Information you provide
Depending on the feature you use, ENKI may process account details, health information, AI conversation content and feedback.
- Account: email address, display name, preferred language and timezone
- Health context: check-ins, blood pressure, weight, water intake, preferences and records you choose to enter
- Companion: your messages and the context needed to answer them
- Feedback: category, message, page, reply address and a one-way account reference; your registered email is used as the reply address when the optional field is blank
How the information is used
We use information to authenticate accounts, keep users separated, provide requested health tools, personalize the companion, protect the service, respond to feedback and maintain reliability. ENKI does not sell personal or health information.
Current storage model
Registered accounts and sessions are stored in PostgreSQL. Passwords are stored as salted scrypt hashes and session tokens are stored as hashes. The current prototype keeps health-tool state and AI conversation history in user-scoped server memory; it can be reset and may be lost when the service restarts. It is not yet a permanent medical-record system.
AI processing
When you send a companion message, ENKI sends the message, limited recent conversation history and a minimized health snapshot to the configured DeepSeek API so it can generate a response. The snapshot currently includes preferences, check-ins and up to 12 recent records. The model has no shell, SSH, filesystem, deployment or database-administration tools.
Cookies and session security
ENKI uses a Secure, HttpOnly, SameSite=Lax session cookie for authentication. A language cookie and a language-suggestion preference may also be stored. Security metadata such as user-agent and IP-derived hashes may be used to protect sessions without storing those raw values in the session table.
Service providers and international processing
Information is shared only when needed to operate a feature, such as infrastructure hosting, PostgreSQL, DeepSeek for requested AI responses and an email-delivery provider when feedback delivery is configured. Providers may process information in other jurisdictions under their own terms and safeguards.
Retention and controls
Sessions normally expire after 14 days and can be revoked by signing out. Conversation state can be reset from the companion interface. Account, correction, export or deletion requests can be started through the authenticated feedback route. Some operational logs or backups may persist for limited security and recovery needs.
Security and limitations
ENKI uses HTTPS, least-privilege services, user-scoped database policies and server-side credentials. No internet service can guarantee absolute security. Avoid entering information that is not needed for the feature you are using.
Changes and questions
We may update this notice as storage, providers or product features change. The date above identifies the current version. Privacy questions can be sent through the Contact route.
Published under the responsibility of the ENKI Health Editorial Team. Corrections and source changes update the page date.