assertion.me · fhir · privacy

Privacy policy — personal health-record client

This policy covers the single-user application described at /fhir/. The application is run by the owner of this domain, for the owner's own medical records only. The owner is its only user and the only person whose data it handles.

What data is handled

Nothing else is collected. The application has no accounts, no sign-up, and no user other than the owner.

How it is used and where it is kept

The sign-in redirect

One step of sign-in passes through this website, and it is the only part of the process that does. When the health system finishes authenticating the owner it sends the browser back to /fhir/callback/ with a one-time authorization code in the address. That page is static: it runs no script, sets no cookie, and the server keeps no access log for it. The owner copies the address into the application on their own computer, which exchanges the code for access using a secret (a PKCE code verifier) that never left that computer. A code without that secret cannot be exchanged by anyone, and it is single-use and expires within minutes.

No medical record ever passes through this website. Records travel directly between the health system and the owner's computer.

Who receives the data

Nobody. There is no cloud storage, no analytics, no advertising, no data sale, and no sharing with any third party. These pages set no cookies and load no third-party resources.

Retention and deletion

Changes

This page is the current policy. A change is a new "last updated" date below; nothing is versioned elsewhere.

Contact

contact@assertion.me

Last updated 2026.09.08