Data storage and AI permissions

What is saved

After you create a Health University account, saved resources, notes, symptom records, attachments and authorised AI exchanges are stored on the server. Sign in with the same username and password on another device to access them. Passwords are salted and hashed, not stored in plain text. Email and SMS password resets are not available yet; keep your credentials in a password manager.

Who can access it

Private records are excluded from public pages and knowledge searches. The server checks the session and record ownership for every read, download, update and delete. Signing out invalidates the current session; changing your password signs out other devices. Do not share your password, and sign out after using a shared device. The site and hosting service process the data to provide storage; this is not end-to-end encryption with keys held only by you. Upload only records you are entitled to store.

What the AI receives

You confirm permission before each request. The AI receives your question, the written records you select and relevant course excerpts. Unselected records and original attachments are not sent. This version does not read report images or PDFs and will not claim to have checked an original. Processing that has already occurred cannot be recalled.

Keeping, exporting and deleting records

You can edit saved resources, notes, symptom records and report notes, download original attachments and export all written records. Saved AI exchanges can be viewed, exported or deleted, but not edited. Attachments are downloaded separately. Deleting a record also deletes its attachments. If a service failure interrupts deletion, the record is first made inaccessible and the page offers a retry. Deletion from the site does not undo external AI processing or guarantee immediate removal from a hosting provider’s policy-governed backups or security logs.

Limits and purpose

Each space can hold up to 500 records and 200 MB of attachments. A report can have up to five files, each no larger than 20 MB. Once connected, the AI allows up to 20 requests per space per day; submitted requests that fail may still count. This is a personal organisation and learning service, not a hospital medical-record system or emergency monitoring service.

Model requests disable storage of retrievable API responses. This does not mean the provider retains no data at all. OpenAI’s data policy describes its handling. OpenAI: Your data

Back to My Health