Your health story is private. We designed Sanare so you can see everything we hold, remove any of it, and delete all of it. We do not sell your personal information, and we do not use your health information to target advertising.
Information we collect
Account information — your name and email, your password if you create one (stored only as a secure hash), and an optional profile photo. If you sign in with Google or Microsoft, we receive your name and email from that provider and never see your provider password.
Health information you provide — what you tell us in conversation (typed or spoken), health forms, records you upload or scan with your camera, records you email to our records address (held for your review before anything is added), files you choose to import from Google Drive (only the files you pick, transferred directly in your browser), records you import from your patient portal (you sign in to your own portal; access is one-time and we never store your portal password or access token), and (if you add them) insurance details. This is the information used to build your story and summary.
Voice — if you dictate, your audio is transcribed to text by our cloud speech service; if you use the voice-conversation mode, your speech is processed in real time by the AI speech service in our cloud environment so it can reply out loud. In both cases we keep the text transcript as part of your conversation — we do not keep the audio.
Optional check-ins — if you answer the brief "did your visit give you direction?" question, we store your answer choice and, if you add one, a short optional note. Neither is ever joined to your health story or shared summary.
Technical information — basic logs needed to operate and secure the service (e.g., request identifiers, error diagnostics), and count-only usage events (for example, that a summary was viewed or a record was uploaded) that contain no health content.
Emails and notifications
We send transactional email (verification, password reset, records-received confirmations) and occasional reminder emails about your own story; reminders are count-based and never include your health details, and you can opt out any time from the email or your account page. If you enable push notifications, they may tell you that something happened ("your story was viewed", "records received") or offer a gentle check-in — they never include your health information.
How we use it
To provide the service to you — organizing your story, generating your summary, and the features you enable.
To secure the service and prevent abuse.
We do not sell your information or use your health data for advertising.
Where your data is processed
Your information is processed on Microsoft Azure, within our cloud environment. The AI processing that helps organize your story runs on Azure OpenAI under our agreements with Microsoft, and on Anthropic's Claude API under our agreement with Anthropic in a HIPAA-oriented configuration. Your health information is never sent to consumer AI apps, and none of these providers may use your information to train their models. A limited number of vetted service providers (for example, transactional email) process data only as needed to operate the service and under confidentiality obligations.
How long we keep it
We keep your information while your account is active. When you remove a source or delete your story or account, we delete the associated data (and everything derived from it), subject to limited retention required by law or for security.
Your choices and rights
See it — your data vault lists every source that fed your story.
Remove it — remove any source, or delete your entire story, at any time.
Export it — download a copy of your data.
Delete your account — this erases your health data and anonymizes your identity.
Depending on where you live, you may have additional rights (for example, under GDPR or state privacy laws). Contact us to exercise them.
Security
We use encryption in transit and at rest, hashed session tokens, access controls, rate limiting, a web application firewall, and monitoring. Password accounts can enable optional two-step verification by email code. No system is perfectly secure, but protecting your health information is a core design goal.