RenalShield
Public policy surface
beta-public

Privacy Policy

Current data-handling posture for the free no-account prototype.

Updated 2026-09-29. Beta policy draft; final paid launch still requires qualified legal, clinical, privacy, and tax review.

Current data model

The current free prototype does not provide user accounts or paid entitlements.

Food logs, daily limits, journal entries, and lab-note fields are stored in this browser's local storage on the user's device. The public app does not upload those records to shared server-side health-state endpoints.

Browser-local records do not automatically sync or back up. Clearing this site's browser data removes them, and anyone with access to the same browser profile may be able to view them.

The More screen can export a versioned JSON backup, preview its export date and record counts, restore a supported backup after confirmation, or erase the browser-local health record after confirmation. Restoring replaces the health data currently in that browser. Exported files can contain sensitive health information; restoring or erasing health data does not change VIP access.

Do not enter emergency information, account credentials, Social Security numbers, insurance identifiers, full medical records, or sensitive information on a shared device.

Renal Coach questions

When a user submits a Renal Coach question, the question and any numeric daily limits the user explicitly chooses to include are sent to the RenalShield server for a response.

The server applies automated personal-information scrubbing before an external AI request and currently tries NVIDIA-hosted models before a local fallback. Automated scrubbing can miss sensitive details, so users should not include names, contact details, record numbers, or other identifying health information.

The access logger records the request method, a scrubbed URL, response status, and timing; it does not read or log the Coach request body. External-provider processing and retention are separate from browser-local storage and require a complete disclosure before accounts or paid plans launch.

Photo companion

Choosing a photo keeps a resized copy in this page's memory. One previous photo and its details can remain there for Undo until discarded or the page is closed. A photo is uploaded only when you agree to the processing notice and select Read my photo.

RenalShield processes uploaded photos in memory, removes image metadata before recognition, and does not save photos or log the upload body. Shopping labels are read on the RenalShield server.

When Groq is shown in the processing notice, meal and cooking photos are sent to Groq for AI food-name suggestions. Groq may retain inputs and outputs for up to 30 days for reliability or abuse monitoring. Avoid faces, personal documents and identifying details. You can enter foods manually without sending a photo.

Food-name suggestions are guesses for you to correct. The photo reader does not establish nutrients, allergens, doneness or kidney safety. Checking your confirmed details sends those entries to RenalShield for the ingredient check, separately from photo recognition.

Professional and shared use

RenalShield can include health-adjacent entries such as food logs, symptoms, weights, blood pressure notes, and lab notes.

Professional, clinic, organization, API, or multi-client use requires a separate privacy/security review and written license before use.

Before accounts or paid plans

RenalShield must define retention, deletion, export, backups, analytics, operator access, incident response, and HIPAA/BAA scope before accounts or paid plans launch.

If RenalShield is used for or by a covered entity or business associate, HIPAA obligations must be reviewed before deployment.

Source Ledger