Restricted platform
Platform privacy notice
This notice applies to people invited to use Braided’s restricted digital platform. It is separate from the shorter notice for visitors to the public information website.
Last updated: September 4, 2026 · Version: 2026-09-04
1. Who we are and who this covers
Braided is operated by Braided Health Limited (Company Number 9352117, NZBN 9429052935855). For platform personal and health information, our current New Zealand legal baseline is New Zealand Privacy Act 2020 and Health Information Privacy Code 2020.
We track readiness work against HIPAA, GDPR, Australian Privacy Principles, but do not present those frameworks as current certifications unless the necessary controls, contracts, and operating evidence are in place.
2. Information the platform may handle
Account and profile data
Contact details, authentication data, account settings, and profile information you provide.
Health and reflection data
Assessments, journal entries, chat content, uploaded documents, and related wellbeing or mental-health information.
Technical and security data
Device, session, network, and security-event information needed to operate and protect the platform.
Consent and audit records
Acknowledgements, access activity, exports, correction requests, and other privacy actions.
Provider and care information
Information created or shared in authorised provider, referral, session, formulation, and care-workflow paths.
Reward and verification evidence
Evidence and audit records used where a reward, challenge, device, venue, or verification feature is enabled.
3. How we use platform information
- Authenticate users and deliver authorised platform features.
- Support reflections, assessments, continuity, provider workflows, and user-requested AI functions.
- Operate security controls, access logs, fraud prevention, and incident response.
- Maintain consent, audit, clinical-continuity, and legal records where required.
- Respond to access, correction, export, withdrawal, and deletion requests.
- Improve the service in controlled ways consistent with the applicable authority and user expectations.
For reward, challenge, and verification features, Braided may process verification and audit evidence such as device or source provenance, timestamps, nonces, venue or reviewer identifiers, location or presence bands where enabled, and eligibility decisions. Braided uses the least intrusive proof path appropriate to the reward or verification rule, escalating to stronger checks only where the programme, value, risk, or review state requires it. These assurance records help assess whether a behaviour or event meets a product rule; they are not a guarantee that a health outcome occurred or was caused by the behaviour.
4. Current platform service providers
The platform currently relies on overseas service providers. Depending on the feature, information may be stored or processed outside New Zealand, including in the United States.
Vercel · Web hosting and edge delivery
United StatesInformation: Limited to traffic and hosted application delivery
Purpose: Serve the Braided web application
Railway · Backend application hosting
United StatesInformation: Application runtime may process personal and health information
Purpose: Run authenticated APIs and application services
Supabase · Authentication and PostgreSQL data
United States / EU services depending on product pathInformation: Authentication data plus application records stored in PostgreSQL
Purpose: Authentication, relational data storage, and protected APIs
MongoDB Atlas · MongoDB document data
United StatesInformation: Assessment, journal, chat, and related document data
Purpose: Store document-oriented application data
Anthropic · AI model processing
United StatesInformation: Before text prompts and session transcripts are sent, Braided removes the structured identifiers it can detect — such as emails, phone numbers, NHI numbers, addresses, and titled names — and restores them only in your own saved record. This reduction is best-effort and not full de-identification: ordinary names and other free-text clinical detail may still be processed. Uploaded documents, images, and provider-authored note templates are sent as-is, because they cannot be reduced before they are read.
Purpose: AI-supported conversations, insights, clinical documentation, and analysis
Google (Gemini API) · AI transcription, embeddings, and voice synthesis
United States (vendor-managed global endpoint)Information: Session audio is sent as-is for transcription (audio cannot be de-identified before it is transcribed); journal and reflection text is embedded for semantic search; and text is submitted for voice synthesis
Purpose: Transcribe provider session audio, power semantic search, and generate spoken audio
Resend · Contact, updates, and transactional email delivery
United StatesInformation: Contact details and message content submitted for email delivery
Purpose: Deliver contact enquiries, requested updates, and transactional email
Amazon Web Services (Simple Email Service) · Encrypted referral email delivery
Deployment-configured AWS region; no single region is promised hereInformation: OpenPGP-encrypted referral content, referrer identity and email address, routing metadata, urgency label, and reference number when that legacy mode is enabled
Purpose: Relay browser-encrypted referrals to the practice mailbox in the legacy email-intake mode
Amazon Web Services (Rekognition and Cognito Identity Pools) · Photo and liveness verification
Australia (Sydney, ap-southeast-2) when enabledInformation: Challenge proof photos, optional selfie or liveness frames, liveness confidence signals, and related verification metadata when that proof path is used
Purpose: Support fraud-resistant reward and challenge verification
5. Security
- Sensitive application data is encrypted at rest in Braided-controlled storage layers.
- Data is sent over authenticated HTTPS/TLS connections in production.
- Audit logging and access logging exist for sensitive backend paths. These controls do not mean that data is encrypted directly between end users.
- Braided does not sell personal or health information to advertisers or data brokers.
No internet service can promise absolute security. Contact privacy@braided.nz if you believe your account or information has been affected by a privacy or security incident.
6. Rights and controls
Access and export
Users can export a copy of their data from account privacy controls.
Correction and rectification
Users can request correction of inaccurate data and Braided can review those requests.
Access history
Users can review recent access history for certain shared or sensitive data paths.
Deletion and withdrawal
Users can request deletion review through account privacy controls where available or by emailing privacy@braided.nz. Legal, clinical, audit, backup, and recipient-mailbox duties may limit deletion.
Where a right is available in the product, start from Account → Privacy & Security. You can also email the privacy contact below.
7. Retention and deletion
- Users can delete connected health source data separately from account deletion where the product exposes that control. That live deletion removes Braided-held source stores for connected health integrations, related metric caches, biometric signposts, and associated search/index records.
- Guide conversations and their continuity context are not silently deleted after a fixed 90- or 180-day period. By default, Braided keeps that history while it supports the person’s ongoing relationship with the service. Users can delete individual chats or request account deletion, subject to records Braided must lawfully retain.
- Account deletion and health-source deletion do not remove records Braided must retain for audit, legal, accounting, safety, reward verification, or clinical continuity purposes.
- Automated backups and point-in-time recovery archives cannot be selectively purged for a single user. Data deleted from live systems may remain in those backup stores until the relevant backup-retention windows expire.
- When encrypted-email referral mode is enabled, the clinical form is encrypted in the referrer’s browser and is not written to Braided’s platform database. Amazon SES handles the encrypted message and routing metadata for delivery. After delivery, the recipient practice mailbox holds the encrypted referral under that mailbox operator’s access, retention, backup, and deletion settings. Braided cannot promise deletion from the recipient mailbox or delivery-provider systems. To request access, correction, or deletion review, contact privacy@braided.nz and quote the referral reference; clinical, legal, audit, or mailbox-retention duties may limit what can be removed.
Retention depends on the information, feature, clinical context, legal duties, and any valid deletion or withdrawal request. Not every processor or backup can be updated on the same timeline.
8. Contact
Privacy: privacy@braided.nz
Support: support@braided.nz
Legal: legal@braided.nz