Data Aggregation
Privacy & Security

Privacy & Security

BetterStep is committed to protecting user data and providing transparent privacy controls.

Data Collection

BetterStep collects:

  • Profile information provided by users
  • Daily check-in responses
  • Quest completion data
  • Health data from connected devices (future)
  • Chat conversation history

User Privacy Controls

Health Permissions (Future)

When Health Connect integration is available:

  • Users control which data types to share
  • Data syncs automatically in the background
  • Users can disconnect devices at any time

Clinic Connection Controls

ControlDescription
Data Sharing ToggleEnable/disable per connected clinic
DisconnectRemove clinic connection at any time
Multi-clinicIndependent controls per clinic

Confidential Tracking

Slip Tracking - Slip tracking is private by default. Only you see this data in your app. It's used to improve your personalized support and is only shared with connected clinics if you have approved the connection.

Data Security

Security MeasureDescription
EncryptionAll data encrypted in transit (TLS) and at rest (AES-256)
AuthenticationSecure JWT tokens with optional Google OAuth
Webhook SecuritySignature verification for all webhook payloads
Access ControlRole-based permissions with audit logging

Historical Data Handling

When a beneficiary disconnects from a clinic:

Data TypeHandling
Previously synced dataRetained by clinic for clinical records
New dataNo longer shared
Chat conversationsSummaries retained, full text not shared

Data Retention

Data CategoryRetention Period
Active user dataDuration of account
Deleted accounts30 days, then purged
Clinical recordsPer clinic policy
Audit logs2 years