Privacy and data use

Effective September 4, 2026

This single-user trial retrieves health data only after the operator authorizes access through the provider's patient login and consent flow. The resulting record is stored in the operator's encrypted local environment.

What the trial does not do

Retention and control

Source evidence is retained indefinitely until the operator manually deletes the isolated local data. The current trial does not expose a complete automated deletion feature. The operator controls the local machine and can obtain the stored source evidence and the application's access audit. Revoking provider access stops future retrieval but does not erase data already retained.

Temporary callback

A stateless HTTPS redirect in the United States handles only the bounded OAuth code or error and state required to return the browser to the local callback. It cannot exchange the code, holds no provider credential or health-record store, does not enable request-event logging, and is disabled after authorization.