Privacy Policy

The formal version.

This is the complete privacy policy. The plain-words version is the same truth told shorter — nothing here contradicts it.

Version 2026-07-21 · Effective 2026-07-21 · What changed

1.Who is responsible

The data controller is [legal entity to be registered before public launch], operating myPacia. Until the entity is registered, the individual operator of myPacia is responsible for your data; this placeholder will be replaced the moment registration completes, and you will be notified of the change.

2.What we collect

Account data: email address, name, password (stored only as a bcrypt hash), optional avatar, and — if you sign in with Google — the identifiers Google shares for sign-in. Profile data: settings such as timezone, tracked categories, notification preferences, and the conditions you select. Health data you enter (special-category data): symptoms, vitals, medications and doses, appointments, uploaded documents, expenses, notes, flares, cycle tracking, mood, sleep, and the other categories you choose to log — plus the emergency card you optionally maintain. Technical data: sign-in events (which method, when — no IP address), operational error logs, and the consent ledger described in section 8.

3.Why we process it, and on what basis

To provide the service (contract): storing your entries, rendering your record, computing your own summaries, correlations and insights, sending the reminders you configure. Health data specifically is processed on the basis of your explicit consent, asked separately at signup — never bundled into terms acceptance. Security and accountability (legitimate interest): sign-in records, error monitoring, and the consent ledger. We do not use your data for advertising, we do not sell it, and we do not train machine-learning models on it. If we ever want to process your data for a genuinely new purpose, we will ask for fresh consent for that purpose first.

4.Who else touches data (processors)

myPacia runs on a small set of infrastructure providers acting on our instructions: Cloudflare R2 stores uploaded files (documents, avatars, attachments; encrypted at rest by the provider); an email delivery provider sends transactional email (verification, invitations, account notices); Google is involved only if you choose Google sign-in; Open-Meteo receives the approximate coordinates of the city you saved — and nothing that identifies you — when weather tracking is enabled; Sentry (error tracking) and a Discord-based operations relay receive technical error events, not your health records, and Sentry is disabled unless explicitly turned on for an environment. Payment processing (Stripe) is integrated in code but inactive during the beta — no payment data exists today; this section will be updated with notice before payments launch.

5.Who can see your record

You, and the caregivers you invite — scoped to the areas you grant and revocable at any time. Emergency-card share links exist only when you create them and can be password-protected and revoked. Our administrators can see account-level data (email, plan, status) to run the service; support staff look at your record only in a support conversation you started. Every administrative write action is recorded in an audit log.

6.How long we keep things

Your record lives as long as your account. Deleting your account starts a 30-day grace window (sign back in to cancel); after it, your data is removed from our systems, including files in storage. Expired session tokens are pruned automatically. Consent-ledger rows are retained as proof that consent existed — after account deletion they are de-identified (the link to you is removed). Operational error logs rotate on the providers’ standard schedules.

7.Security, honestly stated

Connections are encrypted in transit (HTTPS). Passwords are stored only as bcrypt hashes. Sessions use short-lived access tokens with rotating single-use refresh tokens; replaying a stolen refresh token revokes the whole session family. Uploaded files are encrypted at rest by our storage provider. As the plain-words page also says: we will not claim more than we do — full database encryption at rest depends on our hosting configuration and this policy will state it plainly once verified. No system is breach-proof; if a breach affects your data, we will notify you and the competent authorities as the law requires.

8.The consent ledger

When you accept the Terms, acknowledge this policy, or give health-data consent, we record which document version, when, from which flow, and the IP address the acceptance came from. This ledger exists to prove consent was given (and honored when withdrawn) — it is the one place we deliberately store an IP address.

9.Cookies and local storage

myPacia uses only functional storage: an HTTP-only cookie carrying your refresh token, and browser local storage for your session and UI preferences. There are no advertising cookies, no third-party analytics cookies, and no tracking pixels — which is why there is no cookie banner: there is nothing to opt out of.

10.Your rights

You can see everything in the app, correct any entry, export your record (CSV and PDF, Settings → Export), delete your account (Settings — no email required), and withdraw health-data consent (Settings → Privacy; withdrawing stops processing, which closes the account through the same deletion path, grace window included). Depending on where you live you may also have the right to complain to a data-protection authority. Requests the app cannot serve directly: contact us via support and we will answer without undue delay.

11.Age

myPacia is for adults: you must be 18 or older to create an account, and you confirm this at signup. We do not knowingly process children’s data; accounts found to belong to minors are closed and deleted.

12.Changes to this policy

When this policy changes, we update the version and date at the top, describe the change in the changelog below, and notify you in the app. A change that introduces a new purpose for processing your data will never take effect silently — it requires your fresh consent first.

Changelog — in plain words

  • 2026-07-21 — First published version, for the closed beta. The controller entity is marked as pending registration; completing it will be announced. Database-at-rest encryption status is stated as pending verification rather than assumed.