Self Health Wallet Terms & Conditions and Privacy Policy
Self Institute / R Sterling Snead, CEO
Please read carefully. This document governs your use of the Self Health Wallet application and services (“the Service”). By creating an account or using the Service, you agree to be bound by both the Terms & Conditions and the Privacy Policy below. If you do not agree, you must not use the Service.
Part 1: Terms and Conditions
1. Acceptance of Terms
By creating an account or using the Self Health Wallet (“the Service”), you confirm that you have read, understood, and agree to these Terms and Conditions and our Privacy Policy. If you do not agree, you must immediately cease use of the Service.
2. Eligibility, Geography, and Patient Status
You must be at least 18 years old to create an account. The Service is not directed to children, and we do not knowingly collect personal or health information from individuals under 18. If you are a parent or guardian and believe a minor has provided us information, please contact us so we can delete it. Where a guardian manages a dependent’s health records, the account holder is responsible for ensuring they have the legal authority to do so.
The Service is currently available to residents of the United States. We may limit availability of certain features by region where required by local law or by the technical requirements of a connected health system.
No existing patient relationship with a specific provider is required to create an account. The Service is available both to patients of partnered healthcare organizations (including those registering through Epic MyChart or a similar patient portal) and to members of the public who wish to manage their own health records independently.
3. Nature of Service
Not Medical Advice: The Service is a personal health data management tool. It provides information management features only. We do not provide medical advice, diagnosis, or treatment, and nothing in the Service should be interpreted as a substitute for professional medical care.
Emergency Situations: Do not use the Service for emergency medical needs. In an emergency, contact your local emergency services immediately.
No Reliance: Any insights or summaries generated by the Service are informational. You should consult a qualified healthcare professional before making decisions based on them.
4. Self-Sovereign Identity and Data Ownership
The Service is built on self-sovereign identity (SSI) principles. This means:
You Own Your Data: Your health records and identity credentials belong to you. We act as a custodian and processor, not the owner of your personal health information.
You Control Access: You decide what data to store, who may access it, and for how long. Sharing of your records with any third party occurs only at your direction, and you may revoke that access at any time.
Portability: Because you retain ownership, you may export or move your credentials and records out of the Service at will, subject to the technical formats we support.
When you elect to share your health records with a healthcare provider, you acknowledge that you are transmitting your data directly to their care team. You are solely responsible for ensuring the information shared is relevant and accurate. Once you transmit this data to a provider, it is no longer under your sole control and becomes subject to that provider's own HIPAA policies and medical record handling procedures.
Key Custody: Where the Service uses cryptographic keys or credentials under your control, you are responsible for safeguarding any recovery phrases or private keys. We may be unable to recover data secured solely by keys we do not hold.
5. User Responsibilities and Acceptable Use
Account Security: You are responsible for maintaining the confidentiality of your login credentials and any recovery keys, and for all activity under your account.
Accuracy of Information: You represent that any health information you upload is accurate to the best of your knowledge.
Lawful Use: You agree not to use the Service for any unlawful purpose, to infringe the rights of others, or to transmit any malicious code.
In addition, you agree that you will not:
scrape, crawl, harvest, or use bots, scripts, or other automated means to access, index, or extract data from the Service;
share your account credentials with, or grant account access to, any other person, except as expressly permitted for authorized caregivers or dependents;
attempt to interfere with, disrupt, overload, or gain unauthorized access to the Service, its servers, or any connected third-party system (including any connected EHR system);
use the Service to defraud us, other users, or any third party; or
reverse engineer, decompile, or attempt to derive the source code of the Service, except to the extent such restriction is prohibited by applicable law.
6. Intellectual Property
All software, design, trademarks, and content provided by Self Health Wallet (excluding user-uploaded data and user-controlled credentials) are the exclusive property of Self Institute and its licensors. We grant you a limited, non-exclusive, non-transferable license to use the Service for its intended purpose. User-uploaded data remains yours at all times.
7. Third-Party Services and Integrations
The Service integrates with a range of third-party systems, including electronic health record (EHR) and health information networks (such as Epic/MyChart, Cerner, Veradigm, Next Gen, Greenway Health, and others), wearable and device platforms (such as Apple Health, Health Connect, Samsung Health, Fitbit, and Garmin), and other data, nutrition, or analytics providers. These integrations are provided for your convenience, at your direction, and only with your authorization.
We do not control, and are not responsible for, the content, functionality, security, uptime, or privacy practices of any third-party service, including any EHR or device platform. Your use of any third-party service is governed by that provider's own terms and privacy policy, and we encourage you to review them. If a third-party integration becomes unavailable, is discontinued, or is modified by that provider, we are not liable for any resulting loss of functionality or temporary loss of data access, though your previously stored data within the Service remains accessible to you consistent with Section 4 above.
8. Account and Access, Including Epic/MyChart Status
Account Creation and Verification: You must provide accurate registration information and complete any identity-verification steps we require.
Epic/MyChart Account Status:
Where the Service is accessed through, or connected to, an Epic MyChart account — for example, to retrieve or exchange records via a FHIR-based connection — your ability to use certain data-exchange features depends on your MyChart account remaining active and in good standing with your healthcare provider. If your MyChart account is suspended, deactivated, or disconnected by your provider or by Epic, the corresponding data-exchange features of the Service may be paused or unavailable until that access is restored. Health data you have already stored within the Service remains accessible to you independent of your MyChart status, consistent with the self-sovereign identity principles described in Section 4. We are not responsible for account status changes made by your healthcare provider or by Epic, and we will notify you within the Service where we are able to detect that a connection has been interrupted.
Suspension or Termination: You may close your account at any time. We may suspend or terminate your access if you materially breach these Terms, if required by law, or if continued operation poses a security risk. If we close an account, we will give reasonable notice where lawful and practicable, and we will give you an opportunity to export your data before deletion, consistent with the Data Retention section below.
9. Disclaimer of Warranties
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, OR THAT ANY HEALTH INSIGHTS PROVIDED WILL BE ACCURATE OR COMPLETE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF CERTAIN WARRANTIES, SO SOME OF THE ABOVE EXCLUSIONS MAY NOT APPLY TO YOU.
10. Limitation of Liability
To the maximum extent permitted by law, Self Institute shall not be liable for any indirect, incidental, special, or consequential damages resulting from your use of, or inability to use, the Service. Nothing in these Terms excludes liability that cannot be excluded under applicable law.
11. Indemnification
You agree to indemnify, defend, and hold harmless Self Institute, its officers, directors, employees, and agents, from and against any claims, liabilities, damages, losses, and expenses (including reasonable attorneys’ fees) arising out of or in any way connected with: (a) your access to or use of the Service; (b) your violation of these Terms; (c) your violation of any third party’s rights, including intellectual property, privacy, or data-protection rights; or (d) any health information you upload, share, or transmit through the Service. This obligation survives termination of your account and of these Terms.
12. Changes to These Terms
We may update these Terms and the Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date and notify you through the app or by email before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised terms. Where the law requires fresh consent (for example, for new uses of health data), we will ask for it.
13. Governing Law and Dispute Resolution
These Terms are governed by the laws of Oklahoma, without regard to its conflict-of-law rules.
Binding Arbitration. Except as set out below, any dispute, claim, or controversy arising out of or relating to these Terms or the Service shall be resolved by final and binding arbitration under its then-current rules, rather than in court. The arbitration shall take place in Tulsa, Oklahoma, or by remote means where available, before a single arbitrator. Judgment on the award may be entered in any court of competent jurisdiction.
Small Claims Exception: Either party may bring an individual claim in small-claims court if it qualifies, instead of arbitration.
Class Action Waiver: Disputes will be arbitrated only on an individual basis. You and we waive any right to bring or participate in a class, collective, or representative action, to the extent permitted by applicable law.
Opt-Out: You may reject this arbitration agreement by sending written notice to our Data Protection Officer within 30 days of first accepting these Terms. If you opt out, disputes will be resolved in the courts of Tulsa, Oklahoma.
Consumer Rights Carve-Out: Nothing in this section waives any non-waivable right you have under applicable law. Where mandatory consumer-protection law (including for users in the EU, UK, and other GDPR regions) grants you the right to bring proceedings before your local courts or a designated authority, that right is preserved and overrides this arbitration agreement.
Injunctive Relief. Notwithstanding the above, either party may seek injunctive or equitable relief in a court of competent jurisdiction to protect intellectual property or data-security interests.
Part 2: Privacy Policy
We are committed to protecting your sensitive health information and to handling it in line with the principles of the EU/UK General Data Protection Regulation (GDPR) and the safeguards of the U.S. Health Insurance Portability and Accountability Act (HIPAA), as further described below.
1. Information We Collect
Identity Data: Name and date of birth.
Health Data: Medical records, prescriptions that you choose to upload or sync. This is treated as a special category of personal data.
Identity Credentials: Self-sovereign identity credentials, cryptographic keys, biometric data that you create or import, remain securely on your device and are never uploaded or transmitted to us.
Usage Data: Information on how you interact with the app, used to maintain security and improve the user experience.
Sources of Your Data
We collect information from the following sources:
Directly from you, when you register, enter information, or contact support;
From Epic/MyChart or other EHR/FHIR-connected systems, when you authorize a connection to retrieve your records;
From connected medical and fitness devices, such as blood pressure monitors, heart rate sensors, glucose meters, pulse oximeters, weight scales, thermometers, Garmin, and Fitbit, when you authorize or connect these devices;
From health platforms, including Apple Health, Health Connect, and Samsung Health, when you authorize the app to access health information available through those platforms;
Automatically from your device and browser, such as device type, operating system, IP address, and app usage; and
From service providers who support the Service's operation, such as hosting, security, and analytics vendors.
2. How We Use Your Data
Purpose | Data Type | Legal Basis (GDPR) |
Account Management | Identity | Contractual Necessity |
Health Insights | Health Data | Explicit User Consent |
App Security & Fraud Prevention | Usage Data | Legitimate Interest |
Support Requests | Identity / Communication | Contractual Necessity |
Legal Compliance | As applicable | Legal Obligation |
We do not use your health data for advertising, and we do not subject you to solely automated decision-making that produces legal or similarly significant effects without your explicit consent and a right to human review.
3. Regulatory Alignment (HIPAA & GDPR)
We design our practices to align with HIPAA's privacy and security safeguards and with GDPR principles of lawfulness, data minimization, and purpose limitation. Please note:
Certification Status: We are committed to adhering to HIPAA and GDPR standards. We are not currently formally certified or independently audited against them, and HIPAA does not offer a government “certification.” We will update this section as our compliance posture matures, and we will not claim a status we have not achieved.
HIPAA Scope: Where we act as a business associate or covered entity under HIPAA, we will handle protected health information accordingly and enter into Business Associate Agreements with relevant partners. Many consumer health apps fall outside HIPAA; we will state clearly if and when HIPAA applies to a given relationship.
Data Protection Officer: We have designated a Data Protection Officer (DPO) as your point of contact for privacy matters (see Contact Information).
4. How HIPAA Applies to You
Whether HIPAA governs your information depends on how you came to use the Service. The same features may be offered through more than one channel, and a different legal framework may apply to each:
Direct Consumers: If you signed up on your own and upload or manage your own health information, HIPAA generally does not apply to that information once it is in your control within the Service. Your data is instead protected by this Privacy Policy and by applicable consumer-privacy laws, including the U.S. FTC Health Breach Notification Rule, state privacy laws, and the GDPR where relevant.
Consumer-Directed Records Access (EHR Integration): You may direct the Service to retrieve your medical records from a healthcare provider’s electronic health record (EHR) system through a secure connection (for example, using FHIR-based APIs and your provider’s authorization flow, including Epic’s). When you do this, you are exercising your legal right of access to your own records. Once those records are delivered into your consumer-controlled account, they are held on your behalf and governed by this Privacy Policy rather than by HIPAA. We will only connect to a provider with your explicit authorization, and you may revoke that connection at any time.
Provider-Sponsored Use: If you access the Service through a hospital, clinic, or other healthcare provider that has engaged us to handle protected health information on its behalf, then for that information we act as a business associate under HIPAA. In that case, we handle your protected health information in accordance with HIPAA and a Business Associate Agreement with that provider, in addition to this Privacy Policy.
Self-Initiated Sharing: You may proactively share your stored health records with your healthcare provider. This is a consumer-directed action initiated by you. When you trigger this share, you are authorizing us to facilitate the transfer of your health information to your chosen provider. We do not determine the clinical relevance of the data shared; that remains your responsibility.
Regardless of which framework applies, we apply the same baseline security safeguards to all health information in the Service and never sell it. When we connect to an EHR or other external system, we also comply with the terms of our agreements with those providers and with the providers’ technical and authentication requirements, including Epic’s connection and app-registration requirements where applicable.
5. Data Storage and Security
We employ industry-standard encryption — AES-256 for data at rest and TLS for data in transit. Consistent with our self-sovereign identity model, certain data may be encrypted under keys you control, meaning we cannot read it. Your health data is stored in secure environments configured to meet relevant regional health-privacy requirements. No system is perfectly secure, and we cannot guarantee absolute security.
6. Data Retention
Active Accounts: We retain your data for as long as your account is active and as needed to provide the Service.
After Deletion: When you request deletion, we permanently remove your records from active systems within 30 days. Residual copies may persist in encrypted backups for up to 90 days, after which they are overwritten on the normal backup cycle.
Legal Holds: We may retain limited information longer where required by law, to resolve disputes, or to enforce our agreements, and only for as long as necessary.
7. International Data Transfers
If we transfer personal data outside your region (for example, to cloud infrastructure in another country), we will use appropriate safeguards recognized under GDPR — such as Standard Contractual Clauses — and will take steps to ensure your data receives an equivalent level of protection.
8. Cookies and Tracking Technologies
Our website and any web-based components of the Service may use cookies, local storage, and similar tracking technologies to keep you signed in, remember your preferences, and understand aggregate usage patterns. We do not use these technologies to track you across unrelated third-party sites for advertising purposes, and we do not use tracking technologies within the mobile app to serve third-party ads. You can control cookies through your browser settings; disabling cookies may limit some website functionality. Where required by law (for example, under EU/UK ePrivacy rules), we will request your consent before setting non-essential cookies through a cookie banner or preference center.
9. Marketing Communications
We do not use your health data to build marketing profiles or to target advertising to you. We may send you service-related communications (such as security notices or policy updates), which are necessary to the Service and cannot be opted out of while your account is active. We may separately send optional product updates or newsletter communications, which you may opt out of at any time using the unsubscribe link in the email or through your account settings.
10. Third-Party Sharing
We do not sell your health data to third parties. We share information only with:
Service Providers: Cloud hosting and security partners who are contractually bound to protect your data and to process it only on our instructions.
At Your Direction: Recipients you choose to share your records or credentials with, consistent with the self-sovereign identity model, including any EHR system such as Epic that you direct us to connect to.
Legal Requirements: Authorities, but only when compelled by a valid legal order, and we will notify you where lawfully permitted.
11. Data Breach Notification
In the event of a personal data breach affecting your information, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it, consistent with GDPR. Where a breach is likely to result in a high risk to you, or where HIPAA’s Breach Notification Rule applies, we will notify affected users without undue delay and describe the steps we are taking in response.
12. Your Rights
Depending on your location (including under GDPR, UK GDPR, and U.S. state laws such as the CCPA/CPRA), you may have the following rights:
Access & Export: Request a copy of your data in a machine-readable, portable format.
Correction: Update inaccurate or incomplete information.
Deletion: Request permanent removal of your account and associated data, subject to the retention exceptions above.
Restriction & Objection: Limit or object to certain processing of your data.
Withdraw Consent: Rescind permission for consent-based processing at any time, without affecting prior lawful processing.
Complain: Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact our DPO using the details below. We will respond within the timeframe required by applicable law.
Contact Information
If you have any questions regarding these Terms or your privacy, please contact us:
Email: contact@selfresearch.org
Address: 18452 E 111th St Suite 104, Broken Arrow, OK 74011