Security & privacy

Your health data deserves bank-level protection.

We don't sell data. We don't share it. We don't even look at it unless you explicitly ask us to.

GDPR Compliant

Built to meet the highest European data protection standards. Your rights to access, correct, and delete are built into every feature.

Encrypted at rest & in transit

AES-256 encryption protects your records whether they're stored or being accessed. The same standard used by financial institutions.

You show it, you control it

There's no separate doctor login and nothing is shared remotely. You open the record on your own device and show it directly — in person, in the moment, under your control the whole time.

Delete anytime

Want out? One click deletes all your data permanently. No retention periods, no dark patterns, no "are you sure?" loops. Gone means gone.

How we encrypt your health records

If you're trusting an app with your medical history, you deserve a straight answer to one question: can anyone else actually read this? Here's exactly how, in plain language — not legal fine print.

The short version

Your medical records are encrypted before they're ever stored. Not "encrypted at some point." Not "encrypted eventually." The moment you save a record — a medication, an allergy, a scanned prescription — it's scrambled into unreadable ciphertext before it touches our database. If someone got access to our database directly, they wouldn't see your health information. They'd see meaningless noise.

What "encrypted" actually means here

Think of encryption like a locked box with a key. Without the key, the box is just a box — you can hold it, copy it, steal it, and it tells you nothing. Syncura uses an industry-standard encryption method (AES) to lock each individual record, and the key that unlocks it is kept in a separate, specially protected vault — not sitting next to the data itself, and not accessible through the normal app.

This applies to everything:

  • The text of your records — medications, conditions, allergies, appointment notes, whatever you write or scan in
  • Any files you attach — lab PDFs, photos of prescriptions, vaccination cards, insurance documents

Both are encrypted independently, each with their own unique key material, so there's no single point where "cracking one thing" exposes everything.

Who can actually see your records

You can. When you open the app and view a record, it's decrypted just for that moment, just for you, on your own device.

Family members you explicitly share with can — and only the specific records you've marked as shared, never your private ones.

Doctors can — but only when you show them. There's no doctor login, no remote access, no shareable link sitting out there that anyone could stumble onto. When you're in a clinic or hospital, you open your own phone, tap into the relevant record, and hand your device to the doctor — optionally translating it into their language first. The moment that interaction ends, nothing has been shared or copied anywhere. You're always the one holding the key.

We don't, casually. Syncura's own systems are built so that record content isn't something we browse or access in the normal course of running the app — the whole architecture is designed around you holding the access, not us.

Why this matters more for expats specifically

If you're managing your health across borders, your records already have to survive being useful in a system you don't fully trust yet — a new country, a new insurance system, a new hospital that's never seen your file. That's exactly the moment encryption should be doing its job quietly in the background, so the only thing you have to worry about is getting good care, not whether your data is safe getting there.

Questions? If anything here isn't clear, or you want more technical detail, we're glad to answer — reach out at contact@syncura.health.