assertion.me · fhir · privacy
Privacy policy — personal health-record client
This policy covers the single-user application described at /fhir/.
The application is run by the owner of this domain, for the owner's own medical records only.
The owner is its only user and the only person whose data it handles.
What data is handled
- The owner's own medical records — encounters, results, medications, documents — retrieved
from a health system's patient-facing FHIR endpoint (SMART on FHIR, patient-access scope)
after the owner signs in through that health system's own patient portal.
- The access and refresh tokens the portal issues for that retrieval.
Nothing else is collected. The application has no accounts, no sign-up, and no user other than
the owner.
How it is used and where it is kept
- Records are retrieved only when the owner asks, and only into local storage on hardware
the owner controls. That storage is encrypted at rest.
- Tokens are held in the operating system's secret store on the same hardware.
- The application never writes to the health system's records.
Who receives the data
Nobody. There is no cloud storage, no analytics, no advertising, no data sale, and no sharing
with any third party. These pages set no cookies and load no third-party resources.
Retention and deletion
- Records stay on the owner's devices until the owner deletes them. Deleting the local store
deletes every retrieved record.
- Access can be revoked at any time from the health system's patient portal; after
revocation the application can retrieve nothing further.
Changes
This page is the current policy. A change is a new "last updated" date below; nothing is
versioned elsewhere.
Contact
contact@assertion.me
Last updated 2026.09.08