Ømnimind uses third-party large language and vision models to translate your health information into plain language. Sending your health context to a third-party model is what makes that translation possible. This page explains exactly what we do to keep your identity out of that exchange, and what this protection does and does not guarantee.
What actually happens to your message
- Before your message leaves our server,we scan it — along with the account context we're about to add (your profile, memory, and health record snapshot) — for identifying details: your name, email address, phone number, Social Security number, medical record number, and dates of birth.
- Each identifier we find is replaced with an opaque placeholder — for example
"NAME_1"or"SSN_1"— before that text is sent to the AI model. The mapping from placeholder back to your real value is held only in your server request's memory for the duration of that single request. - The AI model reasons over your health content and the placeholders — never your real identifying details. It never receives your actual name, email, phone number, SSN, or MRN.
- When the model's response streams back, any placeholder it echoes is swapped back to your real value before it reaches your screen. That mapping is discarded once your response finishes — it is never written to a database, log, or file.
What this is
A best-effort, pattern-based pseudonymization layer that meaningfully reduces what a third-party AI model ever sees, applied automatically to every message and to the health context we build into the system prompt behind the scenes.
What this is not
This is notHIPAA Safe Harbor de-identification under 45 CFR §164.514(b), which requires removing 18 specific categories of identifiers and generally cannot be achieved reliably with pattern matching alone. Rare diagnoses, unusual free-text phrasing, or a combination of otherwise-ordinary details can still make a person re-identifiable even after our tokenization runs. We are not claiming "zero knowledge" — our servers can and do decrypt and process your data as part of delivering the product to you, and this page does not represent that we cannot. Treat this feature as raising the bar for what an AI model provider ever sees, not as a legal or regulatory de-identification guarantee.
What we detect today
- Your account name (first, last, and full name)
- Email addresses
- Phone numbers
- Social Security numbers
- Medical record numbers (common formats)
- Dates of birth
This list will grow as we identify additional reliably-detectable identifier patterns. It does not currently cover every possible identifying detail that could appear in free-text health information.
Where this applies
This pseudonymization step runs on text sent by Ømnimind's chat, summaries, visit preparation and debrief, research, onboarding follow-ups, memory extraction, internal response audits, status previews, and typed image-scan notes. It also runs on the health context automatically assembled from your records for those features.
Images are an important exception. We pseudonymize the note typed alongside an image, but we do not alter image pixels before sending the image to the vision model. A photographed document, prescription label, or screenshot can contain a visible name, address, date of birth, record number, barcode, or other identifier. Crop or cover those details before uploading if you do not want the vision model to receive them.
This notice supplements Ømnimind's general privacy policy. When the documents conflict, apply the provision that provides you with greater privacy protection unless applicable law requires otherwise.