Privacy & security

Health data is the most personal data there is. We treat it that way.

Plain-English answers to the questions that actually matter: what we collect, who can see it, how long we keep it, and how to get rid of it. No legal fog.

Your controls
Export everything we holdAny time
Delete your account and dataAny time
Choose what syncs, per metricGranular
Sharing links expireYou set it
Sell your health dataNever
Principles

Four commitments, stated plainly

These aren’t aspirations. They’re the constraints our engineering works within.

We do not sell your health data

Not to advertisers, not to insurers, not to data brokers, not in aggregate, not ever. Our revenue comes from services people choose to pay for.

We collect as little as possible

If a feature works without a piece of data, we don’t ask for it. Location is used to find pharmacies and is not stored as a history.

Encrypted in transit and at rest

TLS 1.2+ on every connection, AES-256 on every stored record, with strict internal access controls and full audit logging.

You are in control

Export, correct or delete everything we hold, from the app or by email, without having to explain why you want to.

Sharing controls
Dr. Rivera · medications onlyExpires 24h
Pharmacy · one OTC sheetExpires 1h
Revoke any linkInstant
Full access logVisible to you
Sharing

Nothing leaves your account by accident

Every share is deliberate, scoped and time-limited. You choose which items go out, who receives them and when access ends — and you can see exactly who opened what.

  • Item-level sharing rather than all-or-nothing access to your record.
  • Every link carries an expiry, and you can revoke it before that.
  • A visible access log showing who opened which item, and when.
  • Clinicians in a consultation only receive what you approve beforehand.
How AI uses your information

The part most policies bury

Your conversation powers your answer

What you type or say is processed to generate guidance for you, in that session. That is its primary and default use.

Training is opt-in, not opt-out

Your health conversations are not used to train models unless you explicitly turn that on in settings. It is off by default.

Human review is limited and logged

A small number of conversations may be reviewed for safety. Where that happens, content is de-identified and access is logged.

Retention has a limit

Records are kept while your account is active and deleted on request. Backups roll off within 90 days.

Where HIPAA does and doesn’t apply

An honest answer to a question most apps dodge

Consumer health apps are usually not HIPAA-covered. Here is exactly where the line sits for us.

HIPAA applies

To records created during a consultation with a licensed clinician. The clinician is the covered entity; we act as their business associate under a signed Business Associate Agreement, and those records follow the Notice of Privacy Practices.

HIPAA generally does not apply

To AI conversations, symptom checks, wallet items you upload yourself and wearable data. We protect those under our Privacy Policy, state health-privacy laws such as Washington’s My Health My Data Act, and the FTC Health Breach Notification Rule — to the same standard.

Your rights

What you can ask for, and how long it takes

Access & export

Get a machine-readable copy of everything associated with your account, usually within 30 days and often much sooner.

Correction

Fix anything inaccurate in your profile or records directly in the app, or ask us to do it.

Deletion

Delete your account and associated data. We confirm when it’s done and tell you what, if anything, we’re legally required to retain.

Object & restrict

Withdraw consent for optional processing at any time without losing access to core features.

Found a security issue? Email security@onlinecareai.com with the details. We investigate every report, respond directly to the reporter, and never pursue legal action against good-faith security research.

Questions we haven’t answered here?

Write to our privacy team directly. A person reads it, and you’ll get a real answer rather than a link back to the policy.

Read the full privacy policy

privacy@onlinecareai.com · Acknowledged within 72 hours