Legal · Security

Security & Data Practices

Effective date · June 13, 2026

Eider handles some of the most sensitive information families have — their children's health histories and their own medical records. We treat that responsibility seriously. This page explains exactly how we store, protect, and handle your data.

01Our commitment

Eider handles some of the most sensitive information families have — their children's health histories and their own medical records. We treat that responsibility seriously. This page explains exactly how we store, protect, and handle your data.

02Infrastructure

All Eider data is stored on Google Cloud via Firebase — the same infrastructure that powers Gmail, Google Drive, and Google Workspace. Google Cloud maintains SOC 2 Type II, ISO 27001, and HIPAA Business Associate Agreement certifications for its infrastructure.

03Encryption

  • In transit: TLS 1.3 for all data moving between your device and our servers.
  • At rest: AES-256 encryption on all stored data.
  • Authentication tokens: never stored in plaintext; invalidated on logout.

04Access controls

Firebase Security Rules enforce that each user can only access their own records. No Eider employee can read your health records without your authentication credentials. Administrative access to infrastructure requires multi-factor authentication and is logged.

05HIPAA positioning

Eider is a consumer personal health record (PHR) application. We are not a HIPAA covered entity or business associate — HIPAA does not govern consumer PHR tools under the HITECH Act PHR exemption. However, we voluntarily align our engineering practices, data handling, and security controls with the HIPAA Security Rule. This means we apply the same safeguards a covered entity would apply, even though we are not required to by law.

06FTC Health Breach Notification Rule

Eider is subject to and fully complies with the FTC Health Breach Notification Rule. In the event of a breach affecting your health records, we are required to notify affected users within 60 days and report to the FTC. We maintain an incident response plan and conduct regular security reviews.

07AI features

AI-powered features (voice logging, appointment summaries) use AWS Bedrock — Amazon's HIPAA-eligible AI infrastructure. Data sent to AI features is limited to the specific context needed for that feature (not your full health record), is not logged by the AI provider, and is not used for model training. AI features require explicit user activation.

08Connected health records (FHIR)

When you connect a health system account, data is transferred via SMART on FHIR using OAuth 2.0 with PKCE — an industry-standard, patient-mediated authorization protocol. Access tokens are stored securely and never logged. We request read-only access using minimum necessary scopes. Imported records are stored in your private Firestore document under the same access controls as all other Eider data. See our FHIR Data Use page for the complete scope list and justifications.

09What we never do

  • Sell or share your health data with advertisers, data brokers, or third parties.
  • Use your health data to train AI models.
  • Access your records without your authentication.
  • Store payment information (payments are handled by Apple/Google app stores).
  • Use unsecured or unencrypted storage for any health data.

10User controls

  • Delete your account and all data: available in Settings at any time.
  • Revoke connected health systems: available in Settings.
  • Revoke caregiver access: available in Care Circle at any time.
  • Export your records: available in the app.

11Vulnerability disclosure

If you discover a security vulnerability in Eider, please report it to support@eiderhealth.com. We commit to responding within 5 business days and to not pursuing legal action against good-faith security researchers.

12Contact

Security questions: support@eiderhealth.com · Eider Health LLC · Texas