Privacy Policy

Effective August 24, 2026. Family Stork is a product operated by TruePrimAI, Inc., a Delaware corporation, from the United States.

The short version

Family Stork holds your family's health records so you never have to scramble for them. The record belongs to the person it is about. We do not sell your data, we do not show ads, and nothing in a record is public unless you create a share link, which you can revoke at any time. Export of your record is always available and free.

What we collect

Account information (email, password hash, optional phone for reminders). Health records you connect, upload, forward, or type: records imported when you connect a health portal such as MyChart (through secure, read-only access you authorize and can disconnect any time), documents, photos, videos, timeline entries, medications and dose logs, notes, chat messages about the record, insurance details, and emergency-card information. Technical basics: IP address and access times, kept in a security audit log.

Children's information. Records about children are created and controlled by a parent or guardian. Family Stork does not knowingly collect information directly from children under 13, and accounts may not be held by children under 13. When ownership of a record is handed to the person it is about, they must be at least 13 and hold their own account.

How records are used

To run the product for you: building timelines from your documents, answering your questions from the record, preparing visit notes, and sending the reminders you turn on. Document text and images you submit are processed by an AI service (Anthropic) to extract and summarize your records; videos are stored but never sent to the AI. Our AI provider does not use your content to train its models, and holds it only briefly — to process your request and for standard safety monitoring — before deleting it. We use aggregate counts (number of accounts, documents processed) to operate the service. We do not sell personal information, and we do not use your family's health records for advertising.

Who at Family Stork can see your records

Running the product means our systems process your records — building timelines, answering your questions — so records are encrypted in storage but are not end-to-end encrypted from us. As a matter of policy and access control, our team does not read your family's records. A member of our team accesses your data only to provide support you have requested, to investigate a security or abuse issue, or where the law requires; that access is limited to the purpose, logged, and never used to browse, sell, or advertise. We do not sell personal information, we do not use your records to train AI, and we do not run ads.

Analytics on our public pages only

Our public marketing pages (the homepage, the demo tour, pricing, blog, and legal pages like this one) use Google Analytics so we can tell how people find Family Stork and where they get stuck. It sets a cookie and reports only which public page was visited, never the address bar's query details. The signed-in app — every page where your family's records live — loads no Google script and no third-party analytics of any kind. That boundary is deliberate, and we test for it.

Sharing, always at your direction

Records leave Family Stork only when you act: inviting family or a doctor to the care team, creating an emergency, caregiver, insurance, or moments link, giving a clinic your record's inbox email address, or exporting your record. Every share link is revocable, and every access to a record is written to an audit log you benefit from. Service providers that move data for us (cloud hosting, email and text delivery, AI processing) act on our instructions.

Security and retention

Records live on encrypted storage with daily encrypted backups. Access requires your account; sessions expire. If we ever discover a breach of unsecured records, we will notify affected users consistent with applicable law, including the FTC Health Breach Notification Rule.

Retention policy. We retain a record for one purpose: so the family that stewards it can keep it, and so the person it is about can receive it. A child's record is the child's — held in trust by their parent or steward, transferred to them through the handoff when they come of age, and retained only for as long as the family actively keeps it. We never retain records indefinitely for our own purposes: deleting a record permanently deletes its documents and entries (residual copies in encrypted backups expire on rotation, within 14 days), any steward or owner can delete at any time, and once a record is handed off its owner holds every one of those rights personally. Deleting your account permanently removes your records, documents, photos, and sign-in from Family Stork. Content previously sent to our AI provider for processing is never used to train AI and is deleted by that provider after its own short retention period; your deletion clears it from Family Stork, and the provider deletes its short-term copy on its own schedule. Notifications we send by email or text never contain your medical content — only a note that there is an update, with a link back into Family Stork. Push notifications may show update details, but only on your own device: they are encrypted end-to-end to that device and are not stored in readable form by any provider. Any message already delivered lives in the recipient's inbox or on their device and cannot be recalled by deleting your account. Security audit entries — a limited, de-identified log kept for the integrity and security of the service — are retained separately.

Your rights

Export everything, any time: Download everything under My Family → Manage account & data, or one record from its Ownership card. Delete records or your account yourself, instantly. Correct anything in a record (timeline entries are editable). Questions or requests: info@familystork.com. If you are in a state with a consumer health data law (for example Washington's My Health My Data Act), these rights apply to you without any extra steps; the same export, correction, and deletion controls serve everyone.

Children's privacy (COPPA)

We never collect information directly from children. Children under 13 cannot create accounts; a child's record is created and controlled entirely by their parent or steward, who is our user. The record is the child's — held in trust for the purpose of returning it to them through the handoff — and it is retained on the schedule in the Retention policy above: only while the family actively keeps it, deleted permanently whenever the steward (or, after handoff, the owner) asks. We do not use children's records for advertising, sell them, or use them to train AI models. From age 13, a record's subject can hold their own account with a confidential compartment: items they seal are visible to them alone — no parent unlock, no support override — and never appear on shared links, exports made by others, or AI surfaces rendered for others. Questions about a child's data: info@familystork.com.

Consumer health data

Because Family Stork exists to hold health information, we also publish a dedicated Consumer Health Data Privacy Policy covering the categories we collect, every third party that touches them, and your rights — including for Washington's My Health My Data Act.

Corporate transactions

If TruePrimAI, Inc. is involved in a merger, financing, acquisition, reorganization, or sale of assets, information may transfer as part of that transaction, subject to applicable law and this Policy. We will never sell your records, run ads against them, or use them to train AI models — a commitment that survives any such transaction.

Contact

Questions about privacy: TruePrimAI, Inc. · info@familystork.com.

We will update this policy as Family Stork grows; material changes will be announced in the product before they take effect.