What we hold, what leaks, and what it will not do.
Your medicine list is sensitive, and what can be inferred from it is more sensitive still. Here is the architecture, including the parts that are not airtight.
Built so we hold as little as possible
What we hold
Your shelf is encrypted with a key made on your device and held there. What our servers hold is the sealed version and nothing else. There is no copy of your key on our side.
Anything you write during a crisis stays on your device and is never used for anything else. We do not promise never to contact anyone; we publish what triggers escalation instead, because the absolute version of that promise is the one thing that cannot be honoured.
And here is what still leaks
We can see when each piece of data arrived, to the millisecond. That is our clock stamping receipt, not yours writing. We removed the column and the network still shows us the timing, so we list it rather than claim a totality we do not have.
If you have not set a passphrase, the key is held by the phone, so anything that can unlock the phone can open your data. And a key that gets out cannot be taken back, and there is no button here that undoes that. Both are on the same list, in the app, before you have entered anything.
What it will not do
These are not limitations we are apologising for. Each one is load-bearing, and most cost us a feature we had already designed.
The refusals are the product.
If a feature cannot be built without implying "consider stopping", it does not get built in that form.