How PANDAS Tracker Protects Your Child's Health Data

Families navigating PANDAS and PANS share some of the most sensitive information imaginable — behavioral health records, psychiatric evaluations, and infection histories for their children. Here is exactly how we protect it.

What does "privacy-first architecture" actually mean?

Privacy-first is an architectural decision made before a single line of code is written. It means data protection is not added as a feature at the end — it is the foundation every feature is built on. PANDAS Tracker collects only the data it needs to provide its service, contains zero advertising SDKs, has no data broker relationships, and its privacy policy is written to restrict data use to service delivery only.

Data encryption in PANDAS Tracker

Secure systems design

All data is stored in Google Firebase (Google Cloud Platform), which holds SOC 2 Type II, ISO 27001, and FedRAMP certifications. SPM Health Tech has a Business Associate Agreement (BAA) with Google Cloud as required for HIPAA-aligned use. All access to health records is logged. Vulnerability management includes automated dependency scanning with critical patches within 72 hours.

Privacy principles — what we will never do with your data

Regulatory alignment: HIPAA, COPPA, and GDPR

HIPAA: BAA with Google Cloud, encrypted storage, role-based access controls, audit logging, incident response procedures, minimum necessary data collection. COPPA: accounts created by adult caregivers only, no direct data collection from children under 13, no advertising targeting children. GDPR: right to access, correct, delete, and export data; 72-hour breach notification standard; data minimization by design.

Frequently Asked Questions

How is PANDAS Tracker's privacy-first architecture different from other health apps?
Most consumer health apps monetize user data through advertising partnerships or data licensing. PANDAS Tracker's architecture is built around a strict "collect only what is needed, share nothing" principle, with no advertising SDKs, no analytics that leak data to third parties, and no data broker relationships.
What encryption does PANDAS Tracker use for data at rest?
All health data is stored in Google Firebase Firestore, which encrypts all data at rest using AES-256 encryption with keys managed by Google Cloud Key Management Service (KMS) with hardware-level security modules.
Is PANDAS Tracker HIPAA compliant?
PANDAS Tracker follows HIPAA-aligned security practices including encrypted data storage, strict access controls, audit logging, and Business Associate Agreements (BAAs) with Google Cloud (Firebase). SPM Health Tech is committed to maintaining and exceeding HIPAA standards as the platform grows.