Privacy Policy
Privacy at a glance. This summary is not a substitute for the full policy, but here is what matters most: You own your health information — ChartKey is a tool to help you organize it. We do not sell your personal information, and we do not use it for advertising. We do not use your health information to train artificial-intelligence models. Our AI helps you document your health story and may offer general, common-sense suggestions — it does not diagnose or treat, and nothing it says is a substitute for your clinicians. You can export or permanently delete your data at any time. We encrypt your data in transit and at rest, and we log every access to your health information so you can see who viewed it.
Contents
- 1. Who we are & what this covers
- 2. The nature of the Service
- 3. Key terms
- 4. Information we collect
- 5. How we use your information
- 6. Artificial intelligence
- 7. How & when we share
- 8. Your rights & choices
- 9. Caregiver access & consent
- 10. Children's privacy
- 11. How long we keep information
- 12. How we protect information
- 13. Where information is stored
- 14. Data breach notification
- 15. Third-party services & links
- 16. Changes to this policy
- 17. How to contact us
- 18. Washington residents (MHMDA)
1. Who we are and what this policy covers
ChartKey is operated by ChartKey LLC, a Colorado limited liability company located at 2519 S Shields Street, Suite 1K #963, Fort Collins, CO 80526 ("ChartKey," "we," "us," or "our"). ChartKey is a patient-owned healthcare information platform that helps patients and caregivers bring fragmented medical information into a single, understandable timeline, document symptoms, and view a plain-language summary of a person's health.
This Privacy Policy explains what information we collect through our websites (including yourchartkey.com and app.yourchartkey.com), our web application, and any future mobile applications (collectively, the "Service"), how we use and protect it, when and with whom we share it, and the rights and choices you have. It applies to everyone who uses the Service, including patients and caregivers. It forms part of, and should be read together with, our Terms of Service.
Because ChartKey handles sensitive health information, we hold ourselves to a HIPAA-aligned standard and to the requirements of laws that protect consumer health data, including the Washington My Health My Data Act ("MHMDA"), California's Confidentiality of Medical Information Act ("CMIA"), and the U.S. Federal Trade Commission's Health Breach Notification Rule, as described throughout this policy.
2. The nature of the Service — please read
ChartKey is not a healthcare provider, and the Service is not medical care. ChartKey helps you organize and document health information. It does not diagnose conditions, prescribe or provide treatment, or triage the urgency of symptoms. Our artificial-intelligence features assist with clarification and documentation, and the Keeper voice companion may also offer general, common-sense suggestions (such as encouraging rest or a conversation with your doctor). Any such suggestion is informational only and is not professional medical advice. Always rely on qualified healthcare professionals for medical decisions.
ChartKey is not for emergencies. If you think you are experiencing a medical emergency, call 911 or your local emergency number, or go to the nearest emergency department. In the United States you can also call or text 988 for the Suicide and Crisis Lifeline. Do not use the Service to request emergency help.
3. Key terms used in this policy
- Health information / PHI: information relating to your physical or mental health, the healthcare you receive, or symptoms you document — including data drawn from your connected medical records and symptoms you record in the Service.
- Consumer health data: personal information that is linked to you and identifies your past, present, or future physical or mental health status, as defined under laws such as the Washington MHMDA and California CMIA.
- Caregiver: a person who uses the Service to help manage the care of another individual (for example, an adult child managing care for a parent).
- Care group / care circle: the set of linked accounts and permission grants that allow caregivers to view a patient's information or document symptoms on the patient's behalf.
- Connected records: clinical data retrieved, with your authorization, from an external health system such as Epic MyChart.
4. Information we collect
4.1 Information you provide to us
- Account and identity information: when you sign up, we collect your name, email address, and authentication credentials (managed through Amazon Cognito). For a patient profile you or a caregiver may provide date of birth and the relationship between a caregiver and a patient.
- Health information you enter: symptoms and related details you document through our guided AI intake or the Keeper voice companion, and any notes or health information you add to a timeline.
- Voice conversations with Keeper: if you choose to use the Keeper voice companion (a separate, optional opt-in you can withdraw at any time), your microphone audio is streamed in real time to our AI provider (Amazon Bedrock) inside our secured AWS environment for speech processing, and Keeper’s replies are synthesized speech. We do not retain the audio itself. What you said is captured as a transcript-based note that is shown to you for confirmation — nothing is saved to your record unless you confirm it.
- Push notifications (iOS app, optional): if you turn on notifications in the ChartKey iOS app — a separate, optional opt-in that is never required to use the Service — we store an Apple push token for your device (an opaque identifier Apple issues so notifications can be delivered to that device) together with your quiet-hours preference. Notification messages themselves never contain health details: they are fixed, generic reminders to open the app. Turning notifications off deletes the device registration, and it is removed entirely when you delete your account. We also keep a minimal log of which reminder cycles have already been notified (rule identifiers and dates only, no health text) so we never notify you twice about the same thing.
- Caregiver and relationship information: the identities and relationships of people in a care group, the permissions granted, and caregiver self-attestations of authorization.
- Communications and feedback: messages you send us, including in-app feedback and any screenshots you choose to attach. Feedback and its attachments are stored entirely within ChartKey’s own secured, BAA-covered environment (encrypted at rest) — nothing is sent to any third party. A screenshot of your own record is fine; please don’t include another person’s health information. You can delete feedback with your account, and deleting your account removes it (and any attachments) permanently.
4.2 Information from your connected health records
If you choose to connect a health record system such as Epic MyChart, you authenticate directly with that provider using a secure, industry-standard authorization protocol (SMART on FHIR / OAuth 2.0). We never see your provider-portal password. With your authorization, we retrieve clinical data — which may include encounters, conditions, observations and laboratory results, medications, allergies, and clinical notes — and place it onto your ChartKey timeline. To keep your data current, we securely store an access/refresh token, which is held encrypted in AWS Secrets Manager and never stored in our application code, logs, or general database. You can disconnect a connected record at any time.
4.3 Information collected automatically
When you use the Service we automatically collect limited technical and usage information needed to operate and secure it — such as log data, device and browser type, and security event records. We design the Service so that health information is not written to application or infrastructure logs. We use only the cookies and similar technologies necessary to keep you signed in and to keep the Service secure and functioning. We do not use advertising cookies, and we do not allow third-party advertising trackers on the Service. For basic, privacy-preserving product analytics we rely on our own first-party server access logs (standard web-request records such as page requested, referring site, approximate region, and browser type). This analysis is cookieless, stays within our own infrastructure, does not set analytics cookies, and does not track you across other sites.
5. How we use your information
We use your information only to provide and improve the Service you have asked for, to keep it secure, and to meet our legal obligations. Specifically, we use it to:
- Build and maintain your patient-owned timeline from connected records and documented symptoms;
- Operate the guided AI intake so you can clarify and document symptoms;
- Generate plain-language, explainable summaries of your current health state, with each point traceable to its source encounter or symptom;
- Enable caregiver access and care-group features strictly in accordance with the consent and authorization rules in Section 9;
- Authenticate you, secure the Service, prevent fraud and abuse, and maintain the access and audit logs that let you see who viewed your information;
- Communicate with you about the Service, respond to your requests, and provide support;
- Comply with legal obligations and enforce our Terms of Service.
What we do not do
We do not sell your personal information. We do not use your health information for advertising or to build advertising profiles. We do not use your health information to train artificial-intelligence models. We do not disclose your health information to anyone except as described in this policy and, for caregiver access, only with the authorization described in Section 9.
6. Artificial intelligence and automated processing
Some features use artificial intelligence to help you document and understand your health information. These features run on Amazon Bedrock within our secured Amazon Web Services ("AWS") environment, which is covered by a signed Business Associate Addendum, so your information stays within our protected boundary. Key points:
- Documentation first. The guided text intake clarifies and documents symptoms and summarizes information you already have; it is constrained by design not to diagnose, prescribe treatment, or triage urgency. The Keeper voice companion may additionally offer general, common-sense suggestions and always directs you to your clinicians — its suggestions are informational only and are not professional medical advice.
- Voice processing. Voice conversations with Keeper are processed in real time within the same protected AWS environment. The audio itself is not retained; only the transcript-derived note you review and confirm is written to your record.
- Explainable. Summaries cite the specific encounter or symptom they are drawn from, so you can verify them and the Service is not a black box.
- Safety. If the intake detects language suggesting a crisis or emergency, it stops and directs you to appropriate emergency and crisis resources rather than continuing to document.
- Not used to train models. Your information is not used to train or improve any general-purpose AI model, and our AI provider does not retain your prompts for its own model training.
- Human decisions remain yours. The AI does not make decisions about your care. Medical decisions should always be made by you and your healthcare professionals.
8. Your privacy rights and choices
You have meaningful control over your information. Depending on where you live, some of these rights are guaranteed by law (including the Washington MHMDA and California CMIA); we extend them to all users as a matter of principle.
- Access and see who viewed your data. You can view your information in the Service and review an access log showing who accessed a patient's health information and when (Settings → Access log).
- Export (data portability). You can request an export of your complete record as machine-readable FHIR JSON plus a readable PDF summary. The export is encrypted and delivered through a secure, expiring link.
- Delete. You can permanently delete individual self-reported timeline entries, or delete your entire account and all associated data. Account deletion is immediate and irreversible — we recommend exporting your data first.
- Withdraw consent and revoke caregiver access. You can withdraw consent for the collection or sharing of your consumer health data, revoke or narrow a caregiver's permissions, and disconnect a connected health record at any time.
- Correct. You can edit or remove self-reported information. Data sourced from a connected provider reflects that provider's records; corrections to source records are made with the provider.
To exercise these rights, use the controls in the Service or contact us at privacy@yourchartkey.com. We will respond within the timeframes required by applicable law. We will not discriminate against you for exercising your privacy rights.
A note on deletion. Because ChartKey is built so that nothing is silently retained, deletion is designed to be complete and unrecoverable: we remove your records, connected-record tokens, stored documents and exports, and your sign-in identity. We retain only a minimal, health-information-free audit record where required for security and legal compliance.
9. Caregiver access and the consent model
Protecting a patient's health information means being careful about who may see it. Creating a caregiver profile and checking a self-attestation box lets a caregiver set up a profile shell (name, date of birth, relationship), but is not by itself sufficient to access a patient's actual health information. Access to health information requires one of the following:
- The patient themselves — always has access to their own record.
- A parent or legal guardian of a minor — has presumed access as the minor's personal representative. This presumed access ends automatically when the minor turns 18, calculated from the date of birth; continued access after that requires the now-adult patient's explicit consent.
- Every other relationship (adult child, spouse, sibling, parent of an adult, and others) — requires the patient's explicit, scoped, and revocable consent, or verified legal documentation (such as a power of attorney or guardianship) for an incapacitated adult.
For adult caregiving, the patient grants consent through an invitation-and-claim flow: the caregiver invites the patient to claim their own record via a single-use, email-bound, expiring link; on claiming, the patient becomes the owner of the record and explicitly grants the caregiver the specific permissions they choose. Consent is recorded, scoped to specific capabilities, revocable at any time, and every cross-account access is logged.
10. Children's privacy
ChartKey account holders must be at least 18 years old and able to form a binding contract. The Service enforces this at sign-up: a person under 18 cannot create their own ChartKey account. A minor is supported only as a patient whose record is created and managed by an adult account holder — a parent or legal guardian acting as the child's personal representative, as described in Section 9 — and never as an account creator. Because account creation is limited to adults, we do not knowingly permit anyone under 18 (and, in particular, no child under 13, consistent with the Children's Online Privacy Protection Act (COPPA)) to create their own account or to submit personal information to us directly rather than through an adult account holder. A guardian's presumed access to a minor's record ends automatically when the minor turns 18. If you believe a minor has created an account or provided us information improperly, contact us and we will take appropriate steps to delete it.
11. How long we keep your information
We keep your information for as long as your account is active and as needed to provide the Service. When you delete individual entries or your account, we delete the associated data promptly and irreversibly, as described in Section 8. We retain a minimal, health-information-free audit record where necessary for security, fraud prevention, and legal compliance. Aggregated or de-identified information that can no longer reasonably be linked to you may be retained.
12. How we protect your information
We apply layered technical and organizational safeguards, including:
- Encryption everywhere: data is encrypted in transit (TLS) and at rest (AES-256 for our database and customer-managed KMS keys for stored documents).
- Strict access controls: least-privilege access, network isolation within a private cloud environment, and connected-record tokens held in a dedicated secrets manager — never in code or logs.
- Auditability: every access to a patient's health information is recorded in an application audit log, and infrastructure activity is logged for security monitoring.
- Data minimization: we design the Service so that health information is not written to logs or included in AI prompts beyond what a task strictly requires.
- Contractual protection: our cloud infrastructure operates under a signed Business Associate Addendum with AWS.
No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security, and you use the Service with that understanding.
13. Where your information is stored
The Service is operated in the United States on AWS infrastructure, and your information is stored and processed in the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States.
14. Data breach notification
If we discover a breach of unsecured health or personal information, we will investigate and notify affected individuals, and any regulators or authorities, as and when required by applicable law — including the U.S. Federal Trade Commission's Health Breach Notification Rule (which applies to consumer health applications like ChartKey), HIPAA-aligned breach-notification standards, and applicable state laws such as the Washington MHMDA, California CMIA, and state data-breach statutes. Our notification will describe, to the extent known, what happened, the information involved, and the steps you can take.
15. Third-party services and links
When you connect a health record system such as Epic MyChart, your use of that system is governed by that provider's and Epic's own terms and privacy practices, not this policy. The Service may contain links to third-party sites we do not control; we are not responsible for their privacy practices, and we encourage you to review their policies.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you through the Service or by email. Your continued use of the Service after an update means you accept the revised policy.
17. How to contact us
For privacy questions or to exercise your rights, contact us at:
- ChartKey LLC
2519 S Shields Street, Suite 1K #963
Fort Collins, CO 80526
United States - Privacy: privacy@yourchartkey.com
- General: hello@yourchartkey.com
18. Additional disclosures for Washington residents (My Health My Data Act)
If you are a Washington resident, or your consumer health data is collected in Washington, the MHMDA gives you specific rights, which we honor for all users: the right to consent before we collect or share your consumer health data for purposes beyond providing the Service; the right to withdraw that consent; the right to access your consumer health data and a list of third parties with whom it has been shared; and the right to have your consumer health data deleted. We do not sell consumer health data, and we do not collect or use geolocation to identify health facilities. To exercise these rights, contact privacy@yourchartkey.com. If we deny a request, you may appeal by replying to our response; you may also contact the Washington State Attorney General.