What's different ?
- One app for everything related to personal health.
- Privacy:
- No Ts&Cs that bury commitments to share data (even in "anonymised" form) with any person or organisation
- No ads
- No tracking
- No profiling
- WISH will not ask for access to contacts, messages, email, or photos
- The user is NOT the product
-
Patients will be in control:
- Patients decide with whom to share their data
- Sharing will be revokable at any time
- A full log of who has accessed data their data, when and from where, will be available to users
-
Public standards:
- Open API: anyone will be able to adapt their equipment and systems to be compatible.
-
Encryption:
- Cloud based sharing will use copies (and usually subsets) of patient data encrypted with the authorised reader's public key; these copies will be deleted if access is revoked or after a specified timespan
- WISH will not be able to read the data that is stored on the cloud: in the event that WISH's cloud infrastructure is compromised, the bad guys could theoretically steal encrypted copies of user data, but they will not have access to the encryption keys (which are in the hands of the patients) and so will not be able to read it.
-
Hosting
- Initially WISH will host cloud data in data centres in Switzerland. Swiss data protection laws are stronger than most other jurisdictions. If compelled by a court of law to hand over a patient's data, we would be obliged to do so, but the data would never-the-less remain unreadable without a key (which would not be in our possession).