OpenRecord is software you run yourself. It signs in to your Epic MyChart patient portal from your own device and reads your records there. Fan Pier Labs does not operate a server that holds your medical records, and there is no OpenRecord account containing a copy of them. Two things do leave your device: the question you send to an AI model, and — on the desktop tools only — anonymous usage data. Both are described in full below.
Who this covers
This policy is from Fan Pier Labs ("we"), and covers the OpenRecord Claude Desktop extension,
the OpenRecord iPhone app, the mychart-cli command-line tool and library, and the
website at openrecord.fanpierlabs.com including its demo.
It does not cover MyChart itself. Your health system and Epic hold your medical record and decide what happens to it; their notice of privacy practices governs that, not this document. It also does not cover the AI provider you choose — see below.
What stays on your device
Everything OpenRecord reads from your portal is stored on the device that read it, and it is the only copy OpenRecord makes:
- Your MyChart username, password, TOTP secret and any passkey you register.
- The session cookies that keep you signed in to your portal.
- Any records, documents or images you download.
On iPhone, credentials are held in the iOS Keychain, restricted to that device and readable
only while it is unlocked. On desktop, the Claude Desktop extension keeps them in
~/.openrecord-mcpb/ and the command-line tool keeps them in the directory you run
it from, in files whose permissions are set to your user account only. Anyone with
administrator access to your computer, or with your unlocked device, can read them — the same
as any other application data on your machine.
Removing an account in the iPhone app's settings, or disconnecting one in the Claude Desktop
extension, deletes that account's stored credentials, passkey and session. The command-line
tool has no disconnect command — delete its .cookie-cache and
.totp-secrets folders yourself.
The exception: AI calls
OpenRecord is built to answer questions about your health record, and no AI model can answer a question about information it has not been given. When you ask one, the parts of your record needed to answer are sent to that model, which runs on a computer belonging to whoever provides it.
This is the moment your health information leaves your device. Which company receives it depends on the client you are using and how you have configured it.
| How you use OpenRecord | Where your prompt goes |
|---|---|
| Claude Desktop extension | Anthropic, through your own Claude account, under Anthropic's terms and privacy policy. Nothing passes through Fan Pier Labs. |
| iPhone app, included free tier | An AI proxy operated by Fan Pier Labs on AWS, which forwards it to Google's Gemini API. |
| iPhone app with your own API key | Straight to the provider whose key you supplied. Nothing passes through Fan Pier Labs. |
| Command-line tool and library | Nowhere by default — it does not call a model. If you build something on top of the library, that is your call to make. |
| Website demo | The same proxy, but with a fictional patient record. The demo never connects to a real portal. |
We have no business associate agreement with Google or any other model provider, and the free tier should not be treated as a HIPAA-compliant channel. If that matters for your situation, use the Claude Desktop extension or supply your own API key, so your data goes to a provider you have your own relationship with.
What our AI proxy records
When the iPhone app's free tier or the website demo calls a model, our proxy sees the request in order to forward it. It writes the following to its logs: the model name, the number of messages, input and output token counts, whether the caller was signed in, and a timestamp. It does not log the contents of your prompt or the model's reply.
Alongside that it keeps:
- A spend ledger — for signed-in users, a running total of the estimated cost of your calls for the current calendar month, stored against the identifier Google issues for your account. This is what enforces the included monthly credit.
- Rate-limiting counters — a short-lived count of requests per source address, and a total request count per ten-minute window, both discarded shortly afterwards.
Google receives the prompt itself and handles it under its own API terms and retention policy.
Signing in with Google
The iPhone app asks you to sign in with Google. We receive your email address and Google's account identifier, and use them for exactly two things: to confirm you are who the app says you are when it calls the AI proxy, and to meter your monthly AI credit. Your Google account is deliberately separate from your MyChart login — signing in to OpenRecord gives us no access to your portal.
The website
The site is static files on Amazon S3 served through Amazon CloudFront. AWS records standard request logs, which include IP addresses. There are no analytics services, advertising networks, or third-party tracking scripts on the site itself. The desktop clients do report anonymous usage, which is the next section.
If you enter your email address in the waitlist form, we store it and use it to tell you when OpenRecord ships. Ask us and we will delete it.
Usage analytics
The command-line tool and the Claude Desktop extension report anonymous usage, so we can see how much OpenRecord is being used and which health systems to look at when logins start failing. The iPhone app reports none of it — that code is replaced with an empty stub in the app's build.
An event is sent when the tool starts, and when a login begins. Each one carries:
- A random identifier created the first time you run it and kept in a cache folder. It is not derived from your name, your account, or anything about your machine.
- The event name, and for login events the hostname of the MyChart portal you are signing in to — which health system, and nothing else. Never your username, your password, or anything from your record.
- Your operating system and its version, the processor architecture, and the Node or Bun version.
These go to Amplitude, a third-party analytics product, and to our own logging endpoint on AWS.
Naming the health system you are a patient of is more than we would want a tool to send about
us without saying so, which is why it is written out here. To send none of it, set
MYCHART_CLI_TELEMETRY_DISABLED=1 in the environment the tool runs in.
The update check
On start, the command-line tool fetches a small file from this site listing the current
version of each thing we publish, so it can tell you when you are running an old one. It
sends no information about you. Like any web request it reveals your IP address to
our CDN, and how often you run the tool — never your username, the health system
you use, or anything from your record. The same
MYCHART_CLI_TELEMETRY_DISABLED=1 turns it off.
What we never do
- We do not sell your personal information, and we do not share it with advertisers or data brokers.
- We do not use your health information to train AI models, and we do not send it anywhere except as described above.
- We do not have a copy of your medical record to hand over, look at, or lose.
Deleting your data
Your records and credentials are on your device, so removing them is in your hands: disconnect the account in the client, or delete the app and its stored data. To have your waitlist email or AI spend ledger deleted, write to us at the address below.
Children
OpenRecord is not directed at children under 13 and we do not knowingly collect their personal information. Adults with proxy access to a child's or another adult's MyChart record can read it through OpenRecord exactly as they can through MyChart, and are responsible for that use.
Not medical advice
OpenRecord and any AI model it talks to can be wrong, can miss things, and can misread a result. Nothing either produces is medical advice or a substitute for your clinician. Do not use it to make a treatment decision on your own.
Changes
If this policy changes in a way that affects what happens to your data, we will update the date at the top and note the change on this page.
Contact
Questions about this policy, or a request to delete something we hold: ryan@fanpierlabs.com.