Legal · Privacy

Privacy Policy

Effective date · June 13, 2026

Eider is a consumer personal health record. This policy explains, in plain language, what we collect, how we protect it, and the controls you hold. The short version: you own your data, we never sell it, and only the people you choose can see it.

01Who we are

Eider Health is a consumer personal health record company based in Texas. We build tools that help families and individuals organize, track, and share health information. Eider is not a medical provider, health plan, or healthcare clearinghouse, and is not a HIPAA covered entity. As a consumer PHR application, Eider operates under the HITECH Act consumer PHR framework and is subject to the FTC Health Breach Notification Rule.

02What data we collect

We collect only what you choose to enter or import: health logs (medications, symptoms, temperatures, appointments, notes), profile information for children and yourself, your account credentials, health records you choose to import from a connected health system, and basic usage data (device type, app version, anonymized screen visit counts) to keep the app functioning and understand which features are used. We do not collect precise location data, advertising identifiers, or tracking linked to your identity.

The eiderhealth.com website and the Eider app use Vercel Analytics, a cookieless, privacy-first analytics service, to count page views and understand general usage patterns. Vercel Analytics does not collect IP addresses, personal identifiers, health data, or advertising identifiers, and uses no cookies. No health information is transmitted to Vercel. It cannot identify you as an individual.

03Connected health records

Eider allows you to connect participating health systems (such as Epic MyChart) to import your existing health records. This is always optional and user-initiated. When you connect a health system, Eider requests read-only access to specific record types (conditions, medications, allergies, immunizations, basic demographics), imports that data into your private account, and does not transmit it to any third party. We never write back to your health system. You can revoke access at any time from Settings. For full details, see our FHIR Data Use page.

04Your data belongs to you

You own your data. Eider stores it on your behalf and does not claim any rights to it. You can export, delete, or stop using Eider at any time. Under the FTC Health Breach Notification Rule, if we experience a breach affecting your health records, we are required to notify you within 60 days and report to the FTC.

05How we use your data

We use your data only to operate Eider for you — to display your records, generate summaries, support features you activate, and provide AI-assisted features you choose to use. We do not use your health data to train AI models, serve advertisements, profile you commercially, or contribute to any marketing database.

06AI features and your data

AI features (voice logging, appointment summaries, visit prep) process only the specific records relevant to your request — not your full health history. AI processing uses AWS Bedrock, a HIPAA-eligible infrastructure. Inputs are not stored or used for model training. AI features require explicit activation and do not run in the background.

07We never sell or share your data

Eider does not sell, rent, license, or trade your personal or health data to any third party — ever. The only exceptions: records you explicitly share via Care Circle with a caregiver you designate; valid legal process (we notify you first if permitted); and FTC breach reporting as required by law.

08Children's privacy (COPPA)

Children are profiles within your adult account — they are not users and do not have their own accounts. We do not knowingly collect personal information directly from children under 13.

09Your rights

You have the right to access all your data, export your records, delete your account and all associated data, correct information you've entered, and revoke any connected health system or caregiver access. Account deletion permanently removes all data within 30 days.

10Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256) on Google Cloud infrastructure. Per-user Firebase Security Rules mean no Eider employee can access your records without your credentials. See our Security & Data Practices page for full details.

11Data retention

Data is retained for as long as your account is active. Account deletion removes all data permanently within 30 days. We do not retain health data after deletion for any purpose.

12Contact

support@eiderhealth.com · Eider Health LLC · Texas