Trust center

Sleep is intimate. So is your data.

This page is maintained by MyRemD to answer common privacy, security and responsible-AI questions. It describes practices as they exist today and clearly marks what's on the roadmap.

Privacy principles

Four commitments. Held quietly.

01

Patients hold their data

You own your sleep data. You choose what is shared, with whom, and when.

02

Minimum necessary

We collect only what a feature requires. Nothing extra, nothing speculative.

03

No sale of personal data

MyRemD does not sell personal data. Ever.

04

Consent-first sharing

Data shared with a clinician requires your explicit, revocable consent.

Security overview

Defense in depth.

  • · Reputable cloud infrastructure with hardened baselines
  • · Least-privilege access controls and audit logging
  • · Segregated environments for development and production
  • · Ongoing dependency and vulnerability monitoring
  • · Formal incident response process
Encryption

At rest, in transit.

  • · Data encrypted in transit using modern TLS
  • · Data encrypted at rest at the storage layer
  • · Managed keys with rotation policies
  • · Sensitive fields treated with additional care
Data ownership

Your data. Your terms.

You can export what you've shared with MyRemD and request deletion at any time. We keep only what we need to keep the service working.

Responsible AI

Companion, not clinician.

MyRemD's AI is designed to support education and behavior change, not to diagnose or treat. It defers to licensed clinicians for medical decisions and is guardrailed for safety.

AI limitations

What it doesn't do.

  • · Does not diagnose sleep disorders
  • · Does not prescribe medication or therapy
  • · Does not replace a clinician's judgment
  • · May be wrong; always defer to your care team
Transparency

We show our work.

Recommendations link back to their evidence base. Planned features are labeled. Regulatory status is not implied. If we don't yet know, we say so.

Accessibility

Built for everyone.

MyRemD targets WCAG 2.1 AA. Every surface is reviewed for keyboard support, screen reader semantics, color contrast and reduced motion.

Regulatory roadmap

Paced to responsibility.

MyRemD is a consumer-facing sleep health companion today. Compliance and regulatory pathways are pursued deliberately, not preemptively.

  1. HIPAA readiness

    Administrative, physical and technical safeguards aligned to HIPAA; formal BAA support for enterprise partners.

    In progress
  2. SOC 2 Type II

    Independent audit of security, availability and confidentiality controls.

    Planned
  3. GDPR & UK GDPR

    Lawful basis, DSAR support, and DPA for EU/UK partners.

    Planned
  4. Software-as-medical-device

    Pathway evaluation for any feature that would require regulatory clearance.

    Planned
Contact security

Report a vulnerability.

Security researchers and partners: we welcome coordinated disclosure. We'll acknowledge every report.

For non-security questions, please use the general contact form.