Privacy & Security Policy
Private by design. Shared only by choice.
This policy explains how ChartNest Inc. handles information in the ChartNest iOS app and on the ChartNest website. The app is local-first, and website information stays separate from private app care records.
Policy scope
One policy for the app and website.
Effective July 22, 2026. This policy applies to the ChartNest iOS app, chartnest.app, website forms, first-party website analytics, support inquiries, and related privacy requests. It should be read with the Terms and Medical Disclaimer.
Questions can be sent to contact@chartnest.app. Do not include medical records, diagnoses, medication details, patient names, or document contents in ordinary email or website forms.
| Area | What this policy covers | Primary boundary |
|---|---|---|
| iOS app | Care records, documents, settings, purchases, local reminders, exports, iCloud backup, and configured collaboration. | Ordinary care records begin on the user's device and are not submitted through the ChartNest website. |
| Website | Contact and inquiry forms, consent records, limited first-party analytics, support conversations, and data requests. | Website forms are not intended for medical records or private health details. |
Local-first
Core care records start on the device.
Care profiles, medications, appointments, notes, tasks, documents, loops, and many review records are designed around local organization. The app does not require a ChartNest account, and ordinary local care records are not sent to a ChartNest-operated app server. Local-first is not the same as absolute local-only. Export, share, iCloud backup, App Store services, and configured sharing workflows are explicit exceptions.
App information
The app processes the records you choose to create.
ChartNest uses app information to organize the selected care profile, operate requested features, prepare user-reviewed outputs, remember settings, and show the access level recognized through Apple. The app is not designed to sell care information, build advertising profiles, or track users across other companies' apps and websites.
| Information category | Examples | Why it is used | Where it begins |
|---|---|---|---|
| Care and profile content | Names, contact context, medications, allergies, history, appointments, notes, tasks, documents, forms, reports, and review records entered or imported by the user. | Organize records, prepare workflows, and create selected outputs. | On the user's device. |
| Files and document context | Imported files, scans, photos, titles, categories, dates, reminders, and source notes. | Keep source material findable and available to selected app workflows. | On the user's device; attached file bytes may remain device-local. |
| Settings and app state | Preferences, app-lock timing, reminder choices, notification status, feature state, and local audit or review context. | Operate the app and preserve user choices. | On the user's device. |
| Purchase access | Apple product metadata, entitlement state, and recognized transaction status. | Display plans, unlock purchased access, and restore purchases. | Handled through Apple's App Store and StoreKit services. |
| Optional iCloud information | Eligible backup records, recovery points, sync state, document metadata, and selected Care Circle content where configured. | Provide user-enabled automatic or manual backup, supported-device continuity, recovery, restore, or permissioned collaboration. | Sent to the user's Apple iCloud context only through the relevant feature. |
Advanced app features
Capture, search, answers, connected data, and portability stay purpose-limited.
Advanced features use only the information needed for the action the user chooses. Captured or imported details remain reviewable before authoritative records change, Ask ChartNest cites authorized sources, optional Apple Health access follows the user's selected permissions, and exported files leave app control when the user sends or saves them elsewhere.
| Feature | Information involved | Processing and control | Boundary |
|---|---|---|---|
| Document text recognition and search | Supported scans, photos, PDFs, extracted text, corrections, and search terms. | Apple on-device text-recognition frameworks extract searchable text; users can review, correct, or reprocess it. | Text extraction is not medical interpretation or clinical verification. |
| Smart Capture | Selected labels, cards, notices, reports, instructions, invoices, claims, receipts, documents, and codes. | Possible details become drafts that the user reviews, edits, accepts, or rejects before authoritative records change. | Recognition quality varies, and ChartNest does not silently replace a current record. |
| Ask ChartNest | The question, authorized local or shared records, search indexes, citations, and linked source records. | The current implementation searches authorized ChartNest information locally and returns source-cited organizational answers or states that information was not found. | It does not use an external medical knowledge service, train an external model with app records, or answer diagnosis, treatment, dosage, prognosis, or triage questions. |
| Optional Apple Health | Only selected supported categories and source context allowed by the user. | Read-only access follows Apple permission controls; users can disconnect access or delete connected information through available controls. | Availability depends on device, region, support, release, and permission, and it is not continuous medical or emergency monitoring. |
| Administration and refill planning | Providers, referrals, insurance, claims, expenses, receipts, communication notes, pharmacy details, quantities, dates, and user-entered estimates. | ChartNest organizes the information, reminders, assignments, and selected reports the user maintains. | It does not guarantee coverage, reimbursement, claim acceptance, pharmacy ordering, dosage changes, or provider integration. |
| Standards-aware import and export | Supported FHIR R4 JSON, C-CDA/XML, CSV, ChartNest archives, PDF output, validation results, conflicts, and provenance. | Users preview sources, review duplicates or conflicts, confirm imports, and choose export content and destination. | ChartNest does not claim formal FHIR certification or universal compatibility with every provider or hospital system. |
iCloud
Backup begins with user choice and uses the user's Apple account.
Plus and Family backup remain optional and begin only after the user enables the iCloud feature. After opt-in, ChartNest can back up eligible records after meaningful changes, retain manual Back Up Now control, show status or failure information, retry when appropriate, support continuity across compatible devices, and present recent recovery points. Backup language stays qualified because timing depends on Apple services and network conditions, and attached document files may remain device-local in metadata-only behavior.
| Action | Who initiates | What is stored | What is not promised |
|---|---|---|---|
| Enable backup | The user through app settings where configured. | Eligible app records, backup status, and supported recovery information in the user's Apple iCloud context. | ChartNest web account storage, automatic provider sync, or a guarantee against every form of loss. |
| Automatic and manual backup | Automatic backup can run after meaningful changes only after opt-in; the user can also choose Back Up Now. | Eligible supported record data and document metadata. | Instant completion under every network condition or inclusion of every attached document file byte. |
| Continuity and recovery | The user reviews sync status or selects a recovery point and restore action. | Supported same-user continuity data and recent recovery points available to the feature. | A substitute for separately preserving important original files or every exported copy. |
| Restore backup | The user on their own device and Apple account. | Eligible backed-up record data. | Guaranteed recovery of every attached document file byte. |
| Export separately | The user when they choose an export path. | Selected PDF, text, JSON, or Health Bundle output. | Automatic sharing or submission. |
Apple platform services
Apple handles purchases, iCloud, notifications, and chosen shares.
ChartNest uses Apple platform services when the user requests the related feature. Apple processes those services under the user's Apple account, device settings, and Apple's own terms and privacy practices.
- StoreKit and the App Store handle product information, purchases, subscriptions, billing, and restore behavior. ChartNest does not receive payment-card details.
- CloudKit and iCloud handle eligible private backups, supported-device continuity, recovery information, and configured shared records under the user's Apple account.
- Apple Health provides optional read-only categories only after the user grants the requested permissions.
- Local notifications are scheduled on the device for reminders or user-defined routines the user enables and require iOS permission.
- When present in a validated released build, App Intents, Spotlight, widgets, Live Activities, deep links, or companion surfaces can expose selected actions or authorized information through Apple system controls.
- The iOS share sheet sends selected text or files only to the destination the user chooses.
User-controlled sharing
Exports and summaries are selected.
ChartNest can support selected text shares, PDF packets, local JSON and ChartNest archives, CSV, supported standards-aware exports, offline packets, and Health Bundle output. Users should review exports before sending them. ChartNest does not turn private records into a public web account.
| Choice | User control | Boundary |
|---|---|---|
| Text share | Select the content and recipient. | Not an automatic sync or ongoing feed. |
| PDF packet | Choose the packet scope and review before sending. | Not an official medical record. |
| Local JSON | Export where entitlement and configuration allow. | Not a clinical exchange guarantee. |
| Health Bundle | Create a selected structured export. | FHIR-inspired organization, not certified FHIR. |
| Supported FHIR R4, C-CDA, CSV, or archive | Preview selected source data or choose the records and destination for export. | Not certification, universal compatibility, automatic provider integration, or a replacement for source records. |
| Emergency or travel packet | Choose the fields, documents, contacts, and offline content that belong in the packet. | Not a replacement for emergency services, Apple Medical ID, professional advice, or a medication-timing recommendation. |
| Care Circle | Grant limited sharing where configured. | Not whole-archive exposure by default. |
Family access and collaboration
Sharing is explicit, permission-aware, and reviewable.
Family collaboration uses the user's Apple iCloud context and applies only to Care Circles the owner creates or joins. Roles, profile access, section permissions, temporary or guest windows, shared Apple Health snapshots, invitations, acknowledgments, approvals, and important access changes remain under the available Family controls.
| Family control | What it does | Privacy boundary |
|---|---|---|
| Roles and sections | Assign Owner, Organizer/Editor, or Viewer access and choose the profiles and sections a person can use. | Members see only the profiles and sections their permissions allow. |
| Tasks, activity, and handoffs | Share selected responsibilities, important updates, user-written instructions, acknowledgments, and expiration details. | A shared workflow exposes only the content and actions authorized for that member. |
| Temporary or guest access | Set selected profiles, sections, tasks or shifts, role, start date, end date, and revocation. | Access can expire or be revoked and does not create provider status or legal authority. |
| Inbox and approvals | Collect incoming drafts and let authorized members propose, compare, accept, partially accept, reject, or clarify changes. | Draft information does not silently replace a current record. |
| Consent and audit controls | Review members, roles, permissions, invitations, selected sharing, and important access or change history. | Users remain responsible for recipient choices and for copies another authorized person exports or retains. |
| Continuity | Designate a backup organizer, transfer ownership explicitly, archive or export a circle, and recover from supported failures. | These product controls do not establish guardianship, power of attorney, or other legal authority. |
Privacy architecture
Device, optional backup, explicit sharing.
The privacy model is intentionally simple: organize on the device, opt into user-controlled backup and connected data where available, and share only selected information.
- Device
- Core care records, notes, documents, tasks, review context, on-device recognition, and authorized record search begin under user control.
- Optional iCloud and connected data
- iCloud continuity, Apple Health access, indexing, notifications, and Apple system surfaces begin only through the relevant user choice, permission, or enabled control.
- Explicit share
- Packets, exports, summaries, selected Apple Health snapshots, guest access, and Care Circle sharing happen only through selected user actions and permissions.
Outside the private record boundary
Website contact data, support messages, and first-party analytics stay separate from app medical records.
Website data
Website forms are not for health records.
Website forms collect contact and inquiry information, consent choices, source information, and general non-medical message text. Depending on the form, this can include a name, email address, telephone number, organization, role, country, selected form answers, message, page route, referral source, and campaign parameters. The website does not request health records, documents, diagnoses, medication names, or patient names.
First-party analytics use a random browser session identifier stored in local storage and allowlisted events such as page route, device category, referrer category, button clicks, FAQ openings, downloads, and form starts or submissions. Analytics events do not accept names, emails, free text, or medical details. Security processing may add a one-way hashed IP address and a shortened hash of the browser user-agent string.
| Data area | Purpose | Boundary |
|---|---|---|
| App records | Personal care organization in the iOS app. | Not collected through website forms or first-party website analytics. |
| Website contact data | Respond to access, support, partner, press, or privacy requests. | No health records, diagnoses, medication details, patient names, or document contents requested. |
| Consent and routing data | Record permission to process and respond, prevent duplicate submissions, route the request, and preserve the applicable policy version. | Used for the submitted website request, not to access app records. |
| First-party analytics | Understand broad page use, downloads, FAQ activity, and form completion while protecting the site from abuse. | Allowlisted operational events without names, emails, free text, or medical details. |
Use and disclosure
Information is used to operate, support, secure, and improve ChartNest.
ChartNest uses information only for the app or website purpose that produced it, related support and administration, security and abuse prevention, legal compliance, and limited product or website improvement. ChartNest does not sell app care records or website contact information and does not use them for third-party targeted advertising.
- App operation
- Store and display user-created records, run selected workflows, prepare previews and exports, schedule requested reminders, and recognize Apple purchase access.
- Support and communication
- Respond to website submissions, purchase or product questions, privacy requests, and messages the visitor asks ChartNest to answer.
- Security and integrity
- Validate submissions, enforce rate limits, maintain consent and administrative records, investigate misuse, and protect the website and app experience.
- Improvement
- Review limited first-party website analytics and general non-medical feedback to understand which pages, resources, and support paths are useful.
- No sale or targeted advertising
- ChartNest does not sell personal information or health-related app content and does not use third-party advertising or cross-app tracking SDKs in the iOS app.
Service providers
A small number of providers support the app and website.
Providers process information only to deliver the relevant service. Their own terms and privacy practices also apply. A user-chosen export or share can additionally be processed by the destination, recipient, or service the user selects.
| Provider or service | Role | Information involved |
|---|---|---|
| Apple | App Store and StoreKit purchases; iCloud and CloudKit backup, continuity, recovery, or sharing; optional Apple Health permissions; on-device recognition; notifications; and selected iOS system or sharing controls. | Apple account, transaction, device, permission, backup, recovery, shared record, connected category, indexed item, or destination information needed for the selected Apple service. |
| Netlify | Website hosting, serverless functions, request delivery, and configured website storage. | Website requests, operational logs, analytics events, and submitted form records needed to run the site. |
| Email delivery provider | Send confirmation or administrative email when email delivery is configured. ChartNest may use Resend or another configured delivery service. | Recipient address, subject, confirmation content, and delivery metadata. Free-text form details are intentionally omitted from administrative notification emails. |
| User-selected destinations | Receive an app export, PDF, text share, JSON file, Health Bundle, QR payload, or other selected output. | Only the content the user chooses to send, subject to the recipient's or destination service's practices. |
Retention and deletion
Different data stays in different places.
ChartNest keeps information only for the period reasonably needed for the purpose described here, to provide the requested service, maintain security and consent records, resolve disputes, or meet legal obligations. The practical retention and deletion path depends on where the information is stored.
| Location | General retention | Deletion or control |
|---|---|---|
| On-device app data | Remains until the user edits or deletes it, deletes all local ChartNest data, or removes it through normal device and app controls. | The app includes Delete All Local Data and record-level deletion controls. Local deletion also removes scheduled ChartNest notifications. |
| Apple iCloud backup | Remains in the user's Apple iCloud context under Apple's storage and account controls. | Deleting local app data does not automatically delete a separate iCloud backup. The user should also review Apple iCloud storage controls. |
| Recovery history | Recent supported recovery points remain in the user's Apple iCloud context according to the feature's current retention behavior and available Apple storage. | The user can review or restore available points through the app. A recovery point does not control separate original files or copies exported elsewhere. |
| Apple Health connection | Permission remains under Apple Health controls, while any selected snapshot or imported record the user saves can remain as ChartNest app data. | The user can revoke Apple Health permission or disconnect the feature, and must separately delete any information already saved as an app record, shared snapshot, or export. |
| Care Circle sharing | Selected shared information remains in the configured Apple shared iCloud context while the circle, membership, and records remain active. | Owners and participants use available circle, membership, leave, and delete controls. Information already exported or copied by a recipient may remain outside ChartNest's control. |
| Temporary or guest access | Selected shared information remains available for the configured access window unless it is revoked earlier. | Expiration or revocation stops future authorized access through ChartNest but cannot retrieve a copy an authorized recipient already exported or retained. |
| User-created exports | Remains wherever the user saves or sends the file or text. | The user must delete the exported copy from the selected device, recipient, or service. |
| Website forms and consent records | Retained as reasonably needed to respond, administer the relationship, document consent, protect the site, and meet legal obligations. | A visitor can request access, correction, or deletion through the data request page. Verified deletion removes or anonymizes the associated contact and message information unless retention is legally required. |
| Website analytics | The current system keeps a bounded set of recent allowlisted events rather than an unlimited event history. | Analytics records are not designed to identify a person by name or email. ChartNest may retain non-identifying aggregate information. |
Controls and boundaries
Use the controls built into the app and website.
ChartNest uses iOS protections, local storage behavior, explicit sharing choices, app settings, local delete controls, source references, and review history. No security method is perfect, so users should protect their device, Apple account, exports, and chosen recipients. ChartNest does not claim unsupported certifications or guarantees.
- App lock and iOS protections
- ChartNest relies on the user's device and operating-system protections rather than claiming unsupported certification.
- Explicit sharing
- Exports, packets, and Care Circle sharing depend on user choice and review.
- Connected data
- Optional iCloud, Apple Health, indexing, notifications, system surfaces, temporary access, and Family sharing have separate permission, status, revoke, disconnect, or unshare controls where supported.
- Source review
- Source-aware tools help people notice what needs confirmation without making clinical decisions.
- Deletion
- Local app data, Apple iCloud data, shared records, exported copies, and website records have separate deletion paths.
Children and family profiles
ChartNest is intended for adults organizing care.
ChartNest is not directed to children and the website is not intended to collect contact information directly from children. An adult may choose to create a care profile about a child or dependent when the adult has the authority to organize that information. The adult remains responsible for what is entered, stored, exported, or shared.
Policy changes and contact
The current policy stays at this address.
ChartNest may update this policy when the app, website, providers, or legal requirements change. The effective date at the top will be revised when the policy changes. Material changes may also be communicated through the app, website, or another appropriate channel.
For privacy questions or requests, email contact@chartnest.app or use the website data request page. App data stored only on a device or in the user's Apple iCloud account must generally be managed through the app, device, or Apple account controls available to that user.
Privacy FAQ
Trust questions.
Does everything stay local?
ChartNest is local-first by default. Explicit exceptions can include export, sharing, iCloud backup, App Store services, and configured collaboration flows. Those actions depend on user choice, entitlement, and available configuration. Users should review the destination and scope before moving information off the device.
Does the website collect medical records?
No. Website forms are for general contact, support, privacy, and related requests. They warn visitors not to submit records, diagnoses, medication details, patient names, or document contents. Messages should remain general and non-medical.
Is ChartNest a certified EHR?
No. ChartNest is a private care-organization product, not a certified electronic health record. It does not replace official provider systems or source records. Users should confirm important information with original documents and qualified professionals.
Does ChartNest sell health data?
No. ChartNest does not sell app care records or website contact information and does not use them for third-party targeted advertising. Website operations focus on contact, support, limited first-party analytics, and data-request flows. Forms are not intended to collect medical records or private health details.
Can I delete app data?
Yes. The app includes record-level controls and a Delete All Local Data action. Deleting local data does not automatically remove separate iCloud backups, shared information, or copies already exported or sent. Those locations must be managed through the available Apple, sharing, recipient, or destination controls.
Can I request deletion of website data?
Yes. Use the data request page for website lead or contact data. Provide enough contact information for ChartNest to identify and route the request. Do not include medical records or private health details in the request.
Is backup automatic?
Backup does not begin until an eligible user deliberately enables the optional iCloud feature. After opt-in, Plus or Family can run automatic backup after meaningful changes while retaining a manual Back Up Now action, status, and retry controls. Scope and timing depend on the app version, entitlement, Apple services, network conditions, and supported data. Users should review the current backup and recovery status inside the app.
Does Ask ChartNest send my records to an external AI service?
The current Ask ChartNest implementation searches authorized ChartNest records locally and uses source-cited record retrieval. It does not require an external AI service to answer organizational questions. The current implementation does not use those app records to train an external model. Family answers remain limited by the requester's permissions.
How does Apple Health access work?
Apple Health access is optional and begins only after the user chooses supported categories and grants permission. ChartNest retains source context and offers available disconnect or delete controls. Family sharing of a selected snapshot requires an explicit user action and applicable permission. Availability varies by device, region, Apple Health support, and the current released app.
Policies and requests
This is the ChartNest privacy policy.
Use this page as the privacy policy for both the ChartNest iOS app and the ChartNest website. The related pages below cover legal terms, medical boundaries, accessibility, and website data requests.