Last updated: 6 August 2026
Healthidia ("we", "us") provides the Healthidia personal health record platform. We are an early-stage venture and not yet incorporated as a company; the operator of the service acts as the data controller for the personal data described here. Contact: support@healthidia.com. We will update this page with full corporate and, where required, EU/UK representative details on incorporation.
We do not collect payment data — Healthidia does not currently charge for anything — and we run no advertising or analytics trackers.
Your records are visible only to you inside the app. Access is enforced by database row-level security that scopes every row to the account that owns it. There is no clinician, clinic, or administrator console that can browse your records.
We do not sell, rent, or share your personal data with third parties for their own purposes. Data leaves our systems only to the processors listed below, acting on our instructions, or to a recipient you personally choose when exporting or emailing a summary.
Each processor is bound by a data processing agreement and may only act on our instructions.
Automated processing. AI extraction is fully automated: the result you see is generated by artificial intelligence, and no doctor or other healthcare professional reviews your documents, your records, or the AI output. Nothing is saved without your review, and the processing has no legal or similarly significant effect on you — you can always enter data by hand instead. See the AI Medical Disclaimer.
Only for the service. We use your personal information solely to provide, secure, and improve Healthidia — never for advertising, profiling for third parties, or sale.
Healthidia serves users globally and our processors operate infrastructure in multiple regions, including the United States. Where data is transferred out of the EEA or UK, it is covered by the European Commission's Standard Contractual Clauses (and the UK Addendum) together with the technical measures described in our Security Policy.
For as long as your account exists, so your history stays useful over time. Full periods and the deletion process are in the Data Retention Policy.
Wherever you live, we apply these rights to everyone. Under GDPR/UK GDPR you have the right to:
Exercise any right by emailing support@healthidia.com from your registered address. We respond within 30 days and never charge for a first request. We do not carry out automated decision-making that produces legal or similarly significant effects.
Healthidia is a consumer-controlled personal health record. It is not a covered entity or a business associate under HIPAA, we have no HIPAA certification, and we make no compliance claim. Data you enter is your own personal health information, held under your control. If a clinician or organisation ever wants to use Healthidia with patient data, a Business Associate Agreement would be required first — contact us.
Encryption in transit and at rest, hashed passwords, passkey sign-in, row-level access control, private storage buckets, and audit logging. Details and current limitations are in the Security Policy. No system is perfect; keep your original medical documents.
Only essential storage plus optional functional preferences — no advertising or analytics trackers. See the Cookie Policy, and use "Cookie Settings" in the footer to change your choice at any time.
Healthidia is not intended for children under 16 to use independently. A parent or guardian may maintain records on behalf of a child in their care.
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and inform affected users without undue delay.
We may update this policy. Material changes will be announced in the app and take effect on the date shown above.
Privacy questions, data requests, and deletion requests: support@healthidia.com or via our Contact page.