S
Syntropy Health
Privacy Policy & Data Use Disclosure

Patient Data Privacy Policy

Last Updated: September 2026 • Compliant with ONC USCDI & Epic Data Use Standards

Key Summary:

Syntropy Health is designed as a local-first, self-hosted personal health record platform. Syntropy Labs does not host, collect, process, sell, or transmit your protected health information (PHI) to any cloud servers or third parties. All medical records remain exclusively under your direct physical and cryptographic custody on your personal device.

1. Data Sovereignty & Architecture

Syntropy Health empowers individuals to aggregate and view their own longitudinal medical records under the rights established by HIPAA and the 21st Century Cures Act. The application operates using a client-side and self-hosted model:

  • Connections established via SMART on FHIR communicate directly and point-to-point between your local device and your healthcare institution (e.g. Kaiser Permanente, Epic MyChart).
  • Tokens, diagnostic results, vital signs, medications, and conditions are cached exclusively in local memory and local database files on your own hardware.
  • The domain health.syntropylabs.io acts solely as a zero-knowledge static relay to route OAuth callbacks into your local runtime. It does not possess a backend database and cannot log or intercept health records.

2. Categories of Data Accessed

When you explicitly authorize access through your health network's patient portal, Syntropy Health requests access strictly to authorized standard USCDI clinical resources:

  • Demographics: Patient legal name, date of birth, gender, and identifier.
  • Observations: Diagnostic laboratory panels, vital signs, and clinical measurements.
  • Medication Requests: Active and past prescribed medications, dosage instructions, and schedules.
  • Conditions: Problem lists, active diagnoses, and clinical status.

3. Prohibition of Commercialization & Third-Party Sharing

Syntropy Labs enforces an absolute prohibition on data commercialization:

  • No Sale of Data: We never sell, lease, rent, or trade your personal or health data.
  • No Advertising: Syntropy Health contains zero advertisements, tracker scripts, or third-party behavioral pixels.
  • No Data Brokering: No clinical records are made available to insurers, pharmaceutical companies, data brokers, or AI model aggregators.

4. Cryptographic Security & Transmission

All communication with clinical health networks utilizes industry-standard security protocols:

  • OAuth 2.0 with PKCE (RFC 7636): Standalone authorization uses high-entropy SHA-256 Proof Key for Code Exchange to prevent authorization code interception.
  • End-to-End Transport Layer Security: All API requests to EHR endpoints are protected via TLS 1.2+ encryption.

5. Data Retention, Export & Deletion

Because Syntropy Health runs locally under your control, you maintain total authority over data retention:

  • You can disconnect and wipe all local cached patient records, sessions, and tokens with a single click in the user interface.
  • Deleting the application directory or local database completely removes all stored data from your physical machine.
  • You may revoke Syntropy Health's access at any time through your healthcare provider's MyChart application settings.

6. Contact & Inquiries

For questions regarding this privacy policy or the local-first architecture of Syntropy Health, contact:

Syntropy Labs • security@syntropylabs.io