Health Data Notice

How we handle your health data

You're trusting us with some of the most personal information there is. This page explains exactly what health data we collect, where it goes, and who can see it — no legal jargon, just honest answers.

Last updated: September 19, 2026

1

What health data we collect

When you use Little C, you may choose to enter the following types of health information. We only collect what you actively provide — we do not pull data from external sources without your action.

Cancer diagnosis info

Type, stage, tumor markers, receptor status, pathology details

Symptom logs

Category, severity, frequency, triggers, relief measures, and notes you add

Medication records

Names, dosages, schedules, side effects, adherence tracking

Appointment details

Doctor names, hospitals, appointment dates, notes, and action items

Emotional wellness

Mood entries, journal content, meditation sessions, and wellness check-ins

Nutrition data

Meal logs, food descriptions, water intake tracking

Insurance information

Provider name, plan details, policy numbers you choose to store for reference

Family & caregiver information

Names, relationships, contact details, and permissions for people in your care circle

2

How your health data is stored

Data is stored in the cloud and in your browser. Service providers also process information to operate Little C.

Cloud database

Your health data is stored in a Supabase PostgreSQL database with row-level security to restrict access. Sharing features and administrative services also access records to operate the app; access is not limited to you alone.

Browser storage

Your browser holds information while you use Little C and saves some preferences on your device. Older versions may have left health data in browser storage. Not all local information is encrypted; you can clear site storage in your browser settings.

3

AI processing of your health data

Important: When you use AI features, your inputs and health context are sent to third-party AI providers to generate responses. Please read this section carefully so you understand what is shared and with whom.

Which AI providers receive your data

Anthropic and OpenAI process inputs for AI features. The Navigator uses Anthropic, and document analysis sends document content to both providers.

What is sent to these providers

Messages, attachments, document text, and relevant health records can be sent. Depending on the feature, profile context includes your name, diagnosis, treatment status, tumor markers, care team, date of birth, menopausal status, or ZIP code. Information you submit is not automatically anonymized.

Provider retention

AI providers may retain inputs and outputs for service operation, safety, or legal reasons. Little C has not verified special retention arrangements and does not promise zero retention.

Account AI preference and connected assistants

AI processing is an account-level choice enforced by the server. Disabling it stops Little C AI features and revokes connected assistants. Re-enabling does not reconnect them. Each assistant needs separate category permissions. Disconnecting stops future access, but does not erase data already received by that assistant. Each proposed write requires your approval in Little C.

AI responses are not medical advice

Everything the AI Navigator provides is informational only. It is not a substitute for professional medical advice, diagnosis, or treatment. Always consult your oncologist or care team for medical decisions.

Provider policies and account verification

Published API training defaults: OpenAI and Anthropic state that API inputs and outputs are not used to train their models by default. Opt-ins or voluntary submissions such as provider feedback can change this. These published defaults do not verify Little C's account settings or agreements.

OpenAI retention: Its API documentation describes abuse-monitoring logs that may include prompts and responses, normally kept for up to 30 days, with longer retention for legal or safety reasons. The Responses API used by several Little C features also stores response data for at least 30 days by default. This is separate from abuse-monitoring logs. See OpenAI's API data controls.

Anthropic retention: Its standard API policy describes deletion of inputs and outputs within 30 days, with exceptions including legal obligations, policy enforcement, submitted feedback, and different agreements or services. Flagged content and related safety records can be kept longer. See Anthropic's retention policy and commercial-product training policy.

Little C's account-specific arrangements: We have not verified account-specific enterprise agreements, Data Processing Addenda (DPAs), Business Associate Agreements (BAAs), training opt-ins, or special retention settings for Little C. Published vendor policies are not confirmation of those arrangements. We do not promise zero retention or that providers use data only to generate a response. Deleting data in Little C does not itself delete provider-held copies.

Official vendor documentation reviewed September 18, 2026.

AI features: information sent and storage

This inventory covers the current web app and its AI services. Features receive the information described below when used. Account records are stored with Supabase. Request processing and error logs may also contain data; page memory does not mean providers retain no copies.

AI feature providers, inputs, and application storage
Feature / providerInformation sentLittle C storage
Appointment companion draftsOpenAIPatient priorities, chosen reporting interval, authorized symptoms and dose logs, open questions, follow-ups, reviewed discussion, typed visit notes for extraction, and explicitly selected saved document analyses. Exclusions are applied server-side.Separate versioned drafts, source excerpts, patient-reviewed revisions, accepted questions and follow-ups are saved to the account. Billing metadata is recorded separately.
Care NavigatorAnthropicMessages and attachments plus relevant saved entries retrieved by scoped tools: profile, treatment, symptoms, medications, appointments, nutrition, mood or fertility. No browser record snapshot is used as authority.Messages, attachments, sources, displayed profile context, and selections are saved in your account’s conversation history. Confirmed health actions save account records. Usage, performance, and submitted feedback records are stored separately.
Document analysisOpenAI and AnthropicDocument text and type go to OpenAI for classification and extraction, and to Anthropic with extracted data for explanations. Derived findings also pass between providers for questions and urgency checks.File content stays in page memory. Successful analyses and filenames are saved privately to your account. Usage and financial records are stored separately.
Symptom analysisOpenAISubmitted symptom logs or messages, plus name, cancer type, stage, and treatment status.Insights stay in web page memory. The source symptom logs are separate account records.
Appointment preparationOpenAIAppointment type, title, provider name, and notes; cancer type, stage, and treatment status.Generated questions are saved with the appointment in the account database.
After-visit action itemsOpenAIAppointment type, title, provider name, pre-appointment notes, and post-visit notes.Draft action items stay in the dialog; saving the visit saves notes and action items with the appointment.
Recipe generationOpenAIName, cancer type, stage, treatment status, dietary restrictions, allergies, cuisine preferences, excluded ingredients, preparation time, and difficulty preference.Generated recipes and recipe preferences are saved in the account database, including recipes not marked as favorites.
Nutrition supportOpenAISubmitted messages plus name, cancer type, stage, and treatment status.The service returns a response without saving conversation content in the account database. Storage by other clients depends on their implementation.
Emotional supportAnthropicSubmitted messages and mood, plus name, cancer type, stage, treatment status, and oncologist name.The service returns a response without saving conversation content in the account database. Storage by other clients depends on their implementation.
Fertility supportAnthropicSubmitted messages plus name, cancer type, stage, treatment status, menopausal status, and date of birth.The service returns a response without saving conversation content in the account database. Storage by other clients depends on their implementation.
Symptom urgency assessmentAnthropicSubmitted symptoms or messages; medication names, doses, and frequencies; name, cancer type, stage, treatment status, oncologist, and hospital.The service returns a response without saving assessment content in the account database. Storage by other clients depends on their implementation.
AI trial matchingAnthropicSubmitted messages plus cancer type, stage, treatment status, tumor markers, and ZIP code.The service returns a response without saving matching content in the account database. This is separate from trial search and saved trials.
Insurance appeal draftingAnthropicSubmitted claim details, including service, date, amounts, denial reason, and status; name, cancer type, stage, treatment status, oncologist, and hospital.The draft stays in web page memory and can be copied. Source claim records are saved separately in the account database.
4

A note about HIPAA

Little C is an independent, direct-to-consumer breast cancer companion. Service providers, including AI providers, process information to operate the app.

We do not claim HIPAA compliance or that your use of Little C is covered by a Business Associate Agreement (BAA).

Little C is not your healthcare provider's patient portal. Read our Privacy Policy for service-provider processing, sharing, and retention details.

5

Your health data rights

These options help you manage your information. See the Privacy Policy for details and limitations.

Export your data

Download a JSON export of supported account and health records from Settings. Contact us for information not included in the export.

Request account deletion

Request account deletion in Settings. Provider records, backups, and copies shared with others may remain; see the Privacy Policy.

Control sharing

Manage your matching profile in Community and caregiver roles in the Guardian Portal. Public pages are accessible without signing in, and anyone with a guest portal link can use it.

Saved sharing preferences

The anonymous data sharing preference in Settings is saved on your device. It does not change current service-provider processing.

6

Data retention

Retention varies by record type and service provider.

Active accounts

Account and health records are retained while your account is active to provide the service. See the Privacy Policy for retention details.

Deleted accounts

Account deletion removes records through the app's deletion process. It does not guarantee immediate removal of every record, backup, or provider-held copy.

AI content and records

Navigator conversations, attachments and response sources are saved to your account. External Navigator sessions are stored separately per connection, using only the content explicitly supplied to Little C. They are included in account export and deletion. Document analysis currently holds content in page memory. Confirmed actions, appointment questions and recipes are saved to your account. Usage logs and submitted feedback are stored separately. Provider-held copies follow separate retention policies.

7

Questions about your health data?

If you have any questions about how your health data is handled, or if you want to exercise any of your data rights, we are here to help.

Reach our privacy team

Email us with questions about processing, sharing, retention, or data requests.

privacy@littlec.health