Sleep is intimate. So is your data.
This page is maintained by MyRemD to answer common privacy, security and responsible-AI questions. It describes practices as they exist today and clearly marks what's on the roadmap.
Four commitments. Held quietly.
Patients hold their data
You own your sleep data. You choose what is shared, with whom, and when.
Minimum necessary
We collect only what a feature requires. Nothing extra, nothing speculative.
No sale of personal data
MyRemD does not sell personal data. Ever.
Consent-first sharing
Data shared with a clinician requires your explicit, revocable consent.
Defense in depth.
- · Reputable cloud infrastructure with hardened baselines
- · Least-privilege access controls and audit logging
- · Segregated environments for development and production
- · Ongoing dependency and vulnerability monitoring
- · Formal incident response process
At rest, in transit.
- · Data encrypted in transit using modern TLS
- · Data encrypted at rest at the storage layer
- · Managed keys with rotation policies
- · Sensitive fields treated with additional care
Your data. Your terms.
You can export what you've shared with MyRemD and request deletion at any time. We keep only what we need to keep the service working.
Companion, not clinician.
MyRemD's AI is designed to support education and behavior change, not to diagnose or treat. It defers to licensed clinicians for medical decisions and is guardrailed for safety.
What it doesn't do.
- · Does not diagnose sleep disorders
- · Does not prescribe medication or therapy
- · Does not replace a clinician's judgment
- · May be wrong; always defer to your care team
We show our work.
Recommendations link back to their evidence base. Planned features are labeled. Regulatory status is not implied. If we don't yet know, we say so.
Built for everyone.
MyRemD targets WCAG 2.1 AA. Every surface is reviewed for keyboard support, screen reader semantics, color contrast and reduced motion.
Paced to responsibility.
MyRemD is a consumer-facing sleep health companion today. Compliance and regulatory pathways are pursued deliberately, not preemptively.
- HIPAA readiness
Administrative, physical and technical safeguards aligned to HIPAA; formal BAA support for enterprise partners.
In progress - SOC 2 Type II
Independent audit of security, availability and confidentiality controls.
Planned - GDPR & UK GDPR
Lawful basis, DSAR support, and DPA for EU/UK partners.
Planned - Software-as-medical-device
Pathway evaluation for any feature that would require regulatory clearance.
Planned
Report a vulnerability.
Security researchers and partners: we welcome coordinated disclosure. We'll acknowledge every report.