Website privacy notice

Restricted platform

Platform privacy notice

This notice applies to people invited to use Braided’s restricted digital platform. It is separate from the shorter notice for visitors to the public information website.

Last updated: September 4, 2026 · Version: 2026-09-04

1. Who we are and who this covers

Braided is operated by Braided Health Limited (Company Number 9352117, NZBN 9429052935855). For platform personal and health information, our current New Zealand legal baseline is New Zealand Privacy Act 2020 and Health Information Privacy Code 2020.

We track readiness work against HIPAA, GDPR, Australian Privacy Principles, but do not present those frameworks as current certifications unless the necessary controls, contracts, and operating evidence are in place.

Platform access is restricted. This notice does not mean that accounts, clinical care, referrals, or every described feature are available to the public.

2. Information the platform may handle

Account and profile data

Contact details, authentication data, account settings, and profile information you provide.

Health and reflection data

Assessments, journal entries, chat content, uploaded documents, and related wellbeing or mental-health information.

Technical and security data

Device, session, network, and security-event information needed to operate and protect the platform.

Consent and audit records

Acknowledgements, access activity, exports, correction requests, and other privacy actions.

Provider and care information

Information created or shared in authorised provider, referral, session, formulation, and care-workflow paths.

Reward and verification evidence

Evidence and audit records used where a reward, challenge, device, venue, or verification feature is enabled.

3. How we use platform information

  • Authenticate users and deliver authorised platform features.
  • Support reflections, assessments, continuity, provider workflows, and user-requested AI functions.
  • Operate security controls, access logs, fraud prevention, and incident response.
  • Maintain consent, audit, clinical-continuity, and legal records where required.
  • Respond to access, correction, export, withdrawal, and deletion requests.
  • Improve the service in controlled ways consistent with the applicable authority and user expectations.

For reward, challenge, and verification features, Braided may process verification and audit evidence such as device or source provenance, timestamps, nonces, venue or reviewer identifiers, location or presence bands where enabled, and eligibility decisions. Braided uses the least intrusive proof path appropriate to the reward or verification rule, escalating to stronger checks only where the programme, value, risk, or review state requires it. These assurance records help assess whether a behaviour or event meets a product rule; they are not a guarantee that a health outcome occurred or was caused by the behaviour.

4. Current platform service providers

The platform currently relies on overseas service providers. Depending on the feature, information may be stored or processed outside New Zealand, including in the United States.

Vercel · Web hosting and edge delivery

United States

Information: Limited to traffic and hosted application delivery

Purpose: Serve the Braided web application

Railway · Backend application hosting

United States

Information: Application runtime may process personal and health information

Purpose: Run authenticated APIs and application services

Supabase · Authentication and PostgreSQL data

United States / EU services depending on product path

Information: Authentication data plus application records stored in PostgreSQL

Purpose: Authentication, relational data storage, and protected APIs

MongoDB Atlas · MongoDB document data

United States

Information: Assessment, journal, chat, and related document data

Purpose: Store document-oriented application data

Anthropic · AI model processing

United States

Information: Before text prompts and session transcripts are sent, Braided removes the structured identifiers it can detect — such as emails, phone numbers, NHI numbers, addresses, and titled names — and restores them only in your own saved record. This reduction is best-effort and not full de-identification: ordinary names and other free-text clinical detail may still be processed. Uploaded documents, images, and provider-authored note templates are sent as-is, because they cannot be reduced before they are read.

Purpose: AI-supported conversations, insights, clinical documentation, and analysis

Google (Gemini API) · AI transcription, embeddings, and voice synthesis

United States (vendor-managed global endpoint)

Information: Session audio is sent as-is for transcription (audio cannot be de-identified before it is transcribed); journal and reflection text is embedded for semantic search; and text is submitted for voice synthesis

Purpose: Transcribe provider session audio, power semantic search, and generate spoken audio

Resend · Contact, updates, and transactional email delivery

United States

Information: Contact details and message content submitted for email delivery

Purpose: Deliver contact enquiries, requested updates, and transactional email

Amazon Web Services (Simple Email Service) · Encrypted referral email delivery

Deployment-configured AWS region; no single region is promised here

Information: OpenPGP-encrypted referral content, referrer identity and email address, routing metadata, urgency label, and reference number when that legacy mode is enabled

Purpose: Relay browser-encrypted referrals to the practice mailbox in the legacy email-intake mode

Amazon Web Services (Rekognition and Cognito Identity Pools) · Photo and liveness verification

Australia (Sydney, ap-southeast-2) when enabled

Information: Challenge proof photos, optional selfie or liveness frames, liveness confidence signals, and related verification metadata when that proof path is used

Purpose: Support fraud-resistant reward and challenge verification

Braided is actively planning a staged move toward AWS Sydney and related regional infrastructure, starting with Bedrock Sydney for model inference. Until each move is complete, this notice continues to describe the current live stack above.

5. Security

  • Sensitive application data is encrypted at rest in Braided-controlled storage layers.
  • Data is sent over authenticated HTTPS/TLS connections in production.
  • Audit logging and access logging exist for sensitive backend paths. These controls do not mean that data is encrypted directly between end users.
  • Braided does not sell personal or health information to advertisers or data brokers.

No internet service can promise absolute security. Contact privacy@braided.nz if you believe your account or information has been affected by a privacy or security incident.

6. Rights and controls

Access and export

Users can export a copy of their data from account privacy controls.

Correction and rectification

Users can request correction of inaccurate data and Braided can review those requests.

Access history

Users can review recent access history for certain shared or sensitive data paths.

Deletion and withdrawal

Users can request deletion review through account privacy controls where available or by emailing privacy@braided.nz. Legal, clinical, audit, backup, and recipient-mailbox duties may limit deletion.

Where a right is available in the product, start from Account → Privacy & Security. You can also email the privacy contact below.

7. Retention and deletion

  • Users can delete connected health source data separately from account deletion where the product exposes that control. That live deletion removes Braided-held source stores for connected health integrations, related metric caches, biometric signposts, and associated search/index records.
  • Guide conversations and their continuity context are not silently deleted after a fixed 90- or 180-day period. By default, Braided keeps that history while it supports the person’s ongoing relationship with the service. Users can delete individual chats or request account deletion, subject to records Braided must lawfully retain.
  • Account deletion and health-source deletion do not remove records Braided must retain for audit, legal, accounting, safety, reward verification, or clinical continuity purposes.
  • Automated backups and point-in-time recovery archives cannot be selectively purged for a single user. Data deleted from live systems may remain in those backup stores until the relevant backup-retention windows expire.
  • When encrypted-email referral mode is enabled, the clinical form is encrypted in the referrer’s browser and is not written to Braided’s platform database. Amazon SES handles the encrypted message and routing metadata for delivery. After delivery, the recipient practice mailbox holds the encrypted referral under that mailbox operator’s access, retention, backup, and deletion settings. Braided cannot promise deletion from the recipient mailbox or delivery-provider systems. To request access, correction, or deletion review, contact privacy@braided.nz and quote the referral reference; clinical, legal, audit, or mailbox-retention duties may limit what can be removed.

Retention depends on the information, feature, clinical context, legal duties, and any valid deletion or withdrawal request. Not every processor or backup can be updated on the same timeline.

8. Contact