We do not sell your health data
Not to advertisers, not to insurers, not to data brokers, not in aggregate, not ever. Our revenue comes from services people choose to pay for.
Plain-English answers to the questions that actually matter: what we collect, who can see it, how long we keep it, and how to get rid of it. No legal fog.
These aren’t aspirations. They’re the constraints our engineering works within.
Not to advertisers, not to insurers, not to data brokers, not in aggregate, not ever. Our revenue comes from services people choose to pay for.
If a feature works without a piece of data, we don’t ask for it. Location is used to find pharmacies and is not stored as a history.
We use encryption in transit and encryption at rest for supported production systems, together with access controls and audit logging. Specific controls can vary by data type, system and service provider.
Request access, export, correction or deletion of eligible personal data, subject to identity verification and legal or clinical record-retention requirements.
Every share is deliberate, scoped and time-limited. You choose which items go out, who receives them and when access ends — and you can see exactly who opened what.
What you type or say is processed to generate guidance for you, in that session. That is its primary and default use.
If the product truly has an optional data-contribution/model-improvement setting, describe its exact scope and provider behavior here. If no such setting exists, replace with: "We do not permit our contracted AI service providers to use your health content to train their general models, subject to our provider agreements and Privacy Policy."
Authorized personnel may review limited information for safety, quality, security or support purposes as described in the Privacy Policy. Access should be limited, logged and de-identified where feasible.
Records are kept while your account is active and deleted on request. Backups roll off within 90 days.
Protects stored data using encryption managed by the service or its infrastructure. “Zero-knowledge” protection is stronger and applies only when OnlineCare cannot obtain the keys needed to decrypt protected content.
Consumer health apps are usually not HIPAA-covered. Here is exactly where the line sits for us.
To records created during a consultation with a licensed clinician. For HIPAA-covered clinical services, the healthcare provider or medical group responsible for the consultation is the covered entity. OnlineCare acts as a business associate when it creates, receives, maintains or transmits PHI on behalf of that covered entity under a written Business Associate Agreement.
To AI conversations, symptom checks, wallet items you upload yourself and wearable data. We protect those under our Privacy Policy, our Privacy Policy and applicable consumer-health privacy laws, including state laws and the FTC Health Breach Notification Rule where applicable. These laws are different from HIPAA and provide different rights and obligations.
Get a machine-readable copy of everything associated with your account, usually within 30 days and often much sooner.
Fix anything inaccurate in your profile or records directly in the app, or ask us to do it.
Delete your account and associated data. We confirm when it’s done and tell you what, if anything, we’re legally required to retain.
Withdraw consent for optional processing at any time without losing access to core features.
Write to our privacy team directly. A person reads it, and you’ll get a real answer rather than a link back to the policy.
privacy@onlinecare.com · Privacy requests are handled according to applicable law and our published process