Privacy Policy
Who we are
Organized.Health is operated by The Armory Enterprises LLC, doing business as Organized.Health ("we", "us"). We build software that helps people with chronic illness organize their medical lives.
This policy covers:
- our website at organized.health
- the member portal at my.organized.health
- the Organized.Health iOS app
- the provider upload page at upload.organized.health, which medical offices use to send us records a member asked for
Questions about this policy: support@organized.health.
The short version
- We do not sell your information, and we never will. We don't share it with advertisers or data brokers.
- There are no analytics, advertising pixels, or session-replay tools anywhere behind the sign-in.
- Your health information is encrypted, and the most sensitive fields are encrypted individually on top of that.
- We keep an append-only log of access to your information, and you can read it from your settings at any time.
- Text messages are optional, never contain health information, and stop when you reply STOP.
Where HIPAA fits, and where it doesn't
HIPAA applies to health plans, health care clearinghouses, health care providers who bill electronically, and the vendors those organizations hire. Organized.Health is none of those. You choose us directly, and no doctor or insurer pays us or directs what we do with your information. Under the U.S. Department of Health and Human Services' published guidance on health apps, that means HIPAA does not legally bind us today.
We built to the HIPAA standard anyway. Our infrastructure runs under a signed Business Associate Addendum with Amazon Web Services, and the fax service that carries your records requests is under a signed Business Associate Agreement too.
Other laws do apply to us, including the Federal Trade Commission Act, the FTC's Health Breach Notification Rule, and state privacy laws depending on where you live.
What we collect
Information you give us
| Account | Name, email address, password (held by our sign-in provider, never by us), and a profile photo if you add one |
|---|---|
| Health information | What you add: medications and doses, symptoms, conditions, allergies, appointments and visits, notes, reminders, tasks, and documents such as visit notes, lab results, and imaging |
| Insurance | Plan details, including member ID and group number, and photos of your insurance card if you upload them |
| Records requests | To request your records from a provider on your behalf: your date of birth, sex, address, phone number, email, a photo of your ID, and your signature on the authorization. Also the provider's name and fax number, dates of service, and any notes you add |
| Records you receive | Medical records your providers send us for you, by fax or through our provider upload page |
| Care team | Names and contact details of people you add to your care team, their office locations, and what you allow each of them to see |
| Phone number | Only if you turn on text messages |
| Questionnaires and messages | Your answers, including anything you write in an open response, and what you write to us in your message thread |
| Feature requests and problem reports | What you submit |
Information we generate
| Sign-in records | Time, outcome, IP address, and a description of the device for each sign-in and sign-out |
|---|---|
| Devices | A description of each browser or device with an active session |
| Access log | An append-only record of access to your information: who, what, and when, never the contents |
| Text message verification | A short-lived code we text you to confirm your number |
From medical offices using the upload page
When someone uses the provider upload page, we record the attempt, including their IP address and browser details. This protects the page from people trying to guess access codes.
What we don't collect
Your Social Security number, your bank or card details, or your precise location. Nothing in the product asks for them.
Open-response fields
Questionnaires and messages include free-text fields. You decide what goes in them. If you describe symptoms, treatments, or diagnoses there, we treat what you wrote as health information and protect it the same way.
How we use it
- To run your account and keep it secure
- To store and organize the health information you add
- To request your medical records from the providers you choose, and file what they send back
- To share information with the care team members you authorize
- To send you notifications you asked for
- To answer your messages and review what you ask us to build
- To investigate security problems and misuse
We do not use your information for advertising, and we do not use it to train AI models, ours or anyone else's.
Who we share it with
We do not sell your personal information. We do not share it with advertisers or data brokers. Here is everyone outside our company who can receive information from the portal, the app, or the provider upload page, and why. The public website is covered separately in Our website.
| Who | What they receive | Protection |
|---|---|---|
| Amazon Web Services | All application data, stored in our own AWS account in the United States. This includes sign-in, which runs on Amazon Cognito | Business Associate Addendum, signed |
| Sinch (fax) | When you request records: the cover sheet and your signed authorization, which include your name, date of birth, sex, contact details, photo ID, and signature. Also the records your providers fax back. We delete received faxes from Sinch once we've stored them | Business Associate Agreement, signed |
| The providers you choose | Your records request, authorization, and ID, so they can release your records | Sent only when you ask |
| Your care team | Only what you allow each person to see | You control it and can remove access at any time |
| Twilio (text messages) | Your phone number and the text of each message | No business associate agreement. That's why our texts never contain health information (see Text messages below) |
| Namecheap Private Email | Emails you exchange with us at support@organized.health | Standard email service |
| Public reference databases from the U.S. Food and Drug Administration, National Library of Medicine, and Centers for Medicare & Medicaid Services | When you look up a medication, a medical device barcode, or a provider, we send only the search term, never your name or account details | Public government services |
| Perplexity (iOS app, research feature only) | If you use it, the question you type. The app refuses to send a question containing a phone number, email address, date, or ID number. It can't detect names, so please leave names out | Business associate agreement on file |
That is the complete list. If it grows, this policy changes first.
We will disclose information if we are legally compelled to, such as by a subpoena or court order. Where the law lets us, we will tell you first.
If we are ever acquired, your information would pass to the new owner, who would be bound by this policy until you are given notice and a real chance to delete your information first.
Care team access
You can invite people to help with your care, and you decide what they see.
- Portal questionnaire invitations let someone see and answer questionnaires with you, and nothing else.
- Care team members in the app can be given access to specific areas: medications, symptoms, appointments, records, or ride requests, or full access. For each area you choose whether they can only view it or also make changes.
You can change or remove anyone's access at any time, and it takes effect immediately.
How we protect it
- Encrypted in transit with TLS, and encrypted at rest with keys we control in AWS Key Management Service
- Encrypted a second time, field by field, for the most sensitive information: your messages, open questionnaire responses, problem reports, date of birth, and insurance member ID
- We never see your password. Sign-in on the portal happens on a page run by Amazon Cognito, not a page we serve
- You're signed out after 15 minutes of inactivity, enforced on our servers, not just in your browser
- The database has no public internet address. It sits in a private network
- The access log is append-only, enforced by the database itself, so entries can't be edited or deleted through the application
- We monitor our infrastructure with AWS's threat detection and security services
Multi-factor authentication isn't required on every account yet. We'll update this section when it is.
No system is perfectly secure, and anyone who says otherwise is selling something.
How long we keep it
| Health information, documents, records requests, questionnaire answers, messages | Until you delete them or your account is closed |
|---|---|
| Account details, sign-in records, and devices | While your account is open |
| Access log entries | At least six years, including after you delete everything else |
| Faxes held by our fax provider | Deleted from their systems once we've stored them |
| Provider upload attempt records | Kept as security records |
The access log is the one deliberate exception to "we delete what you ask us to." A deletion record that deletes itself proves nothing. If you ever need to show what happened to your information and when, that log is the evidence. It records that something happened, never what it contained.
Backups. When you delete something, it's removed from the service right away. Encrypted copies can remain for a while in our database backups and in the version history of stored files. We don't yet expire those automatically. If you want them removed too, email us and we will.
Your choices
- Delete records from Settings. This immediately and permanently deletes your questionnaire answers, messages, problem reports, and notifications.
- Delete individual items such as medications, symptoms, notes, appointments, and tasks, wherever the app shows a delete option.
- Delete everything else. For information the app can't delete yet, including documents, insurance, identity documents, and records requests, email support@organized.health and we'll delete it within 30 days.
- Close your account. Request it in Settings or by email, and we'll close it within 30 days. Closing your account is separate from deleting records. You can do either or both.
- Export your data. Request a copy in Settings or by email, and we'll send it within 30 days.
- Correct your information at any time.
- See your access history at any time, from Settings.
- Turn off text messages in Settings, or reply STOP to any message.
Depending on where you live, you may have more rights under state law, such as the right to know what we hold and to be free from discrimination for using your rights. Ask us, and we'll honor these requests wherever you live.
Text messages
We only text you if you turn it on. It works like this:
- You enter your mobile number in Settings. It's optional.
- We text you a code, and you enter it to prove the number is yours.
- You separately switch on text messages. The switch is off until you turn it on, and the full consent language is shown right beside it.
Consent is never a condition of using Organized.Health.
What we send: account notifications only, such as a new message or questionnaire waiting in your portal, records request updates, and account and security notices. No marketing. Our texts never include health information. They tell you something is waiting and ask you to sign in.
Frequency and cost: message frequency varies. Message and data rates may apply. US numbers only.
Stopping and help: reply STOP to any message to stop, or HELP for help. You can also turn texts off in Settings. For support, email support@organized.health.
Your mobile number stays with us. We share it only with the provider that delivers our texts, and only to send them. Mobile phone numbers and text-message opt-in consent are never sold, rented, or shared with third parties or affiliates for marketing or promotional purposes.
We keep a record of your consent: your number, whether texts are on, the exact consent wording you saw, and when each change happened.
Our website
This section covers organized.health itself, the public site you're reading now. The portal, the app, and the upload page are covered above.
Hosting. The site is a set of static pages hosted by Netlify and served only over HTTPS. Like any web host, Netlify receives your IP address and browser details when your browser asks it for a page.
Analytics. We use Google Analytics to count visits and
see which pages people read. It loads from Google's servers on every page of this site.
If you visit from the European Union, the European Economic Area, the United Kingdom, or
Switzerland, it runs without setting cookies. Everywhere else, it sets two cookies,
_ga and _ga_RYEL5WM761. You can block or delete them in your
browser settings, and the site works the same without them.
Fonts. The site's typefaces come from Google Fonts, so your browser downloads them from Google, which receives your IP address and browser details when it does.
Cookies. Apart from the two Google Analytics cookies above, the site sets no cookies and stores nothing in your browser.
Nothing else runs here. There are no advertising pixels, social media trackers, session-replay tools, chat widgets, or embedded videos or maps. The share buttons on blog posts are plain links, and Facebook, LinkedIn, and X receive nothing unless you click one.
Forms. The website has no forms. It doesn't ask for your name, email address, or phone number, and you can't sign up for text messages here. Text messages are turned on only inside the portal, as described in Text messages. To reach us, email support@organized.health. "Log in" and "Create account" take you to the member portal at my.organized.health, which the rest of this policy covers.
Children and teens
You must be at least 13 to use Organized.Health. If you're between 13 and 18, a parent or legal guardian must agree to our Terms on your behalf.
We don't knowingly collect information from children under 13. If you believe a child under 13 has given us information, email support@organized.health and we'll delete it.
If there is a breach
If your information is exposed, we'll tell you what happened, what was involved, and what we're doing about it, without waiting to be forced to. The FTC's Health Breach Notification Rule sets the minimum, and we'll meet it and be plain about what went wrong.
Changes
When we change this policy, we'll post it here with a new date. If a change materially affects how we handle your information, we'll tell you directly instead of relying on you to notice.
Contact
The Armory Enterprises LLC, doing business as Organized.Health
support@organized.health
You can also message us from inside the portal.