HealthTrajectory Privacy Policy
Last updated September 16, 2026 · Applies to the HealthTrajectory application
HealthTrajectory is an educational tool, not a medical device. It does not diagnose, treat, cure or prevent any disease, and nothing it shows you is medical advice. AI-generated insights can be incomplete or wrong. Always talk to a qualified clinician about your health, and if you think you are having a medical emergency, call 911 or your local emergency number immediately — do not use this app.
The short version: HealthTrajectory collects health information because that is what it exists to organise. We do not sell it, we do not use it to advertise to you, and we do not share it with anyone except the service providers needed to run the app. You can export it or delete it permanently at any time, and you can disconnect any provider integration without losing your account.
1. Scope and who we are
This Privacy Policy explains how Espyeon LLC (“Espyeon”, “we”, “us”) collects, uses, discloses and protects information in connection with the HealthTrajectory application and related services (the “App”). Espyeon LLC is the controller of that information.
It applies in addition to the Espyeon company Privacy Policy. Where the two differ on anything specific to HealthTrajectory, this document controls. The technical controls behind it are described in the Data Security & HIPAA Framework.
Contact us about anything in this policy at Contact@espyeon.com.
2. Our regulatory position, stated plainly
HealthTrajectory is a consumer application, and in most cases we are not a HIPAA covered entity or business associate. When you direct your own records to a standalone consumer app that you chose, the app generally falls under Federal Trade Commission consumer protection law rather than HIPAA — including the FTC Health Breach Notification Rule, which applies to apps like this one.
We say this plainly because it matters to you: health information in HealthTrajectory does not carry the same federal protections it had while it sat with your provider. We therefore engineer to HIPAA Security Rule standards by choice, and commit to the practices in this policy contractually. But you should understand which protections are legal obligations and which are our commitments, and this is the latter.
3. Information we collect
Information you give us
- Account information — your name, email address and authentication credentials. Passwords are stored only as salted cryptographic hashes, never in a readable form.
- Health information you enter — bloodwork and other lab values, conditions, procedures, medications, family history, symptoms and notes.
- Lifestyle and diet information — sleep, activity, dietary intake and related habits you choose to log.
- Correspondence — what you write to us for support.
Information from your healthcare provider
Where you explicitly authorise it, we retrieve records from your electronic health record through Epic’s FHIR / SMART on FHIR integration. The retrieval is limited to the scopes you approved at your provider’s authorisation screen, and may include problems, medications, allergies, immunisations, laboratory results, vitals, procedures and encounter history. We never receive your provider portal password — authorisation happens on your provider’s system, not ours.
Information collected automatically
- Technical and diagnostic data — device model, OS version, app version, crash reports and error traces, used to keep the App working.
- Security and audit records — authentication events, API calls and record-access events, retained to detect misuse and to give you an account of who touched what.
HealthTrajectory does not use third-party advertising SDKs, cross-app tracking identifiers, or advertising identifiers.
4. How we use your information
We use it only for these purposes:
- to operate the App and give you the features you asked for;
- to generate the trends, educational insights, areas worth attention and lifestyle suggestions the App exists to produce — this involves automated and AI processing of the health information you provide;
- to authenticate you and keep your account secure;
- to connect to, and retrieve from, integrations you authorise;
- to answer your support requests;
- to detect, investigate and prevent fraud, abuse and security incidents;
- to fix defects and improve reliability, using aggregated or de-identified information wherever that is sufficient; and
- to comply with law and to establish or defend legal claims.
What we do not do with it. We do not sell your personal or health information. We do not share it for advertising of any kind, behavioural or contextual. We do not use it to build advertising or marketing profiles. We do not use your health information to train third-party foundation models, and we do not permit our AI providers to train on it.
Legal bases (EEA/UK). Where GDPR applies, we rely on your explicit consent for processing health data, which is a special category under Article 9 and which you may withdraw at any time; performance of a contract to deliver the App; legitimate interests for security and abuse prevention; and legal obligation where the law requires retention or disclosure.
5. Automated and AI processing
Generating insights means your health information is processed by automated systems, and in some cases transmitted to an AI model provider acting as our processor under contract. Where that happens:
- transmission is encrypted;
- the provider is contractually prohibited from using your data to train its models or for any purpose other than returning a result to us;
- we send the minimum context needed to produce the output, not your entire record; and
- we do not send your name or contact details as part of that context.
No automated decision producing legal or similarly significant effects is made about you. The App’s output is educational, is not a diagnosis, and is not used to determine your eligibility for anything. The Terms & Conditions explain the limits of that output, and they are worth reading.
7. How we protect it
Health information is protected with encryption in transit (TLS 1.3), encryption at rest (AES-256), OAuth 2.0 and SMART on FHIR for authorisation, role-based internal access limited to what the platform requires to function, multi-factor authentication on administrative systems, and audit logging across authentication and record access.
The Data Security & HIPAA Framework sets out the architecture in detail.
No system is perfectly secure, and we do not claim otherwise. You can materially reduce your own risk by using a unique password and enabling every authentication factor the App offers.
8. If there is a breach
As a consumer health application we are subject to the FTC Health Breach Notification Rule. If your identifiable health information is acquired without your authorisation, we will notify you — and, where the Rule requires, the Federal Trade Commission and the media — without unreasonable delay and in any event within sixty (60) calendar days of discovery. We will tell you what happened, what information was involved, what we have done, and what you can do. We will also comply with every applicable state breach notification law, several of which require faster notice.
9. How long we keep it
- Account and health information — for as long as your account is open. Deletion follows the schedule on the Account & Data Deletion page.
- Records retrieved from a provider — kept until you delete them or your account. Disconnecting an integration stops future retrieval but does not by itself delete what was already retrieved.
- Security and audit logs — up to twelve (12) months.
- Support correspondence — up to twenty-four (24) months.
- Transaction records — as long as tax and accounting law requires, generally seven years. These contain no health information.
10. Your rights and choices
Whatever jurisdiction you are in, HealthTrajectory gives you the ability to:
- See everything held about you, in the App itself;
- Correct anything you entered — records retrieved from a provider must be corrected with that provider, because they hold the source of truth;
- Export your data in a portable, machine-readable format;
- Delete individual records, an entire integration, or your whole account, permanently;
- Disconnect any provider integration at any time; and
- Withdraw consent to health-data processing, which means closing your account, since the App cannot function without it.
Depending on where you live you may also have statutory rights to restrict or object to processing, to non-discrimination for exercising a right, and to appeal a refusal. We do not charge for any request and will not degrade your service for making one.
How to exercise them. Use the controls in the App, or email Contact@espyeon.com from your account address. We verify every request before acting, because deletion is irreversible and we will not let someone else delete your records. We respond within the period the applicable law requires — generally 30 days under GDPR and 45 days under most US state laws.
11. US consumer health data laws
Washington (My Health My Data Act) and Nevada (SB 370). Consumer health data collected by HealthTrajectory is used only to provide the App as described in section 4. We do not sell consumer health data, and we would not do so without the separate signed authorisation those statutes require. Washington residents may exercise their rights to access, delete and withdraw consent by emailing us, and may appeal any refusal by replying to our response.
California. Health information is sensitive personal information under the CCPA as amended. We use it only for the purposes in section 4 — all of which are purposes for which the statute does not require an opt-out — and we do not sell or share it. You have the rights to know, delete, correct, and to non-discrimination, and we honour Global Privacy Control signals.
Other states. Residents of states with comprehensive privacy laws have equivalent rights to access, correct, delete, port and appeal, and we treat health information as sensitive data requiring consent in every one of them.
12. Children
HealthTrajectory is for adults. You must be 18 or older to create an account, and the App is not directed to children. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account or that their information has been entered, contact Contact@espyeon.com and we will delete it promptly.
13. International data transfers
We operate in the United States and our service providers may process data there and in other countries. Where we transfer personal information out of the EEA, the UK or Switzerland we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK Addendum, together with encryption and access controls. You may request a copy of the relevant safeguards from us.
14. Changes to this policy
We may update this policy. We will change the date at the top and, for any material change to how we handle health information already collected, we will give you notice in the App or by email and — where the change requires it — ask for your consent before it applies to you. We will not retroactively reduce the protections applying to information already collected without asking you first.
15. Contact us
For any privacy question, request or complaint, email Contact@espyeon.com. Our company details are on the About page. EEA, UK and Swiss residents have the right to complain to their supervisory authority, and we would appreciate the chance to resolve the matter first.
Questions about this document? Write to Contact@espyeon.com.