Skip to content
Legal

Privacy policy

VitalMesh handles protected health information, real-time biometric streams, and signed consent grants. The full legal text is being finalised with counsel; below is the plain-language summary that the security page already links to. The final document will replace this stub without a URL change.

  1. What we collect. The minimum needed to run the service: your account email, a wallet address (yours or your hospital’s), signed consent grants, the hash-chained audit ledger, and — for hospital plans — vitals streams from the ingest pipeline.
  2. Where it lives. Neon Postgres with TLS in transit and AES-256 at rest. Bangladesh hospital deployments are provisioned in the AWS Mumbai region to keep every byte under DPDP Act §14.
  3. What we never do. We do not sell PHI, run third-party trackers on clinical surfaces, or share vitals with anyone outside the bridge the patient explicitly granted. On-chain consent memos publish only the consentPda + pubkey pair in plaintext — the clinical payload (grantee name, reason, urgency, expiry) is sealed under the SSID envelope.
  4. Your rights. Export your data at any time from the patient dashboard. Revoke a consent grant and the change propagates within one second. Right-to-erasure is multi-approver on Family and Hospital plans so a compromised patient account can’t wipe another household member’s records.
  5. Contact. Email privacy@vitalmesh.example for any data-protection request. We respond within one business day.

Last updated 2026 · awaiting counsel sign-off on the long-form legal text. Read the security posture →