Privacy Policy

Last updated: September 8, 2026

The short version

Jillybean is built around patient control. We do not sell your medical information. We only use your data to create, improve, gather, and share your Medical Passport when you ask us to.

What we collect

  • Account information. We store the basics needed to let you sign in, such as your email address.
  • Launch notification requests. If you ask for iPhone or Android release updates, we use your email address only for the beta and launch notices you selected.
  • Medical Passport data. If you create an account, we store the medical details you enter or approve, including profile details, allergies, medications, conditions, labs, procedures, timeline items, documents, and record sources.
  • Audit logs. We log access events, such as share-link creation and clinical view reads, for your security. These logs are visible to you where the app supports it.
  • Basic usage metrics. We may count operational events, such as email sends or record-source checks, to run and improve the product. No personal health information is included.

What we never do

  • Sell your data to anyone, ever
  • Share your medical information with advertisers
  • Use your medical records for advertising
  • Use expired clinical-share payloads to provide future access
  • Track you across other websites

Encryption

The authoritative browser passport uses client-first encrypted storage, where medical records are encrypted before they leave the authorized browser. The Android companion currently hands record updates to that browser vault rather than maintaining a separate authoritative native vault. Deployment environments use managed encryption at rest and secure transport.

Sharing

When you share your passport via QR code, a temporary session is created that expires after 3 minutes. The receiving party sees a read-only clinical view. After expiration or revocation, the view is no longer accessible through Jillybean. Expiration and revocation cannot erase screenshots, notes, copies, photos, browser data, prints, or emails already received. We log access events for security and user-visible history where supported.

Who can see your information

Your medical records are encrypted on your own device before they reach us, so Jillybean staff cannot read them. What we hold is scrambled text we have no key for. We can see account basics such as your email address, and security audit logs, which we look at only to keep accounts safe, investigate abuse, fix a fault you report, or when the law requires it. The people who can see your actual medical information are you, and anyone you choose to share with.

Companies that help us run Jillybean

We use a small number of service providers to operate the product: Railway for application hosting and the database, Cloudflare for the website, Resend for account email such as sign-in and verification messages, and Stripe for payments if you buy a paid plan. These companies process only what they need for that job, act on our instructions, and are not permitted to use your information for their own purposes. Because your medical records are encrypted before they leave your device, our hosting and database providers store only encrypted content they cannot read. We do not sell your data, and we do not share your medical information with data brokers, advertisers, or researchers.

Sharing that affects other people

Some health information says something about your relatives as well as you. Family history, inherited conditions, and genetic results are the clearest examples: sharing them can reveal risk information about a parent, sibling, or child who never agreed to it. Jillybean does not request genetic data, but you can type anything you like into your passport. Before you share, please look at what the other person will see and consider whether it tells them something about someone else. Once a share has been viewed, we cannot take that knowledge back.

AI features

AI summary generation is not active in the current patient workflow. Any future AI processing of Medical Passport data will require a separate provider, privacy, security, and compliance review plus explicit, versioned consent.

Medicare records

Medicare is the only automated record source in Jillybean, and it is entirely your choice. Nothing is requested from Medicare until you pick Medicare records and sign in on the official Medicare site. Jillybean never sees or stores your Medicare username or password.

What we collect. With your permission, Jillybean requests your Medicare profile, coverage, and claims records (including diagnoses, procedures, services, and prescription claims). We request only these records and only for the account that authorized them.

Why. To build your medical history for you, so you can find it, review it, and show it to a clinician without calling every office yourself.

How it is stored. Imported Medicare records are encrypted on your device and saved into your encrypted passport. Claim details are shown to you as suggestions first; a claim only becomes a condition, procedure, or medication in your passport after you review and confirm it. A claim is evidence that something was billed, not confirmation of a diagnosis.

How to disconnect. You can disconnect Medicare at any time from Record sources. Disconnecting revokes Jillybean's access with Medicare and deletes the stored authorization from our systems, so no further records can be requested. Records already imported stay in your passport until you delete them.

How to delete. Delete individual imported records from your passport, or delete your whole account to remove them along with everything else. We never sell Medicare data, never use it for advertising, and never share it with anyone you have not chosen.

This product uses the Blue Button APIs but is not endorsed or certified by the Centers for Medicare & Medicaid Services or the U.S. Department of Health and Human Services.

Data deletion

If you have a Jillybean account, you can delete it from the dashboard under Privacy controls. You can also request deletion from the web at jillybean.org/account/delete. Account deletion removes your account, Medical Passport records, document review queue, record sources, share links, and active sessions. Minimal security audit logs may be retained to protect against misuse, fraud, legal, or regulatory risk. Audit logs do not store share tokens or the contents of your medical records. To leave a launch notification list without an account, email support@jillybean.org from the subscribed address.

Withdrawing your permission

You can withdraw permission at any time, and you do not have to close your account to do it. Disconnecting Medicare in Record sources revokes our access with Medicare and deletes the stored authorization, so nothing further can be requested. Revoking a share stops future access through Jillybean. Deleting a record removes it from your passport. Deleting your account removes everything described above. Withdrawing permission does not reach copies another person already saved, printed, or screenshotted while a share was active.

Dormant and closed accounts

We do not delete your records for being inactive. Your passport stays yours whether you sign in weekly or once a year, because a medical record you rarely open is still the one you need in an emergency. If an account is unused for two years, we will email the address on file before taking any action, and you can keep the account simply by signing in. If that address is no longer reachable and the account stays dormant for a further 90 days, we may close it and delete its contents. Closing an account, whether you close it or we do, deletes the passport records, document review queue, record sources, share links, and sessions, and disconnects any connected record source. We keep only the minimal security audit logs described above.

Children

Jillybean accounts are currently intended for adults. Child and dependent account workflows are not available, and we do not knowingly collect personal information from children.

If Jillybean changes hands

If Jillybean is ever sold, merged, or transferred to another company, your information could move with it. If that happens, we will tell you by email and in the app before the change takes effect, and we will tell you what the new operator intends to do. If their intended use of your information is materially different from this policy, you will be able to export your passport and delete your account first, and we will not apply the new use to your data without your agreement. Where a connected record source such as Medicare is involved, we will also notify the agency or program that granted that access. We will not use a sale as a way to hand your medical information to someone who would use it in a manner you did not agree to.

Changes

We'll notify you of material changes to this policy via email (if you're on our APK request list) or in-app notification. The "last updated" date at the top reflects the most recent revision.

Contact

Questions about privacy? Email us at privacy@jillybean.org