Privacy Policy
Your privacy and data security are fundamental to our mission. Learn how we protect, use, and respect your personal health information.
Effective Date: July 28, 2026 · This is our Consumer Health Data Privacy Policy.
NexGenHealth is a consumer Personal Health Record (PHR) service. We are not a HIPAA covered entity or business associate, we are not a healthcare provider, and we do not practice medicine. Because we handle consumer health data, we operate under the laws that actually apply to a consumer health app: Washington's My Health My Data Act (MHMDA), the FTC Health Breach Notification Rule (HBNR), and, for California residents, the Confidentiality of Medical Information Act (CMIA) and CPRA/CCPA. This policy describes what we actually do — please read the security section literally.
1. Who We Are & Scope
NexGenHealth ("NGH," "we," "us") operates NexGenHealth.io, a consumer PHR web application that lets you store, organize, and get AI-assisted educational insights about your own health information. The service is self-hosted on our own server (an on-premises system we control) and reached over an encrypted connection. This policy applies to the consumer health data and other personal information we collect through NexGenHealth.io. You must be 18 or older to use the service (see Section 12).
2. The Consumer Health Data We Collect
2.1 Health data you enter or generate
- Medical conditions and diagnoses you record
- Medications and supplements
- Lab results and blood markers / biomarkers
- Meal plans and nutrition information
- Wearable and activity data (e.g., steps, heart rate) if and when you connect a device or service
- Any other health notes you choose to enter
2.2 Uploaded medical-record files
Documents you upload (e.g., lab reports, records). Note: new file uploads are currently disabled while we finish the encrypted-upload path; existing uploaded files are encrypted at rest. We will not describe upload as available until it is re-enabled.
2.3 Account & identity information
Your name, email address, and phone number; authentication data, including your multi-factor authentication (TOTP) settings if you enable MFA. Standard server logs (e.g., IP address, timestamps) are generated in the normal course of operating the site.
2.4 Payment information
When you pay for a plan, card details are collected and processed by Stripe, our payment processor. NGH does not store your full card number. We do not collect precise geolocation for health purposes, and we do not operate any geofence around health-care facilities.
3. Where the Data Comes From
- Directly from you — everything you type, upload, or configure.
- From devices/services you connect — wearable or activity data, only if you choose to connect such a device or service.
- We do not buy or obtain your consumer health data from data brokers or other third parties.
4. Why We Collect & Use Your Data
We use your consumer health data only to provide and operate the PHR service you asked for:
- To store and display your personal health record
- To provide meal-planning and nutrition features
- To power AI-assisted educational features, which run locally on our own server (see Section 5)
- To operate, secure, and support the service (authentication, MFA, account management, fraud/abuse prevention, troubleshooting)
- To process payments for paid plans (via Stripe)
- To comply with law and enforce our Terms
We do not use your consumer health data for advertising, and we do not sell it. Where we would use your data beyond what is necessary to provide the service, we ask for your consent first (see Section 11).
5. How We Use AI (Local-Only)
Our AI features are local-only. All AI model inference runs on our own server (our model gateway is bound to the local loopback address and is architecturally prevented from calling out). No health data is sent to any third-party AI or large-language-model provider — not OpenAI, not Google, not any external API.
We use a dual-track design:
- Track 1 — your original health data: kept encrypted and used in a minimized way.
- Track 2 — de-identified content: we run your content through an automated PII-redaction engine to strip identifiers, and the AI/retrieval features operate on these de-identified chunks.
Our binding commitment on de-identified data — that we will not re-identify it, will use it only in de-identified form, and will contractually bind any recipient to the same — is published at De-Identified Data Commitment.
Important limitation on de-identification: our de-identification is an automated redaction process that we validate against benchmark datasets. It is not HIPAA "Safe Harbor" de-identification and we do not represent it as such. It substantially reduces, but cannot guarantee elimination of, all identifying information.
6. Who We Share Data With
We do not sell your consumer health data. We do not share it with third parties for advertising or for their own purposes. We do not use third-party advertising or analytics trackers on our health pages.
We rely on a small number of service providers (processors) strictly to run the service:
- Stripe — payment processing. Receives payment/billing data, not your health data.
- Our edge/hosting provider — an edge server we operate at a third-party hosting provider terminates the TLS connection at the edge and forwards your traffic to our local server over a separate encrypted link. It handles your network traffic in transit.
- Cloudflare — DNS for our domain.
- Google (Gmail) — sends transactional email (e.g., verification, password reset). Receives your email address for that purpose, not your health record.
We do not currently share your data with research partners. If we ever offer that, it would be only de-identified and only with your separate, specific, withdrawable consent. We may disclose information if required by law or to protect rights and safety, limited to what is necessary.
7. How We Protect Your Data
- Encryption at rest — structured health data: your conditions, medications, labs, meal plans, and activity data are encrypted at rest using AES-256-GCM at the application layer. Live.
- Encrypted identity vault: your name, email, and phone are stored in a separate encrypted vault (AES-256-GCM).
- Encryption at rest — uploaded files: existing uploaded files are encrypted at rest with a per-file AES-256-GCM envelope. (New uploads are disabled until the encrypted-upload path is re-enabled.)
- Encryption in transit: traffic between you and our server is protected with TLS.
- Key custody: encryption keys are held by NGH (a server-side envelope-encryption model) and escrowed off-site for recovery. This is not client-side, zero-knowledge, or end-to-end encryption — because we hold the keys, we are technically able to decrypt your data to operate the service. We do not represent the service as zero-knowledge or end-to-end encrypted.
- Access controls & MFA: internal access to your data is restricted, and you can enable multi-factor authentication (TOTP).
- No third-party trackers: we self-host our fonts and libraries; our health pages load no third-party advertising or analytics scripts.
We do not claim to be "HIPAA-compliant," and any prior statements to that effect have been corrected.
8. Data Retention & Deletion
We retain your consumer health data for as long as your account is active or as needed to provide the service. You can delete your account and its data at any time from Settings → Security (see Section 9); deletion removes your data from our live systems and it ages out of our encrypted backups on our backup-rotation schedule. We are not a HIPAA covered entity and do not apply any medical-records retention mandate to keep your data against your wishes.
9. Your Rights & How to Exercise Them
For consumer health data (under MHMDA, and for California residents under CMIA/CPRA), you have the right to:
- Access / export your data — our Data Export feature produces a downloadable ZIP of your structured health data and uploaded files.
- Delete your data — a self-service "Delete account" control in Settings → Security permanently deletes your account and its data. You can also request deletion by contacting us.
- Withdraw consent — where we rely on your consent, you can withdraw it at any time.
- Confirm & know — confirm whether we are processing your consumer health data and which processors (Section 6) it was shared with.
- Correct — you can edit your information in the app; California residents may request correction of inaccurate data.
To make a request or appeal a decision, contact us at the address in Section 14. We will respond within the timeframes required by applicable law, and we will not discriminate against you for exercising your rights.
10. Notice of Breach (HBNR)
As a vendor of personal health records, we are subject to the FTC Health Breach Notification Rule. If we discover a breach of security involving your unsecured identifiable health information, we will:
- Notify affected consumers without unreasonable delay and no later than 60 calendar days after discovery;
- Notify the FTC — within 10 business days for breaches involving 500 or more individuals; smaller breaches are logged and reported annually;
- Notify prominent media if a breach affects 500 or more residents of a state;
- Provide the required notice content (what happened, the data involved, steps we are taking, and steps you can take). California residents: a breach may also trigger California's breach-notification statute and CMIA obligations.
11. Consent (MHMDA)
Where the law requires it, we obtain your consent before collecting or using your consumer health data for anything beyond what is necessary to provide the service you requested, and we keep a record of that consent. Because we do not sell consumer health data, no separate authorization to sell is required; if that ever changed, we would obtain a separate, valid MHMDA authorization first. You may withdraw your consent at any time (Section 9).
12. Children
NexGenHealth is intended for adults 18 and older. We do not knowingly collect consumer health data from anyone under 18. If we learn that we have collected data from a person under 18, we will delete it. If you believe a minor has provided us data, contact us (Section 14).
13. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will post the updated policy with a new effective date and, where required, notify you. Where the law requires fresh consent for new uses, we will obtain it.
14. Contact & Effective Date
For questions about this Consumer Health Data Privacy Policy or to exercise your privacy rights, contact us:
Business: NexGenHealth
Privacy contact: nexgenhealth.io@gmail.com
Effective date: July 28, 2026