FC FolksCard

Privacy Policy

Effective 25 August 2026 · Version 1.0 · Draft for legal review

This page has two parts

Part 1 is the general privacy policy. Part 2 is the separate Consumer Health Data Privacy Policy that Washington's My Health My Data Act requires. Both apply. If they ever disagree about consumer health data, Part 2 controls.

It describes the app as it exists today. Features that are designed but not built are named as such rather than described as if they were running. When they ship, this page changes first.

The one paragraph version

FolksCard is a family-run personal health record. You put in what you want the people who love you to be able to find in an emergency. We do not sell your data. We do not give it to advertisers, analytics companies, data brokers, insurers or employers. We use it to run the app for you, and that is all.

Who we are

FolksCard is operated by Shadow Horizon Studios LLC. Reach us at privacy@folkscard.com about anything on this page.

Mailing address to be completed before public launch.

What this covers, and what it does not

This policy covers the FolksCard mobile app, the shared card page at folkscard.com/c/[token], the invitation flow, and anything else that links here.

FolksCard is not a HIPAA-covered entity. HIPAA covers hospitals, insurers, clearing houses and their business associates. We are offered directly to families and are none of those. We are subject to the FTC Health Breach Notification Rule, Washington's My Health My Data Act, Nevada SB370, Connecticut's health data amendments, and California's CCPA and CPRA.

If you copy something a clinician wrote into the app, it stops being HIPAA-protected once it is here, because it is no longer held by a covered entity. It is then covered by this policy.

What we collect

What you give us

WhatWhy
Your email address, a password, and the name you chooseTo sign you in, and to show your family who did what
Details about the person on the card: their name, date of birth, blood type, allergies, medications with dose and schedule, conditions, doctors, emergency contacts including phone numbers, code status, organ donor status, primary language, and where their documents are keptThis is the card. It is the reason the product exists
The name you give an invited family member, and whether they can view or editTo send the invitation and set their access

Nothing is required beyond a name. Every other field is yours to leave empty.

What the app creates as it runs

WhatWhy
Each time a shared card is opened: the time, whether it was a phone or a computer, and a country code where our host provides one. Often it does not, and we store nothingSo the family always knows the card has been looked at
Who recorded giving a dose, and whenSo two people helping the same person can see each other's work
A salted hash used to rate limit requestsTo stop somebody guessing card links. The address itself is never stored

What we do not collect

The largest privacy decision here is yours

When you share a card, anyone holding that link can open it. That is the point of the product. The link is a random token containing no name, and you can turn it off in one tap, but while it is live it works for whoever has it.

You choose what appears. Code status, organ donor, care team names and contact phone numbers are all off unless you switch them on.

What a shared card publishes

Nothing else. No address, no identifiers, no insurance numbers, no files. The list is built by naming each field explicitly rather than by excluding fields, so a new field added to the app cannot leak onto a card by accident.

Who we share with

We share with the companies that run the service for us, and nobody else.

WhoWhat they do
Google, via FirebaseHosting, database, authentication, and the functions that serve the card. United States
ExpoBuilds and delivers the app itself. It does not receive card contents

We do not use a payment processor, an email provider, or a crash reporting service, because nothing in the app bills you, emails you, or reports crashes yet.

We will also disclose information if the law compels it, and we will tell you unless we are legally forbidden from doing so.

Your rights

Email privacy@folkscard.com from the address on your account. We may ask a question or two to be sure we are handing your data to you and not to somebody else. No fee for the first request in any twelve months.

Account deletion is currently handled by writing to us. Deleting it yourself inside the app is designed and not yet built.

How long we keep it

Security

Data is encrypted in transit and at rest by our hosting provider. Access is governed by rules that deny every request not coming from you or somebody you have given access to, and those rules are tested automatically on every change. The only public read path returns the narrow published subset described above. Card links are random tokens, rate limited against guessing, and can carry an optional PIN.

We do not claim to meet HIPAA's administrative requirements. We are not a covered entity, and promising a standard we have not been audited against would be worth less than telling you exactly what we do, which is what this section is for.

Breach notification

If health data is exposed we will notify you, the FTC, and where required the media, in line with the FTC Health Breach Notification Rule. We will tell you what happened, what was involved, and what to do about it.

Children

FolksCard is for adults managing care for adults. It is not intended for anyone under 13 and we do not knowingly create accounts for them.

Cookies

The shared card page sets no cookies except a short-lived one that remembers you entered a card's PIN, so a reload does not ask again. It expires in 12 hours, is readable only by the server, and contains no information about you. We use no tracking cookies anywhere.

Changes

If we change what we collect or who can see it, we will tell you in the app rather than quietly editing this page.

FolksCard is not a medical record and not a medical device

It holds what a family wrote down. It does not diagnose, advise, or replace a clinician, and nothing in it is authoritative for clinical decisions.


Part 2 · Consumer Health Data Privacy Policy

Required by Washington's My Health My Data Act. Also serves Nevada SB370.

What we treat as consumer health data

Everything on a card that describes a person's health: allergies and reactions, medications with dose and schedule, conditions, blood type, code status, organ donor status, the existence of an advance directive or proxy, and the record of who gave a dose and when.

How we collect it

Only from you, typed into the app by you or by a family member you gave edit access to. We do not buy it, infer it, or receive it from any other company, data broker, device, or health service.

Why we collect it

To show it back to you, to show it to the family members you choose, and to publish the narrow subset listed above to whoever holds a share link you created. There is no other purpose. We do not profile you, target you, or train anything on it.

Who we share it with

We do not sell consumer health data. We never have. Under Washington law, selling it would require your written authorisation, and we would ask for that in advance and in plain words.

Your rights over consumer health data

Email privacy@folkscard.com. We answer within 45 days and will say if we need a 45 day extension.

Where it is processed

In the United States, on Google Cloud infrastructure. We do not transfer it abroad.