Privacy Policy
Summary
Angel is a private organizer for your own health records and a research library for the conditions you choose to follow. It helps you find, read, and discuss published research with your clinicians. It does not diagnose, treat, or tell you what to do.
Your vault contents are encrypted on your device before they reach our servers. We design Angel so that operators and hosting providers see ciphertext only, not your health records, filenames, tags, or search terms.
What we collect
Account and session data: sign-in identifiers (such as email or Sign in with Apple subject), session tokens, invite code used at registration, subscription tier, and billing identifiers when you subscribe on the web.
Encrypted vault storage: ciphertext blobs, wrapped encryption keys, and minimal item metadata (item IDs, sizes, timestamps). Filenames and tags live inside your encrypted manifest, not in plaintext on the server.
Research profile (separate, consented): if you opt in during onboarding, condition choices and watch preferences you mark as shareable for research queries. This is stored separately from your encrypted vault and can be deleted in settings.
Audit events: authentication and account events (for example sign-in, item fetch, billing changes) without vault content.
What we do not do
- We do not sell your data.
- We do not run advertising or behavioral analytics SDKs.
- We do not log vault content, extracted text, chat text, or search terms on servers.
- We do not read your passphrase or recovery phrase. We cannot reset them.
Encryption and keys
You choose a vault passphrase. Your browser or app derives keys locally and encrypts documents, notes, imports, and search indexes before upload. Losing both your passphrase and recovery phrase means your vault cannot be recovered. This is intentional.
AI and external services
When you use Ask Angel, selected content is decrypted only on your device, de-identified, and sent over TLS to external AI providers you consent to (for example Anthropic). We use zero-data-retention API settings where available. AI answers cite your vault sources or published research, or state when information is not available.
Daily research digests use your consented research profile only, not your encrypted vault documents.
Imports and integrations
If you connect Google Drive, OAuth tokens are used during your active session to list and download files you select. Downloads are encrypted on your device before upload. Google OAuth credentials are not stored in plaintext on our servers.
Web subscriptions are processed by Stripe. Stripe receives billing data needed to manage your subscription. We do not send vault content to Stripe.
Retention and deletion
You can export your vault from settings (decryption happens in your browser). You can delete your account in settings, which removes server-side ciphertext, sessions, research profile, and billing linkage. Deletion is designed to be immediate.
Security
Traffic uses TLS. We apply strict cache headers, minimize server-visible metadata, and enforce tenant isolation on every data access path. No system is perfectly secure; see our public security documentation for honest limits.
Children
Angel is not directed at children under 13. We do not knowingly collect data from them.
Changes
We may update this policy as the product evolves. Material changes will be reflected on this page with an updated effective date.
Contact
Questions: ryan@last1.enterprises