Privacy Policy
Last updated: September 6, 2026.
Data controller
The data controller for MyHealthHub is Jorge Perez Arribillaga, an individual based in Argentina operating under the trade name FenixSoulAR. For privacy requests and to exercise your rights, contact fenixsoular@gmail.com.
Scope and nature of the service
This policy explains how data is handled when you visit myhealthhub.ar, use the web/PWA application at app.myhealthhub.ar, or contact MyHealthHub support. MyHealthHub is a software service (SaaS) for organizing personal health information. It does not provide medical advice, diagnosis, prescriptions, treatment recommendations, clinical decision support, telemedicine, or healthcare services, and does not replace healthcare professionals.
Account and contact data
We process your email address, account identifiers, profile details you provide, credentials managed by the authentication service, preferences, sessions, and sharing invitations. If you contact us, we receive your message and the contact details you include. Please avoid sending health information that is unnecessary to resolve your request.
Health information and third-party data
You choose what to enter: medications, diagnoses you record, tests and results, medical history, appointments, procedures, professionals, institutions, notes, images, and attached documents. Record metadata and summaries based on that data are also generated. Health information is sensitive. When entering information about relatives or other people, you must have the appropriate authorization or authority to represent them and any required consent. Those people may also exercise their rights over their data.
Purposes and user choices
We use data to create and authenticate accounts; store, organize, and display your records; enable permissions, exports, and reminders you configure; manage plans; answer requests; prevent abuse; and resolve incidents. We process the data you choose to provide to deliver the functions you request and, where applicable, on the basis of consent and applicable legal obligations. Information needed to create an account or complete a purchase is identified in those processes; without it, those functions cannot be provided. We do not use your records to make clinical decisions.
Sharing, exports, and reminders
The account holder chooses whom to invite and can revoke shared access. Read-only or collaborator permissions and limits depend on the plan; Plus supports personal profile sharing and Pro adds family management. A recipient of an export may keep a copy outside MyHealthHub: revoking access does not delete those copies. If you export a calendar event or enable notifications, the selected information may appear in the chosen service or on your device. Reminders are not medical alarms and delivery is not guaranteed.
Authentication, storage, and technology providers
Supabase provides authentication, the database, and file storage for the application. Cloudflare provides hosting and delivery for the website and web/PWA, and may process IP addresses, requests, and technical data to operate and protect its infrastructure. These services process data needed for their functions. Authorized personnel may access information necessary for support, maintenance, or security. Providers do not all have the same access or perform the same role.
Paddle and billing data
For web/PWA purchases processed by Paddle, Paddle acts as Merchant of Record and processes purchase, contact, payment, receipt, and fraud-prevention data under its own policy. MyHealthHub exchanges account, plan, transaction, and subscription identifiers to associate payment with service access. The billing integration does not send health records or attachments to Paddle or provide functional access to them. Only technical and commercial data needed for billing and payments is exchanged; do not include clinical information in payment-support requests. Free is managed internally and does not require a Paddle purchase.
Cookies, local storage, and browsing
The application uses browser storage for sessions and preferences. The website loads fonts through Google Fonts, generating requests to Google with technical connection data. Enabled commercial pages may load Meta Pixel to measure visits and actions such as opening the app; this may involve cookies, browser identifiers, and browsing data sent to Meta. The configuration excludes the private application and legal pages from this measurement; it is not intended to send health records. You can manage cookies and tracking technologies through your browser; blocking essential storage may affect sign-in or preferences.
Data retention
We retain account data and records while needed for the functions you use, until you delete them or request deletion, except where legal reasons justify retaining specific data. Technical logs, support communications, and billing data may be retained as needed for security, issue resolution, and applicable obligations. Backups may follow deletion cycles different from the active system. We do not promise instant deletion of all copies; you can ask about the scope and status of a request through our contact channel.
International transfers
Using cloud and payment providers may involve processing and storage outside Argentina, in countries where those providers and their subprocessors operate. Location depends on the service and its configuration. Where applicable, transfers must use safeguards required by applicable law. You can request information about the providers, destinations, and mechanisms applicable to your data. This policy does not claim that all information stays in Argentina or certify regulatory compliance.
Your rights and account deletion
You may request information, access, correction, updating, or deletion of your data and withdraw consent where applicable. Exercising your rights does not require a paid plan. For requests requiring verification, we may ask for the minimum information necessary to verify identity or authority to act for someone else. The app offers account deletion in Settings; you can also request it by email. Canceling a subscription and deleting an account are separate actions: check your subscription status in the Paddle portal. Deletion in MyHealthHub does not automatically erase receipts Paddle must retain. In Argentina, you can find information about your rights and submit complaints to the Agency for Access to Public Information (AAIP).
Children
An account must be managed by someone with legal capacity to accept the service terms. Children’s data must be entered and managed by a person with the appropriate authority or authorization. Do not upload or share children’s data without that authority. If you identify an account or data processing without authorization, contact us so we can review the situation.
Security and limitations
We apply account and permission-based access controls, data access policies, and HTTPS communications. These measures reduce risk, but no system guarantees absolute security, continuous availability, or freedom from data loss. Protect your credentials and devices, review shared access, and keep the copies you need. We do not claim certifications or regulatory compliance that have not been established.
Contact and policy changes
To exercise your rights, request deletion, or ask about privacy, email fenixsoular@gmail.com. Updates will be published on this page with their date. Where applicable, we will communicate material changes through account contact channels or a notice in the service and request consent if needed.