Chronic Friends

Privacy Policy

Privacy Policy for Chronic Friends
Last updated: 28 July 2026 · Version: 2.5

Chronic Friends is a wellness, self-tracking, and community app for people living with chronic illness. Protecting your data matters deeply to us — especially because we handle information about your health. This Privacy Policy explains, in plain language, what data we collect, why we use it, who we share it with, and what rights you have.

Our mission is to help people all over the world who live with a chronic condition feel less alone, understand their own patterns, and carry their health information with confidence. Chronic Friends is dedicated exclusively to chronic illness and supports a broad and growing range of conditions — digestive, musculoskeletal, autoimmune, respiratory, metabolic, neurological, pelvic, and mental-health conditions, among others (see our Terms of Service for the current list). We do not privilege any single "primary" condition: every condition is treated equally, and whatever condition brought you here, the way we protect your data is exactly the same.

Chronic Friends is available to users around the world. We use the GDPR (EU) and the revFADP (Switzerland) as our global baseline, because they are among the strictest data protection laws in the world. For users in the United States, we also follow the U.S. rules that apply to consumer health apps, such as the FTC Health Breach Notification Rule and state health-privacy laws (for example California's CCPA/CPRA and Washington's My Health My Data Act). We also aim to comply with the data protection laws that apply where you live. Depending on your country or region, you may have additional rights (see Section 8).

1. What data we collect

2. How we use your data

We use your data to: run your account; provide the health and self-tracking features; run the community and messaging; enable video consultations; manage subscriptions and payments; verify doctors; keep the app secure; improve it; and send you important service notices.

Artificial intelligence. This version of Chronic Friends does not send your health data to any artificial-intelligence service. Nothing you log is transmitted to a third-party AI provider, and no AI feature is active in the app.

If we ever introduce a feature that does send your data to an AI provider, we will not switch it on silently. We will first update this policy to name the provider, the data involved, where it is processed and how long it is kept, and we will ask you for separate, explicit consent before a single entry leaves your device. You will be able to withdraw that consent at any time, and refusing it will never block the rest of the app. Any such feature would be informational only: it would describe your own logged data and would not predict, diagnose, or recommend treatment (see Section 11).

We never sell your data and never use it for advertising.

3. Legal basis

4. Who we share with

Verified doctors receive only the health information you choose to share for a given visit. We may also disclose data where the law requires it. We do not share your data with anyone else.

5. Where your data is stored, and international transfers

Your account and health data are stored on Google Cloud / Firebase servers located in the European Union (Frankfurt, Germany — region europe-west3). We deliberately chose an EU region so that health data stays within Europe under the GDPR and the Swiss revFADP. This location is permanent.

One thing never leaves your phone: the readings Health Sync takes from Apple Health or Health Connect (steps, sleep, activity minutes) are stored only on your device. They are not sent to Firebase, they do not reach our servers, and they are not transferred anywhere. If you delete the app, they go with it.

A limited set of providers may process certain non-health data outside Switzerland or the EEA (for example, in the United States): RevenueCat (subscription status), Stripe (doctor verification and consultation payments), and Apple / Google (billing and app distribution). Where this happens, we rely on safeguards such as Standard Contractual Clauses (SCCs) or the EU–US / Swiss–US Data Privacy Framework.

6. Retention

We keep your data while your account is active. After you delete your account, we delete your data within 30 days, except where the law requires us to keep certain records (for example, billing). Consultation records may be subject to specific retention requirements. Backups rotate out in the normal course.

7. Contact and data controller

8. Your rights

You have the right to: access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent. To exercise any of these, email info@chronicfriends.org; we reply within 30 days.

You may also have additional regional rights, including: lodging a complaint with the supervisory authority in Switzerland, the EU, or the UK; rights under US state privacy laws (such as California's CCPA/CPRA and Washington's My Health My Data Act), including the right that we do not sell your data; and similar rights in Brazil, Canada, Australia, Japan, South Korea, India, Singapore, and elsewhere.

9. Data security

We protect your data with encryption in transit and at rest, and with access controls. Sensitive doctor-verification documents are sent directly to Stripe and do not pass through our servers. No system is ever 100% secure, but we work to keep your information safe.

10. Minors

Chronic Friends is intended for people aged 18 and over. We do not knowingly collect data from anyone younger. If you believe a minor has provided us with data, please contact us so we can remove it.

11. Medical disclaimer

Chronic Friends is a wellness, self-tracking, and community tool. It is not a medical device and is not a substitute for professional medical advice, diagnosis, or treatment.

12. Changes

We may update this policy from time to time. We will notify you of significant changes within the app.

13. Contact

Questions about this policy or your data? Email info@chronicfriends.org.