← Family Stork home  ·  Privacy  ·  Health Data Privacy

🔐 Security at Family Stork

A family's health record deserves a straight answer about how it is protected. This page is that answer, in plain words.

How records are protected

Every session requires your account and expires on its own. Sign-in, sharing, and export endpoints are rate-limited. Every access to a record through the app lands in an audit log; families see each share link's open history and their care team's activity. Share links are unguessable tokens, revocable in one tap, with per-open logs and open notifications; caregiver links expire in 90 days, insurance links in 30, and emergency links retire themselves after a year of family inactivity (never while the record is in use — an emergency card must not be dead on the worst night). Nightly backups are encrypted (AES-256) before they leave the machine, with a second encrypted copy off-site.

What we never do

We never sell records, never run ads against them, never train AI models on them, and never share them except at your direction or as the law requires. AI processing runs through a vendor bound to those same terms (named in our health data policy), and children's records carry extra promises under our Children's privacy policy.

Your controls

Export everything free, any time — the archive works forever without us. Delete any record permanently, revoke any link instantly, and delete your account yourself from My Family (no email required; records you hold must be deleted or handed off first, because they belong to the people they are about).

Found something?

Report security issues to security@familystork.com — also published at /.well-known/security.txt. We read every report, we will not pursue good-faith research, and we fix real findings fast. Independent review is part of our roadmap and this page will carry those results as they land.