Security and privacy

We can’t read your patients’ names. By design.

Patient names, MRN, date of birth and notes are encrypted on your device before they are saved or synced, with a key only your PIN or recovery code opens. The server keeps ciphertext and the coded clinical answers that power the audit, hosted in Frankfurt under the GDPR.

Encrypted on your device

Patient names, MRN, date of birth and free-text notes are sealed with AES-256-GCM before they leave the device. Each record’s envelope is bound to that record, so it can’t be moved to another.

A PIN the server can’t brute-force alone

Your key is derived with Argon2id from your PIN and a share the server holds; ten wrong PINs lock it. A recovery code you keep opens it if the PIN is forgotten.

Hospitals hold their own key

A hospital workspace has its own key, wrapped for each member with their P-256 key pair, and rotated when someone leaves. Members compare key fingerprints before sharing.

Reports without identifiers

Hospital reports are built from coded answers only; counts under 5 are withheld, and every report opened is logged for the hospital’s owners.

Hosted in the EU

The database and API run in Frankfurt (Neon). Data stays in the EU under the GDPR.

Your data, your call

Export everything to Excel at any time. "Delete all my data" and "Delete my account" erase it, including the history, and send you a receipt.

What the server can and can’t see

DataOn the server
Names, MRN, date of birth, notesCiphertext only; the key never leaves your devices unencrypted
Clinical answers (eye, dates, biometry, complications, VA)Stored as entered, to sync and to compute the audit
Your PINNever; a proof derived with Argon2id is checked instead
Hospital reportsBuilt from coded answers only; counts under 5 withheld; every look logged
Post-op checksA code hash, the eye, the surgery date and the result; no patient identifiers

Questions about security or a data processing agreement for your hospital:asad@zaions.com.