Legend Helm

  • Home
  • Privacy
  • Terms
  • Contact
  • What it does
  • How it works
  • Why we built it
  • Editions
  • FAQ
PRIVACY POLICY

Last updated: July 1, 2026

This Privacy Policy describes how Legend Personal Care, LLC ("Company," "we," "us," or "our") collects, uses, and protects information in connection with your use of the Legend Helm application and related services (collectively, the "Services").

IMPORTANT NOTICE — ATTORNEY REVIEW PENDING: This Privacy Policy is a working draft and has not yet been reviewed by legal counsel. It is published to satisfy developer portal registration requirements during the pre-launch development phase. It will be updated following attorney review prior to public launch of the Services. Questions may be directed to info@legendpersonalcare.com.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE USE YOUR INFORMATION?
  3. WILL YOUR INFORMATION BE SHARED WITH ANYONE?
  4. HEALTH PORTAL CONNECTIONS AND FHIR DATA ACCESS
  5. EMAIL DISCOVERY
  6. HOW IS YOUR INFORMATION STORED AND SECURED?
  7. HIPAA NOTICE
  8. HOW LONG DO WE KEEP YOUR INFORMATION?
  9. WHAT ARE YOUR PRIVACY RIGHTS?
  10. DO WE MAKE UPDATES TO THIS POLICY?
  11. HOW CAN YOU CONTACT US ABOUT THIS POLICY?

1. WHAT INFORMATION DO WE COLLECT?

Information you provide directly

When you use Legend Helm, you may provide the following information:
  • Patient name, date of birth, gender, contact information, and address
  • Health provider and appointment information entered manually
  • Medication information entered manually
  • Account credentials you create within Legend Helm

Information retrieved from health portals

With your explicit authorization, Legend Helm retrieves health information from connected patient health portals using secure FHIR (Fast Healthcare Interoperability Resources) APIs. This may include:
  • Patient demographic information
  • Appointment and visit history
  • Provider and care team information
  • Medication requests and prescriptions
  • Clinical notes, diagnostic reports, and lab results (where available)
  • Immunization records
  • Conditions and allergies
Health portal data is retrieved only when you initiate a connection and only for the patient account you authorize. See Section 4 for more detail on how health portal connections work.

Information retrieved from email (optional, onboarding only)

If you choose to connect your email account during onboarding, Legend Helm reads email sender information and subject lines only — for the sole purpose of identifying healthcare providers you have communicated with. Legend Helm does not read email body content, does not store email text, and does not retain email credentials after the initial scan. See Section 5 for more detail.

Automatically collected information

Legend Helm is a local Windows desktop application. We do not collect usage analytics, crash reports, or telemetry without your explicit consent. If telemetry features are added in a future version, this policy will be updated and you will be notified before any data collection begins.

2. HOW DO WE USE YOUR INFORMATION?

Information collected through Legend Helm is used solely for the following purposes:
  • To display and organize your personal health records within the application
  • To retrieve health data from connected patient portals at your request
  • To identify healthcare providers you have communicated with, for the purpose of suggesting portal connections during onboarding
  • To enable multi-device synchronization of your health records, if you choose to enable that feature
  • To provide customer support when you contact us
We do not use your health information for advertising, marketing, research, or any purpose other than providing the Services to you.

3. WILL YOUR INFORMATION BE SHARED WITH ANYONE?

We do not sell your personal information or health data. We do not share your information with third parties for advertising or marketing purposes.

Your health data may be transmitted to our private cloud infrastructure solely for the purpose of encrypted synchronization between your authorized devices. This transmission uses end-to-end encryption — our servers route encrypted data between your devices without the ability to read its contents (zero-knowledge architecture).

We may disclose information if required by law, court order, or government authority, or if necessary to protect the rights, property, or safety of Legend Personal Care, LLC, our users, or the public.

4. HEALTH PORTAL CONNECTIONS AND FHIR DATA ACCESS

Legend Helm connects to patient health portals using the SMART on FHIR standard, an industry-standard secure authorization framework for patient-controlled health data access. When you connect a health portal:
  • You are redirected to your health system's own login page — Legend Helm never sees your portal username or password
  • You review and authorize the specific data Legend Helm is requesting access to
  • A time-limited access token is issued by your health system and stored securely on your device using Windows Data Protection API (DPAPI) encryption
  • Legend Helm uses this token to retrieve your health data directly from your health system's FHIR servers
  • You can revoke Legend Helm's access at any time through your health portal's connected apps settings
Re-authorization is required periodically (typically several times per year) as access tokens expire. This is a feature of the SMART on FHIR standard designed to keep you in control of your data access.

Health data retrieved from your portals is stored locally on your device in an encrypted SQLite database. It is not transmitted to our servers except as described in Section 3 (encrypted synchronization between your authorized devices).

5. EMAIL DISCOVERY

During onboarding, you may optionally connect your email account (Gmail or Outlook) to allow Legend Helm to automatically identify healthcare providers you have previously communicated with. If you choose to use this feature:
  • Legend Helm reads email sender names and addresses and subject lines only — email body content is never accessed or stored
  • The scan occurs one time, during onboarding. Legend Helm does not retain your email credentials or access your email again after the initial scan completes
  • No email text, attachments, or content of any kind is stored by Legend Helm
  • Only the derived output of the scan is retained: a list of identified healthcare providers and the approximate number of emails received from each
  • You may skip email discovery at any time and choose your health portals manually
Email connection uses OAuth 2.0 authorization — Legend Helm never sees your email password. The email access token is discarded immediately after the scan completes and is not stored.

6. HOW IS YOUR INFORMATION STORED AND SECURED?

Legend Helm is designed with patient data security as a primary principle:
  • Local storage: Your health data is stored in an encrypted SQLite database on your device, protected by AES-256 encryption with SHA-512 HMAC integrity verification
  • Credential storage: Health portal access tokens and other credentials are stored using Windows Data Protection API (DPAPI), which ties encryption to your Windows user account
  • Zero-knowledge cloud sync: If you enable multi-device synchronization, data is encrypted on your device before transmission. Our servers route encrypted data between your devices without the ability to read its contents
  • No plain-text storage: No health data, credentials, or personal information is stored in unencrypted form at any point
  • Secure transmission: All communications between Legend Helm and health portals or our servers use TLS (Transport Layer Security) encryption
While we implement strong security measures, no system can guarantee absolute security. We encourage you to use a strong Windows account password and to keep your device's operating system and security software up to date.

7. HIPAA NOTICE

Legend Helm is a personal health management application designed for individual patients and caregivers to manage their own health records. The applicability of the Health Insurance Portability and Accountability Act (HIPAA) to Legend Helm and Legend Personal Care, LLC is subject to legal review and will be addressed in a forthcoming update to this policy following attorney consultation.

Health data retrieved from connected portals originates from HIPAA-covered entities (hospitals, health systems, and clinical practices). The transmission of that data to Legend Helm occurs under the patient's own right of access as provided by the HIPAA Right of Access rule (45 CFR § 164.524) and the 21st Century Cures Act's information blocking prohibitions.

8. HOW LONG DO WE KEEP YOUR INFORMATION?

Health data and personal information stored in Legend Helm is retained on your device for as long as you use the application. You may delete individual records, patient profiles, or your entire Legend Helm database at any time from within the application.

If you delete the Legend Helm application, all locally stored data is removed from your device. If you have enabled cloud synchronization, you may request deletion of your synchronized data by contacting us at info@legendpersonalcare.com.

9. WHAT ARE YOUR PRIVACY RIGHTS?

Because Legend Helm stores health data locally on your own device, you have direct control over your information at all times:
  • Access: You can view all data stored in Legend Helm at any time within the application
  • Correction: You can edit or correct any record within the application
  • Deletion: You can delete individual records or your entire health database at any time
  • Portability: Export features are planned for a future version of Legend Helm
  • Revoke portal access: You can revoke Legend Helm's access to any connected health portal at any time through that portal's connected apps settings
To exercise any rights related to data we may hold on our servers (e.g., cloud synchronization data), please contact us at info@legendpersonalcare.com. We will respond to requests within 30 days.

California Residents: California residents may have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). Please contact us at the address below for more information. If any complaint with us is not satisfactorily resolved, you can contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N 112, Sacramento, California 95834 or by telephone at (800) 952-5210 or (916) 445-1254.

10. DO WE MAKE UPDATES TO THIS POLICY?

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this policy. We will notify you of material changes by posting a notice within the Legend Helm application. We encourage you to review this policy periodically.

Continued use of Legend Helm after changes to this Privacy Policy constitutes your acceptance of the updated policy.

11. HOW CAN YOU CONTACT US ABOUT THIS POLICY?

If you have questions or comments about this Privacy Policy or our privacy practices, please contact us at:

Legend Personal Care, LLC
info@legendpersonalcare.com


This Privacy Policy is a pre-launch draft pending attorney review. It is published to satisfy developer portal registration requirements during the development phase of Legend Helm. It will be revised prior to public launch of the Services.

Legend Helm

Developed by Legend Personal Care, LLC.

Contact

info@legendpersonalcare.com

Links

Home
Editions
Terms and conditions
Contact us

© Copyright Legend Helm All Rights Reserved

Designed by BootstrapMade