Legal

Privacy Policy

What we collect, why we collect it, where it lives, and what you can ask us to do with it — written to be read, not skimmed past.

Last updated

The short version

TruHealth is a place to keep your own and your family's health records. That means we hold information about your health, which is some of the most sensitive information there is. Here is the summary, in plain words:

  • You put the information in, and it stays yours. We hold it so the app can show it back to you.
  • Only people you choose can see it. Family members you invite, and caregivers you grant access to. You can take that access away.
  • We do not sell it, and we do not advertise against it. We do not use your health information to train AI models.
  • Canadian records are meant to stay in Canada and US records in the United States. The app already records which region an account belongs to; see Where it is stored for what is finished and what is not.
  • You can ask to see it, correct it, or take it back. Section Your rights explains how.

The rest of this page is the detail behind those five points. If anything below contradicts the summary, the detail is what we mean.

Who we are

TruHealth is a personal and family health record. This policy is issued by <LEGAL ENTITY NAME>, registered at <REGISTERED ADDRESS>. In this policy, “we”, “us” and “TruHealth” mean that company.

Our privacy officer — the person accountable for the information we hold and the person who answers your requests — is <PRIVACY OFFICER NAME>, reachable at <PRIVACY OFFICER EMAIL>.

This policy covers the TruHealth marketing site, the TruHealth web app, and the API behind them. It applies to individuals and families using TruHealth directly.

If your clinic or institution gave you TruHealth

Where an organisation such as a clinic uses TruHealth to hold records about you, that organisation decides what is collected and why, and we handle the information on their instructions. Their own privacy notice governs, and requests about your record should go to them first. We will help them answer you.

What we collect

Information you give us to set up an account

  • Your name and email address.
  • A password, which we never store in readable form. Passwords must be at least 12 characters.
  • The region your account belongs to (Canada or the United States), captured when you sign up, because it decides where your records are kept.
  • Your preferred language, so emails and exports reach you in it.
  • A profile picture, if you upload one.

Health information you record

  • Readings you enter into trackers — blood pressure, blood sugar, oxygen, weight, peak flow and the rest — with the date and time they happened.
  • Journal entries, symptoms, notes and allergies you write down.
  • Medications and reminders you set up, including what they are for.
  • Documents and images you upload to the vault, such as lab reports and prescriptions.
  • Details of the people in your record — the family members you track, including children, and their relationship to you.

In Canadian law this is personal health information; in US law it is protected health information. Both mean the same practical thing: it needs more care than ordinary personal data, and we treat it that way.

Information created automatically

  • Sign-in and session records — when you signed in, signed out, and from which session.
  • Audit records — a log of who looked at or changed a health record, and when. This is a safety feature, not a marketing one: it is how we can answer “who saw this?”.
  • Technical logs — request identifiers, error codes, IP address and browser type, kept so we can find and fix faults. We do not write passwords or session tokens into logs.

Messages you send us

If you use the contact form or email us, we keep what you send and our reply so we can follow the conversation. Please do not put health details in a contact form — use the app.

Why we collect it, and your consent

We collect each piece of information for a stated purpose, and we do not use it for something unrelated without asking you first.

  • To run the service — to show you your records, chart them, remind you, and let the people you invited see what you shared.
  • To keep the service safe — to authenticate you, to keep audit records, and to investigate misuse.
  • To support you — to answer your questions and fix faults you report.
  • To meet legal obligations — where a law requires us to keep or produce something.

Under Canadian privacy law (PIPEDA, and provincial health laws such as Ontario's PHIPA, Alberta's HIA and Quebec's Law 25), your consent is what allows us to handle your health information. You give it when you create an account and enter information, and you can withdraw it — see Your rights. Withdrawing consent means we can no longer provide the parts of the service that depend on that information.

We do not use your information to profile you for advertising, and we do not make automated decisions about you that have a legal or similarly significant effect.

Records about other people

Most TruHealth accounts hold records about more than one person — a child, a parent, someone you care for. That raises a question ordinary privacy policies skip: whose information is it, and who is allowed to see it?

  • You need the authority to add someone. You may create and manage a record for another person only if you are their parent or guardian, or they have asked you to. By adding them, you are telling us you have that authority.
  • Access comes from a live relationship, not from who typed it in. The person who created a record is not automatically the person allowed to read it. Access flows from a current guardian or caregiver relationship, or from a consent that has not been withdrawn.
  • Access can end, and when it ends it really ends. If a guardianship or a caregiver arrangement finishes, that person stops being able to see the record from that moment. We keep a record that the relationship existed and when it ended, because an audit has to be able to answer “who could see this last March?”.
  • Young people take over their own record. When a young person takes control of the record kept for them, guardian access ends and the record becomes theirs to manage. Caregiver arrangements and consents carry on until they are ended separately — growing up is not the same event as dismissing a nurse.

If you believe someone holds a TruHealth record about you or your child without the right to, contact <PRIVACY OFFICER EMAIL> and we will investigate.

Where your information is stored

Health records crossing a border is a real concern, so we designed for it rather than adding it later. Every account belongs to a region chosen when it is created — Canada or the United States — and the region is recorded on the account itself, not guessed from your address or your browser.

The intention is straightforward: records belonging to a Canadian account are held in Canada, and records belonging to a US account are held in the United States.

Some suppliers we use to run the service may process limited information outside your region — for example an email delivery service. Where that happens the information is kept to the minimum needed (for example, an email address and a short message with no health details). The suppliers we use are listed at [SUB-PROCESSOR LIST].

Who we share it with

We share your information in four situations, and no others.

  • People you choose. Family members you invite and caregivers you grant access to. You decide who, for which person, and whether they can view or edit. You can revoke it.
  • Suppliers who help us run the service. Hosting, email delivery, file storage and error reporting. They may only use the information to do that job for us, and they are named at [SUB-PROCESSOR LIST].
  • When the law requires it. A court order, a lawful request, or where a law obliges us to disclose. We will tell you unless we are forbidden from doing so.
  • If the business changes hands. In a merger or sale, your information may transfer to the buyer, who would be bound by this policy or one no weaker. You would be told before it happened.

We do not sell your information, rent it, trade it with data brokers, share it with advertisers, or use it to train machine learning models.

Cookies and browser storage

We use very little here, and none of it follows you around.

  • A session cookie in the app, set when you sign in, so the app knows it is still you as you move between pages. Sign out and it stops working.
  • A light or dark theme preference, stored in your own browser. It never reaches us.

As of the date at the top of this page, this marketing site runs no analytics, advertising or third-party tracking scripts. If we ever add measurement, we will update this section first and, where consent is required, ask for it before anything is set.

How long we keep it

Health records are worth keeping — a blood pressure trend is only useful across years — so our default is to keep what you record for as long as your account exists.

  • Records you delete are removed from your view immediately. Because health records are append-only, a correction adds a new entry that supersedes the old one rather than erasing history; this is what makes a record trustworthy over time.
  • If you close your account, we delete or anonymise your records within <DATA RETENTION PERIOD>, except where a law requires us to keep something for longer.
  • Audit records and technical logs are kept for <AUDIT LOG RETENTION PERIOD>, because the point of them is to be able to look back.

Your rights, and how to use them

These rights come from Canadian privacy law and, for US accounts, from HIPAA. You do not need to give a reason for asking, and asking costs nothing.

  • See what we hold. Ask for a copy of your information and a plain explanation of how it has been used and who it has been given to.
  • Correct it. If something is wrong, tell us and we will fix it. Because health records are append-only, a correction is recorded as a correction — the earlier entry stays visible as superseded, which is what a doctor or an auditor needs to see.
  • Withdraw your consent. You can stop us handling your information at any time. We will explain what you lose by doing it, and we will act on the request regardless.
  • Take it with you. Ask for your records in a portable file you can give to a doctor or another service.
  • Close your account and have your records deleted, subject to anything a law requires us to keep.
  • Complain — to us first, and to a regulator if we do not put it right. See Contact and complaints.

How to make a request

Email <PRIVACY OFFICER EMAIL> from the address on your account, say what you want, and we will reply within <RESPONSE TIME>. We may need to confirm it is really you before we hand over health records — that check protects you, not us.

Where the app can already export the data you want, you can do it yourself without asking. Self-service export and access tooling is being expanded; until it is finished, the email route above always works.

How we protect it

The Security page explains this properly, including a plain list of what is running today and what is still ahead of us. In summary: records are separated at the database level so one account cannot reach another's, access is granted through explicit relationships and consents that can be revoked, health records are append-only, and every access is logged.

No system is perfectly safe, and we will not tell you otherwise. We also hold no security certification and claim none — see the Security page for what that means.

If something goes wrong

If your information is lost or exposed in a way that could put you at real risk of harm, we will tell you, and we will tell the regulators the law requires us to tell — in Canada the Office of the Privacy Commissioner, and in the United States the Department of Health and Human Services. We will say what happened, what information was involved, and what we are doing about it.

Our written breach-response procedure is one of the documents being completed before launch.

Changes to this policy

When we change this policy we update the date at the top. If the change matters to you — a new purpose, a new category of sharing — we will tell you in the app or by email before it takes effect, and where the law requires it, we will ask for your consent rather than assume it.

Contact and complaints

Start with us. Email <PRIVACY OFFICER EMAIL>, or write to <LEGAL ENTITY NAME> at <REGISTERED ADDRESS>. We will acknowledge your complaint, look into it, and tell you what we found.

If you are not satisfied with our answer, you can complain to a regulator.

  • In Canada — the Office of the Privacy Commissioner of Canada, at priv.gc.ca. Depending on your province you may also be able to complain to your provincial privacy commissioner — for example in Ontario, Alberta, British Columbia or Quebec.
  • In the United States — the Office for Civil Rights at the Department of Health and Human Services, at hhs.gov/ocr.