HEMORA

Security and data

The most private thing you own deserves the most serious treatment

A medical record is not a contact list. Here is what we do, put in terms you can check.

Encrypted at rest

Every file, and the text extracted from it, is stored encrypted with AES-256-GCM. Read the database without the key and nothing is legible.

In the European Union

Hosting, the database and the files are in Frankfurt. AI reading and email, in France. Some of these providers are companies with a US parent: their support may access data from outside the EEA to resolve a problem, covered by standard contractual clauses. We say so because promising otherwise would be false.

Only what is needed

We ask for an email and a password. No ID number, no phone, no card to begin with. What does not exist cannot leak.

Nobody trains on your record

The model that reads your documents does not learn from them. The provider retains nothing, and we do not pass data to third parties for commercial purposes. Ever.

You can take it with you

Full export at any time, free, in an open format — and automatic if you close your account. Article 20 of the GDPR requires it; it is also what we would want if this were ours.

Consent on the record

We store that you agreed, which version of the text, and when. You can withdraw it, and see what we hold about you whenever you like.

The specifics

Files and extracted text
AES-256-GCM
Passwords
scrypt · N=2^15, r=8, p=1
Sessions
SHA-256 hash only
IP addresses
truncated to /24
Transport
TLS 1.3 · HSTS
Data residency
European Union

Privacy policy

What we process

Account data: email address, hashed password, your name if you give one, country of residence and language.

Health data: the documents you upload and what is extracted from them — dates, clinics, measured values, summaries — together with what you record in your medical profile: date of birth, sex, height, weight, blood group, allergies, treatments and past conditions.

Technical data: a log of sign-ins and account actions, with the IP address truncated to its first three groups. We use no analytics or advertising cookies.

Why, and on what basis

To run the service — storing, reading and ordering your record — on the explicit consent you give at sign-up (Article 9(2)(a) GDPR, as this is health data) and on performance of the contract (Article 6(1)(b)).

For AI reading, on a separate consent you can withdraw at any time. If you withdraw it we stop sending documents to the model provider; your record keeps working and you can enter values by hand.

For the security of the service — spotting access attempts, preventing abuse — on our legitimate interest (Article 6(1)(f)).

There are no automated decisions with legal effects and no commercial profiling. We do not sell or share data for advertising, with no exceptions.

Who else sees it

Hosting and the database, on servers located in Frankfurt, Germany. The files, in a European object store. All of it encrypted before it leaves our process.

The AI provider that reads the documents, based and hosted in France, with zero retention: it receives the document text in order to file it, and neither keeps nor trains on it. It does not receive your account name.

The transactional email provider, based in France, which receives only your address and the message we send you.

The payment gateway, if you subscribe. It receives your email and billing details; never any of your health data. Your card never passes through our servers.

A processor agreement under Article 28 GDPR is in place with each of them.

Said precisely, because it matters: **your data is stored and processed in the European Union**, but some of these providers are companies with a United States parent. Their support staff may, exceptionally and to resolve a technical problem, access it from outside the European Economic Area. That access is a transfer within the meaning of the GDPR, and it is covered by the European Commission's standard contractual clauses (Article 46) or by the EU–US Data Privacy Framework. We would rather write it this way than promise it does not happen.

How we protect it

Every file, and the text extracted from it, is stored encrypted with AES-256-GCM. The key is not stored alongside the data.

Passwords are stored derived with scrypt, never in clear. Session identifiers are stored only as a hash, so a database dump grants access to no account.

Technical access to a user's data is logged and only happens at that person's request, to resolve a problem.

For how long

For as long as your account is open. When you close it we offer you the full export of your record in the same step, and then destroy the content.

Access logs are kept for twelve months, for security. Proof of consent is kept for as long as needed to demonstrate it against a claim.

Your rights

Access, rectification, erasure, portability, restriction and objection, and withdrawal of consent at any time. Write to privacidad@hemora.es: we answer within one month at the latest.

Export is free and in open formats, always. If our answer does not satisfy you, you may complain to the Agencia Espanola de Proteccion de Datos (AEPD), www.aepd.es.

Access, rectification, erasure, portability, restriction and objection: write to privacidad@hemora.es and we answer within one month at the latest. If our answer does not satisfy you, you may complain to the Agencia Espanola de Proteccion de Datos (AEPD), www.aepd.es.

What it is not

Hemora shows. It does not diagnose.

This is not cautious wording, it is the line that defines the product. Hemora shows you the value your lab printed and the range your lab printed, and lets you watch it change. It does not say whether that is fine, does not suggest a test, does not propose a treatment.