Privacy
Health records are personal. Here is what myPacia stores, what it never does, and the controls you hold — written to be read, not skimmed past.
Your account details, and the entries you choose to make — symptoms, medications, appointments, documents, expenses, notes, and the other things you track. That is the record; it exists so that you can see it, and nothing in it is created without you.
Your data is never sold — not to advertisers, not to data brokers, not to anyone. There are no ads in the product, and no third party buys access to your entries. This is not a feature we may revisit; it is the ground the product is built on.
You, and only the people you invite. Caregiver access is invite-only, limited to the areas you choose, and revocable at any time. Emergency-card links exist only when you create them, and can be protected with a password and revoked. We do not look at your record except when you ask us to (for example, in a support conversation you start).
Your connection to myPacia is encrypted in transit (HTTPS). Passwords are never stored as text — only as bcrypt hashes. Sessions use short-lived tokens with rotating, single-use refresh tokens, and a stolen-token replay revokes the whole session family. We will not claim more than we do: database encryption at rest is not in place today, and this page will say so until it is.
You can export your record whenever you want. You can delete your account yourself — deletion removes your data from our systems after a short grace window in case you change your mind. Both controls live in Settings; neither requires contacting anyone.
myPacia is a personal health organizer, not a medical device and not a diagnostic tool. Insights describe patterns in your own entries — they are starting points for conversations with your clinicians, never medical advice.
This page is the plain-words version, kept accurate against the product as built. The complete formal version lives at /privacy-policy — nothing in it contradicts what you read here.