← Back

Privacy Policy

How we handle your data

Data Collection

What we gather

  • •Account information: email, name, credentials
  • •Clinical data: constitution type, conditions, prescriptions
  • •System usage: logins, feature access patterns
  • •Technical data: IP, browser, device info

Data Usage

Why we use it

  • •Generate diet prescriptions
  • •Maintain secure authentication
  • •Comply with HIPAA
  • •Improve system performance
  • •Prevent fraud and unauthorized access

Data Protection

How we secure it

  • •Encrypted in transit and at rest
  • •Restricted access to practitioners
  • •Audit logs of all data access
  • •Encrypted database backups

HIPAA Compliance

Legal compliance

  • •Designed to comply with HIPAA regulations
  • •Patient records treated as PHI
  • •No third-party data sharing without consent
  • •Breach notification within required timeframes

Data Retention

How long we keep it

  • •Retained while account is active
  • •Deletion available on request
  • •Secure purge within 30 days of deletion

Third-Party Services

External tools we use

  • •Supabase for auth and database
  • •All services HIPAA-compliant
  • •All maintain security standards

Your Rights

What you control

  • •Access your personal data
  • •Correct inaccurate information
  • •Request account deletion
  • •Export data in standard formats
  • •Receive breach notifications

Contact Us

Questions?

  • •Email: privacy@rasacare.io

Key Takeaway

Your data is encrypted, protected, and only used for clinical decision support. You have full control over your information. Patient records are treated as Protected Health Information under HIPAA. Contact us anytime at privacy@rasacare.io.