Apple-Level Privacy for Your Health Data
Your health information belongs to you alone. We use the same encryption that protects Apple Pay and Face ID to keep the records on your device private, even from us.
7 Layers of Protection
Available Health doesn't rely on any single security measure. We implement defense in depth with multiple independent layers.
Biometric Authentication
Face ID, Touch ID, or Optic ID required to open the app
Secure Enclave
Hardware-isolated key storage on Apple's security chip
Field-Level Encryption
Every piece of sensitive data encrypted with AES-256-GCM
Apple File Protection
Database files completely inaccessible when your device is locked
PII Redaction
Personal identifiers stripped before your data goes to an AI model
Encrypted Transit
All network communication over HTTPS with TLS 1.3
Zero Data Retention for Chat
Chat runs on HIPAA-compliant infrastructure and is never stored on our servers
Hardware-Level Security with Apple's Secure Enclave
On supported devices, your encryption keys are stored in the Secure Enclave, a dedicated security chip physically isolated from the rest of your device. This is the same technology Apple uses to protect Face ID data and Apple Pay credentials.
- Your encryption keys are protected at the hardware level
- Even with physical access to your device, keys cannot be extracted
- Apple's security architecture protects your keys on iPhone and iPad
Military-Grade Encryption (AES-256-GCM)
Every piece of your health information is encrypted with 256-bit AES-GCM encryption before it's ever stored. This is the same encryption standard used by governments and financial institutions worldwide.
We encrypt:
Your data is encrypted before it's stored, not just at the storage level. Even with direct database access, your information remains unreadable without your biometric authentication.
Your Face (or Fingerprint) Is the Key
On devices with biometric support, Available Health uses Face ID or Touch ID to unlock your health data. There's no password to remember, lose, or have stolen in a data breach.
- Your biometric data never leaves your device
- Device passcode serves as a secure fallback
- Encryption keys are cleared from memory when the app is locked
Zero-Knowledge Cloud Sync
Want your health records on your iPhone and iPad? Available Health syncs seamlessly across your devices while maintaining complete privacy.
Encrypted on Device
Your data is encrypted on your device before it ever leaves
Secure Transit
Only encrypted data travels to iCloud (Apple sees ciphertext only)
Keys via Keychain
Encryption keys sync separately via iCloud Keychain's end-to-end encryption
Local Decryption
Your other devices decrypt locally after Face ID or Touch ID authentication
What's Protected
Every Available Health user gets the same strong privacy protection, no tiers, no exceptions.
Local Encryption & De-Identification
Your records are encrypted on your device, and your personal identifiers are automatically stripped before your data goes to an AI model.
- Full local encryption
- Biometric authentication
- PII redaction for AI
- Secure Enclave protection
HIPAA Compliance + Zero Data Retention for Chat
Chat is processed with zero data retention. Documents you import are stored encrypted on our HIPAA-covered infrastructure so we can read large files and answer questions about them, and are deleted when you delete them.
- HIPAA-compliant AI processing
- Zero data retention for chat
- Imported documents deleted when you delete them
- BAA-covered infrastructure
- Included for everyone
Automatic Privacy Protection
When you ask questions about your health, we automatically protect your identity before your question goes to an AI model.
This happens automatically, every time, with no action required from you. Your questions get answered. Your identity stays private.
Built for Healthcare Compliance
Our architecture is designed with healthcare regulations in mind.
Why This Matters
Your health records contain some of the most sensitive information about you: your diagnoses, your medications, your genetic risks, your mental health history. This information deserves protection that matches its sensitivity.
Cloud-based AI chat services have their place, but they were not built around your health records. For users who want the benefits of AI on sensitive medical information, a different approach is needed.
That's why we built Available Health as a local-first application. Your health data lives on your device, encrypted with keys only you control. When we do need to process something in the cloud, we strip your identity first, and chat runs with zero data retention for everyone. Documents you import are stored encrypted on our servers so we can read them, and are deleted when you delete them.
Your health data is yours. We built Available Health to keep it that way.
Questions about our security practices?