P
Pillara

Privacy Policy

Last updated: August 2026

1. Who We Are

Pillara Health operates the Pillara medication safety platform at pillara.site. We are committed to protecting the privacy and security of your health information.

This Privacy Policy applies to all users of Pillara and complies with Nigeria's Data Protection Regulation (NDPR) and relevant international data protection standards.

Data Protection Officer: Pillara Health

Email: privacy@pillara.site

2. What Data We Collect

2.1 Account data

  • Email address — used for login, reminders, and system notifications
  • Password — stored only as a bcrypt hash (cost factor 12). We never store or see your actual password.
  • Email verification status and timestamp
  • Account creation date

2.2 Health and medication data

  • Medication names and dosages you enter
  • Known drug allergies you declare
  • Medical conditions you optionally enter (e.g. diabetes, hypertension)
  • Patient profile names (typically first names or initials)
  • Medication reminder schedules you configure

This is your most sensitive data. We treat it accordingly — see Section 5 for security details.

2.3 AI interaction data

  • Questions you ask the AI medication assistant
  • Drug names from your profile (sent as context to AI providers)
  • AI response quality feedback (thumbs up/down)

Your name, email, and account identity are never sent to AI providers. Only drug names and your questions are sent.

2.4 Technical and usage data

  • IP address (used for rate limiting and security)
  • Device type and browser (inferred from User-Agent header)
  • Pages visited and features used (anonymized, via PostHog)
  • Request timestamps
  • Error reports (personal health information scrubbed before transmission to Sentry)

2.5 Audit log data

Every action on patient data is recorded in a tamper-evident audit log including: who performed the action, which profile was accessed, what action was taken, the outcome, and the timestamp. This is a security and compliance requirement, not optional. Audit logs are retained in pseudonymized form even after account deletion.

3. How We Use Your Data

Providing the service: Running drug interaction checks, allergy detection, AI queries, reminders, and profile sharing.

Security: Rate limiting, session management, account lockout, IDOR prevention, and fraud detection.

Communication: Sending medication reminders, verification emails, and important account notices.

Improving accuracy: AI feedback (thumbs up/down) is used to identify where our drug knowledge needs improvement. No personal health data is used for AI training without explicit consent.

Legal compliance: Maintaining audit logs as required by applicable law.

We do not use your health data for advertising. We do not sell your data. We do not use your data to profile you for commercial purposes.

4. Who We Share Data With

Users you authorize

If you share a profile, users you invite can see the medication list and health information on that profile, according to the role you assign them. You control this and can revoke access at any time.

AI providers — Groq and Google Gemini

Your questions to the AI assistant and drug names from your profile are sent to these providers to generate responses. Your name, email address, and account identity are not included. These providers have their own privacy policies and data processing terms.

NeonDB — database infrastructure

Your patient data (medications, allergies, profiles) is stored on NeonDB's PostgreSQL infrastructure, hosted on AWS in the United States. NeonDB handles data with encryption at rest and in transit.

Resend — email delivery

Your email address and the content of reminders and system notifications are sent to Resend for delivery.

Sentry — error monitoring

Technical error reports are sent to Sentry to help us fix bugs. Personal health information (medication names, allergies, medical conditions) is scrubbed from these reports before transmission using a PHI scrubbing layer.

PostHog — usage analytics

Anonymized usage events (e.g. "interaction check run", "reminder set") are sent to PostHog. No personal health data is included in these events. These help us understand which features are useful.

Law enforcement

We will disclose your data to law enforcement or regulatory authorities only when required by applicable law, court order, or when we believe in good faith that disclosure is necessary to protect our legal rights, protect your safety or the safety of others, or prevent fraud.

5. How We Protect Your Data

We have implemented the following security measures:

Password security

Passwords are hashed with bcrypt (cost factor 12) before storage. The original password is never stored or transmitted after the initial set. Password reset tokens are single-use and expire after 30 minutes.

Session management

JWT access tokens expire after 30 minutes. Refresh tokens expire after 7 days. All sessions are validated server-side via Redis on every request — logging out actually invalidates your session, not just deletes a cookie. Sessions are revoked across all devices when you change your password or log out from all devices.

Access control

Every request that accesses patient data verifies that the requesting user has permission for that specific patient's data (IDOR prevention). Role-based access control limits what caregivers and viewers can do. Rate limiting prevents brute force attacks.

Encryption

All data in transit is encrypted via HTTPS/TLS. Data at rest is encrypted by NeonDB (AES-256). Redis session data uses password authentication.

PHI protection in logs

Before any error or event data leaves our servers to monitoring providers, it passes through a PHI scrubbing layer that removes medication names, allergy information, and medical conditions from log entries.

Audit trail

Every create, read, update, or delete operation on patient data is recorded in a tamper-evident audit log with user ID, profile ID, action type, outcome, IP address, and timestamp. This log cannot be deleted by users.

Input security

User input is sanitized before being sent to AI providers (prompt injection defense). AI responses are HTML-stripped before being returned to users (XSS prevention). SQL injection is prevented by using parameterized queries throughout.

6. Data Storage and International Transfer

Your data is stored on servers located in the United States. By creating an account and using Pillara, you consent to this international transfer of your data.

We ensure adequate protection for this transfer by:

  • Using NeonDB, which encrypts data at rest (AES-256) and in transit (TLS)
  • Limiting access to your data to only those systems and personnel that need it
  • Maintaining contractual safeguards with our infrastructure providers

7. Data Retention

Account and health dataRetained until you delete your account, at which point it is permanently deleted
AI conversation historyDeleted automatically after 1 hour (stored in Redis with TTL)
Session tokensAccess tokens expire after 30 minutes; refresh tokens after 7 days
Audit logsRetained indefinitely in pseudonymized form (user UUID only, no personal details after account deletion)
Error reportsRetained for 90 days by Sentry, then automatically deleted
Analytics eventsRetained for up to 1 year by PostHog (anonymized)

8. Your Rights Under NDPR

Under Nigeria's Data Protection Regulation, you have the following rights:

Right to access

You can view all your data at any time from your dashboard. To request a data export, email privacy@pillara.site and we will provide it within 30 days.

Right to deletion (right to erasure)

You can permanently delete your account from Settings → Account → Delete Account. This deletes your user account, all profiles you own, all medications, all reminders, and all notifications. Audit logs are retained in pseudonymized form (the UUID points to no personal data after deletion). This is compliant with NDPR.

Right to correction

You can update your profile, medications, allergies, and account details at any time from the dashboard.

Right to object

You can stop using the service and delete your account at any time. To object to specific processing activities, contact privacy@pillara.site.

Right to data portability

Contact privacy@pillara.site to request your data in a machine-readable format.

To exercise any of these rights, contact us at privacy@pillara.site. We will respond within 30 days.

9. Cookies and Local Storage

Pillara uses browser local storage (not cookies) to store your authentication tokens on your device. These tokens are:

  • Access token — expires after 30 minutes
  • Refresh token — expires after 7 days

These are necessary for the service to function and cannot be disabled without logging you out. We do not use tracking cookies or third-party advertising cookies.

10. Children's Privacy

Pillara is not directed at children under 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, contact us at privacy@pillara.site and we will delete it.

Pillara can be used to manage medication profiles for children under parental supervision, where the parent or guardian creates and controls the account.

11. Medical Disclaimer

⚠️ Important

Pillara is an informational tool only. It does not provide medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional — your doctor or pharmacist — before making any decisions about your medications. Never disregard professional medical advice based on information from Pillara.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by email at least 14 days before the changes take effect and update the date at the top of this page. Continued use of Pillara after changes take effect constitutes acceptance of the updated policy.

13. Contact and Complaints

Privacy questions and data requests: privacy@pillara.site

Security issues: security@pillara.site

General: hello@pillara.site

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Nigeria Data Protection Bureau (NDPB) at ndpb.gov.ng.