Data Privacy at SharedSky

Written by

in

Why Your Health Logs Are End-to-End Encrypted

When you log a physical health entry—whether it is an acute asthma flare-up, a lingering migraine, or unexplained cognitive fatigue—you are sharing deeply personal information. At SharedSky, we recognize that your health logs, location histories, and daily physical baseline entries belong exclusively to you.

Personal health apps often operate on business models that monetize user habits, location movements, or health metrics for targeted advertising and market research. We built SharedSky on a fundamentally different premise: privacy-first architecture. We believe that tracking environmental triggers should never require compromising your personal digital sovereignty.

This post details the technical architecture protecting your data, how we handle sensitive location tracking, our strict stance on data monetization, and how community insights are generated safely through anonymization.

1. Modern Encryption Standards: Protecting Data in Transit and at Rest

To ensure your health records and location logs remain confidential, SharedSky implements multi-layered encryption protocols across every stage of the data lifecycle.

Encryption in Transit: Transport Layer Security (TLS 1.3)

When your device communicates with our servers—whether you are submitting a 15-second symptom entry or fetching local air quality index (AQI) metrics—your data travels through an encrypted communication channel. We enforce Transport Layer Security (TLS 1.3), the current cryptographic standard for internet communications.

TLS 1.3 prevents interception, eavesdropping, and man-in-the-middle attacks. Any data transmitted between your smartphone app and the SharedSky cloud infrastructure is unreadable to external entities, internet service providers, or public network operators.

Encryption at Rest: Advanced Encryption Standard (AES-256)

Once your symptom logs and location entries reach our secure database, they are encrypted using Advanced Encryption Standard with a 256-bit key length (AES-256). AES-256 is the gold standard for cryptographic data protection, utilized by banking institutions and federal agencies worldwide.

Even in the unlikely event of physical server breach or storage media exposure, raw health files remain unreadable ciphertext without the corresponding decryption keys.

USER DEVICE                       EN ROUTE (TRANSIT)                 DATABASE (AT REST)
┌──────────────────────┐          ┌──────────────────────┐          ┌──────────────────────┐
│  Raw Health Entry    │  ───►    │ TLS 1.3 Tunnel       │  ───►    │ AES-256 Encrypted    │
│  & GPS Coordinates   │          │ (Unreadable Stream)  │          │ Storage (Ciphertext) │
└──────────────────────┘          └──────────────────────┘          └──────────────────────┘

2. Hyper-Local Feeds Without Persistent Surveillance

Connecting physical symptoms to environmental metrics like 2.5pm, ground-level ozone (O3), or barometric pressure requires accurate location context. However, fetching environmental data does not mean building a permanent tracking profile of your daily life.

SharedSky uses privacy-focused location routing:

  • On-Demand Location Fetching: The app requests GPS coordinate access primarily when you actively open the app or submit a symptom entry. We do not maintain a continuous real-time movement map of your daily routes.
  • Coarsened Location Queries: When fetching atmospheric data from government stations and satellite networks, your coordinates are rounded to broader regional grid squares. Environmental feeds are fetched for the general area, ensuring atmospheric stations receive geographic queries without pinpointing your exact home address.
  • Granular Device Controls: You retain full authority to grant, restrict, or revoke location permissions at any time within your device operating system.

3. Our Ironclad Commitment: Zero Data Monetization

The core promise of SharedSky is straightforward: We do not sell, rent, lease, or monetize your individual personal health data or location histories to third parties under any circumstances.

Many free mobile applications sustain their operations by building shadow profiles, selling location histories to data brokers, or targeted advertising networks. SharedSky operates on a transparent, subscription-supported model for advanced analytical tools, guaranteeing that our incentives align directly with protecting your privacy.

┌────────────────────────────────────────────────────────────────────────┐
│                        OUR DATA PRIVACY PLEDGE                         │
├────────────────────────────────────────────────────────────────────────┤
│  ✗ NO Data Sales to Advertisers or Marketing Networks                  │
│  ✗ NO Sharing of Individual Logs with Health Insurance Providers       │
│  ✗ NO Brokering of Location Histories or Tracked Routines              │
│  ✓ Full User Ownership, Data Portability, and Right-to-Erasure         │
└────────────────────────────────────────────────────────────────────────┘

Your health symptoms, severity ratings, and medical baseline insights will never be shared with health insurance providers, employers, or ad networks.

4. Protecting Community Insights Through Aggregation and Anonymization

One of SharedSky’s key missions is building privacy-safe community awareness maps. During major atmospheric events—such as wildfire smoke plumes, severe pollen spikes, or urban temperature inversions—aggregated community trends help highlight the human impact of environmental air pollution.

To protect individual identities within community reports, we implement differential privacy and data aggregation protocols:

DIFFERENTIAL PRIVACY
k-Anonymity Thresholds: Individual entries are never displayed publicly or on community trend maps. Symptom reports are aggregated across macro geographic regions (such as an entire zip code or municipal sector). If a specific zone lacks a minimum threshold of logging users, data for that zone is suppressed to prevent re-identification.

IDENTITY DE-COUPLING
Complete Anonymization: All personal identifiers—such as your account email, display name, and IP address—are completely stripped from data points before inclusion in macro research models or urban clean air advocacy charts.

5. Full Ownership: Export or Delete Your Data Anytime

You hold absolute control over your personal data footprint. We believe that true data privacy requires seamless data portability and simple account management:

  • Export Your History: Download your entire symptom history, environmental logs, and baseline trend summaries into structured CSV or PDF files at any time for your personal records or medical consultations.
  • Complete Erasure (Right to be Forgotten): If you choose to delete your account, tapping “Delete Account” in your app settings permanently purges your personal credentials, symptom entries, and location histories from our primary databases and encrypted backups.

Empathetic Technology Built on Uncompromising Trust

Understanding how ambient air impacts human health should not come at the expense of digital privacy. By pairing end-to-end encryption with zero data monetization, SharedSky provides a secure environment for mapping your health triggers.

Have questions about our security infrastructure or data privacy standards? Read our full Privacy Policy page or contact our dedicated privacy team at privacy@sharedsky.app.

Share with