Privacy
What is stored, and how it leaves.
Symptra is not HIPAA certified and not FDA-cleared. Those phrases are not used because they would be false.
On this server
An account holds a name, an email, a password hash, and a plan flag. Profiles hold conditions, allergies, medicines, vaccine dates, clinics, emergency contacts, care notes, diary notes, and an optional date of birth. An optional insurance card photo is encrypted like a lab file. An optional PIN can cover the screen on this device after it sits idle. That cover is not a sign-out. Symptra is not HIPAA certified. Visits hold the complaint, symptoms, capture features, lab values, and the written assessment. Those health fields are encrypted at rest. Photos, video, audio, lab files, and the card photo sit in an uploads folder until you delete the visit that holds them. Account deletion is not available yet.
What a capture does
The camera and microphone stay in the browser until you choose to use the take. Quality checks run on the device. There is no advertising pixel on the health pages.
A model key
If an OpenAI key is configured, that visit’s features can be sent to complete the read. Symptra runs a local ranking when no key is set, so a visit does not require that call. The ranking is not a diagnosis.
Your controls
Settings can download a JSON copy. A counsel-reviewed production export is not offered yet. Account deletion is not available yet; it is planned for production. That control does not remove the user, profiles, visits, or files. While you are signed in, a session log lists screens opened and things stored. It does not copy complaints, lab numbers, or files, and it is removed when you sign out. The public access form stores an email only, and it asks you not to include health details. Plus interest stays in this browser and is not sent. An invite code is copied on the device. It is not emailed.
Questions: legalmoneyla@gmail.com.