Privacy Policy
Last updated: August 2026
Smartypants ("the app," "we") is a small, personal, non-commercial project built and run by two people, Blake Engel and Jessica Taylor. It helps a person, and any family caregivers they choose to authorize, securely retrieve, understand, and stay on top of their own health records from their healthcare providers' patient portals (Epic / MyChart). It is invite-only, has no public sign-up, and is used today by our own family and a small number of invited families. This policy explains, in plain language, what information the app handles and why.
Information the app handles
- Details you give us: names, email addresses, caregiver relationships, time zones, and notification and delivery preferences for the people in your care group.
- Health records you authorize us to retrieve: after you sign in on your provider's own MyChart screen and grant permission, the app retrieves the categories of health information you approve there, which can include demographics, conditions, medications, allergies, immunizations, lab and test results, visits, clinical documents and notes, care plans, and (where the app and your provider support them) categories such as appointments, referrals and orders, and insurance coverage. Access is read-only: the app never writes to or changes your medical record. The MyChart permission screen shows you the exact list before you agree, and you can approve or decline each category.
- A connection credential: so the app can fetch new records on your behalf, it stores a "refresh token" from your provider's system for the access period you approve on the MyChart screen. This token is encrypted before it is stored. The app never sees or stores your MyChart password.
- Visit transcripts (optional feature): if you choose to record a doctor's visit (with the required permissions and in compliance with your state's recording laws), the audio is encrypted on your phone the moment it is captured, sent over a secure connection, converted to text, and the audio is discarded immediately after. The raw recording is never kept, not on your phone and not on our servers. Only the written transcript is stored, encrypted like everything else.
How the app uses this information
Only to provide the service to you, and for nothing beyond it:
- Automatic delivery: when a new document appears in a connected portal, the app picks it up and makes it available in the app, optionally prints it at home (see below), and sends a push notification to the phones of the patient and authorized caregivers. Notifications never contain medical details. They say only that something new arrived and which clinic or provider it came from.
- Plain-language summaries: each document gets a summary written at an easy reading level, with medical terms explained. Drug names, doses, dates, and test values are never changed or simplified.
- Answering your questions: a chat feature answers questions using only that person's own stored records, and shows which document each answer came from.
We do not sell your information, do not use it for advertising of any kind, do not use it for research, and do not use data about you beyond providing these direct services. We never email your medical information. Email is used only for operational notices (for example, that a portal connection needs attention).
Service providers we rely on
To operate, the app shares the minimum necessary information with a few service providers. They process it solely on our behalf to perform the functions below; they are not permitted to keep it or use it for their own purposes:
- Epic / MyChart: your provider's system, the source of your records.
- Supabase: the database that stores your retrieved records and connections, on servers in the United States. Health information is encrypted by the app before it is stored there.
- Render: hosts the application, in the United States.
- Google: provides sign-in. Sign-in is the only thing Google does for the app; your health information is not shared with Google.
- Anthropic (Claude AI): receives the text of your documents and your chat questions in order to produce the plain-language summaries and answers.
- Voyage AI: receives document text to build the search index that lets the chat find the right documents.
- Deepgram: receives encrypted visit-recording audio solely to convert it to text; the audio is discarded immediately after transcription.
- Apple and Google push services: carry the push notifications, which never contain medical details.
- Resend: sends operational emails (never medical content).
The app also stores a small amount of data locally on your own device (for example, the offline recording queue and the app's cached pages).
The optional home-printing device
If your family uses the optional Smartypants printing device, new documents are sent to it over an encrypted connection, printed, and deleted from the device immediately. Your records live in the app, not on the device. The device talks only to your printer and to Smartypants; it does not scan or connect to anything else on the home network. We can connect to the device remotely to update its software or fix printing problems; that connection reaches the device only, not anything else on the network. Please remember that printed pages sit in the printer tray like any home printout. Printing is a convenience, not a private delivery method.
Who can see your records
- The people you authorize. Records are organized into "care pods," and each pod's records are visible only to the people in that pod. Adding someone to a pod does not by itself grant access to a person's records. Each patient (or, for a dependent, the caregiver who manages their care) specifically approves each member who may see them.
- Us, when needed to fix a problem. As the people running the service, we can access stored records to diagnose and fix problems. Every such access through the app's administrative tools is recorded in a durable log, and you can request a copy of the access record for your data at any time. That covers administrative access through the app since August 2026, and it does not cover views by the family members you have authorized. At this early stage of development you are ultimately trusting us personally, and we are building the controls that turn that from a promise into a guarantee.
How your information is protected
Your medical information is encrypted both while it's stored and while it's being sent. Connection credentials are encrypted before storage, and all secrets are kept out of the app's source code. If a phone is lost or stolen, you (or another authorized family member) can sign that person out of all devices with one click. Please understand this is an early-stage personal project built with security principles from the ground up, but it has not gone through formal outside certification or an independent professional security audit.
Your choices and rights
- Get a copy of the complete record of data the app holds about you, on request.
- Delete all of your data and close your account, on request. Nothing is retained after account closure (routine encrypted backups age out on their own schedule).
- Disconnect a portal at any time, from the Smartypants dashboard or from MyChart itself.
- Request the access record of administrative access to your data (see above).
- Turn notifications on or off per person at any time.
Deletion and data-copy requests are currently handled personally rather than by a self-serve button. Contact us (below) and we will act on them promptly.
Your right of access, and HIPAA
This app helps you obtain your own records at your request, which is your right of access under U.S. law. Because it acts on your direction rather than on behalf of your provider, it is generally not a HIPAA "business associate," and your providers' HIPAA obligations do not transfer to it. In practice this means the protections here come from this policy and applicable consumer-privacy law, not from HIPAA. This mirrors what Epic's own consent screen tells you when you connect.
How long we keep it
Your information is kept for as long as your account is open: indefinitely, until you ask us to delete it or close your account.
Children
The app is not directed to children and is not intended to be used by anyone under the minimum age set by the law of their state. It is intended for use by a parent or legal guardian to connect to and manage their child's health records, where and as permitted by the governing law of their state (for example, through the proxy access their healthcare provider grants them).
Changes
We may update this policy; the "last updated" date above will change when we do. If a change would expand how your data is used or who can see it, we will tell you directly before it takes effect.
Contact
Questions or requests: Blake Engel, blake@blakeengel.com.