Security
The specific things we do to protect your family's data.
Last updated 2026-09-05
KeptWell holds some of the most sensitive information a family ever shares: diagnoses, scans, conversations with doctors, voice recordings, private chat. Here is what protects it, in detail. If anything below is unclear, email hello@keptwell.org.
Encryption
- In transit
- TLS on every request to KeptWell. We require HTTPS and send HSTS, so a browser will not connect any other way. The exact TLS version is negotiated by our edge.
- At rest
- AES-256 on the database, applied at the field level for chat content, journal entries, audio transcripts, and patient names.
- Private AI chats
- AI chat history is encrypted at rest and access-restricted to your account. Other members of your circle cannot read your chats through KeptWell.
Where your data lives
- Database
- PostgreSQL on US-based infrastructure.
- Files (PDFs, images, audio)
- Cloudflare R2 in the United States.
- File access
- Every download is a signed URL that expires after 5 minutes. There are no permanent public URLs to your documents.
- Processing
- KeptWell's primary storage and hosting are in the United States. AI providers may process data in other locations under their terms.
Who can see what
Care circles are isolated. A document uploaded in one circle is not visible to any user in any other circle, ever.
Two roles per circle: admin (manages uploads, invitations, members) and member (view, comment, chat).
Your private notes and your AI chat are private to you, even inside a shared circle.
Sensitive fields are encrypted at rest. KeptWell staff cannot read them through the application; access is limited to the small number of operators with production database and key-management credentials, and only for incident response or with your explicit consent. We can see metadata (account email, when you logged in, how many uploads you have) for support and billing.
AI handling
Depending on the active configuration, KeptWell uses OpenAI or Anthropic to read and summarize uploaded documents and to power AI chat. Supporting AI tasks use Anthropic's Claude API. We send only the content each task needs.
KeptWell does not opt in to model training. OpenAI and Anthropic do not use API inputs or outputs to train their models by default.
Under standard API terms, both providers may retain content for up to 30 days for safety and abuse monitoring. KeptWell also disables OpenAI response storage for its requests.
When you ask the AI a question, only the documents and notes it needs to answer go to the AI provider, not your full medical record.
When the active chat configuration includes web research, the AI can search and read pages on a curated allowlist of clinical sources (NIH, NCI, PubMed, major academic medical centers, ACS). KeptWell instructs the AI not to include personal information in search queries and audits the queries it produces.
Subprocessors
We use a small number of vendors to run KeptWell. Each has a contract in place that limits what they can do with your data:
- OpenAI
- Document reading and summarization, and AI chat, when configured (response storage disabled; no training on API data by default).
- Anthropic
- Supporting AI tasks, plus AI chat and document processing when configured (no training on API data by default).
- AssemblyAI
- Transcribes audio recordings of appointments. It receives the recording through a time-limited link, plus the names of your circle members so it spells them correctly. It retains content under its API terms.
- Cloudflare
- File storage in the US region, where R2 encrypts stored files at rest with Cloudflare-managed keys. Cloudflare also indexes your extracted document text for search and runs the AI Gateway that proxies our requests to the AI providers, so prompt content passes through it in transit.
- Sentry
- Error reporting (identifying details scrubbed before transmission).
- Resend
- Transactional email (sign-in links, notifications).
- Database and application hosting
- US-based infrastructure.
Compliance status
- KeptWell does not currently offer a Business Associate Agreement or claim HIPAA compliance.
- We are not currently HITRUST-certified.
- Health care providers and other HIPAA-regulated organizations should not upload protected health information until a Business Associate Agreement is available.
What we ask of you
- Use a strong, unique password.
- Don't share your account login. Invite family members to your circle instead. That's what circles are for.
- Lock your phone. KeptWell is only as secure as the device you're signed in on.
If something goes wrong
Vulnerability reports: email hello@keptwell.org. We respond within one business day.
Want the plain-English version of how we handle your data?
See your data, in plain English →