Effective 25 August 2026 · Version 1.0 · Draft for legal review
Part 1 is the general privacy policy. Part 2 is the separate Consumer Health Data Privacy Policy that Washington's My Health My Data Act requires. Both apply. If they ever disagree about consumer health data, Part 2 controls.
It describes the app as it exists today. Features that are designed but not built are named as such rather than described as if they were running. When they ship, this page changes first.
FolksCard is a family-run personal health record. You put in what you want the people who love you to be able to find in an emergency. We do not sell your data. We do not give it to advertisers, analytics companies, data brokers, insurers or employers. We use it to run the app for you, and that is all.
FolksCard is operated by Shadow Horizon Studios LLC. Reach us at privacy@folkscard.com about anything on this page.
Mailing address to be completed before public launch.
This policy covers the FolksCard mobile app, the shared card page at folkscard.com/c/[token], the invitation flow, and anything else that links here.
FolksCard is not a HIPAA-covered entity. HIPAA covers hospitals, insurers, clearing houses and their business associates. We are offered directly to families and are none of those. We are subject to the FTC Health Breach Notification Rule, Washington's My Health My Data Act, Nevada SB370, Connecticut's health data amendments, and California's CCPA and CPRA.
If you copy something a clinician wrote into the app, it stops being HIPAA-protected once it is here, because it is no longer held by a covered entity. It is then covered by this policy.
| What | Why |
|---|---|
| Your email address, a password, and the name you choose | To sign you in, and to show your family who did what |
| Details about the person on the card: their name, date of birth, blood type, allergies, medications with dose and schedule, conditions, doctors, emergency contacts including phone numbers, code status, organ donor status, primary language, and where their documents are kept | This is the card. It is the reason the product exists |
| The name you give an invited family member, and whether they can view or edit | To send the invitation and set their access |
Nothing is required beyond a name. Every other field is yours to leave empty.
| What | Why |
|---|---|
| Each time a shared card is opened: the time, whether it was a phone or a computer, and a country code where our host provides one. Often it does not, and we store nothing | So the family always knows the card has been looked at |
| Who recorded giving a dose, and when | So two people helping the same person can see each other's work |
| A salted hash used to rate limit requests | To stop somebody guessing card links. The address itself is never stored |
When you share a card, anyone holding that link can open it. That is the point of the product. The link is a random token containing no name, and you can turn it off in one tap, but while it is live it works for whoever has it.
You choose what appears. Code status, organ donor, care team names and contact phone numbers are all off unless you switch them on.
Nothing else. No address, no identifiers, no insurance numbers, no files. The list is built by naming each field explicitly rather than by excluding fields, so a new field added to the app cannot leak onto a card by accident.
We share with the companies that run the service for us, and nobody else.
| Who | What they do |
|---|---|
| Google, via Firebase | Hosting, database, authentication, and the functions that serve the card. United States |
| Expo | Builds and delivers the app itself. It does not receive card contents |
We do not use a payment processor, an email provider, or a crash reporting service, because nothing in the app bills you, emails you, or reports crashes yet.
We will also disclose information if the law compels it, and we will tell you unless we are legally forbidden from doing so.
Email privacy@folkscard.com from the address on your account. We may ask a question or two to be sure we are handing your data to you and not to somebody else. No fee for the first request in any twelve months.
Account deletion is currently handled by writing to us. Deleting it yourself inside the app is designed and not yet built.
Data is encrypted in transit and at rest by our hosting provider. Access is governed by rules that deny every request not coming from you or somebody you have given access to, and those rules are tested automatically on every change. The only public read path returns the narrow published subset described above. Card links are random tokens, rate limited against guessing, and can carry an optional PIN.
We do not claim to meet HIPAA's administrative requirements. We are not a covered entity, and promising a standard we have not been audited against would be worth less than telling you exactly what we do, which is what this section is for.
If health data is exposed we will notify you, the FTC, and where required the media, in line with the FTC Health Breach Notification Rule. We will tell you what happened, what was involved, and what to do about it.
FolksCard is for adults managing care for adults. It is not intended for anyone under 13 and we do not knowingly create accounts for them.
The shared card page sets no cookies except a short-lived one that remembers you entered a card's PIN, so a reload does not ask again. It expires in 12 hours, is readable only by the server, and contains no information about you. We use no tracking cookies anywhere.
If we change what we collect or who can see it, we will tell you in the app rather than quietly editing this page.
It holds what a family wrote down. It does not diagnose, advise, or replace a clinician, and nothing in it is authoritative for clinical decisions.
Required by Washington's My Health My Data Act. Also serves Nevada SB370.
Everything on a card that describes a person's health: allergies and reactions, medications with dose and schedule, conditions, blood type, code status, organ donor status, the existence of an advance directive or proxy, and the record of who gave a dose and when.
Only from you, typed into the app by you or by a family member you gave edit access to. We do not buy it, infer it, or receive it from any other company, data broker, device, or health service.
To show it back to you, to show it to the family members you choose, and to publish the narrow subset listed above to whoever holds a share link you created. There is no other purpose. We do not profile you, target you, or train anything on it.
We do not sell consumer health data. We never have. Under Washington law, selling it would require your written authorisation, and we would ask for that in advance and in plain words.
Email privacy@folkscard.com. We answer within 45 days and will say if we need a 45 day extension.
In the United States, on Google Cloud infrastructure. We do not transfer it abroad.