DoctorVault
Privacy policy

Where your data lives

Your health data lives in storage you own, encrypted before it leaves your browser, under keys only you hold. This page explains what that means — including what we cannot promise.

Last updated August 4, 2026. Plain language for clarity — not a substitute for professional legal advice.

Part 1

Your data stays in your storage

When you use the vault, your records, chats, files, reminders, and profile are stored in a place you control: an S3-compatible bucket (AWS S3, Cloudflare R2, Backblaze B2, MinIO) or a hidden app-data folder in your own Google Drive.

Everything written there is encrypted first, in your browser, with AES-256-GCM. Each encrypted blob is bound to its storage path, so ciphertexts cannot be swapped or replayed. What sits in your bucket is unreadable to your storage provider and unreadable to us.

Part 2

What our servers see — and don't

DoctorVault runs on two hosted origins. Neither receives your health records, encryption keys, storage credentials, or LLM API keys.

doctorvault.ai (the vault app) serves the static application shell only: the landing page, vault UI, legal pages, and a health check. There is no endpoint on this origin that accepts vault payloads.

accounts.doctorvault.ai (the accounts service) is used only if you sign in for DoctorVault Pro. It stores your email address, a signed session cookie, and subscription status. It does not store or process health records, chats, files, reminders, passphrases, recovery codes, storage credentials, or LLM keys.

Our servers never receive:

  • Your health data — not stored, not proxied, not logged on either origin.
  • Your encryption keys— your vault key exists only in your browser's memory while unlocked; wrapped copies live in your storage, not ours.
  • Your storage credentials — S3 keys and Google authorizations are acquired and held in your browser only.

You still trust the application code we serve. A malicious update could betray that trust, which is why the vault contains no analytics or telemetry, and why we document the data boundary plainly on our Security page.

Public pages (landing and legal) may load Google Analytics when we configure a measurement ID at deploy time. That script is never loaded on /vault.

Part 3

DoctorVault Pro and billing

Pro is optional. The free tier includes your encrypted vault, manual records, reminders, AI record import, panel record updates (with review), panel consults (up to three specialists), and keyword search — with your own storage and API keys.

If you upgrade to Pro, checkout and subscription management are handled by Lemon Squeezy, which acts as merchant of record for payment processing. We receive subscription status from Lemon Squeezy webhooks so the vault can unlock Pro features — not your card details, which stay with Lemon Squeezy.

Lemon Squeezy's privacy policy applies to payment data they collect. See our Terms of Service for subscription pricing, renewal, and cancellation.

Part 4

AI chat uses your own provider, under your key

Panel consults are where your health information deliberately leaves your device — and it goes to a provider you choose and pay, not to us. Relevant excerpts from your records and profile are sent directly from your browser to Anthropic or OpenAI using the API key you saved in your vault.

We are not in that path. Review your LLM provider's terms, data retention, and training settings. Use enterprise or opt-out options if you need a stronger posture.

Part 5

Recovery: no escrow, no back door

We cannot reset your passphrase — there is no email reset for data we cannot read. When you create your vault you receive a one-time recovery code and must prove you saved it before storing health data.

  • Forgot your passphrase? Unlock with the recovery code, set a new passphrase, and get a fresh code.
  • Lost the recovery kit but know your passphrase? Issue a new code from settings.
  • Lost both? Your data is unrecoverable — by design. Nobody, including us, can get it back.

Part 6

Reminders: a deliberate trade-off

Reminders are computed on your device and delivered through browser notifications while the app is open. There is no push notification service, because operating one would require our servers to see your reminder schedule.

Part 7

Deletion that actually deletes

“Delete my vault” wipes every object from your storage. Because your storage holds the only copy, this is true deletion — there is no server-side replica for us to forget about.

Signing out of DoctorVault Pro or canceling a subscription does not delete your vault. Your encrypted data remains in your storage until you delete it.

Part 8

Compliance scope (including HIPAA)

DoctorVault is designed for personal use by individuals managing their own health information. It is not HIPAA-compliant, not certified as a medical device, and not intended for clinics, covered entities, business associates, or any scenario where regulated protected health information must be handled under HIPAA or similar frameworks without a separate compliance program.

Our architecture reduces custody risk — we do not store your vault contents on our servers — but that is not the same as HIPAA compliance. You are responsible for how you use the product and whether your use case requires formal compliance review.

See also our Terms of Service for medical disclaimers and limitations of liability.