Privacy Policy
What we collect, why we collect it, where it lives, and what you can ask us to do with it — written to be read, not skimmed past.
Last updated
Draft — this privacy policy has not been reviewed by a lawyer
We are publishing it early so you can see exactly how we intend to handle your information, and so our legal advisers can mark it up. Please do not rely on it as a final legal document yet.
Anything highlighted like [THIS] is a detail a human still has to fill in before launch.
The short version
TruHealth is a place to keep your own and your family's health records. That means we hold information about your health, which is some of the most sensitive information there is. Here is the summary, in plain words:
- You put the information in, and it stays yours. We hold it so the app can show it back to you.
- Only people you choose can see it. Family members you invite, and caregivers you grant access to. You can take that access away.
- We do not sell it, and we do not advertise against it. We do not use your health information to train AI models.
- Canadian records are meant to stay in Canada and US records in the United States. The app already records which region an account belongs to; see Where it is stored for what is finished and what is not.
- You can ask to see it, correct it, or take it back. Section Your rights explains how.
The rest of this page is the detail behind those five points. If anything below contradicts the summary, the detail is what we mean.
Who we are
TruHealth is a personal and family health record. This policy is issued by <LEGAL ENTITY NAME>, registered at <REGISTERED ADDRESS>. In this policy, “we”, “us” and “TruHealth” mean that company.
Our privacy officer — the person accountable for the information we hold and the person who answers your requests — is <PRIVACY OFFICER NAME>, reachable at <PRIVACY OFFICER EMAIL>.
This policy covers the TruHealth marketing site, the TruHealth web app, and the API behind them. It applies to individuals and families using TruHealth directly.
If your clinic or institution gave you TruHealth
Where an organisation such as a clinic uses TruHealth to hold records about you, that organisation decides what is collected and why, and we handle the information on their instructions. Their own privacy notice governs, and requests about your record should go to them first. We will help them answer you.
What we collect
Information you give us to set up an account
- Your name and email address.
- A password, which we never store in readable form. Passwords must be at least 12 characters.
- The region your account belongs to (Canada or the United States), captured when you sign up, because it decides where your records are kept.
- Your preferred language, so emails and exports reach you in it.
- A profile picture, if you upload one.
Health information you record
- Readings you enter into trackers — blood pressure, blood sugar, oxygen, weight, peak flow and the rest — with the date and time they happened.
- Journal entries, symptoms, notes and allergies you write down.
- Medications and reminders you set up, including what they are for.
- Documents and images you upload to the vault, such as lab reports and prescriptions.
- Details of the people in your record — the family members you track, including children, and their relationship to you.
In Canadian law this is personal health information; in US law it is protected health information. Both mean the same practical thing: it needs more care than ordinary personal data, and we treat it that way.
Information created automatically
- Sign-in and session records — when you signed in, signed out, and from which session.
- Audit records — a log of who looked at or changed a health record, and when. This is a safety feature, not a marketing one: it is how we can answer “who saw this?”.
- Technical logs — request identifiers, error codes, IP address and browser type, kept so we can find and fix faults. We do not write passwords or session tokens into logs.
Messages you send us
If you use the contact form or email us, we keep what you send and our reply so we can follow the conversation. Please do not put health details in a contact form — use the app.
Why we collect it, and your consent
We collect each piece of information for a stated purpose, and we do not use it for something unrelated without asking you first.
- To run the service — to show you your records, chart them, remind you, and let the people you invited see what you shared.
- To keep the service safe — to authenticate you, to keep audit records, and to investigate misuse.
- To support you — to answer your questions and fix faults you report.
- To meet legal obligations — where a law requires us to keep or produce something.
Under Canadian privacy law (PIPEDA, and provincial health laws such as Ontario's PHIPA, Alberta's HIA and Quebec's Law 25), your consent is what allows us to handle your health information. You give it when you create an account and enter information, and you can withdraw it — see Your rights. Withdrawing consent means we can no longer provide the parts of the service that depend on that information.
We do not use your information to profile you for advertising, and we do not make automated decisions about you that have a legal or similarly significant effect.
TruHealth is not a medical service
TruHealth records what you measure and shows you the patterns in it. It does not diagnose, treat, or give medical advice, and correlations it shows you do not prove that one thing caused another. Talk to your doctor about decisions. The Terms of Service say more about this.
Records about other people
Most TruHealth accounts hold records about more than one person — a child, a parent, someone you care for. That raises a question ordinary privacy policies skip: whose information is it, and who is allowed to see it?
- You need the authority to add someone. You may create and manage a record for another person only if you are their parent or guardian, or they have asked you to. By adding them, you are telling us you have that authority.
- Access comes from a live relationship, not from who typed it in. The person who created a record is not automatically the person allowed to read it. Access flows from a current guardian or caregiver relationship, or from a consent that has not been withdrawn.
- Access can end, and when it ends it really ends. If a guardianship or a caregiver arrangement finishes, that person stops being able to see the record from that moment. We keep a record that the relationship existed and when it ended, because an audit has to be able to answer “who could see this last March?”.
- Young people take over their own record. When a young person takes control of the record kept for them, guardian access ends and the record becomes theirs to manage. Caregiver arrangements and consents carry on until they are ended separately — growing up is not the same event as dismissing a nurse.
If you believe someone holds a TruHealth record about you or your child without the right to, contact <PRIVACY OFFICER EMAIL> and we will investigate.
Where your information is stored
Health records crossing a border is a real concern, so we designed for it rather than adding it later. Every account belongs to a region chosen when it is created — Canada or the United States — and the region is recorded on the account itself, not guessed from your address or your browser.
The intention is straightforward: records belonging to a Canadian account are held in Canada, and records belonging to a US account are held in the United States.
What is finished, and what is not
The region rule is built into the software today: every account carries its region, and the work that processes records is tied to the same region.
The hosting arrangements that place those regions in specific Canadian and US data centres — <HOSTING PROVIDER> and the agreements that go with it — are being completed before we open the service to the public. Until this page says otherwise, treat that part as planned, not done.
Some suppliers we use to run the service may process limited information outside your region — for example an email delivery service. Where that happens the information is kept to the minimum needed (for example, an email address and a short message with no health details). The suppliers we use are listed at [SUB-PROCESSOR LIST].
How long we keep it
Health records are worth keeping — a blood pressure trend is only useful across years — so our default is to keep what you record for as long as your account exists.
- Records you delete are removed from your view immediately. Because health records are append-only, a correction adds a new entry that supersedes the old one rather than erasing history; this is what makes a record trustworthy over time.
- If you close your account, we delete or anonymise your records within <DATA RETENTION PERIOD>, except where a law requires us to keep something for longer.
- Audit records and technical logs are kept for <AUDIT LOG RETENTION PERIOD>, because the point of them is to be able to look back.
Still being written
Our full written retention schedule — exactly how long each kind of record is kept, and how deletion is carried out in backups — is one of the documents being completed before launch. The placeholders above are where those periods will go.
Your rights, and how to use them
These rights come from Canadian privacy law and, for US accounts, from HIPAA. You do not need to give a reason for asking, and asking costs nothing.
- See what we hold. Ask for a copy of your information and a plain explanation of how it has been used and who it has been given to.
- Correct it. If something is wrong, tell us and we will fix it. Because health records are append-only, a correction is recorded as a correction — the earlier entry stays visible as superseded, which is what a doctor or an auditor needs to see.
- Withdraw your consent. You can stop us handling your information at any time. We will explain what you lose by doing it, and we will act on the request regardless.
- Take it with you. Ask for your records in a portable file you can give to a doctor or another service.
- Close your account and have your records deleted, subject to anything a law requires us to keep.
- Complain — to us first, and to a regulator if we do not put it right. See Contact and complaints.
How to make a request
Email <PRIVACY OFFICER EMAIL> from the address on your account, say what you want, and we will reply within <RESPONSE TIME>. We may need to confirm it is really you before we hand over health records — that check protects you, not us.
Where the app can already export the data you want, you can do it yourself without asking. Self-service export and access tooling is being expanded; until it is finished, the email route above always works.
How we protect it
The Security page explains this properly, including a plain list of what is running today and what is still ahead of us. In summary: records are separated at the database level so one account cannot reach another's, access is granted through explicit relationships and consents that can be revoked, health records are append-only, and every access is logged.
No system is perfectly safe, and we will not tell you otherwise. We also hold no security certification and claim none — see the Security page for what that means.
If something goes wrong
If your information is lost or exposed in a way that could put you at real risk of harm, we will tell you, and we will tell the regulators the law requires us to tell — in Canada the Office of the Privacy Commissioner, and in the United States the Department of Health and Human Services. We will say what happened, what information was involved, and what we are doing about it.
Our written breach-response procedure is one of the documents being completed before launch.
Changes to this policy
When we change this policy we update the date at the top. If the change matters to you — a new purpose, a new category of sharing — we will tell you in the app or by email before it takes effect, and where the law requires it, we will ask for your consent rather than assume it.
Contact and complaints
Start with us. Email <PRIVACY OFFICER EMAIL>, or write to <LEGAL ENTITY NAME> at <REGISTERED ADDRESS>. We will acknowledge your complaint, look into it, and tell you what we found.
If you are not satisfied with our answer, you can complain to a regulator.
- In Canada — the Office of the Privacy Commissioner of Canada, at priv.gc.ca. Depending on your province you may also be able to complain to your provincial privacy commissioner — for example in Ontario, Alberta, British Columbia or Quebec.
- In the United States — the Office for Civil Rights at the Department of Health and Human Services, at hhs.gov/ocr.
Related pages