What this covers
Two different things, with almost nothing in common. This website, which anyone can read and which collects one form. And the app, which is end-to-end encrypted and collects far less than a website normally would.
Where the app handles Protected Health Information for a provider, the Business Associate Agreement governs it and controls over anything here that conflicts.
The short version
- Ciphertext we have no key for, and never had one.
- A provider’s name, work email, NPI and plan.
- A count of how many patients a provider has connected.
- Roughly when data arrived, to the hour.
- Any patient’s name, email or phone number.
- What was logged, when a patient logged it, or how it was rated.
- Anything either party wrote, or what any color means.
- Any way to tell which patient a connection belongs to, or that two connections are the same person.
This website
The early access form asks for your name, your work email and three multiple-choice answers about your practice. It reaches our inbox through Schoodic Mailer, an ordinary mail relay that is not covered by any Business Associate Agreement, so keep patient information out of it.
The form is protected by Cloudflare Turnstile, which sees the IP address that solved its challenge. The typefaces load from Google Fonts, which sees the IP address and browser of anyone who loads a page. Netlify serves the site and keeps its own request logs. Page views are counted by Umami, which sees the same request details the others do and sets no cookie.
No advertising, no tracking pixels, no third-party cookies. The one thing this site stores in your browser is which color palette you picked, in local storage, so the board looks the same when you come back. Clearing site data removes it.
Your account, if you are a provider
We hold what a business tool holds about a professional customer:
- Your name and work email.
- Your NPI, and the result of checking it against NPPES.
- Which version of the Business Associate Agreement you accepted, and when.
- Public keys for the devices you have enrolled, and their hardware attestation.
- Your plan, and on the paid plans a billing record held by our payment processor. We never see a card number.
- On the Group plan, seat assignments and audit logs of which device read which connection. Those logs cover access, never content.
Your patients
A patient has no account with us. There is no row to hold a name, because there is no name to hold, and no email address or phone number was ever asked for. What a connection consists of, on our side, is a public key and a state.
The map from a connection to the person it belongs to lives encrypted on your own devices and nowhere else. The link you need and the link our database would have had were never the same link.
Logs
Our access logs keep no IP addresses. What they do hold is kept for 7 days and contains no content. What that does and does not protect against is set out on the security page.
What we do with what we hold
We use it to run the service, keep it available, bill for it, verify licenses, and answer support requests. That is the whole list.
We do not sell it, rent it, or share it for advertising. We do not use it to train machine-learning models. We do not de-identify it or derive datasets from it.
Who else touches it
| Who | What they do | What reaches them |
|---|---|---|
| [Hosting provider] | Runs the sync server and its backups | Ciphertext, provider account rows, sealed key material, and the hour a record arrived. No key that opens any of it. |
| [Payment processor] | Subscription billing on the Solo and Group plans | Your name, email and card details. Nothing from any patient connection, and we never see or store a card number. |
| Netlify | Hosts bronwin.xyz | Requests to this website. Nothing from the app, which does not talk to it. |
| Cloudflare | The anti-spam check on the early access form | The challenge itself and the IP address that solved it. |
| Google Fonts | Serves the typefaces on this website | The IP address and browser of anyone who loads a page here. |
| Schoodic Mailer | Delivers the early access form to our inbox | The name, work email and three answers on that form. |
Each one that handles Protected Health Information is under its own Business Associate Agreement. Providers get 30 days’ notice by email before a new one is added.
When someone comes with a subpoena
We comply with valid legal process, and what we can produce under it is the same pile described above: ciphertext, a provider’s identity, a count, and hours. We cannot produce what a patient logged, what it meant, or who they are, because we do not have it and there is no mechanism by which we could obtain it.
Where a demand covers 42 CFR Part 2 records we will resist it absent a court order meeting §2.64 or §2.65. We notify the affected provider unless we are legally prohibited from doing so, and we do not notify patients because we have no way to reach them.
How long we keep things
- Early access form submissions: until the cohort closes, then deleted.
- Provider account records: for as long as the account is open.
- Ciphertext and connection rows: until the connection is revoked or the account closes, then deleted within 30 days and gone from backups within 35 days.
- Access logs: 7 days.
- Records of which Business Associate Agreement version was accepted, and billing records: as long as law or accounting requires, after which they go too.
Your choices
If you are a patient: you can disconnect at any time, without asking your provider, which stops anything new from being shared. What your provider already has, they keep — the same as any notes they have taken about you. Deleting the app from your phone destroys your own copy and your own keys, and we cannot restore either.
If you are a provider: you can see, correct or export your account data, and closing your account triggers the deletion described above. Export what you need first; we cannot recover it afterward.
Consumer health data, and state rights
This section is our consumer health data privacy policy for the purposes of Washington’s My Health My Data Act and Nevada SB370.
- What consumer health data we collect. From a patient: nothing that identifies them, and no readable health information at all — only ciphertext we cannot open, a per-connection public key, and the hour something arrived. From a provider: the account details listed above, which identify a clinician rather than a patient.
- Where it comes from. Directly from the app on your own device. We collect none of it from third parties, data brokers or public sources.
- Why we collect it. To deliver the service you asked for, and for nothing else.
- Who we share it with. Only the subprocessors listed above, in the roles listed. We do not share it with anyone else, and we do not sell it. Washington requires a signed authorization for any sale of consumer health data; we have never sought one.
- Your rights. You may confirm whether we hold data about you, see what we hold, withdraw your consent, and have it deleted. Write to privacy@bronwin.xyz. We answer within 45 days and will tell you if we need a permitted extension. If we refuse, you may appeal to the same address, and if the appeal is denied you may complain to the Washington Attorney General.
California residents have the rights the CCPA gives them, and California’s Confidentiality of Medical Information Act applies to us regardless of the encryption — the same address handles those requests. We do not discriminate against anyone for exercising a privacy right; there is no service tier that depends on giving up one.
Security, and where it stops
Content is encrypted on the device under keys held in hardware-backed storage, sealed behind a PIN that never leaves the phone. Transport is TLS. The server authenticates the caller, moves the blob, and performs no cryptography over your content.
Two limits, both stated in full on the security page. We route the first key exchange, so a dishonest or compelled operator could in principle insert itself into it — which is what the in-person safety number check exists to catch. And transport-level correlation remains possible for whoever can watch the network, which is why we keep no addresses in our own logs.
If something goes wrong
For Protected Health Information, we notify the provider, who notifies their patients — that is how the Breach Notification Rule runs for a Business Associate, and it is also the only way it could work here, since we have no way to reach a patient directly. We report within five business days of discovery, and we say plainly what was and was not covered by encryption.
Where state law requires us to notify someone directly, we will, using whatever contact information we hold — which for a patient is none.
Who can use Bronwin
Adults 18 and over, in the United States, through a licensed clinician. Providers attest to both age and the treatment relationship when they connect someone, because they are the ones in a position to know. We do not knowingly hold data about anyone under 18; if we learn a connection covers a minor, we suspend it and tell the provider.
We do not offer the service in the EU, the UK or Switzerland, and the app is not distributed there.
Changes, and how to reach us
This policy is versioned and dated at the top. Material changes are emailed to providers at least 30 days before they take effect, and previous versions stay available.
[Legal entity], [Notice address]. privacy@bronwin.xyz for anything on this page.