Privacy policy
Last updated 23 August 2026. Foundation draft for Phase 1.
Sangre treats health information as highly sensitive. We collect only what is needed to operate your account and, in later phases, the health features you choose to use.
Phase 1 stores account identity, role, optional profile fields you provide, consents, invites, and audit logs. Medical records are not processed in this release.
You can export your account data or delete your account from the app. Deletion removes your profile, consents, and sessions. Audit entries may be retained in a minimised form where required for security.
Data is accessed only through an authenticated API with role checks. Staff see support metadata, not medical records. Access is logged.
Contact privacy questions through your account administrator once the service is hosted.