Privacy Policy
1. Introduction & scope
SteadyHeart (稳心; "SteadyHeart," "the app," or "we") is a home health record-keeping and management tool for heart-failure patients of all ages and their family caregivers. We take the protection of your personal information and privacy seriously, especially health-related sensitive personal information. This Privacy Policy explains how we collect, use, store, share, and protect your personal information, and what rights you have.
The personal-information handler (controller) under this policy is 李国庆. This policy applies to the SteadyHeart mobile app (bundle identifier: info.steadyheart.app) and to the SteadyHeart website (https://steadyheart.dalizixun.cn), including all features and services they provide.
Medical positioning: SteadyHeart is a health-management and record-keeping tool. It is not a medical device and does not provide medical diagnosis, treatment advice, or prescriptions. Deterministic alerts in the app are reminders to seek in-person care promptly, not medical decisions. See the Medical Disclaimer for details.
Please read this policy carefully before using SteadyHeart. By starting to use the app, you acknowledge that you have read it. For sensitive personal information, we process it only after obtaining your separate consent (see Section 4).
2. What data we collect
We collect information only to the extent necessary to deliver specific features. The table below lists the categories of information we process, with examples and purposes. Health-related data is treated as sensitive personal information and subject to stricter safeguards.
| Category | Examples | Purpose |
|---|---|---|
| Account information | Phone number, login credentials (passwords stored as salted hashes, never in plaintext) | Creating and signing in to your account, identification, account security |
| Health data (sensitive personal information) | Weight, vital signs, blood oxygen saturation (SpO₂), fluid intake/output, medication records, lab results (including BNP/NT-proBNP), electrocardiogram (ECG) files, hospitalization records, symptom records | Health self-management, trend tracking, reminders and deterministic alerts, report generation, doctor sharing where you consent |
| Device, usage & log data | Device model and OS version, app version, crash and diagnostic logs, operation audit logs, necessary preference settings | Keeping the service stable and secure, troubleshooting, auditing and abuse prevention |
| Voice input | Audio used for voice entry (recognized locally on your device by default) | Converting speech into recorded text; cloud voice recognition is used only with your separate consent |
| Photos | Images used for lab-report OCR | Reading values from lab reports to make entry easier; used only when you choose to |
We do not collect information unrelated to the above purposes without your knowledge, and we do not require you to provide information that is not necessary for a given feature.
3. Purposes & legal bases
We process your personal information for the following purposes:
- Helping you with health self-management and record-keeping;
- Providing reminders for medication, measurements, and similar tasks;
- Triggering deterministic alerts based on the data you enter (notifications based on fixed thresholds/rules, not medical judgments);
- Generating reports you can reference or bring to in-person care;
- Synchronizing data across your devices;
- Responding to your support and service requests.
Legal bases: our primary basis for processing personal information is your consent. For health-related sensitive personal information, we rely on your separate consent. In addition, we may process necessary information to comply with legal obligations, safeguard the security of the service, or protect your or others' life and health in an emergency, where permitted by law. For users in regions such as the European Economic Area, processing may also rely on performance of a contract, legitimate interests, or legal obligations (see Sections 12 and 14).
4. Separate consent for sensitive data & withdrawal
Health data (such as vitals, SpO₂, intake/output, medications, lab results, ECG, hospitalization records, and symptoms) is sensitive personal information. We collect and process such data only after obtaining your separate consent, and we explain the purpose, method, and scope of processing through a clear, standalone consent screen in the app.
Withdrawing consent: you can withdraw your consent to the processing of sensitive personal information at any time in the app settings, or by contacting us at steadyheart@keephealthy.work. Withdrawal does not affect the lawfulness of processing carried out based on consent before the withdrawal.
Effect of withdrawal: after you withdraw consent, features that rely on such data (trend tracking, alerts, reports, doctor sharing) can no longer be provided to you. Processing of the related data will stop according to your choice, and you may request its deletion under Section 7.
5. Storage & security
We apply technical and organizational measures commensurate with the sensitivity of the information:
- Local-first: your health data is stored primarily on your device by default; cloud sync is an optional feature.
- Field-level encryption: sensitive fields are encrypted at the field level using AES-256-GCM.
- Searchable hashing: fields that need to be searched use HMAC hashing to enable lookups without exposing plaintext.
- Encryption in transit: data is encrypted with TLS while transmitted over the network.
- Access controls & audit logs: data access is governed by least-privilege controls and recorded in audit logs for traceability.
- Biometric unlock: you can enable biometric unlock (such as fingerprint or face) on your device to further protect local data.
Please note: no technology can guarantee absolute security over the internet. Keep your login credentials and device unlock method safe, and avoid signing in from untrusted environments.
6. Data minimization
We follow the principle of data minimization: we collect only the information genuinely necessary for the features you use, keep it only for as long as necessary, and limit access to the personnel and systems needed to achieve the purpose. When information is no longer necessary to achieve the purpose, we delete or anonymize it.
7. Retention & deletion
We retain your personal information only for as long as necessary to achieve the purposes described in this policy, unless a longer retention period is required by law. Retention periods are determined by weighing the category of information, feature needs, legal obligations, and security needs.
Specific retention periods are as follows:
You may request deletion of your account and all health data at any time. For deletion methods and timelines, see the Account & Data Deletion page. After deletion is completed, we delete or anonymize your personal information, except for the minimum information we are required to retain by law.
8. Sharing & disclosure
We do not sell your personal information. We share or disclose your information only in the following limited circumstances:
- Patient-authorized doctor access: only after you (or your legal representative) actively authorize it can a doctor access the corresponding scope of health data. Authorization is scope-limited and revocable at any time, with an audit trail throughout. We verify the doctor's professional qualifications. Once you revoke authorization, the doctor can no longer access the relevant data.
- Processing on our behalf: to deliver specific features, we may engage processors to handle information under our instructions (see Section 9), bound by contract to confidentiality and security obligations.
- Legal & emergency: where required by laws and regulations, in response to lawful requests by regulatory or judicial authorities, or to protect the life, health, or major legitimate interests of you or others in an emergency, we may disclose necessary information as permitted by law.
9. Third parties & processors
To deliver certain features, we may rely on the following types of third-party capabilities, with clear boundaries on data flows:
- Speech recognition (ASR): completed locally on your device by default, with no cloud upload. Cloud speech recognition is used only with your separate consent.
- Lab-report OCR: during recognition, the image is sent to the processor for text recognition, which returns a pending result for you to confirm; the OCR boundary is limited to that recognition task.
- Push and model-capability adapters: message push and model capabilities are integrated through an adapter layer, passing only the data necessary to deliver the relevant feature and staying within the service boundary.
Where any such processing involves cross-border transfer, we apply safeguards in accordance with Section 12.
10. Children & caregiver/guardian proxy
SteadyHeart can be used by patients themselves or managed by family caregivers on their behalf:
- Minors: a minor's information is managed by their guardian after guardianship is confirmed. We do not provide services to minors independently.
- Family proxy for adult patients: family members may manage an adult patient's health data on their behalf after confirming proxy authorization and obtaining the consent of the patient (or their legal representative).
If you believe we have processed personal information without appropriate authorization, please contact us at steadyheart@keephealthy.work and we will promptly verify and address it.
11. Your rights & how to exercise them
To the extent permitted by applicable law, you have the following rights regarding your personal information:
- Access: to know about and access the personal information we process about you;
- Copy & portability (export): to obtain a copy of your data or, where technically feasible, transfer it to a recipient you designate;
- Correction: to correct inaccurate or incomplete information;
- Deletion (right to be forgotten): to have your personal information deleted where conditions are met;
- Withdraw consent: to withdraw consent to processing (including of sensitive personal information) at any time;
- Complaint: to lodge a complaint with us about the processing of personal information, or with a competent supervisory authority.
How to exercise: you can exercise these rights directly in the relevant in-app settings (such as export, correction, deletion, and revoking authorization), or by emailing steadyheart@keephealthy.work. To protect your account, we may need to verify your identity before processing a request.
12. International transfers
SteadyHeart uses the laws of the People's Republic of China, including the Personal Information Protection Law (PIPL) and the Data Security Law (DSL), as its compliance baseline. If you use the app outside mainland China, or if your data genuinely needs to be transferred across borders, we apply the safeguards required by applicable law (such as obtaining separate consent, conducting impact assessments, and entering into data-transfer clauses). For users in regions such as the European Economic Area, we also take into account the requirements of the General Data Protection Regulation (GDPR); and where U.S. health-information protection (HIPAA) is relevant, we handle data with corresponding awareness and care.
13. Contact
If you have any questions, comments, or complaints about this policy or our processing of personal information, or wish to exercise your rights, please contact us:
- Personal-information handler: 李国庆
- Contact email: steadyheart@keephealthy.work (steadyheart@keephealthy.work)
If a Data Protection Officer (DPO) or other dedicated contact is designated, their details will be added here.
14. Compliance alignment & references
This policy is drafted with reference to, and aligned with, the following laws and frameworks:
- Personal Information Protection Law of the People's Republic of China (PIPL)
- Data Security Law of the People's Republic of China (DSL)
- Awareness of the General Data Protection Regulation (GDPR) for overseas users
- Awareness of the Health Insurance Portability and Accountability Act (HIPAA) where U.S. health information is involved
15. Changes to this policy
We may update this policy from time to time to reflect changes in features, laws, or processing practices. When we make material changes, we will notify you through in-app notices, website announcements, or other appropriate means; where material changes involve the processing of sensitive personal information, we will obtain your separate consent again. The effective date and last-updated date of this policy appear at the top of the page.