Last updated: February 2026
FHIR Gateway ("Service") is an API gateway that connects users to healthcare FHIR endpoints. This policy explains what data we collect, how we use it, and your rights regarding that data.
We collect the following data to operate the Service:
We do not store, cache, or retain any Protected Health Information (PHI) or personal health data. All healthcare data flows through the Service in real-time and is not persisted.
We use collected data solely to:
We do not use your data for marketing, advertising, analytics profiling, or any purpose other than providing the Service.
We disclose data only in the following circumstances:
We do not sell, rent, or share your personal data or health information with third parties for marketing or any other commercial purpose.
You explicitly consent to each healthcare platform connection through the OAuth authorization flow. Each platform requires separate authorization. We only access data from platforms you have authorized.
You can withdraw consent at any time by:
When you withdraw consent, your session tokens are immediately deleted. Since we do not persistently store PHI, there is no health data to delete.
We protect your data through:
We do not collect, use, or disclose de-identified health information. Request logs contain only operational metadata (timestamps, resource types, status codes) and cannot be used to identify individuals or their health conditions.
Any third-party service providers (such as hosting providers) are contractually obligated to protect your data and may only use it to provide services to us.
If the Service undergoes a change in ownership or ceases operation:
We may update this policy from time to time. Material changes will be noted with an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy. For significant changes affecting data use, we will seek re-affirmation of consent where feasible.
You have the right to:
For questions about this privacy policy or to exercise your rights, please open an issue on our GitHub repository or contact the maintainers.