Launching soon  ·  Free 7-day trial

Privacy Impact Assessment

Cureva Health - Personal & Family AI Health Companion for Caregiving

Version 1.0 Issued: September 22, 2026 Classification: Public Review: September 2027
This Privacy Impact Assessment was prepared by Cureva Health in accordance with the Office of the Privacy Commissioner of Canada's PIA guidelines and provincial health privacy legislation. It is provided publicly to support institutional procurement, regulatory review, and transparency commitments. For a signed copy or supplementary questionnaire responses, contact [email protected].

1. Executive Summary

Cureva Health operates a mobile application and supporting web infrastructure that enables patients and family caregivers to manage medications, track health vitals, coordinate care, and receive daily health check-ins from Eva, an AI-powered health companion. The application handles Personal Health Information (PHI) as defined under Canadian federal and provincial law.

This PIA concludes that Cureva's current technical architecture, data governance policies, and organizational controls adequately protect personal health information. All data is stored in Canada (AWS ca-central-1, Montreal), encrypted at rest with AES-256 and in transit with TLS 1.3, and is never sold or shared for commercial purposes. Residual risks are low and are actively monitored.

2. Organization and System Description

2.1 Organization

2.2 System

The Cureva system consists of:

3. Personal Information Inventory

Data ElementTypeSourceStorage LocationRetention
Medication names, dosages, schedulesPHIUser-enteredSupabase ca-central-1Until account deletion
Dose confirmation logs (taken / missed)PHIApp interactionSupabase ca-central-1Until account deletion
Vitals (blood pressure, heart rate, weight, glucose)PHIUser-enteredSupabase ca-central-1Until account deletion
Symptoms and health notesPHIUser-enteredSupabase ca-central-1Until account deletion
Eva conversation transcriptsPHIAI conversationSupabase ca-central-1Until account deletion
Health conditions disclosedPHIUser-enteredSupabase ca-central-1Until account deletion
Appointment dates and notesPHIUser-enteredSupabase ca-central-1Until account deletion
Name and email addressPersonal informationRegistrationSupabase ca-central-1Until account deletion
Push notification tokenDevice identifierApp registrationSupabase ca-central-1Until account deletion
Billing informationPaymentStripeStripe (not Cureva)Per Stripe retention policy

Cureva does not collect device contacts, precise geolocation, biometrics, or government identifiers (SIN, health card numbers).

4. Data Flows

4.1 Primary data flow

  1. User enters health data (medications, vitals, symptoms) in the mobile app.
  2. Data is transmitted over TLS 1.3 to Cureva's backend API (Railway, hosted in Canada).
  3. Backend writes data to Supabase (AWS ca-central-1, Montreal). Data is encrypted at rest using AES-256.
  4. Authorized family caregivers linked to the account can view dose status and receive push notifications. Caregivers do not receive raw health data beyond dose status.

4.2 AI processing flow

  1. User initiates a conversation with Eva or responds to a scheduled check-in.
  2. The conversation content is sent from the Cureva backend to Anthropic's Claude API over TLS.
  3. Anthropic processes the request and returns a response. Under Cureva's enterprise agreement, Anthropic does not log, store, or train on conversation data.
  4. Eva's response and a summary are stored in Supabase ca-central-1 and used to build the user's longitudinal health context.

4.3 Third parties with data access

VendorPurposeData SharedLocation
Supabase / AWSDatabase infrastructureAll PHI (encrypted)ca-central-1, Canada
AnthropicAI (Eva) processingConversation content (zero-retention)US (enterprise agreement)
StripePayment processingBilling only - no health dataUS (Stripe infrastructure)
ExpoPush notificationsDevice token + notification text only (no PHI in payload)US
Google Analytics (GA4)Anonymous website analyticsAnonymous page views only - not in-appGoogle infrastructure

No health data is shared with advertisers, pharmaceutical companies, insurers, or data brokers. No health data is used for advertising targeting.

5. Privacy Risk Assessment

RiskLikelihoodImpactResidual RiskMitigation
Unauthorized access to health database LowHighLow AES-256 at rest, TLS 1.3 in transit, least-privilege access, audit logging, Supabase row-level security policies.
Caregiver accessing more data than authorized LowMediumLow Caregiver access is limited to dose status and alert notifications. Raw vitals, symptoms, and Eva conversations are not accessible to caregivers unless explicitly shared by the patient.
AI vendor (Anthropic) retaining health data LowHighLow Enterprise agreement specifies zero data retention and no training use. Anthropic's API processes the request and returns the response without persistent storage of conversation content.
Data breach or unauthorized disclosure LowHighMedium Encryption, access controls, and audit logging are in place. In the event of a breach, Cureva will notify affected users and the Office of the Privacy Commissioner of Canada within 72 hours, in compliance with PIPEDA's mandatory breach reporting requirements.
Session token compromise LowHighLow Tokens stored in device secure enclave (iOS Keychain / Android Keystore). Short expiry with refresh rotation. No tokens stored in plain text or in app-accessible storage.
User unable to exercise deletion rights Very LowMediumLow In-app account deletion is available at all times. Web-based deletion available at cureva.app/delete-account. Deletion is processed within 30 days with a confirmation email.

6. Compliance Mapping

RequirementLaw / FrameworkHow Cureva Satisfies It
Consent before collecting PHIPIPEDA, PHIPA, HIAExplicit informed consent obtained during onboarding and at each data type introduction. Users can withdraw consent by deleting their account.
Purpose limitationPIPEDA, PHIPA, HIA, GDPRHealth data is used only to provide the Cureva service. It is not used for advertising, research, or secondary commercial purposes.
Data minimizationPIPEDA, GDPROnly data necessary to deliver the medication management and health check-in service is collected. No speculative data collection.
Data residency in CanadaPHIPA (ON), HIA (AB), PIPA (BC)All PHI stored in Supabase AWS ca-central-1 (Montreal, Quebec, Canada).
Encryption at restHIPAA Security Rule, PHIPA, HIAAES-256 encryption applied to all stored health data at the infrastructure level (Supabase). Supabase is SOC 2 Type 2, ISO 27001, and HIPAA certified - Cureva operates within this certified infrastructure environment.
Access controls and audit trailsHIPAA Security Rule, PHIPALeast-privilege access enforced. All administrative access to PHI is logged with timestamp and identity.
Breach notification - 72 hoursPIPEDA (mandatory breach reporting)Incident response policy requires OPC notification within 72 hours for material breaches. User notification without undue delay.
Right to access and correctionPIPEDA, PHIPA, GDPRUsers can view, export (PDF), and correct all their health data in-app. Written requests responded to within 30 days.
Right to deletionPIPEDA, GDPR, CCPAPermanent account and data deletion available in-app and at /delete-account. Processed within 30 days.
No sale of personal informationCCPA, PIPEDACureva's sole revenue is subscription fees. Health data is not sold, licensed, or shared for commercial purposes.

7. Outstanding Items and Roadmap

8. Sign-off

Taranjit Singh, Founder

Prabhjot Kaur, COO

September 22, 2026

September 2027 (or upon material system change)

Need a signed copy or have procurement questions?

We respond to all institutional privacy requests within 5 business days.

Contact Privacy Team →