Privacy
How Hopedeck handles your information. Last updated June 2026.
The short version
Your health records are encrypted on your device with a key derived from your passphrase. We never receive that passphrase or the key, so we cannot read your data — not your records, not your messages, not anything you store. What our server holds is unreadable ciphertext.
What we store
- Your email address (to sign you in).
- A one-way hash of a login key derived from your passphrase — never the passphrase itself.
- Your encrypted records and settings as opaque ciphertext we cannot decrypt.
Connecting a patient portal
When you connect a portal (e.g. MyChart via SMART-on-FHIR), the sign-in and record fetch happen in your browser. The access token stays on your device and is never sent to our server. Records are encrypted before they are stored or synced.
The AI assistant
By default, the assistant and the “scout” run on a model you control (for example a local model on your own machine), so your information stays on your device. If you choose to use a third-party AI provider with your own API key, the text of your request is sent to that provider — the app tells you this and that option is off by default.
What we don't do
- We don’t sell or share your data.
- We don’t use your data to train models.
- We don’t show ads or track you across the web.
Your control
Your data is yours. You can export or delete it. If you forget your passphrase, your recovery code is the only way back in — because of the encryption, we genuinely cannot reset it for you.
Not medical advice
Hopedeck organizes information from your own records and surfaces options and evidence to discuss with your care team. It does not give medical advice and is not a medical device.
Who operates Hopedeck
Hopedeck is operated by Netzinga LLC. The project is mission-first and free to patients and caregivers; we intend to establish a dedicated nonprofit to carry it forward.
Contact
Questions about privacy: privacy@hopedeck.org.
This policy is a working draft pending review by a health-privacy attorney before public launch.