Security

How your medical records are protected.

This page lists everything the Private Health Passport app and this website keep, where each piece is kept, and who can read it.

Your medical records stay on your own phone, encrypted under a key only you hold. What we keep is what you send us through this website.

Last updated

What lives where

Everything we and the app keep.

  • Your medical records

    History, medications, scans, results and insurance documents.

    Where
    On your own phone, encrypted
    Who can read it
    You, and a doctor you show them to
  • Your passphrase

    The one thing that unlocks your records.

    Where
    With you. It is never stored
    Who can read it
    You
  • The salt for your key

    A random value that makes your key unique. Useless on its own.

    Where
    On your own phone
    Who can read it
    Your phone
  • An enquiry sent through this website

    Your name, email, home country, the procedure you asked about, your message and the page you wrote from.

    Where
    Our database, with an email copy to hello@zkomi.com
    Who can read it
    The Private Health Passport team
  • A launch sign-up

    Your email and the button you used.

    Where
    Our database, with an email copy to hello@zkomi.com
    Who can read it
    The Private Health Passport team

Encryption

Locked on the phone, with your key.

AES-256-GCM
Your records are encrypted on the phone with AES-256 in GCM mode, which also detects any tampering with the stored data.
A key made from your passphrase
The key is derived from your passphrase with PBKDF2, one hundred thousand rounds, on the phone itself. The passphrase is never stored. Only the salt is kept, on your device.
Zero-knowledge
Private Health Passport and Zkomi hold no key and no copy of your records. The app needs no account and no email address to hold a record.

The research behind it

The design, in Zkomi’s published research.

Zkomi, which builds Private Health Passport, publishes the design in its own research papers: Paper 004, The Zero-Knowledge Architecture, and Paper 016, Memory Without Custody, on keeping a medical history continuous across borders with no central custodian.

Sharing

How a record reaches a doctor.

With a doctor in the room
A sharing session runs directly between your phone and the doctor's device, with no network calls. The doctor sees one screen written for clinicians: current medication and recent results.
With someone further away
A link you send expires by itself. The status link for family carries its contents in the fragment of the address, the part that browsers keep out of every request to a server.
In an emergency
Your emergency card is encoded inside a QR code and reads on a paramedic's phone in aircraft mode. A two-second hold shows blood type, allergies and your contact by default, and you decide whether to add more.
Paper letters
Photograph a discharge letter or a prescription and the text is read inside your browser on the phone, with the recognition engine served from our own site.
After the consultation
What a doctor writes in their own notes becomes part of their clinic's record, under their clinic's rules. Share what the consultation needs, and keep the rest in your vault.

Your passphrase

Keep your passphrase somewhere safe.

Your passphrase is the only way into your records. That is what keeps them private, and it also means a forgotten passphrase stays forgotten: there is no reset, from us or from anyone else.

Write it down and keep it somewhere safe and offline, the way you would keep a spare house key. If you lose your phone, the records on it stay encrypted, and whoever finds it sees locked data.

Requests for your data

Asked for your records, we have none to give.

If anyone asks us for your medical records, a court or a government included, the answer is the same: we hold none, and no key to open them. What we hold is listed above: enquiries and launch sign-ups sent through this website.

A breach of our servers would reach those enquiries and sign-ups. It would reach no medical records, because none are there.

Questions about security go to hello@zkomi.com, where a person reads every message. How we write about all this is set out in our editorial policy.