Seriya Health · Security & Privacy

Your health data deserves
the same care you do.

Seriya Health is built on HIPAA-compliant infrastructure with signed Business Associate Agreements, end-to-end encryption, and strict access controls — so you can focus on healing.

Built With

HIPAA-Compliant Infrastructure

Encryption · BAAs · Zero PHI in Transit

“The Lord will keep you from all harm — he will watch over your life.”

Psalm 121:7 · The Standard We Hold Ourselves To

How We Protect You

Three layers of protection for every piece of your health data

From the moment you enter a check-in to when a caregiver receives an alert, your information is protected at every step.

Encryption at rest & in transit

All your health data is encrypted with AES-256 while stored on our servers, and every connection uses TLS 1.2 or higher — so your information is protected both at rest and as it travels between your phone and us.

Row-level security

Every database table is locked so only you can access your own records. No other user’s data can ever be returned in response to your requests.

Secure device storage

Sensitive information on your phone — including caregiver contacts — is stored in Keychain, hardware-backed storage that other apps cannot read, rather than in general app storage.

Generic notifications

Push notifications and SMS alerts never contain medication names or health data. They simply prompt you to open the app, where data is protected.

Signed Business Associate Agreements

Every vendor that touches your health data has signed a HIPAA Business Associate Agreement, making them legally accountable under federal law.

Your right to deletion

Delete your account and all associated health data at any time from within the app. Deletion is permanent and complete within 30 days.

Business Associate Agreements

Every vendor is legally accountable

A Business Associate Agreement (BAA) is a federal contract that makes our vendors legally responsible under HIPAA for protecting your health information. We only work with vendors who have signed one.

Amazon Web Services

Caregiver SMS alerts via SNS · BAA signed

Apple / Expo EAS

App distribution · No PHI transmitted

Data Retention

How long we keep your data

We retain personal and health-related information only as long as necessary to provide our services and comply with legal obligations:

Account & health data

Retained for as long as your account remains active, including profile information, care team details, medications, and AI-generated care summaries.

Data after account deletion

When you delete your account, we permanently delete your personal data from our active systems within 30 days, except where retention is required by law (HIPAA-related records may be retained for up to 6 years as required by federal regulation).

Backups

Data may persist in encrypted backups for up to 30 days after deletion before being permanently purged.

Analytics data

Aggregated usage data collected through PostHog is retained for up to 1 year.

Crash/error logs

Retained by our error monitoring provider (Sentry) for up to 30 days and do not contain protected health information (PHI).

Emergency contact & caregiver SMS data

Retained only while your account is active; SMS message content is not stored beyond delivery confirmation by our messaging provider (AWS SNS).

You may request deletion of your account and associated data at any time by contacting us at support@seriyahealth.com or through the in-app account deletion feature.

Our Commitments To You

What we never do with your health data

We never sell your data

Your health information is never sold, rented, or shared with advertisers, data brokers, or any third party for commercial purposes.

We never log PHI in system records

Our application logs contain zero health information. Medication names, check-in responses, and caregiver details never appear in any log file.

We never share data without consent

Your data is only shared with caregivers you explicitly invite. We never disclose your information to hospitals, insurers, or employers without your written authorization.

We never store PHI in notifications

Medication names and health details never appear in push notification banners or SMS messages — only inside the app, after you authenticate.

“Above all else, guard your heart, for everything you do flows from it.”

Proverbs 4:23

Seriya Health was built on the belief that healing is sacred — and that the information you share during your most vulnerable moments deserves the same reverence. Security isn’t a feature here. It’s a conviction.

Questions about your privacy?

We’re transparent about how your data is handled. Reach out anytime.