Security
MemorySignal uses layered access controls to help protect family and care-recipient data. This page describes the current product architecture; it is not a certification or a claim of HIPAA compliance.
How access is protected
- Clerk handles account authentication and Convex enforces server-side authorization.
- Care-recipient records are scoped to authorized family roles.
- Provider report links expire and sharing activity is recorded.
- OpenAI requests are made from server actions; API credentials are not shipped in the app.
- Payment credentials are handled by Apple and RevenueCat, not stored by MemorySignal.
Report a concern
Email support@memorysignal.ai with the subject “Security concern.” Do not include passwords, invite codes, access tokens, or sensitive health details in the message.