Hearts+
Back to sign in

Privacy Policy

Effective August 6, 2026.

See also Terms and Conditions and Usage Policy.

Our commitment to you

Hearts+ is a health platform. The information you share with us is health information, and we treat it that way. Your data is protected under the Health Insurance Portability and Accountability Act (HIPAA) and the regulations issued under it, including the Privacy Rule, the Security Rule, and the Breach Notification Rule. Every system that stores or processes your health information operates under these protections, and every service provider that touches it is bound by a Business Associate Agreement. We do not sell your data. We do not use it for advertising. We do not share it with anyone outside the circle described in this policy.

Information we collect

We collect the information you give us and the information your use of the platform creates:

  • Account information: your name, email address, password, and optional phone number.
  • Conversations: the messages you exchange with SAHRA.
  • Health information you record: symptoms, weight, blood pressure, heart rate, medications and doses, meals and food photos, and the contents of your care plan, including the hospital discharge plan you upload.
  • Connected device data: readings from devices and services you choose to pair, such as smart scales, blood pressure cuffs, smartwatches, and Apple Health.
  • Location information, only if you turn it on: the home address you enter and, if you separately allow it, your live location, used to bring local conditions such as air quality and heat into your care.
  • Support requests: what you tell us when you ask for help.
  • Technical records: your account identifier, the time of each interaction, and the records our systems keep to run reliably and securely.

We do not collect financial information or any data unrelated to your heart failure self-care.

How we use your information

Your information is used to run Hearts+ for you:

  • To let SAHRA respond to you, check in with you, and tailor guidance to your care plan and your history.
  • To show you your own record: your boards, charts, medications, and trends.
  • To share with the care contacts you invite, to the extent you choose.
  • To reach you on the channels you pick, such as app notifications or text messages.
  • To keep the platform safe, including detecting misuse and fixing failures.
  • For research, only as described in the research study section below.

Automated systems, including artificial intelligence models, process your messages and health records to generate SAHRA's responses. These systems run inside the same HIPAA-covered infrastructure as the rest of your data, and what they process is logged the same way every other access is logged.

Text messaging

If you choose to receive support from SAHRA by text message, message and data rates may apply. Message frequency varies and depends on how you use the service and the reminders in your care plan.

Text messaging is optional and is never a condition of enrolling in Hearts+ or of receiving care. We do not sell your mobile phone number, and no mobile information is shared with third parties or affiliates for their own marketing or promotional purposes. The fact that you consented to text messaging is never shared with third parties. Your number is used only to deliver your Hearts+ care messages, and it is disclosed only to the messaging providers that carry those messages for us, which handle it under Business Associate Agreements and only on our instructions.

You can stop text messages at any time by replying STOP to any message, which unsubscribes that number. Reply HELP for help. You can also turn text messaging off in the app under Settings.

How HIPAA protects your information

HIPAA is not a label we put on the platform; it is how the platform is built. In practice, it means:

  • Your health information is encrypted in transit and at rest.
  • Your information lives only in systems covered by Business Associate Agreements, and processing happens in the United States.
  • Apps and websites never read the health database directly. Every request goes through our backend service, which checks who you are and what you are allowed to see before anything is returned.
  • Every access to your health information, by a person or by a system, is recorded in an audit log.
  • Your health record is kept as an append-only history: entries are added, never silently rewritten or erased.
  • Access follows the minimum necessary standard: people and systems see only what their role requires.
  • If a breach of your health information ever occurs, we are obligated to investigate it and notify you and the authorities as the Breach Notification Rule requires, and we will.

Who can see your information

  • You. Your record is yours, on every device you sign in from.
  • Care contacts you invite, and only to the extent you allow.
  • The research team, under the rules in the research study section below.
  • Authorized technical staff, under strict access controls, when maintaining the platform requires it.
  • Our service providers, such as cloud hosting, database, AI processing, messaging, email, and device-data services, each bound by a Business Associate Agreement and each limited to the minimum needed to do its job.
  • Authorities, if and only to the extent the law requires us to disclose.

No one else. There is no sale of data, no advertising use, and no third-party marketing.

The research study

Hearts+ operates as part of a research study, and the study has its own rules, set out in the informed consent you accepted when you enrolled.

  • Your participation in the study is governed by that consent, not by this policy. Where they overlap, the consent controls for research data.
  • Study analysis uses de-identified data. Researchers see your identified record only if you have given a separate, explicit consent for a specific study.
  • You may withdraw from the study at any time, in the way the consent describes, without losing access to care from your own providers.

Your rights and choices

  • You can see your information in the app at any time.
  • You can correct your account details and health entries you control.
  • You can turn location off and have your saved location deleted, in Settings.
  • You can disconnect any paired device, in Settings.
  • You can choose and change how we contact you.
  • You can ask for your data to be deleted. We delete your operational data; records the law requires us to keep, such as consent records, access logs, and the record of the deletion itself, are retained.
  • You can withdraw from the research study as the consent describes.

To exercise any of these rights, use Help and support in the app or contact the research team using the details in your consent document.

Data retention

We keep your information while your account is active. If you ask for deletion, we delete your operational data and retain only the compliance records described above, for as long as the law requires.

Security

We maintain administrative, technical, and physical safeguards appropriate to health information: encrypted storage and transport, role-based access, audit logging, monitoring, and an incident response process. No system is perfectly secure, which is why our obligations under the Breach Notification Rule exist: if your information is ever compromised, you will hear it from us.

Children

Hearts+ is for adults. You must be at least 18 years old to have an account.

Changes to this policy

If we change this policy in a meaningful way, we will tell you in the app before the change takes effect, and the version number above will move.

Contact

For questions about this policy or about your information, use Help and support in the app, or contact the research team using the details in your consent document.