Privacy policy
Last updated: July 22, 2026
WholeChart exists to help you organize your own health information. That only works if you can trust us with it, so this policy is written to be read — not skimmed past. The short version: your record belongs to you, we never sell it, we never advertise against it, and you can delete all of it at any time.
What we collect
- Account information: your email address, name, and password (stored as a salted hash — we never see it).
- The health record you build: symptoms, diagnoses, medications, lab values, allergies, physicians, family history, hospitalizations, appointment notes, and any documents, photos, audio recordings, or videos you upload.
- Basic technical logs (such as authentication events) needed to run and secure the service.
We do not collect advertising identifiers, we do not embed third-party ad or analytics trackers in the app, and we do not scrape data from other sources about you. The app does load a web font from Google Fonts, so Google receives that request (your IP address and browser) — no health information is ever included.
How your data is used
- To show your record back to you — timelines, reports, reminders.
- To power AI features you explicitly trigger (structuring your story, transcribing an appointment, extracting document values, generating discussion topics, and the “Connect the dots” discussion). When you press those buttons — or send a message in a discussion — the relevant parts of your record, which for several features means your whole record, are sent to our AI processing provider to produce the result, and the output is stored back in your record. Discussions are saved so you can return to them: both your messages and the replies live in your account until you delete them. We select providers whose terms cover processing on our behalf, and we never send your record to an AI provider except to fulfil a request you made.
- To notify you about your account (confirmation and password-reset emails).
What we never do
- We never sell your data, to anyone, for any reason.
- We never show advertising, and we never share your data with advertisers or data brokers.
- We never share your record with employers, insurers, or family members — sharing happens only when you yourself export and send a report.
Security
Your data is encrypted in transit (TLS) and at rest. Every database row and stored file is protected by row-level security so it is accessible only to your authenticated account. You can enable two-factor authentication in your profile settings, and we recommend it. Uploaded files are served only through short-lived signed links.
Deletion
Profile → “Delete account & data” permanently erases your entire record: every entry, every document and recording, and your login itself. We keep no copy. This is immediate and irreversible.
Legal status of this service
WholeChart is a direct-to-consumer record organizer. It is not a healthcare provider, and using it does not create a clinician–patient relationship, so it is generally not a HIPAA “covered entity.” We nevertheless aim to handle your data with HIPAA-level care, and as a consumer health app we are subject to the FTC Health Breach Notification Rule: if a breach of identifiable health information occurs, we will notify you and the FTC as that rule requires.
Children
WholeChart is for adults. It is not directed at children under 13, and we do not knowingly collect their information. Dedicated profiles for dependents, with appropriate protections, may come in a future version.
Changes and contact
If this policy changes materially, we will tell you in the app before the change takes effect. Questions or requests: contact the operator of this deployment.