Trust & security
Your child's record, on your terms
A child-health record is only worth keeping if you trust where it lives. Here is exactly how access works, in plain terms.
How access works
Nothing is visible by default
Enforced at the database
Every row of health data is protected by database-level access rules, not just by what the app chooses to show. A request without a valid grant returns nothing.
Explicit sharing only
Caregivers and clinicians see a child's record only through an invitation you create, with the permissions you pick. Knowing a name or an ID grants nothing.
Revocable, immediately
Withdraw an access grant and it stops working at once — including for anyone already signed in.
Audit logging
Access to clinical records is recorded, so you can see that the record is being read only by the people you authorised.
Expiring document links
Files in the document vault are private. Viewing one issues a short-lived link rather than a public URL that could be forwarded.
Verified professionals
Clinician accounts are verified before clinical access is enabled. Professional status is checked, not self-declared.
What we do with your data
- We do not sell, rent or share your child's health information with advertisers or data brokers.
- We do not run advertising inside AVYOMI.
- You can export your child's record, and you can delete your account and its data.
- We collect the minimum needed to run the product, and say so in the privacy policy rather than burying it.
We describe the safeguards we have actually built. We do not claim certifications or regulatory approvals we do not hold.
