Privacy Policy
We say this in plain English, then again with the legal precision a regulator expects. If anything is unclear, email privacy@canary.health and we'll fix the wording.
The short version
- We collect only what we need to fulfill an inspection and generate documentation a clinician + the IRS will accept.
- Protected Health Information (PHI) — your diagnosis, symptoms, medications, and the address of the property tested — is encrypted at rest with AES-256-GCM. Inspectors do not see your health information.
- We do not sell your data. Ever. Not de-identified. Not aggregated. Not anonymously.
- You can download everything we hold about you in one tap from the mobile app or by request. You can request deletion, with the caveats below.
- Three groups can see PHI: (a) you, (b) the inspector you booked — only after they accept, only the minimum needed, (c) the licensed provider reviewing your LMN. That's it.
What we collect
Account information
Name, email, password (hashed with bcrypt), phone (optional). First name, last name, and phone are stored encrypted as application-layer ciphertext when associated with a health booking.
Booking information
The service you requested, the date and time, the street address of the property being tested, the price, your selection of HSA/FSA payment, and your explicit consent (versioned, timestamped, IP-stamped) authorizing the disclosures below. Address and city are stored encrypted.
Health questionnaire (HSA/FSA flow only)
If you select HSA/FSA payment, we collect a short questionnaire: diagnosis or condition being investigated, symptoms, symptom duration, current medications, optional home description, and your reason for testing. The first four fields are PHI and stored encrypted.
Inspection results
The PDF report your inspector produces and the lab results that
underlie it. Stored in our encrypted cloud storage bucket
(canary-phi-prod). Accessed by you via a 15-minute
signed download URL — never a publicly-shareable link.
Technical telemetry
Anonymous usage telemetry: which pages you visit, what device you use, latency of requests. We do not use third-party analytics on any page that displays PHI.
Why we collect it
- To fulfill the inspection — match you to an inspector, get samples to a lab, deliver the report.
- To generate documentation — a Letter of Medical Necessity (LMN) signed by a licensed provider so HSA and FSA dollars can pay for the test under IRS Publication 502.
- To meet legal obligations — HIPAA Privacy + Security Rules, state telehealth scope, EPA / OSHA / AIHA standards for the testing itself.
- To improve the platform — aggregate, de-identified analytics only.
Who can see what
| Role | Can see | Can NOT see |
|---|---|---|
| You (the patient) | Everything | — |
| Your inspector — before accepting | Service requested, your first initial, your city + state, scheduled date, estimated price | Last name, phone, street address, ZIP, diagnosis, symptoms, medications |
| Your inspector — after accepting | Above + your first name, last name, phone, full address | Diagnosis, symptoms, medications, anything from the LMN questionnaire |
| Your reviewing provider (HSA/FSA flow) | Your questionnaire responses, your first + last name, the inspection service requested | Your street address, your inspector's identity, your payment details |
| Lab partner | De-identified sample ID, sample type, chain-of-custody metadata | Your name, your address, your health information |
| Canary employees (Privacy + Security Officer designees) | Access on a strict need-to-know basis with full audit logging | Everything else by default |
How we protect it
- Encryption at rest: AES-256-GCM with HKDF key derivation, application-layer (not just disk-level).
- Encryption in transit: TLS 1.2+ enforced on every endpoint. Our servers do not accept unencrypted HTTP.
- Audit log: every PHI access — by you or by anyone else — is recorded in a SHA-256-chained audit log. Tampering with the log breaks the chain at that point.
- Access controls: role-based. Inspectors get inspector access. Providers get provider access. Nobody gets both unless their account is dual-role and they've signed both BAAs.
- Multi-factor authentication: required for providers + admins. Optional but encouraged for inspectors and patients.
- Idle timeout: 10 minutes for providers and admins; 30 minutes for everyone else. After timeout you're signed back out and we re-check your account state on the next request.
- Vendor controls: we sign Business Associate Agreements (BAAs) with every vendor that touches PHI. We are in the process of signing BAAs with our cloud provider (Google Cloud Platform), email vendor, and SMS vendor as of the effective date of this policy.
Your rights
Right of access (HIPAA §164.524)
You can download the complete electronic record we hold about you in one tap from the mobile app: Account → Download my data. By web, email privacy@canary.health and we'll deliver a JSON export within 30 days (often within 48 hours).
Right of amendment (HIPAA §164.526)
If you believe a piece of your record is inaccurate, request an amendment from Account → Request amendment. We'll respond within 60 days. Accepted amendments rewrite the field; denied amendments are logged alongside your original statement so the audit trail shows both.
Right to an accounting of disclosures (HIPAA §164.528)
You can pull a six-year log of every PHI access tied to your record — by us, by the inspector, by the provider — from Account → Activity log.
Right to restrict (HIPAA §164.522)
Email us. We'll work with you on the specific restriction and confirm in writing what we can and can't accommodate.
Right of deletion
You can request account deletion. We will purge all PHI within 30 days, with two caveats: (a) we retain a record of the LMN and the receipt for as long as IRS Publication 502 requires for HSA/FSA substantiation (currently 7 years); (b) the audit log rows themselves remain to preserve the integrity of the chain, but they reference your record by an opaque ID rather than by your name.
Disclosures we do NOT make
- We do not sell your data.
- We do not share with advertisers.
- We do not respond to civil subpoenas without a court order naming the records (we will notify you in advance whenever legally permissible).
- We do not de-identify and sell research data without your explicit opt-in, separate from this policy.
Children's privacy
Canary is intended for users 18 and older. Parents and legal guardians can book on behalf of a minor, in which case the minor's health information is collected and protected under the guardian's account with the same controls. We do not knowingly permit a minor to create their own account.
State-specific notices
California, Colorado, Connecticut, Virginia, Utah, and several other states grant additional privacy rights (CCPA / CPRA / CTDPA / VCDPA / UCPA). If you reside in one of those states, your rights under those laws are additive to the rights above. The state-specific disclosures are at /privacy/state-rights (forthcoming).
Changes to this policy
If we materially change how we handle PHI, we will notify you in the app, by email, and via a banner on this page at least 30 days before the change takes effect. The version date at the top of this page tracks every revision. Previous versions are available on request.
Contact
Privacy Officer: privacy@canary.health
Security Officer: security@canary.health
General questions: hello@canary.health