Development policy draft — requires review and completion before public launch.
The local demo stores only fictional family data and test records in your browser. Medical form entries are not saved in demo storage. A connected deployment stores account, family, contact, subscription, emergency, and optional profile information.
Live medical profiles use application encryption and audited server access. Location access follows explicit permissions. Evidence capture is not enabled. Production encryption keys and storage policies are the deployment operator’s responsibility.
Configured authentication, billing, push, and monitoring providers process only the information necessary for their task. Final provider names, contracts, subprocessors, and geographic processing locations must be documented before launch.
Location retention is configurable and a database cleanup function is provided. A production scheduler must run it. Request account deletion or data export through authenticated support. The final policy must state legal retention exceptions and response timelines.
The legal entity, privacy contact, jurisdiction, effective date, children’s privacy procedures, and international transfer terms must be completed before accepting production users.