Seriya Health · Security & Privacy
Your health data deserves
the same care you do.
Seriya Health is built on HIPAA-compliant infrastructure with signed Business Associate Agreements, end-to-end encryption, and strict access controls — so you can focus on healing.
Built With
HIPAA-Compliant Infrastructure
Encryption · BAAs · Zero PHI in Transit
“The Lord will keep you from all harm — he will watch over your life.”
Psalm 121:7 · The Standard We Hold Ourselves To
How We Protect You
Three layers of protection for every piece of your health data
From the moment you enter a check-in to when a caregiver receives an alert, your information is protected at every step.
Encryption at rest & in transit
All your health data is encrypted with AES-256 while stored on our servers, and every connection uses TLS 1.2 or higher — so your information is protected both at rest and as it travels between your phone and us.
Row-level security
Every database table is locked so only you can access your own records. No other user’s data can ever be returned in response to your requests.
Secure device storage
Sensitive information on your phone — including caregiver contacts — is stored in Keychain, hardware-backed storage that other apps cannot read, rather than in general app storage.
Generic notifications
Push notifications and SMS alerts never contain medication names or health data. They simply prompt you to open the app, where data is protected.
Signed Business Associate Agreements
Every vendor that touches your health data has signed a HIPAA Business Associate Agreement, making them legally accountable under federal law.
Your right to deletion
Delete your account and all associated health data at any time from within the app. Deletion is permanent and complete within 30 days.
Business Associate Agreements
Every vendor is legally accountable
A Business Associate Agreement (BAA) is a federal contract that makes our vendors legally responsible under HIPAA for protecting your health information. We only work with vendors who have signed one.
Amazon Web Services
Caregiver SMS alerts via SNS · BAA signed
Apple / Expo EAS
App distribution · No PHI transmitted
Data Retention
How long we keep your data
We retain personal and health-related information only as long as necessary to provide our services and comply with legal obligations:
Account & health data
Retained for as long as your account remains active, including profile information, care team details, medications, and AI-generated care summaries.
Data after account deletion
When you delete your account, we permanently delete your personal data from our active systems within 30 days, except where retention is required by law (HIPAA-related records may be retained for up to 6 years as required by federal regulation).
Backups
Data may persist in encrypted backups for up to 30 days after deletion before being permanently purged.
Analytics data
Aggregated usage data collected through PostHog is retained for up to 1 year.
Crash/error logs
Retained by our error monitoring provider (Sentry) for up to 30 days and do not contain protected health information (PHI).
Emergency contact & caregiver SMS data
Retained only while your account is active; SMS message content is not stored beyond delivery confirmation by our messaging provider (AWS SNS).
You may request deletion of your account and associated data at any time by contacting us at support@seriyahealth.com or through the in-app account deletion feature.
Our Commitments To You
What we never do with your health data
We never sell your data
Your health information is never sold, rented, or shared with advertisers, data brokers, or any third party for commercial purposes.
We never log PHI in system records
Our application logs contain zero health information. Medication names, check-in responses, and caregiver details never appear in any log file.
We never share data without consent
Your data is only shared with caregivers you explicitly invite. We never disclose your information to hospitals, insurers, or employers without your written authorization.
We never store PHI in notifications
Medication names and health details never appear in push notification banners or SMS messages — only inside the app, after you authenticate.
“Above all else, guard your heart, for everything you do flows from it.”
Proverbs 4:23
Seriya Health was built on the belief that healing is sacred — and that the information you share during your most vulnerable moments deserves the same reverence. Security isn’t a feature here. It’s a conviction.
Questions about your privacy?
We’re transparent about how your data is handled. Reach out anytime.