Privacy Policy

HealthFramework, Inc. (“HealthFramework,” “we,” “us,” or “our”) is a Delaware corporation that operates the HealthFramework website at hlthframework.com and develops HealthFramework Monitor.

This Privacy Policy explains how information is handled through our website and the current limited-access version of Monitor.

1. Scope

This Policy applies to:

The current limited-access evaluation is intended for synthetic test data. Participants should not use Monitor with real personal health information unless HealthFramework expressly authorizes that use under updated terms and privacy disclosures.

2. Information handled through the website

The website does not currently provide account registration, forms, file uploads, newsletters, or public access to Monitor.

We may receive information that you choose to send to us by email, such as your name, email address, organization, and the contents of your message.

Our website is delivered through Cloudflare. Cloudflare may process standard technical and security information needed to deliver and protect the website, such as IP address, browser or device information, request timestamps, and security signals.

HealthFramework does not currently use website analytics, advertising pixels, or behavioral advertising technologies.

3. Information used within Monitor

Monitor is designed to organize information selected by the user, which may include:

In the current local-first version, Monitor content remains in the user-controlled environment. HealthFramework does not operate cloud storage or backup for readable Monitor health content and does not receive or store that content.

Monitor may create local technical information needed to operate the application, such as local session, audit, source, and provenance information.

4. User-authorized external connections

AI services

A user may choose to connect Monitor to an external AI service. Monitor provides only the information selected or authorized for the interaction.

Selected information is transmitted from the user-controlled Monitor environment through the configured connection to the AI service chosen by the user. The connection may rely on infrastructure operated by the AI provider or another connectivity provider. In the current local-first service, HealthFramework does not receive or store the selected health context, the user’s broader AI conversation, or the AI service’s response.

External AI services process information under their own terms, privacy policies, account settings, and retention practices. Users should review those terms before connecting a service.

Health-record sources

When enabled and authorized by the user, Monitor may connect to a healthcare provider or patient portal and import available records into the user-controlled environment.

In the current local-first version, readable records are retrieved from the provider and stored locally rather than passing through HealthFramework-controlled cloud storage. The healthcare provider and its technology providers may process connection and access information under their own policies.

Third-party identity services

Monitor may include components supplied by a third-party identity provider, such as Google, and may offer sign-in through that provider as the limited-access service develops.

A third-party identity provider may receive standard technical information when its components are loaded. If third-party sign-in is enabled and selected, the provider may supply information needed to authenticate or manage access, such as a name, email address, account identifier, verification status, or profile image.

The provider handles information under its own privacy policy and account settings. HealthFramework will update this Policy if the authentication information used by Monitor materially changes.

5. AI-generated content and write-back

Monitor may allow an AI service to propose content for storage in the user-controlled environment, such as a document abstract, structured laboratory information, a summary, or another conversation artifact.

AI-generated content is saved only following user authorization. Saved material remains distinguishable from the original source and may retain information about its source and AI provenance. Monitor does not modify the original source record as part of this process.

6. How HealthFramework uses information

HealthFramework may use information that it receives to:

HealthFramework does not sell personal information, share personal information for targeted advertising, use personal information for behavioral advertising, or combine website visitor information with third-party marketing profiles.

HealthFramework does not currently send marketing email.

7. Cookies, local storage, and tracking

HealthFramework does not currently use analytics or advertising cookies on the public website. Cloudflare may use cookies or similar technologies that are strictly necessary to deliver, secure, or protect the website.

Monitor may use local cookies, browser storage, local files, and a local database to provide application functionality within the user-controlled environment.

HealthFramework does not track users across unrelated websites for advertising purposes. Because we do not engage in that type of tracking, browser “Do Not Track” signals do not change our current practices.

8. Sharing and disclosures

HealthFramework may disclose information that it receives:

HealthFramework does not disclose locally stored Monitor health content because HealthFramework does not receive or maintain that content in the current local-first service.

9. Retention and deletion

Email messages and related business communications may be retained for as long as reasonably necessary to respond, maintain business records, resolve disputes, or comply with legal obligations.

Monitor content remains in the user-controlled environment. Available deletion controls vary by data type in the current limited-access version, and the application does not yet provide a single in-app control that permanently erases every category of locally stored information. HealthFramework does not maintain a cloud copy of locally stored Monitor health content.

Where HealthFramework receives limited authentication, access, or communication information, it may retain that information for as long as reasonably necessary for the purpose for which it was received, security, recordkeeping, or legal compliance.

Questions about retention or deletion may be sent to privacy@hlthframework.com.

10. Security

HealthFramework uses reasonable administrative and technical measures appropriate to the limited information it receives and controls.

The security of locally stored Monitor content also depends on the user-controlled device, operating system, user accounts, and connected services. HealthFramework does not currently represent application-level encryption of all locally stored Monitor content as a product feature.

No storage or transmission method can be guaranteed to be completely secure.

11. Privacy rights

Depending on where you live, you may have rights concerning personal information that HealthFramework maintains about you, including rights to request access, correction, or deletion.

To submit a request, contact privacy@hlthframework.com. We may need to verify the request before responding. We will process applicable requests in accordance with relevant law.

12. Age eligibility

Monitor is intended only for individuals who are at least 18 years old. HealthFramework does not knowingly permit anyone under 18 to participate in the limited-access evaluation.

13. Changes to this Policy

We may update this Privacy Policy as the website, Monitor, or our information practices develop. The revised Policy will be posted on this page with a new effective date.

If a change materially affects how information already collected by HealthFramework is used or disclosed, we will provide any additional notice or consent required by applicable law.

14. Contact

For privacy questions or requests, contact:

HealthFramework, Inc.
Email: privacy@hlthframework.com