Skip to content
ConsentLoom
← ConsentLoom

Privacy and data handling

Updated September 8, 2026.

One shared application, eleven tools

FinchApps Personal Health Tools includes VisitQuill, DoseFolio, LabPrism, PulseTrellis, CareThread Atlas, AllergyFolio, VaxLedger, ConsentLoom, FHIR Trail, SourceWeave, WhenWillIDie. These sites provide read-only personal record review. Each asks for the categories needed for its view; you can reduce that selection before continuing.

Your choice of access

FinchNode hosts collection and sharing consent and routes you to your healthcare organization's sign-in. We never ask for your EHR password. The request is for a one-time transfer and one day of sharing; you may revoke sooner through FinchNode data controls. Revoking this shared application can affect access from all eleven sites.

What passes through the service

After your authorization, selected normalized records pass from FinchNode through our connection service hosted on Render to your browser. Those records may include identity and health information in the categories you select. We do not sell records, send them to advertising or AI services, or use analytics trackers.

Retention and copies

The connection service does not save clinical records to a database, disk, or application logs. It holds a pseudonymous connection reference and a hashed session token in memory for up to 30 minutes. Server restarts end sessions earlier. Your tab stores only its temporary access token in sessionStorage; records are held in page memory, cleared when the tab is hidden, and refreshed against consent when you return. Closing or ending the session removes local access. API responses are marked private and non-cacheable.

FinchNode and your source organization maintain records and consent under their own policies. Local session expiry does not delete those copies. If you choose Download or Print, the resulting file is under your control and will not update or disappear automatically.

Revocation and deletion

Use FinchNode data controls to revoke sharing or request deletion there. Signed lifecycle notifications invalidate active sessions; every record request also checks live consent. The visible page rechecks at least every 30 seconds while open. End this session clears this site's access immediately.

Hosting and technical data

Render delivers the sites and connection service and necessarily processes network request information such as your IP address. GitHub hosts source code only. Neither health records nor production API keys are published in repositories. Service providers' own retention and security practices also apply.

Site and privacy contact

Site name: consentloom.onrender.com. For privacy questions or requests, contact software@council.health.

Record limitations

Coverage, freshness and completeness depend on FinchNode and your source organization. Missing records never establish absence of a condition, medication, allergy or event. These tools do not diagnose, prescribe, or replace professional review.