SECURECORDSSECURECORDS

Privacy Policy

Last updated: September 29, 2026 · SECURECORDS is operated by UzBur Tech Solutions, Ontario, Canada ("we", "us").

The short version

  • Your health records are end-to-end encrypted. They're encrypted in your browser with a key only you can unlock, and we store only the encrypted result. We cannot read your values, which markers you track, the dates of your readings, your notes, your life events, your custom biomarkers, or the names, dates of birth, sex or height of you or your family profiles.
  • We see only what's needed to run the service: your email address, sign-in and security data, billing status, and basic counts and timestamps (details below).
  • No selling, no advertising, no tracking. We don't sell or rent data, show ads, or use third-party analytics or tracking scripts.

1. What's encrypted — and what that means

Everything you record — biomarker values, units, dates and times, notes, which markers you track, custom biomarker definitions, life events, reference-range overrides, dashboard preferences, and the personal details of you and any family profiles (name, date of birth, sex, height) — is encrypted on your device with AES-256-GCM before it's sent to us. The key that unlocks it is protected by your password and, separately, by your recovery key. We never receive either.

Because we never hold your unlocked key, we cannot read, search, analyse, recover or hand over your health records, including in response to a legal demand, because we don't have them in readable form. It also means we can't restore your records if you lose both your password and your recovery key.

2. Information we can see and why

Email address
To identify your account, sign you in, and contact you about your account, security or billing. At sign-up we email a one-time code to confirm the address.
Sign-in data
A salted hash of a value your browser derives from your password (never the password itself), your encrypted keys, and a record that your address was confirmed. If you use passkey unlock: each passkey's public identifier, a copy of your key that only that passkey can open, the device name you chose (encrypted), and when it was added and last used. We never receive fingerprints, face data or your device PIN.
Account metadata
How many encrypted records you have and their sizes, whether each tracked item is built-in or custom (not which one), how many profiles your account has (not who they are or which records belong to them), and when records were created or changed.
Plan and billing
Your plan, billing period and subscription status, and the Stripe customer and subscription identifiers. We never receive your card number.
Security records
For sign-up, sign-in, code-confirmation and account-recovery attempts: the IP address, the domain of the email address used (for example "gmail.com", never the full address), what was attempted, whether it succeeded, and when. We use these to detect and stop abuse; nothing blocks anyone automatically.
Technical logs
Our hosting provider records standard web-server logs (such as IP address, time and requested page) to operate and secure the service.
Contact messages
If you use the contact form: your name, email address and message, used only to respond to you. Please don't include health information — messages aren't end-to-end encrypted.

We use this information only to provide, secure and bill for SECURECORDS and to communicate with you about it. We don't use it for advertising or profiling, and we don't combine it with data from other sources.

3. Service providers

We use a small number of providers to run SECURECORDS. None of them can read your encrypted health records.

Render (hosting and database)
Hosts the application and the database of encrypted records, in the United States (Oregon).
Stripe (payments)
Processes payments and calculates sales tax for paid plans. You enter card details on Stripe's own pages. Stripe receives your email address, payment details and billing address, and handles them under its own privacy policy.
Resend (email)
Delivers our emails, such as sign-up codes. It receives your email address and the email's content (never health information).
Cloudflare Turnstile (bot check)
Runs on the first sign-up step and on the contact form only, to tell people from automated abuse. It receives your IP address and technical information from your browser on those two pages. It never runs where you type your password or where your keys are created.

These providers may process information outside Canada, including in the United States, where it may be accessible to authorities under local law. We choose providers with appropriate security and contractual protections.

4. Cookies and browser storage

  • One essential cookie keeps you signed in. It can't be read by page scripts and is sent only to our own site.
  • Browser storage remembers your light/dark theme choice and, if you use passkeys, which passkey belongs to this device and whether you chose not to use one here. Your decryption key is never stored — it stays in memory until the page is closed or locks.
  • We use no advertising or analytics cookies.

5. How long we keep information

  • Account and encrypted records: until you delete them or your account. Deleting your account removes it and every record immediately.
  • Backups: deleted data can remain in our hosting provider's encrypted database backups for up to 30 days before it's overwritten.
  • Security records (sign-in and sign-up attempts): 30 days.
  • Unfinished sign-ups: the pending code (stored only in hashed form) and address are deleted within one day.
  • Technical logs: kept by our hosting provider for a limited period, up to 30 days.
  • Contact messages: until we've dealt with them and delete them.
  • Billing records: kept by Stripe, and as long as tax and accounting laws require.

6. Security

Besides end-to-end encryption, we use HTTPS for all connections, a strong password-derivation function (Argon2id) on your device, rate limits and bot protection on sign-in and sign-up, automatic locking after inactivity, and access limited to the few people who operate the service. They can see the information described in section 2 when needed to run or secure SECURECORDS — never your health records. If a breach creates a real risk of significant harm, we'll notify you and the Privacy Commissioner as the law requires. More detail is on our Security page.

7. Family profiles

On the Pro plan you can keep records for other people, such as family members. Please add someone only if you're responsible for them or have their permission. Their details and records are encrypted exactly like yours, and you control them.

8. Your choices and rights

  • Access and download: download everything you've stored at any time in Settings → Your data (included in every plan).
  • Correct: edit your records and details in the app at any time.
  • Delete: delete individual records, family profiles, passkeys or your whole account in the app.
  • Ask us: you can ask what personal information we hold about you and how it's used, or ask us to correct it, through our contact form. Because your health records are encrypted, we can only tell you what we can see (described above).
  • Complain: if you're not satisfied with our answer, you can contact the Office of the Privacy Commissioner of Canada.

9. Age

SECURECORDS is for people aged 18 and over. We don't knowingly create accounts for anyone younger.

10. Changes to this policy

If we make a significant change, we'll tell you by email or in the app before it takes effect, and update the date above.

11. Contact

For privacy questions or requests, use our contact form and choose "Security or privacy concern". UzBur Tech Solutions, Ontario, Canada.

An unhandled error has occurred. Reload 🗙