Trust & Safety

Compliance & safeguards

HealthNaviq is a personal health record. It is not a covered entity under HIPAA, but we apply HIPAA-style safeguards to the health data you trust us with.

User consent, first

Before you use the app, you review and accept a HIPAA-style privacy notice, a medical-use disclaimer, and our Terms. Your acceptance is stored with a timestamp and the notice version. You can withdraw consent by deleting your account from Settings → Privacy.

Encryption in transit and at rest

All traffic between your device and HealthNaviq uses TLS 1.2+. Your health records, uploaded documents, notes, and connected-service data are stored in our managed database with disk-level encryption (AES-256) and row-level security scoping every read to your account.

Encrypted third-party tokens

OAuth access and refresh tokens for connected services (e.g. Google Health, Dexcom) are stored encrypted server-side, never exposed to the browser, and used only from server code to sync data you have explicitly connected. Disconnecting an integration deletes the stored tokens.

Audit logs for sensitive actions

Reads, exports, sharing, and administrative actions on protected health information are recorded in an append-only audit log. You can review your own access log from Settings → Privacy. Administrative actions are recorded separately in an admin audit log.

Role-based access control

Every table enforces row-level security so users can only see their own data by default. Family/care access is granted via explicit, revocable invites at one of four levels (Emergency, View, Manage, Full). Admin capabilities require a role stored server-side in a separate roles table and cannot be self-assigned.

Minimum-necessary data

We request the smallest set of permissions and scopes needed to power a feature you turned on. Read-only wherever possible. Connected-service data is limited to what appears on your dashboards and reports.

Retention & deletion

You can export or delete your data from within the app. Disconnecting an integration removes the tokens immediately and its imported data within 30 days. Deleting your account removes personal data on the same schedule, subject to legal retention obligations.

Not a substitute for medical care

HealthNaviq helps you organize your health information. It does not diagnose, treat, cure, or prevent any disease and is not a replacement for advice from a licensed clinician. In an emergency, call your local emergency number.

Medical disclaimer

Content shown in HealthNaviq — including AI-generated summaries, nutrition scores, and reminders — is for informational and organizational purposes only. It is not medical advice, diagnosis, or treatment. Always seek the guidance of a qualified healthcare provider with any questions about a medical condition.

Questions or a security concern? Contact us at security@healthnaviq.com. This page is maintained by the HealthNaviq team and describes the safeguards currently enabled in the product; it is not an independent certification.