Privacy

This page explains what happens to your data when you use Health Record.

How your data is stored

Health Record is operated as a hosted service — your medical records are stored in a database we operate on your behalf, so there's no server for you to set up or maintain. We do not sell your data or share it with advertisers, and we do not access individual records except as needed to operate, maintain, or support the service. If you'd rather keep your data on infrastructure you control directly, Health Record can also be self-hosted — contact us to talk through that option.

How your data is protected

Account passwords, and any password you set on a shared link, are hashed and never stored in plain text. Multi-factor authentication (TOTP, RFC 6238) is available as an optional extra layer on every account. All traffic between your browser and Health Record is encrypted in transit.

Deleting your account

You can permanently delete your account at any time from Settings → Danger Zone. Deletion is immediate and irreversible — every record, measurement, document, and shared link tied to your account is removed, with no retention window or recovery period.

Third-party integrations

If you choose to connect an optional integration (such as Google Fit, Strava, Withings, or Oura), that provider's own privacy policy and terms govern the data it shares with Health Record. OAuth tokens for these integrations are stored securely and are never shared with anyone else.

Shared links

Health Record lets you generate password-protected, expiry-limited shared links to give someone read-only access to selected sections of your record. You control what is shared, with whom, and for how long — links can be revoked at any time.

Cookies

This website uses a single functional cookie to remember your language preference. It does not use analytics, tracking, or advertising cookies of any kind.