🛡️ Trust Center
Where your family's health records live, what we do with them, and every control you hold over them — on one page, in plain words.
The promises, and the button behind each one
Everything is yours to take, any time
One tap downloads your whole account: every record you hold, every original file, and an open-me.html viewer that works forever with no internet and no Family Stork. Five downloads a day, always free. Sign in to download →
Leaving takes one click, no email, no waiting
Delete any record permanently, or erase your entire account yourself, in the app. We keep one anonymized security log (sign-in times, no IP addresses, no health data) and nothing else. What delete actually deletes →
You can see and end every sign-in
Change your password without a reset email, sign out every other device in one tap, and see your recent sign-in activity, all from My Family → Manage account. Every sign-in from a device you have not remembered sends you an email the moment it happens. How records are protected →
A password alone cannot open your account
Turn on two-step sign-in and a new device also needs a code emailed to you; eight one-time recovery codes cover a lost inbox. Devices you remember stay quiet for 30 days, and every remembered device is forgotten the moment you change your password or tap “sign out everywhere else”. Google sign-ins carry Google’s own second step. Turn it on →
Every share is a choice you can take back
Share links are unguessable, revocable in one tap, logged per open, and expire on their own (caregiver 90 days, insurance 30). Relatives see only the parts of a record you chose to share with them; nothing they send lands on a record without your tap. Health Data Privacy Policy →
A child’s record is the child’s
Held in trust by their parent, then handed off to them for real when they come of age, with a 72-hour window and a full transfer record. Children’s privacy →
Never sold, never advertised against, never used to train AI
Those hold even if Family Stork is ever acquired. AI reads your documents only to build your timeline and answer your questions, through a vendor bound to the same terms. Straight talk →
How it is protected
- Encrypted in transit, always: HTTPS only, with browsers told to never try plain HTTP again (HSTS).
- Nightly encrypted backups (AES-256 before they leave the machine), with a second encrypted copy off-site, rolling off on rotation.
- Every access logged. Each record shows its holder who touched it and when; every share link shows its open history.
- Rate limits on sign-in, sharing, uploads, and exports; sessions expire on their own after 7 days.
- Connected portals (MyChart and other Epic portals) use SMART on FHIR with asymmetric keys; portal tokens are encrypted at rest and deleted with the connection.
- A responsible-disclosure channel: security@familystork.com, published at /.well-known/security.txt.
What we are honest about
To build your timeline and answer your questions, our systems read your records, so they are not sealed away from us the way an end-to-end encrypted message is. No one on our team browses records; a person reaches your data only when you ask for help, when we must investigate abuse, or when the law compels us, and every such case is limited and logged.
An independent security review is on our roadmap and this page will carry its results when it is real, not before.
The documents
🕊️ Straight talk (the plain-English version) · 🔐 Security · Privacy Policy · Consumer Health Data Privacy Policy · Terms of Service · security.txt
A question this page does not answer: info@familystork.com. A person replies.