Privacy Policy
Last updated: July 2025
1. Our Commitment
Deeply Health (“Deeply,” “we,” “us”) is committed to protecting your privacy. We built this platform because we know what it's like to live with a rare chronic condition - and we know that trust is everything when it comes to health data.
Your medical condition, treatment history, and personal health information are yours. We encrypt sensitive health data at the application level, meaning even we can't read it without your explicit consent. We never sell your data. We never share your condition status with third parties without your permission.
2. Information We Collect
To provide our services, we collect:
- Account information: name, email address, authentication method, and profile details you choose to share.
- Health information: condition type, treatment logs, bleed logs, symptom tracking, and health journal entries. This data is encrypted at the application level.
- Community content: forum posts, comments, reactions, and direct messages within the platform.
- Usage data: anonymized analytics about how you use the platform to help us improve.
- Location data: only if you opt in to the global community map feature. Approximate, not precise.
3. Medical ID & PHI Encryption
Your Medical ID (name, date of birth, emergency contact, blood type, diagnosis, medications) is considered Protected Health Information (PHI). This data is encrypted at the application layer using AES-256-GCM before storage. Decryption keys are managed separately from the data store.
Health tracking data (bleed logs, treatment journals, symptom records) is encrypted with the same standard. You control who can access this information through granular sharing settings.
4. How We Share Data
We do not sell your personal information. We share data only:
- With your consent: when you choose to share your profile or health information with other community members.
- With service providers: trusted third parties who help us operate the platform (hosting, email delivery, analytics). They are bound by data processing agreements.
- For legal compliance: if required by law, subpoena, or to protect the safety of our users.
- In aggregate: anonymized, de-identified data for research purposes (e.g., “X% of hemophilia patients report joint pain as their primary symptom”).
5. Data Retention & Deletion
You can delete your account at any time. Upon deletion, we soft-delete your data for 30 days (allowing account recovery), then permanently purge it. Forum posts are anonymized rather than deleted to preserve community conversation continuity.
You can request a full export of your data at any time through your account settings. We provide exports in machine-readable format within 30 days of request.
6. Security
We implement industry-standard security measures including:
- AES-256-GCM encryption for PHI at the application layer
- TLS 1.3 for all data in transit
- JWT RS256/HS256 authentication with 15-minute access tokens
- Rotating refresh tokens with family rotation
- Account lockout after 5 failed login attempts
- Strict Content-Security-Policy headers
- HIPAA-compliant infrastructure and BAAs with providers
7. Your Rights
Depending on your jurisdiction, you may have rights under GDPR, CCPA, HIPAA, or other privacy regulations. You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your data in a portable format
- Withdraw consent for data processing
- Lodge a complaint with your local data protection authority
8. Contact Us
For privacy-related questions or to exercise your data rights, contact us at pk@deeplyhealth.org.