AfterCare does not share, sell, or transfer your medical data to any third party. Your documents and recovery information are used only to generate and display your own recovery guide.
Encryption at rest
Every document you upload is encrypted before it is stored. AfterCare uses AES-256-GCM encryption — the same standard used in healthcare and financial systems worldwide. In plain terms, this means:- Your file is scrambled into unreadable data before it ever touches persistent storage.
- Each document is encrypted separately, so two identical files produce two completely different encrypted blobs in storage. No one can identify your document by comparing encrypted data.
- Without the matching key, the stored data is meaningless — even to someone with direct access to the storage infrastructure.
Deduplication
If you upload the same document more than once, AfterCare recognises it automatically. Uploading an identical file a second time:- Does not create a duplicate entry.
- Does not re-run the processing pipeline (saving time and cost).
- Does not store the file a second time.
Audit logging
AfterCare records an access log every time your data is requested. This log follows a HIPAA-shaped pattern: it captures who accessed what and when, without ever recording the contents of your document, your extracted medical information, or your recovery plan text. Each audit entry records:- The action performed (for example, a document was viewed or a medication list was fetched).
- The resource identifier (the document or record involved).
- The timestamp of the access.
- The IP address of the request.
- The HTTP status code of the response.
Deleting your data
You can delete any document and all associated recovery plan data at any time. Deleting a document removes the encrypted file, all extracted recovery data, and all audit records associated with that document. Deleting a document is permanent and cannot be undone.Local mode and your privacy
When AfterCare runs in Local mode (no account, no cloud), your data never leaves your browser at all.- Documents are stored entirely within your browser on your own device.
- Recovery guide data is saved locally in your browser’s storage.
- No network requests are made to any AfterCare server for storage or retrieval.
- Audit logging does not apply because no server handles your data.