ENKIBack to ENKI

Privacy notice

What ENKI collects, why it is used, and where the boundaries are.

This notice describes the current ENKI web service. We do not claim HIPAA, GDPR or another formal certification unless that status is stated separately with supporting details.

Last updated: 10 August 2026Current web service
01

Information you provide

Depending on the feature you use, ENKI may process account details, health information, AI conversation content and feedback.

  • Account: email address, display name, preferred language and timezone
  • Health context: check-ins, blood pressure, weight, water intake, preferences and records you choose to enter
  • Companion: your messages and the context needed to answer them
  • Feedback: category, message, page, reply address and a one-way account reference; your registered email is used as the reply address when the optional field is blank
02

How the information is used

We use information to authenticate accounts, verify email ownership, keep users separated, provide requested health tools, personalize the companion, protect the service, respond to feedback and maintain reliability. Registered accounts cannot submit or view private health information or use the AI companion until their email address is verified. ENKI does not sell personal or health information.

03

Current storage model

Registered accounts and sessions are stored in PostgreSQL. Passwords are stored as salted scrypt hashes; session, email-verification and password-reset tokens are stored only as hashes. Verification links expire after 24 hours, reset links expire after 30 minutes, and both are single-use. Token links use a URL fragment that is removed from the address bar immediately after the login screen reads it, so the token is not sent in the HTTP request target or referrer. When the database is configured, health records, approved companion memories, and AI conversation history are encrypted in user-scoped PostgreSQL rows protected by row-level security. Companion memory is created only after an explicit request and can be deleted from the memory panel. Local demo mode uses temporary memory and may be lost when the service restarts. ENKI is not a medical-record system.

04

AI processing

When you send a companion message, ENKI sends the message, a limited user-scoped recent conversation window and a minimized health snapshot to the configured DeepSeek API so it can generate a response. The snapshot includes preferences, check-ins, the latest saved value for each supported metric and a bounded recent-record window. Earlier AI replies are treated only as conversation context; the newest server health snapshot remains the source of personal recorded facts. The model has no shell, SSH, filesystem, deployment or database-administration tools.

05

De-identified AI response quality metrics

To monitor reliability and safety, ENKI may retain de-identified quality events after a companion reply. These events contain protected HMAC event and day-rotating contributor digests, language, provider and model labels, a fixed latency bucket, fixed indicators for required and completed answer structure and citations, fallback use, safety blocking, provider failure and sensitivity, plus an optional one-time Helpful or Not helpful rating. They do not contain the prompt, answer, account or message ID, health records or values, source URLs, error text or free text. Administrators see only daily groups that reach at least 10 contributors, or 20 for sensitive groups. Events are removed after no more than 180 days; account deletion removes contributions still derivable with the active and previous protected secrets.

06

Optional pseudonymous editorial analytics

This setting is off by default. If you turn it on in Preferences, a local fixed-topic classifier may count the general kidney-health topic of a new companion question so ENKI can prioritize educational guides. The editorial system does not receive or store the message, account ID, conversation ID, health measurements or AI answer. It temporarily stores a topic-bound pseudonymous contribution derived with a protected server secret; each consenting account can contribute at most once per topic in a fixed 14-day window. Administrators never receive contributor hashes and see only topics that reach at least 10 distinct contributors, or 20 for designated sensitive topics. Temporary contribution rows are removed by scheduled retention processing after 14 days. Turning the setting off stops future contributions, and deleting the account removes contribution hashes that can still be derived with the active analytics secret.

07

Cookies and session security

ENKI uses a Secure, HttpOnly, SameSite=Lax session cookie for authentication. A language cookie and a language-suggestion preference may also be stored. Security metadata such as user-agent and IP-derived hashes may be used to protect sessions without storing those raw values in the session table.

08

Service providers and international processing

Information is shared only when needed to operate a feature, such as infrastructure hosting, PostgreSQL, DeepSeek for requested AI responses and an email-delivery provider when feedback delivery is configured. Providers may process information in other jurisdictions under their own terms and safeguards.

09

Retention and controls

Sessions normally expire after 14 days. You can review active sessions, revoke other sessions and reset conversation state from the authenticated interface. Password reset signs out every session. Permanent account deletion is available in Preferences and removes the account, active sessions, health records, approved memories and companion history; limited security logs or recovery backups may remain temporarily according to operational retention.

10

Security and limitations

ENKI uses HTTPS, least-privilege services, user-scoped database policies and server-side credentials. No internet service can guarantee absolute security. Avoid entering information that is not needed for the feature you are using.

11

Changes and questions

We may update this notice as storage, providers or product features change. The date above identifies the current version. Privacy questions can be sent through the Contact route.

Editorial responsibility

Published under the responsibility of the ENKI Health Editorial Team. Corrections and source changes update the page date.