Privacy

Privacy policy

The short version: your health record lives on your device, not on my servers. I can't see it, sell it, lose it, or be made to hand it over. Here is the whole picture, in plain language.

Who I am

Seen. (seencare.org) is a symptom-tracking tool for people with complex, under-recognized invisible illness. It is built and run by one person, Nicole, in the United States. This policy covers the seencare.org website and the Seen. app.

Last updated July 27, 2026.

Your health record never reaches me

Everything you log in Seen. (your symptoms, medications, daily entries, profile, notes) is stored on your own device, in your browser's or the app's local storage. By default it is never sent to my servers: no cloud copy, no sync service, and no database of patient records anywhere. The one exception is opt-in and encrypted, and I still cannot read it (see Encrypted cloud backup, below).

This is the design, not a side effect. I cannot see your health data, I cannot sell it, I cannot lose it in a breach of my systems, and I cannot be compelled to produce what I do not have.

Because your record lives only on your device, backups are in your hands too. Seen. builds backup files and physician-ready PDF exports on your device, and they go only where you choose to send them. If you ask me to email you a backup or an export, that file passes through my email provider once, to be delivered to you, and is not stored by me afterward.

Encrypted cloud backup. If you turn on Encrypted cloud backup, an encrypted copy of your record is stored on my server so you can recover it on a new device. It is sealed on your device with a key only you hold, unlocked by your Face ID or a recovery phrase. I cannot open it, and I could not hand over anything readable if asked. It is off by default, and the copy on your device is always the record; the cloud backup is only a copy.

What I do hold, and why

Running a subscription requires holding a small amount of account information. All of it together:

That is the complete list. There are no advertising trackers, no analytics scripts, no behavioral profiling, and no third-party cookies on seencare.org or in the app. The only cookie is the session token described above.

The services I rely on

Three companies process limited data on my behalf, each for one job:

None of these companies receives your health record. I do not sell or share personal information with anyone, for any purpose.

Your choices and your rights

A note on HIPAA

HIPAA applies to "covered entities" like clinics, hospitals, and insurers, and to vendors handling records for them. Seen. is neither: it is a tool you use directly, and your data stays with you. The protection here is structural rather than regulatory. Your record is not on my servers, so the risks HIPAA regulates cannot arise from my side.

Children

Seen. is not directed at children under 13, and I do not knowingly collect personal information from them. If you believe a child has created an account, email me and I will delete it.

Changes to this policy

If this policy ever changes in a way that matters, I will say so plainly on this page and update the date at the top. The core commitment will not change: your health record stays on your device, period.