Effective 2026-05-29 · v1

Privacy Policy

We say this in plain English, then again with the legal precision a regulator expects. If anything is unclear, email privacy@canary.health and we'll fix the wording.

Draft pending counsel review. This document is accurate as a description of what the platform actually does, but the final text must be reviewed by a privacy attorney licensed in every state we operate in before it becomes the legally binding version. We publish the working draft so you can see what we plan to commit to.

The short version


What we collect

Account information

Name, email, password (hashed with bcrypt), phone (optional). First name, last name, and phone are stored encrypted as application-layer ciphertext when associated with a health booking.

Booking information

The service you requested, the date and time, the street address of the property being tested, the price, your selection of HSA/FSA payment, and your explicit consent (versioned, timestamped, IP-stamped) authorizing the disclosures below. Address and city are stored encrypted.

Health questionnaire (HSA/FSA flow only)

If you select HSA/FSA payment, we collect a short questionnaire: diagnosis or condition being investigated, symptoms, symptom duration, current medications, optional home description, and your reason for testing. The first four fields are PHI and stored encrypted.

Inspection results

The PDF report your inspector produces and the lab results that underlie it. Stored in our encrypted cloud storage bucket (canary-phi-prod). Accessed by you via a 15-minute signed download URL — never a publicly-shareable link.

Technical telemetry

Anonymous usage telemetry: which pages you visit, what device you use, latency of requests. We do not use third-party analytics on any page that displays PHI.

Why we collect it

Who can see what

RoleCan seeCan NOT see
You (the patient) Everything
Your inspector — before accepting Service requested, your first initial, your city + state, scheduled date, estimated price Last name, phone, street address, ZIP, diagnosis, symptoms, medications
Your inspector — after accepting Above + your first name, last name, phone, full address Diagnosis, symptoms, medications, anything from the LMN questionnaire
Your reviewing provider (HSA/FSA flow) Your questionnaire responses, your first + last name, the inspection service requested Your street address, your inspector's identity, your payment details
Lab partner De-identified sample ID, sample type, chain-of-custody metadata Your name, your address, your health information
Canary employees (Privacy + Security Officer designees) Access on a strict need-to-know basis with full audit logging Everything else by default

How we protect it

Your rights

Right of access (HIPAA §164.524)

You can download the complete electronic record we hold about you in one tap from the mobile app: Account → Download my data. By web, email privacy@canary.health and we'll deliver a JSON export within 30 days (often within 48 hours).

Right of amendment (HIPAA §164.526)

If you believe a piece of your record is inaccurate, request an amendment from Account → Request amendment. We'll respond within 60 days. Accepted amendments rewrite the field; denied amendments are logged alongside your original statement so the audit trail shows both.

Right to an accounting of disclosures (HIPAA §164.528)

You can pull a six-year log of every PHI access tied to your record — by us, by the inspector, by the provider — from Account → Activity log.

Right to restrict (HIPAA §164.522)

Email us. We'll work with you on the specific restriction and confirm in writing what we can and can't accommodate.

Right of deletion

You can request account deletion. We will purge all PHI within 30 days, with two caveats: (a) we retain a record of the LMN and the receipt for as long as IRS Publication 502 requires for HSA/FSA substantiation (currently 7 years); (b) the audit log rows themselves remain to preserve the integrity of the chain, but they reference your record by an opaque ID rather than by your name.

Disclosures we do NOT make

Children's privacy

Canary is intended for users 18 and older. Parents and legal guardians can book on behalf of a minor, in which case the minor's health information is collected and protected under the guardian's account with the same controls. We do not knowingly permit a minor to create their own account.

State-specific notices

California, Colorado, Connecticut, Virginia, Utah, and several other states grant additional privacy rights (CCPA / CPRA / CTDPA / VCDPA / UCPA). If you reside in one of those states, your rights under those laws are additive to the rights above. The state-specific disclosures are at /privacy/state-rights (forthcoming).

Changes to this policy

If we materially change how we handle PHI, we will notify you in the app, by email, and via a banner on this page at least 30 days before the change takes effect. The version date at the top of this page tracks every revision. Previous versions are available on request.

Contact

Privacy Officer: privacy@canary.health
Security Officer: security@canary.health
General questions: hello@canary.health

See also our Notice of Privacy Practices (the HIPAA-required disclosure document you acknowledge at signup) and our Terms of Service.