Privacy

Your vault stays on your device. HearMeDoc never receives its contents.

Effective 2026-09-29. First released 2026-05-23.

Who runs this site

HearMeDoc is a private, encrypted, patient-side medical vault at hearmedoc.com, operated by Honeycutt Ai Labs (Honeycutt AI Labs LLC, Princeton, TX, USA). The older address mymedlock.com redirects to hearmedoc.com, so this policy applies to both. Contact: hello@honeycuttailabs.com or edwin@honeycuttailabs.com.

The short version

HearMeDoc runs in your browser. Everything you put into your vault stays on your device, encrypted with a key derived from a passphrase only you know. No copy is sent to us, to any cloud, or to any third party. There is no account, no analytics and no telemetry. Website connection information and email correspondence are described below.

What the server does and logs

The server is nginx on a Honeycutt Ai Labs server hosted on Amazon Web Services. It hands your browser the application files (HTML, JavaScript, CSS, fonts and bundled public data) over HTTPS. Its access log is turned off for this site, so page requests are not written to an access log. The server’s error log and the hosting provider’s network infrastructure can still record connection information such as an IP address, as with any website. None of it can contain your medical data, because your medical data is never sent. All fonts are served from this site itself; nothing is fetched from other companies.

Cookies and browser storage

The site sets no cookies and the app never reads or writes one. It uses browser storage only to hold your encrypted vault and its settings on your own device.

WhereWhat it holds
IndexedDBYour record entries, profile, medications, allergies, labs, symptoms, appointments and providers. Every record is AES-256-GCM encrypted.
localStorageA salt, a verification envelope, your preference settings, the date of your last backup and the Pro-unlock flag. Never any medical information.
sessionStorageA counter of failed passphrase attempts and the time of the next allowed attempt. Cleared when the tab closes or the vault unlocks.
Browser cacheThe app’s own files, kept by the service worker so the app opens offline.

The “Destroy Vault” button in the app wipes IndexedDB, localStorage, caches and the service worker registration on your device.

What we do not do

When you contact us

If you click Request a feature in the app, your browser’s email client opens with a message you typed. No vault data is included. When you send it, it goes through your own mail provider to hello@honeycuttailabs.com.

Payments, children, and regulation

HearMeDoc v1 has no paid features and no payment flow. It is not directed at children under 13. Honeycutt Ai Labs is not a HIPAA-covered entity or business associate, because no PHI is transmitted to, received by or stored by us.

The full text, including the vault controls and regulatory posture, is in PRIVACY.md. If the two ever differ, this page carries the current effective date.

Changes

If this policy changes, the effective date above changes with it. Material changes will be announced on the home page with at least 30 days notice.