Eligibility (18+ Only)
HealStroke is intended strictly for users aged 18 and older. We do not knowingly collect personal information from individuals under 18.
Sensitive Health Data Classification
Given the nature of HealStroke, we treat essentially all user-level recovery information you provide as sensitive health data (or 'special category data' under the GDPR and 'sensitive data' under LGPD and U.S. state laws).
- Stroke diagnosis, type, date, and recovery stage
- Mobility, disability, aphasia, and dysphagia status
- Vitals (blood pressure, heart rate, SpO2)
- Medications and comorbidities
- Therapy goals, results, and exercise completion logs
- Cognitive, vision, and speech assessments
- Speech and audio recordings
- Uploaded medical records, photos, or videos showing disability
- Caregiver relationships and emergency contacts
- Precise location data (only when SOS/emergency features are activated)
- HealthKit and Health Connect data you explicitly authorize
- AI-generated or inferred recovery assessments
- Device IDs and IP/logging data tied to your health account
Explicit Consent
We require your explicit, affirmative consent to process your sensitive health data. This consent is captured during onboarding and recorded in our consent ledger. Under GDPR Article 9, this explicit consent serves as our condition for processing special category data, alongside our Article 6 lawful basis (performance of a contract and explicit consent).
Zero Sale of Health Data & Strict Advertising Separation
We do not sell your personal health information. Furthermore, HealStroke does not sell your personal health information for advertising. Health attributes never enter advertising systems.
We maintain a strict two-plane analytics architecture. Marketing analytics (e.g., installation source, generic events) are kept completely separate from health-product telemetry. We do not send your stroke type, aphasia status, blood pressure, or any other health data to third-party advertising SDKs such as Meta, Google Ads, TikTok, Amplitude, or Mixpanel.
Artificial Intelligence Processing
Certain information may be processed by artificial intelligence systems (such as OpenAI or similar providers) to generate requested responses, educational summaries, or personalized features.
CRITICALLY: HealStroke customer health information is NOT used to train general-purpose AI models. We contractually prohibit our AI subprocessors from retaining your identifiable health data for their own model training.
Provider and Caregiver Sharing
HealStroke does not share your recovery information with your healthcare provider or caregiver unless you specifically choose a feature that explicitly does so (e.g., generating a clinician export or inviting a family member).
Research and Data Use
Any future use of user health histories to train proprietary models, publish stroke research, or build clinical datasets will require separate, distinct, and explicit research consent. It is not bundled into your general use of the app.
Your Rights: Deletion, Export, and Correction
You have the right to access, download/export, correct, and delete your personal information. Deleting your account initiates a comprehensive deletion orchestration process that removes your health database records, object storage records (uploads), AI conversation history, and searchable logs. We also notify applicable processors to delete your data.
International Transfers and Subprocessors
HealStroke utilizes trusted infrastructure providers (subprocessors), including cloud hosting and AI inference services, primarily located in the United States. We maintain a strict subprocessor register and require Data Processing Agreements (DPAs) or Business Associate Agreements (BAAs) where appropriate.
For users outside the U.S., your data will be transferred to the United States. We rely on recognized transfer mechanisms, including Standard Contractual Clauses (SCCs) and adequacy decisions, to safeguard these transfers.
Incident Response and Breach Notification
We maintain a comprehensive incident response plan. In the event of a security compromise affecting your health information, we will notify you and applicable regulators in accordance with strict global standards, including the FTC Health Breach Notification Rule, GDPR 72-hour reporting requirements, and other applicable regional laws.
U.S. State and Regional Privacy Rights
Depending on your jurisdiction, you may have specific rights. For U.S. residents, this includes rights under the Washington My Health My Data Act, Connecticut Data Privacy Act, and California CCPA/CPRA, which govern the collection and strict protection of consumer health data.
For users in the EU, EEA, and UK, you have rights under the GDPR and UK GDPR. Stroke Technology, Inc. is the data controller. We maintain a Data Protection Impact Assessment (DPIA) and Records of Processing Activities (ROPA). If you are an EU or UK resident, you may contact our appointed Article 27 Representative (details to be published on our legal hub upon regional launch).
Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including encryption at rest and in transit. However, no method of transmission over the internet is completely secure.
Privacy Contact and DPO
For privacy-related requests, to exercise your data rights, or to contact our Data Protection Officer (DPO), please email us at privacy@stroke.technology.