Cureva Health - Personal & Family AI Health Companion for Caregiving
Cureva Health operates a mobile application and supporting web infrastructure that enables patients and family caregivers to manage medications, track health vitals, coordinate care, and receive daily health check-ins from Eva, an AI-powered health companion. The application handles Personal Health Information (PHI) as defined under Canadian federal and provincial law.
This PIA concludes that Cureva's current technical architecture, data governance policies, and organizational controls adequately protect personal health information. All data is stored in Canada (AWS ca-central-1, Montreal), encrypted at rest with AES-256 and in transit with TLS 1.3, and is never sold or shared for commercial purposes. Residual risks are low and are actively monitored.
The Cureva system consists of:
| Data Element | Type | Source | Storage Location | Retention |
|---|---|---|---|---|
| Medication names, dosages, schedules | PHI | User-entered | Supabase ca-central-1 | Until account deletion |
| Dose confirmation logs (taken / missed) | PHI | App interaction | Supabase ca-central-1 | Until account deletion |
| Vitals (blood pressure, heart rate, weight, glucose) | PHI | User-entered | Supabase ca-central-1 | Until account deletion |
| Symptoms and health notes | PHI | User-entered | Supabase ca-central-1 | Until account deletion |
| Eva conversation transcripts | PHI | AI conversation | Supabase ca-central-1 | Until account deletion |
| Health conditions disclosed | PHI | User-entered | Supabase ca-central-1 | Until account deletion |
| Appointment dates and notes | PHI | User-entered | Supabase ca-central-1 | Until account deletion |
| Name and email address | Personal information | Registration | Supabase ca-central-1 | Until account deletion |
| Push notification token | Device identifier | App registration | Supabase ca-central-1 | Until account deletion |
| Billing information | Payment | Stripe | Stripe (not Cureva) | Per Stripe retention policy |
Cureva does not collect device contacts, precise geolocation, biometrics, or government identifiers (SIN, health card numbers).
| Vendor | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase / AWS | Database infrastructure | All PHI (encrypted) | ca-central-1, Canada |
| Anthropic | AI (Eva) processing | Conversation content (zero-retention) | US (enterprise agreement) |
| Stripe | Payment processing | Billing only - no health data | US (Stripe infrastructure) |
| Expo | Push notifications | Device token + notification text only (no PHI in payload) | US |
| Google Analytics (GA4) | Anonymous website analytics | Anonymous page views only - not in-app | Google infrastructure |
No health data is shared with advertisers, pharmaceutical companies, insurers, or data brokers. No health data is used for advertising targeting.
| Risk | Likelihood | Impact | Residual Risk | Mitigation |
|---|---|---|---|---|
| Unauthorized access to health database | Low | High | Low | AES-256 at rest, TLS 1.3 in transit, least-privilege access, audit logging, Supabase row-level security policies. |
| Caregiver accessing more data than authorized | Low | Medium | Low | Caregiver access is limited to dose status and alert notifications. Raw vitals, symptoms, and Eva conversations are not accessible to caregivers unless explicitly shared by the patient. |
| AI vendor (Anthropic) retaining health data | Low | High | Low | Enterprise agreement specifies zero data retention and no training use. Anthropic's API processes the request and returns the response without persistent storage of conversation content. |
| Data breach or unauthorized disclosure | Low | High | Medium | Encryption, access controls, and audit logging are in place. In the event of a breach, Cureva will notify affected users and the Office of the Privacy Commissioner of Canada within 72 hours, in compliance with PIPEDA's mandatory breach reporting requirements. |
| Session token compromise | Low | High | Low | Tokens stored in device secure enclave (iOS Keychain / Android Keystore). Short expiry with refresh rotation. No tokens stored in plain text or in app-accessible storage. |
| User unable to exercise deletion rights | Very Low | Medium | Low | In-app account deletion is available at all times. Web-based deletion available at cureva.app/delete-account. Deletion is processed within 30 days with a confirmation email. |
| Requirement | Law / Framework | How Cureva Satisfies It |
|---|---|---|
| Consent before collecting PHI | PIPEDA, PHIPA, HIA | Explicit informed consent obtained during onboarding and at each data type introduction. Users can withdraw consent by deleting their account. |
| Purpose limitation | PIPEDA, PHIPA, HIA, GDPR | Health data is used only to provide the Cureva service. It is not used for advertising, research, or secondary commercial purposes. |
| Data minimization | PIPEDA, GDPR | Only data necessary to deliver the medication management and health check-in service is collected. No speculative data collection. |
| Data residency in Canada | PHIPA (ON), HIA (AB), PIPA (BC) | All PHI stored in Supabase AWS ca-central-1 (Montreal, Quebec, Canada). |
| Encryption at rest | HIPAA Security Rule, PHIPA, HIA | AES-256 encryption applied to all stored health data at the infrastructure level (Supabase). Supabase is SOC 2 Type 2, ISO 27001, and HIPAA certified - Cureva operates within this certified infrastructure environment. |
| Access controls and audit trails | HIPAA Security Rule, PHIPA | Least-privilege access enforced. All administrative access to PHI is logged with timestamp and identity. |
| Breach notification - 72 hours | PIPEDA (mandatory breach reporting) | Incident response policy requires OPC notification within 72 hours for material breaches. User notification without undue delay. |
| Right to access and correction | PIPEDA, PHIPA, GDPR | Users can view, export (PDF), and correct all their health data in-app. Written requests responded to within 30 days. |
| Right to deletion | PIPEDA, GDPR, CCPA | Permanent account and data deletion available in-app and at /delete-account. Processed within 30 days. |
| No sale of personal information | CCPA, PIPEDA | Cureva's sole revenue is subscription fees. Health data is not sold, licensed, or shared for commercial purposes. |
Taranjit Singh, Founder
Prabhjot Kaur, COO
September 22, 2026
September 2027 (or upon material system change)
We respond to all institutional privacy requests within 5 business days.
Contact Privacy Team →