Privacy Policy
Effective date: April 1, 2026 · Last updated: July 26, 2026
PainLog ("we," "us," or "our") is operated by Result Horizon LLC. We are committed to protecting your privacy and the security of your personal health information. This Privacy Policy explains how we collect, use, store, and protect your data when you use the PainLog application and website.
1. Information we collect
When you use PainLog, we collect the following types of information:
- Account information: Email address and authentication credentials when you create an account. If you sign in with Google, we receive your name and email from Google.
- Health data: Pain logs you create, including pain level, symptoms, triggers, timestamps, duration, and any notes you enter. This information may constitute Protected Health Information (PHI) under HIPAA.
- Usage data: Basic technical information such as device type and browser version, collected automatically to ensure the app functions correctly.
2. How we use your information
We use your information solely to provide and improve the PainLog service:
- To create and manage your account
- To store and display your pain log entries
- To enable data export features (TXT, CSV, PDF)
- To maintain the security and functionality of the application
We do not sell, rent, or share your personal health information with third parties for marketing or advertising purposes. We will never monetize your health data.
3. Data storage and security
Your data is protected using industry-standard security measures:
- Encryption at rest: All health data is stored in AWS DynamoDB with AES-256 encryption.
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.3.
- User isolation: Your data is stored with a unique user identifier. No other user can access your entries.
- Authentication: Access to your data requires authentication through AWS Cognito, with optional multi-factor authentication (MFA).
- Session management: Sessions automatically expire after 15 minutes of inactivity.
- Audit logging: All access to infrastructure is logged via AWS CloudTrail.
- Backups: Point-in-time recovery is enabled, allowing data restoration within a 35-day window.
Our infrastructure is hosted on Amazon Web Services (AWS), which maintains HIPAA-eligible services and has signed a Business Associate Agreement (BAA) with us.
4. Third-party services
PainLog integrates with the following third-party services:
- Amazon Web Services (AWS): Cloud infrastructure, authentication (Cognito), and database (DynamoDB). AWS has signed a BAA with us.
- Google Sign-In: Optional authentication method. When used, Google provides us with your name and email address only. Google does not receive your health data.
- Cloudflare: Hosts the static frontend application and provides CDN and security services.
5. Your rights
You have the following rights regarding your data:
- Access: You can view all your pain log entries at any time within the app.
- Export: You can export your entries in TXT, CSV, or PDF format at any time, and download a complete copy of your whole account when you begin account deletion.
- Correction: You can edit any entry at any time through the app.
- Deletion: You can delete individual entries at any time. To delete your entire account, tap Account in the app and follow the delete steps: you'll be offered a full export first, then deletion is scheduled with a 7-day grace period during which you can cancel it by signing in and tapping Cancel deletion. If you cannot access the app — or you are an authorized representative acting for an account holder — email us at the address below and we will verify your identity before acting.
- Portability: Your data exports use standard formats that can be opened with other tools or shared with your healthcare provider.
6. Data retention
We retain your health data for as long as your account is active. When you delete your account, deletion is scheduled after a 7-day grace period. Once the deadline passes, your entries, your feedback submissions, and your sign-in are permanently removed from our production systems — normally within 48 hours of the deadline, and in all cases within 30 days.
Deleted data may persist in encrypted backups until those backups expire — currently within 35 days of deletion — and is never restored to production except for disaster recovery.
Two things are deliberately not erased by an account deletion. First, if you sent us feedback or corresponded with support, copies of that correspondence may be retained in our operational email. Second, we keep security and audit records — including a metadata-only record of the deletion itself (dates and item counts, never health data) and application access logs identifying the acting account by an internal identifier — for the period required by HIPAA's audit-control and documentation rules — no less than six years. These records exist so that access to health data remains accountable and so that a deletion can be evidenced; they contain no entry content.
We may also retain data beyond these periods where retention is required for security investigations or to meet legal obligations.
7. Children's privacy
PainLog is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly.
8. Cookies and tracking
PainLog does not use cookies for advertising or tracking. We use only essential authentication tokens stored in your browser's local storage to maintain your login session. We do not use analytics tracking, pixels, or third-party advertising scripts.
9. Breach notification
In the event of a data breach that affects your personal health information, we will notify affected users within 60 days of discovering the breach, as required by HIPAA and applicable law. Notification will be sent to the email address associated with your account.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of PainLog after changes constitutes acceptance of the updated policy.
11. Contact us
If you have questions about this Privacy Policy, your data, or believe your privacy rights have been violated, contact us:
Result Horizon LLC
Email: [email protected]
You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. You will not be retaliated against for filing a complaint.