Skip to main content
AfterCare handles medical documents, so protecting your data is not optional — it is built into how the service works at every layer. This page explains exactly what happens to your documents and recovery data, how AfterCare protects them, and the controls you have.
AfterCare does not share, sell, or transfer your medical data to any third party. Your documents and recovery information are used only to generate and display your own recovery guide.

Encryption at rest

Every document you upload is encrypted before it is stored. AfterCare uses AES-256-GCM encryption — the same standard used in healthcare and financial systems worldwide. In plain terms, this means:
  • Your file is scrambled into unreadable data before it ever touches persistent storage.
  • Each document is encrypted separately, so two identical files produce two completely different encrypted blobs in storage. No one can identify your document by comparing encrypted data.
  • Without the matching key, the stored data is meaningless — even to someone with direct access to the storage infrastructure.
You do not need to manage keys yourself. Encryption and decryption happen automatically whenever the AfterCare service handles your document.

Deduplication

If you upload the same document more than once, AfterCare recognises it automatically. Uploading an identical file a second time:
  • Does not create a duplicate entry.
  • Does not re-run the processing pipeline (saving time and cost).
  • Does not store the file a second time.
This protects you from accidental double-uploads and ensures you are not charged processing time for the same paperwork twice.

Audit logging

AfterCare records an access log every time your data is requested. This log follows a HIPAA-shaped pattern: it captures who accessed what and when, without ever recording the contents of your document, your extracted medical information, or your recovery plan text. Each audit entry records:
  • The action performed (for example, a document was viewed or a medication list was fetched).
  • The resource identifier (the document or record involved).
  • The timestamp of the access.
  • The IP address of the request.
  • The HTTP status code of the response.
This means that if there is ever a question about who accessed your data, there is a complete record — and that record cannot include the sensitive contents themselves.

Deleting your data

You can delete any document and all associated recovery plan data at any time. Deleting a document removes the encrypted file, all extracted recovery data, and all audit records associated with that document.
A self-service delete button is coming to the AfterCare dashboard in a future release. In the meantime, contact support to request deletion of any document and its associated data.
Deleting a document is permanent and cannot be undone.

Local mode and your privacy

When AfterCare runs in Local mode (no account, no cloud), your data never leaves your browser at all.
  • Documents are stored entirely within your browser on your own device.
  • Recovery guide data is saved locally in your browser’s storage.
  • No network requests are made to any AfterCare server for storage or retrieval.
  • Audit logging does not apply because no server handles your data.
Local mode data is tied to the browser you used. Clearing your browser data, uninstalling the browser, or switching to a different device will permanently remove your locally stored documents and recovery guide.

Summary of protections