Privacy Policy
This is the complete privacy policy. The plain-words version is the same truth told shorter — nothing here contradicts it.
Version 2026-07-21 · Effective 2026-07-21 · What changed
The data controller is [legal entity to be registered before public launch], operating myPacia. Until the entity is registered, the individual operator of myPacia is responsible for your data; this placeholder will be replaced the moment registration completes, and you will be notified of the change.
Account data: email address, name, password (stored only as a bcrypt hash), optional avatar, and — if you sign in with Google — the identifiers Google shares for sign-in. Profile data: settings such as timezone, tracked categories, notification preferences, and the conditions you select. Health data you enter (special-category data): symptoms, vitals, medications and doses, appointments, uploaded documents, expenses, notes, flares, cycle tracking, mood, sleep, and the other categories you choose to log — plus the emergency card you optionally maintain. Technical data: sign-in events (which method, when — no IP address), operational error logs, and the consent ledger described in section 8.
To provide the service (contract): storing your entries, rendering your record, computing your own summaries, correlations and insights, sending the reminders you configure. Health data specifically is processed on the basis of your explicit consent, asked separately at signup — never bundled into terms acceptance. Security and accountability (legitimate interest): sign-in records, error monitoring, and the consent ledger. We do not use your data for advertising, we do not sell it, and we do not train machine-learning models on it. If we ever want to process your data for a genuinely new purpose, we will ask for fresh consent for that purpose first.
myPacia runs on a small set of infrastructure providers acting on our instructions: Cloudflare R2 stores uploaded files (documents, avatars, attachments; encrypted at rest by the provider); an email delivery provider sends transactional email (verification, invitations, account notices); Google is involved only if you choose Google sign-in; Open-Meteo receives the approximate coordinates of the city you saved — and nothing that identifies you — when weather tracking is enabled; Sentry (error tracking) and a Discord-based operations relay receive technical error events, not your health records, and Sentry is disabled unless explicitly turned on for an environment. Payment processing (Stripe) is integrated in code but inactive during the beta — no payment data exists today; this section will be updated with notice before payments launch.
You, and the caregivers you invite — scoped to the areas you grant and revocable at any time. Emergency-card share links exist only when you create them and can be password-protected and revoked. Our administrators can see account-level data (email, plan, status) to run the service; support staff look at your record only in a support conversation you started. Every administrative write action is recorded in an audit log.
Your record lives as long as your account. Deleting your account starts a 30-day grace window (sign back in to cancel); after it, your data is removed from our systems, including files in storage. Expired session tokens are pruned automatically. Consent-ledger rows are retained as proof that consent existed — after account deletion they are de-identified (the link to you is removed). Operational error logs rotate on the providers’ standard schedules.
Connections are encrypted in transit (HTTPS). Passwords are stored only as bcrypt hashes. Sessions use short-lived access tokens with rotating single-use refresh tokens; replaying a stolen refresh token revokes the whole session family. Uploaded files are encrypted at rest by our storage provider. As the plain-words page also says: we will not claim more than we do — full database encryption at rest depends on our hosting configuration and this policy will state it plainly once verified. No system is breach-proof; if a breach affects your data, we will notify you and the competent authorities as the law requires.
When you accept the Terms, acknowledge this policy, or give health-data consent, we record which document version, when, from which flow, and the IP address the acceptance came from. This ledger exists to prove consent was given (and honored when withdrawn) — it is the one place we deliberately store an IP address.
myPacia uses only functional storage: an HTTP-only cookie carrying your refresh token, and browser local storage for your session and UI preferences. There are no advertising cookies, no third-party analytics cookies, and no tracking pixels — which is why there is no cookie banner: there is nothing to opt out of.
You can see everything in the app, correct any entry, export your record (CSV and PDF, Settings → Export), delete your account (Settings — no email required), and withdraw health-data consent (Settings → Privacy; withdrawing stops processing, which closes the account through the same deletion path, grace window included). Depending on where you live you may also have the right to complain to a data-protection authority. Requests the app cannot serve directly: contact us via support and we will answer without undue delay.
This is the consent asked at signup (and again if it ever needs to be renewed). It is deliberately separate from agreeing to the Terms.
I consent to myPacia processing the health data I choose to enter — such as symptoms, medications, appointments, documents and related entries — for the sole purpose of providing the service to me: storing my record, showing it back to me, computing my own summaries and insights, and sharing it only with caregivers I invite. I can withdraw this consent at any time in Settings, which stops the processing and closes my account.
Withdrawal is as easy as giving it: Settings → Privacy → Withdraw health-data consent.
myPacia is for adults: you must be 18 or older to create an account, and you confirm this at signup. We do not knowingly process children’s data; accounts found to belong to minors are closed and deleted.
When this policy changes, we update the version and date at the top, describe the change in the changelog below, and notify you in the app. A change that introduces a new purpose for processing your data will never take effect silently — it requires your fresh consent first.