Privacy Policy
Last updated: September 28, 2026
1. Introduction
HealthSpoke™ is a consumer and family health platform designed to help users track vitals, organize prescriptions, log wellness activity, securely store insurance cards, and navigate healthcare costs. HealthSpoke is published and operated by Sanora AI, Inc. ("Sanora AI", "we", "us"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information, as well as your choices and rights.
2. Information We Collect & How It Is Handled
2.1 Account & Identity Data
- Account credentials (email address, hashed password, and local biometric tokens stored securely in your device's Keychain/Keystore).
- Profile preferences (name, age attestation, unit preferences).
- Family profile details created by the account owner to track dependents in the Family Care Circle.
2.2 Health, Vitals & Activity Logs
When you log health metrics or connect wearable devices, HealthSpoke collects:
- Biometrics and vitals (blood pressure, heart rate, blood glucose, weight, sleep metrics).
- Nutrition and meal logs.
- Medication schedules, dosages, refill reminders, and personal symptom notes.
- Extracted label text from prescription bottles and medical bills scanned with your phone camera. Camera OCR reads text on your phone; the extracted text is sent to our servers to structure your records.
2.3 Digital Insurance Cards & Local Storage
Photos of physical insurance cards captured in the app are stored locally in your device's sandboxed application directory and are protected by a biometric Face ID / Touch ID / Passcode prompt. Raw card photos are not uploaded to Sanora AI servers. Extracted metadata (such as Member ID, Group Number, RxBIN, RxPCN, RxGRP, and Copay tiers) is synchronized to your encrypted account profile to enable benefits matching. Please note: standard OS-level device backups (such as Apple iCloud Backup or Google Cloud Backup) may include local application files unless you exclude them in your device settings.
2.4 Wearable Integrations (Apple Health, Health Connect, Strava, Oura)
If you explicitly connect Apple Health, Google Health Connect, Strava, or Oura, we access only the data categories you authorize (such as daily steps, resting heart rate, and sleep duration). Data synced from health platforms is encrypted at rest and is never used for advertising or sold to third parties.
3. How We Use Your Information
We use your information strictly to provide and maintain the Service:
- To log and visualize your vitals, habits, and medication schedules.
- To generate AI-assisted health briefings, nutrition plans, and appointment preparation notes when you ask questions in the app.
- To estimate out-of-pocket healthcare costs and track annual deductible pacing from your entered expenses.
- To enable provider searches against the public CMS NPPES national registry.
- To transmit operational communications, security OTPs, and user-configured medication reminders.
4. Third-Party Service Providers & AI Processing
We work with trusted third-party infrastructure providers to deliver the Service. These providers process information on our behalf:
- Cloud Infrastructure: UpCloud provides secure US-based cloud hosting and PostgreSQL/Redis database infrastructure.
- Payment Processing: Stripe, Inc. securely handles payment transactions, subscription billing, and Stripe Connect practitioner payouts. Sanora AI never stores raw credit card or banking numbers.
- Transactional Email: Resend, Inc. delivers transactional emails, including password reset OTPs, deletion receipts, account notices, and optional scheduled reminder digests.
- SMS Notifications: Twilio, Inc. delivers verification SMS codes and urgent account alerts.
- Push Notifications: Expo (Expo Application Services) dispatches mobile push notifications for user-scheduled reminders and health insights. Reminders use standard schedule payloads.
- Community Integrations: Discord, Inc. hosts optional external group community channels for practitioners and clients who choose to join external Discord servers. Content on Discord is governed by Discord's terms and privacy policy.
- AI Analysis Sub-Processors: When you submit questions in "Ask Sanora" or request AI health summaries, relevant query text and contextual health snippets (without direct identifiers like your name or email) are processed via commercial developer APIs provided by Groq, Cerebras, Mistral, Google Gemini, and Anthropic (Claude). Under standard commercial developer API terms, these providers do not use customer API inputs to train default foundation models, and may temporarily retain API logs (typically up to 30 days) solely for security, abuse detection, and operational debugging before deletion.
5. Data Security & Encryption
In Transit: All communications between the mobile app, website, backend servers, and API providers are encrypted using Transport Layer Security (TLS 1.2 / TLS 1.3).
At Rest: Sensitive health fields (such as chronic conditions, medication notes, and family profile records) are stored using server-side field-level cryptography (**AES-256-GCM Authenticated Encryption**). Email lookups are performed using cryptographic HMAC-SHA256 hashes.
FTC Breach Notification Rule: In the event of an unauthorized acquisition of unsecured consumer health data, Sanora AI will notify affected users and regulatory authorities in compliance with the FTC Health Breach Notification Rule.
6. Zero Advertising & No Data Brokering
HealthSpoke is 100% ad-free. We do not host third-party advertisements, do not use ad-tracking SDKs, and do not sell, rent, or trade your personal health data to data brokers or advertising networks.
7. Age Requirements & Children's Privacy
Primary account holders must be at least 18 years of age. We do not offer standalone accounts to minors under 18 or children under 13.
Parents and legal guardians may create and manage dependent profiles for their minor children strictly within the household Family Care Circle feature under the adult's account authority.
8. Your Rights & State Privacy Disclosures (MHMDA & CCPA)
Under applicable state health privacy laws, including the Washington My Health My Data Act (MHMDA) and the California Consumer Privacy Act (CCPA/CPRA), you have the following rights:
- Right to Access & Confirm: You may confirm whether we process your health data and review the information stored in your account.
- Right to Export: You can download a complete, portable copy of your health and care logs in standard JSON format at any time directly in the App.
- Right to Delete: You can permanently delete your account and all associated server-side health data under Profile → Account → Delete Account.
- Right to Revoke Permissions: You may disconnect wearable integrations or notification permissions at any time.
- No Geofencing: Sanora AI does not geofence or track physical locations around healthcare facilities.
9. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
privacy@sanoraai.com · support@sanoraai.com
Sanora AI, Inc.