Tai · ReadyLooking with you at Privacy
TV
Tai
Search everything…⌘K
TaiToday

Core

Money & BillsCourt & LegalHealthTextsComms

Explore

CalendarTasksAlertsSportsSearchAll of Tai
Settings

Tai

Privacy Policy

Last updated June 18, 2026

What Tai is

Tai is a private, single-owner personal command center. It exists to help one person — its owner — keep their own life organized: appointments, bills, legal matters, and personal health records. It is not a multi-user product, an advertising business, or a data broker. There is exactly one account holder, and the only person Tai shows data to is that account holder, signed in.

Health data Tai accesses

When you choose to connect a patient health record (for example, an AdventHealth MyChart account through Epic's patient FHIR API), Tai reads your own health information so it can show it back to you inside the app. With your explicit authorization, the categories it may read are the standard USCDI data classes:

  • Patient demographics (your name and identifiers)
  • Conditions / problems
  • Medications
  • Lab results and vital signs (Observations)
  • Allergies and intolerances
  • Immunizations
  • Procedures and encounters
  • Clinical documents (DocumentReference)

Tai only ever reads data the health system actually returns for your account. It never writes to, changes, or deletes anything in your medical record — the connection is read-only.

How the connection works

Connecting uses the SMART-on-FHIR standard with the OAuth 2.0 authorization-code flow and PKCE. You sign in directly on your health system's own login page — Tai never sees or stores your MyChart username or password. Your health system returns a time-limited access token to Tai, which Tai uses to fetch your records.

You authorize the connection, and you can revoke it at any time from within Tai (Health → Connect → Disconnect) and from your health system's patient portal.

SMS messaging and mobile number

Tai offers optional SMS alerts — appointment reminders, bill alerts, and status updates — sent to the account owner's mobile number via Twilio.

  • Your mobile number is collected only when you explicitly provide it in Settings → SMS Alerts and check the opt-in box. It is not collected automatically.
  • Your mobile number and SMS consent record are stored in the owner's private, row-level-secured database. They are used solely to send the SMS messages you requested.
  • Mobile opt-in information and consent are not shared with or sold to third parties and are not used for marketing or advertising purposes.
  • No mobile information is shared with third parties for any purpose.
  • You can opt out at any time by replying STOP to any message from Tai, or by unchecking the opt-in box in Settings → SMS Alerts.

How your data is stored and protected

  • Your data is stored in the owner's private database, protected by row-level security so it is only ever readable by the signed-in owner.
  • Access and refresh tokens are encrypted (AES-256-GCM) with a key that lives only on the server. The encrypted token is never returned to the browser and is useless without the server key.
  • Sensitive personal and health data stays within the owner's own system. It is not sold, shared with advertisers, or sent to any third-party analytics or external AI service for training.
  • All network connections use HTTPS/TLS.

How your data is used

Your records are used for one purpose: to display and organize your own information for you inside Tai — for example, showing your medications, surfacing an upcoming lab trend, or letting you search your own clinical documents. There is no secondary use. Tai does not provide medical advice; anything it surfaces is informational and should be confirmed with your clinicians.

Data retention and deletion

Records that were really fetched remain in the owner's database as a personal health history until the owner removes them. Disconnecting a health-record connection stops future syncing and disables the stored tokens. To have stored data deleted, the owner can request deletion via the contact below.

Children's privacy

Tai is a personal tool for its adult owner and is not directed at children.

Changes to this policy

If this policy changes, the updated date at the top of this page will change. Material changes affecting how health data is handled will be reflected here before they take effect.

Contact

Questions about privacy or a data request can be sent to tonf461@gmail.com.

Tai is operated by its individual owner for personal use. This policy describes the actual behavior of the app: a private, single-owner application that reads the owner's own records, stores them securely, and never sells or shares them.