Privacy Policy

Last updated: July 25, 2026

The short version

Jillybean is built around patient control. We do not sell your medical information. We only use your data to create, improve, gather, and share your Medical Passport when you ask us to.

What we collect

  • Account information. We store the basics needed to let you sign in, such as your email address.
  • Launch notification requests. If you ask for iPhone or Android release updates, we use your email address only for the beta and launch notices you selected.
  • Medical Passport data. If you create an account, we store the medical details you enter or approve, including profile details, allergies, medications, conditions, labs, procedures, timeline items, documents, and record sources.
  • Audit logs. We log access events, such as share-link creation and clinical view reads, for your security. These logs are visible to you where the app supports it.
  • Basic usage metrics. We may count operational events, such as email sends or record-source checks, to run and improve the product. No personal health information is included.

What we never do

  • Sell your data to anyone, ever
  • Share your medical information with advertisers
  • Use your medical records for advertising
  • Use expired clinical-share payloads to provide future access
  • Track you across other websites

Encryption

Our production goal is client-first encrypted storage, where medical records are encrypted before they leave your device. During early access, some account-backed passport features store structured records in the Jillybean API while we build the mobile encryption layer. Production deployment environments must use managed encryption at rest and secure transport.

Sharing

When you share your passport via QR code, a temporary session is created that expires after 3 minutes. The receiving party sees a read-only clinical view. After expiration or revocation, the view is no longer accessible through Jillybean. Expiration and revocation cannot erase screenshots, notes, copies, photos, browser data, prints, or emails already received. We log access events for security and user-visible history where supported.

AI features

AI summary generation is not active in the current patient workflow. Any future AI processing of Medical Passport data will require a separate provider, privacy, security, and compliance review plus explicit, versioned consent.

Data deletion

If you have a Jillybean account, you can delete it from the dashboard under Privacy controls. You can also request deletion from the web at jillybean.org/account/delete. Account deletion removes your account, Medical Passport records, document review queue, record sources, share links, and active sessions. Minimal security audit logs may be retained to protect against misuse, fraud, legal, or regulatory risk. Audit logs do not store share tokens or the contents of your medical records. To leave a launch notification list without an account, email support@jillybean.org from the subscribed address.

Children

Caregiver and dependent access is not active in the current preview. The controlled synthetic-data pilot is limited to named adults and must not be used for a child or dependent. We do not knowingly collect personal information from children.

Changes

We'll notify you of material changes to this policy via email (if you're on our APK request list) or in-app notification. The "last updated" date at the top reflects the most recent revision.

Contact

Questions about privacy? Email us at privacy@jillybean.org