← OpenRecord

Privacy Policy

Last updated 14 August 2026

OpenRecord is software you run yourself. It signs in to your Epic MyChart patient portal from your own device and reads your records there. Fan Pier Labs does not operate a server that holds your medical records, and there is no OpenRecord account containing a copy of them. Two things do leave your device: the question you send to an AI model, and — on the desktop tools only — anonymous usage data. Both are described in full below.

Who this covers

This policy is from Fan Pier Labs ("we"), and covers the OpenRecord Claude Desktop extension, the OpenRecord iPhone app, the mychart-cli command-line tool and library, and the website at openrecord.fanpierlabs.com including its demo.

It does not cover MyChart itself. Your health system and Epic hold your medical record and decide what happens to it; their notice of privacy practices governs that, not this document. It also does not cover the AI provider you choose — see below.

What stays on your device

Everything OpenRecord reads from your portal is stored on the device that read it, and it is the only copy OpenRecord makes:

On iPhone, credentials are held in the iOS Keychain, restricted to that device and readable only while it is unlocked. On desktop, the Claude Desktop extension keeps them in ~/.openrecord-mcpb/ and the command-line tool keeps them in the directory you run it from, in files whose permissions are set to your user account only. Anyone with administrator access to your computer, or with your unlocked device, can read them — the same as any other application data on your machine.

Removing an account in the iPhone app's settings, or disconnecting one in the Claude Desktop extension, deletes that account's stored credentials, passkey and session. The command-line tool has no disconnect command — delete its .cookie-cache and .totp-secrets folders yourself.

The exception: AI calls

OpenRecord is built to answer questions about your health record, and no AI model can answer a question about information it has not been given. When you ask one, the parts of your record needed to answer are sent to that model, which runs on a computer belonging to whoever provides it.

This is the moment your health information leaves your device. Which company receives it depends on the client you are using and how you have configured it.

How you use OpenRecordWhere your prompt goes
Claude Desktop extension Anthropic, through your own Claude account, under Anthropic's terms and privacy policy. Nothing passes through Fan Pier Labs.
iPhone app, included free tier An AI proxy operated by Fan Pier Labs on AWS, which forwards it to Google's Gemini API.
iPhone app with your own API key Straight to the provider whose key you supplied. Nothing passes through Fan Pier Labs.
Command-line tool and library Nowhere by default — it does not call a model. If you build something on top of the library, that is your call to make.
Website demo The same proxy, but with a fictional patient record. The demo never connects to a real portal.

We have no business associate agreement with Google or any other model provider, and the free tier should not be treated as a HIPAA-compliant channel. If that matters for your situation, use the Claude Desktop extension or supply your own API key, so your data goes to a provider you have your own relationship with.

What our AI proxy records

When the iPhone app's free tier or the website demo calls a model, our proxy sees the request in order to forward it. It writes the following to its logs: the model name, the number of messages, input and output token counts, whether the caller was signed in, and a timestamp. It does not log the contents of your prompt or the model's reply.

Alongside that it keeps:

Google receives the prompt itself and handles it under its own API terms and retention policy.

Signing in with Google

The iPhone app asks you to sign in with Google. We receive your email address and Google's account identifier, and use them for exactly two things: to confirm you are who the app says you are when it calls the AI proxy, and to meter your monthly AI credit. Your Google account is deliberately separate from your MyChart login — signing in to OpenRecord gives us no access to your portal.

The website

The site is static files on Amazon S3 served through Amazon CloudFront. AWS records standard request logs, which include IP addresses. There are no analytics services, advertising networks, or third-party tracking scripts on the site itself. The desktop clients do report anonymous usage, which is the next section.

If you enter your email address in the waitlist form, we store it and use it to tell you when OpenRecord ships. Ask us and we will delete it.

Usage analytics

The command-line tool and the Claude Desktop extension report anonymous usage, so we can see how much OpenRecord is being used and which health systems to look at when logins start failing. The iPhone app reports none of it — that code is replaced with an empty stub in the app's build.

An event is sent when the tool starts, and when a login begins. Each one carries:

These go to Amplitude, a third-party analytics product, and to our own logging endpoint on AWS. Naming the health system you are a patient of is more than we would want a tool to send about us without saying so, which is why it is written out here. To send none of it, set MYCHART_CLI_TELEMETRY_DISABLED=1 in the environment the tool runs in.

The update check

On start, the command-line tool fetches a small file from this site listing the current version of each thing we publish, so it can tell you when you are running an old one. It sends no information about you. Like any web request it reveals your IP address to our CDN, and how often you run the tool — never your username, the health system you use, or anything from your record. The same MYCHART_CLI_TELEMETRY_DISABLED=1 turns it off.

What we never do

Deleting your data

Your records and credentials are on your device, so removing them is in your hands: disconnect the account in the client, or delete the app and its stored data. To have your waitlist email or AI spend ledger deleted, write to us at the address below.

Children

OpenRecord is not directed at children under 13 and we do not knowingly collect their personal information. Adults with proxy access to a child's or another adult's MyChart record can read it through OpenRecord exactly as they can through MyChart, and are responsible for that use.

Not medical advice

OpenRecord and any AI model it talks to can be wrong, can miss things, and can misread a result. Nothing either produces is medical advice or a substitute for your clinician. Do not use it to make a treatment decision on your own.

Changes

If this policy changes in a way that affects what happens to your data, we will update the date at the top and note the change on this page.

Contact

Questions about this policy, or a request to delete something we hold: ryan@fanpierlabs.com.