English
Privacy & Data Protection
Your data. Your choice. Fully transparent.
Last updated: 21 August 2026
What data do we store?
- Implant Card — Name, date of birth, blood type, device type/brand/model/serial number, implant date, MRI compatibility, leads, implant hospital, cardiologist, emergency contact, medications, allergies, notes.
- Health Diary — Entry type, date/time, heart rate, intensity, symptoms, description, shock type, activity.
- Health Data (heart rate) — Heart rate in BPM, timestamp, source, anomaly flag.
- Forum Posts — Title, content, category, display name (alias), email (not public), language, likes.
- Access Code — The unique code, label, used status, session ID, expiry date.
- User Account — Email address, name, role.
Where is your data stored?
All of the above data is stored on the secure servers of Base44, our platform provider. Only your language preference and session token are stored locally on your phone (no medical data).
Does your data leave the phone?
- Yes, to the server: implant card, diary, health data, forum posts.
- Yes, to Google Translation API: interface text only, for languages not built in (no medical data).
- Yes, to Google Places API: hospital searches and travel planner (no medical data).
- No, stays on the phone: GPS location (only for sorting nearby hospitals) and fall detection (processed locally).
QR code and emergency card
The QR code on your implant card contains a link to a public emergency page with your implant data. This page is accessible without login — deliberately, for first responders in emergencies. The page shows device type, MRI status, leads, emergency contact, medications, allergies and device-specific instructions. You decide who you share the QR code with; the page is not indexable by search engines.
Location and fall detection
Your GPS location is only used locally to sort hospitals by distance — not stored, not sent. Fall detection uses the accelerometer on your phone and only works if you enable it. On a hard fall, a 10-second countdown starts; if you do not cancel, the app opens your SMS app with an emergency message and (if available) your location as a Google Maps link. No data is stored.
Forum and automatic translation
Forum posts are stored on the server. Your email address is not publicly visible — only your chosen display name. Posts can be automatically translated via Google Translation API for users in a different language; the original text is preserved.
Which third parties do we use?
- Base44 — platform provider: database, authentication, hosting.
- Google Translation API — automatic translation of interface text.
- Google Places API — hospital finder and travel planner.
- Google Maps — location link in the SMS emergency message on a fall.
We never sell your data to third parties and do not share medical data with advertisers.
Retention periods
Data typeRetention periodImplant CardKept while account active; deleted on account deletion or after 5 years inactivityHealth DiaryKept until you delete it yourself (no automatic purge)Health Data (heart rate)90 days rolling, oldest automatically deletedForum PostsKept until author deletes; after 2 years inactivity, email removed and post anonymisedAccess Code (used)Kept 1 year for audit, then deletedInactive accountAfter 3 years no login: 1 reminder, then data deleted
Deleting your data
In the app (Info page) you find "Delete my data" — this permanently deletes your implant card, diary, health data and forum posts. This cannot be undone. To delete your full account, email info@heartdevicecompass.online (processed within 30 days). You also have the right to a copy of your data and correction of incorrect data.
Questions about your privacy?
Email: info@heartdevicecompass.online Postal address: Stichting Heart Device Compass Foundation, Valkenburgerweg 125, 6321 GC Wijlre, Netherlands Chamber of Commerce: 99409267 · RSIN: 868977342
Your health. Your choice. We only keep what is necessary, and you always stay in control.