll get a real answer rather than a link back to the policy.
privacy@onlinecareai.com · Acknowledged within 72 hours