Privacy Policy
Version 2026-06-01
This Privacy Policy explains what protected health information (PHI) DPerspective collects, how that information is safeguarded, and the rights you have over your data as a data subject under GDPR and HIPAA.
PHI Categories Collected
DPerspective collects and stores the following categories of protected health information that you provide:
- Symptoms — symptom logs, severity, and related notes.
- Conditions — diagnosed conditions, severity, onset dates, and notes.
- Medications — medication names, dosages, frequencies, and related conditions.
- Allergies — allergy names, severity, and onset.
- Appointments — appointment titles, providers, locations, and notes.
- Mood entries — mood logs and accompanying notes.
- Weight — body-weight measurements and units.
- EHR records — imported electronic health record payloads.
- Reports — generated report content and summaries.
- Profile health attributes — height, weight, blood type, date of birth, and listed conditions.
Encryption Safeguards
DPerspective applies the following encryption safeguards to your PHI:
- Encryption at rest (AES-256-GCM). Every PHI field is encrypted before it is written to the datastore using AES-256 in Galois/Counter Mode (AES-256-GCM), an authenticated cipher whose authentication tag also detects tampering. Keys are managed by a key-management scheme and are never stored alongside the encrypted data.
- Encryption in transit (TLS). All communication between your device and the Service is encrypted using TLS (Transport Layer Security). Plaintext HTTP requests are redirected to HTTPS, and HTTP Strict Transport Security is enforced.
Indexed identifiers required to locate your records (such as your user identifier) are not PHI and are stored in plaintext only to make lookups possible; no PHI value is stored in plaintext.
Your Rights
As a data subject you have the following rights over your PHI:
- Right of access. You may request a readable export of all PHI that DPerspective holds about you, including a portable FHIR-formatted export.
- Right of erasure. You may request erasure of your PHI. On erasure your PHI documents are deleted from the datastore. PHI-free accountability records of the erasure itself are retained so the action remains auditable.
To exercise these rights, use the access and erasure features in the application. Requests are scoped to your account so that no other data subject’s information is ever returned.
Data Residency
Your PHI is stored exclusively in DPerspective’s self-hosted datastore. It is not transmitted to, or stored by, any external cloud storage provider.