GDPR & deletion
Privacy controls differ per patient app; Clinician Platform retention follows medical-record norms.
Patient-side controls
| Control | Heartful Baby | Eating Recovery | Heartful Sprout |
|---|---|---|---|
| Data export | Machine-readable JSON of all app records | — | — |
| Account deletion | Two-stage confirmation, then immediate permanent delete | Scheduled 30 days out; family can cancel by signing back in | Contact support |
| Usage analytics toggle | Opt out of telemetry separately from deletion | — | — |
What you see when a family deletes
For Eating Recovery families, the patient's Program Access shows a Deactivated chip with the deletion state: scheduled deletions note the date and pause new check-ins; completed deletions note that everything already shared stays in your record.
Clinician-side retention
- Patient records are retained according to your jurisdiction's medical-records retention rules.
- Archived patients stay in the platform for documentation and billing purposes.
- A family deleting their app account does not remove data already shared into your record.
- For full deletion of a patient record, contact support@heartfulsprout.com.
Specific retention windows by jurisdiction coming soon.