Privacy & compliance
GDPR & deletion

GDPR & deletion

Privacy controls differ per patient app; Clinician Platform retention follows medical-record norms.

Patient-side controls

ControlHeartful BabyEating RecoveryHeartful Sprout
Data exportMachine-readable JSON of all app records
Account deletionTwo-stage confirmation, then immediate permanent deleteScheduled 30 days out; family can cancel by signing back inContact support
Usage analytics toggleOpt out of telemetry separately from deletion

What you see when a family deletes

For Eating Recovery families, the patient's Program Access shows a Deactivated chip with the deletion state: scheduled deletions note the date and pause new check-ins; completed deletions note that everything already shared stays in your record.

Clinician-side retention

  • Patient records are retained according to your jurisdiction's medical-records retention rules.
  • Archived patients stay in the platform for documentation and billing purposes.
  • A family deleting their app account does not remove data already shared into your record.
  • For full deletion of a patient record, contact support@heartfulsprout.com.

Specific retention windows by jurisdiction coming soon.