Last updated: August 2026
Pillara Health operates the Pillara medication safety platform at pillara.site. We are committed to protecting the privacy and security of your health information.
This Privacy Policy applies to all users of Pillara and complies with Nigeria's Data Protection Regulation (NDPR) and relevant international data protection standards.
Data Protection Officer: Pillara Health
Email: privacy@pillara.site
2.1 Account data
2.2 Health and medication data
This is your most sensitive data. We treat it accordingly — see Section 5 for security details.
2.3 AI interaction data
Your name, email, and account identity are never sent to AI providers. Only drug names and your questions are sent.
2.4 Technical and usage data
2.5 Audit log data
Every action on patient data is recorded in a tamper-evident audit log including: who performed the action, which profile was accessed, what action was taken, the outcome, and the timestamp. This is a security and compliance requirement, not optional. Audit logs are retained in pseudonymized form even after account deletion.
Providing the service: Running drug interaction checks, allergy detection, AI queries, reminders, and profile sharing.
Security: Rate limiting, session management, account lockout, IDOR prevention, and fraud detection.
Communication: Sending medication reminders, verification emails, and important account notices.
Improving accuracy: AI feedback (thumbs up/down) is used to identify where our drug knowledge needs improvement. No personal health data is used for AI training without explicit consent.
Legal compliance: Maintaining audit logs as required by applicable law.
We do not use your health data for advertising. We do not sell your data. We do not use your data to profile you for commercial purposes.
Users you authorize
If you share a profile, users you invite can see the medication list and health information on that profile, according to the role you assign them. You control this and can revoke access at any time.
AI providers — Groq and Google Gemini
Your questions to the AI assistant and drug names from your profile are sent to these providers to generate responses. Your name, email address, and account identity are not included. These providers have their own privacy policies and data processing terms.
NeonDB — database infrastructure
Your patient data (medications, allergies, profiles) is stored on NeonDB's PostgreSQL infrastructure, hosted on AWS in the United States. NeonDB handles data with encryption at rest and in transit.
Resend — email delivery
Your email address and the content of reminders and system notifications are sent to Resend for delivery.
Sentry — error monitoring
Technical error reports are sent to Sentry to help us fix bugs. Personal health information (medication names, allergies, medical conditions) is scrubbed from these reports before transmission using a PHI scrubbing layer.
PostHog — usage analytics
Anonymized usage events (e.g. "interaction check run", "reminder set") are sent to PostHog. No personal health data is included in these events. These help us understand which features are useful.
Law enforcement
We will disclose your data to law enforcement or regulatory authorities only when required by applicable law, court order, or when we believe in good faith that disclosure is necessary to protect our legal rights, protect your safety or the safety of others, or prevent fraud.
We have implemented the following security measures:
Password security
Passwords are hashed with bcrypt (cost factor 12) before storage. The original password is never stored or transmitted after the initial set. Password reset tokens are single-use and expire after 30 minutes.
Session management
JWT access tokens expire after 30 minutes. Refresh tokens expire after 7 days. All sessions are validated server-side via Redis on every request — logging out actually invalidates your session, not just deletes a cookie. Sessions are revoked across all devices when you change your password or log out from all devices.
Access control
Every request that accesses patient data verifies that the requesting user has permission for that specific patient's data (IDOR prevention). Role-based access control limits what caregivers and viewers can do. Rate limiting prevents brute force attacks.
Encryption
All data in transit is encrypted via HTTPS/TLS. Data at rest is encrypted by NeonDB (AES-256). Redis session data uses password authentication.
PHI protection in logs
Before any error or event data leaves our servers to monitoring providers, it passes through a PHI scrubbing layer that removes medication names, allergy information, and medical conditions from log entries.
Audit trail
Every create, read, update, or delete operation on patient data is recorded in a tamper-evident audit log with user ID, profile ID, action type, outcome, IP address, and timestamp. This log cannot be deleted by users.
Input security
User input is sanitized before being sent to AI providers (prompt injection defense). AI responses are HTML-stripped before being returned to users (XSS prevention). SQL injection is prevented by using parameterized queries throughout.
Your data is stored on servers located in the United States. By creating an account and using Pillara, you consent to this international transfer of your data.
We ensure adequate protection for this transfer by:
Under Nigeria's Data Protection Regulation, you have the following rights:
Right to access
You can view all your data at any time from your dashboard. To request a data export, email privacy@pillara.site and we will provide it within 30 days.
Right to deletion (right to erasure)
You can permanently delete your account from Settings → Account → Delete Account. This deletes your user account, all profiles you own, all medications, all reminders, and all notifications. Audit logs are retained in pseudonymized form (the UUID points to no personal data after deletion). This is compliant with NDPR.
Right to correction
You can update your profile, medications, allergies, and account details at any time from the dashboard.
Right to object
You can stop using the service and delete your account at any time. To object to specific processing activities, contact privacy@pillara.site.
Right to data portability
Contact privacy@pillara.site to request your data in a machine-readable format.
To exercise any of these rights, contact us at privacy@pillara.site. We will respond within 30 days.
Pillara uses browser local storage (not cookies) to store your authentication tokens on your device. These tokens are:
These are necessary for the service to function and cannot be disabled without logging you out. We do not use tracking cookies or third-party advertising cookies.
Pillara is not directed at children under 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, contact us at privacy@pillara.site and we will delete it.
Pillara can be used to manage medication profiles for children under parental supervision, where the parent or guardian creates and controls the account.
⚠️ Important
Pillara is an informational tool only. It does not provide medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional — your doctor or pharmacist — before making any decisions about your medications. Never disregard professional medical advice based on information from Pillara.
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by email at least 14 days before the changes take effect and update the date at the top of this page. Continued use of Pillara after changes take effect constitutes acceptance of the updated policy.
Privacy questions and data requests: privacy@pillara.site
Security issues: security@pillara.site
General: hello@pillara.site
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Nigeria Data Protection Bureau (NDPB) at ndpb.gov.ng.