Patient privacy and your data
Last updated 18 August 2026
Who this covers
Tessera is a web application run by HealthSyncX for clinicians and researchers who record clinical research cases. This page explains what the service stores about patients and about you, and what you can do with it.
Patients: de-identified by design
Case records hold no patient name, date of birth, address or medical record number — only a study ID you choose and the age at the time of the study. Fields that could hold an identifier carry an amber tag, and anything that looks like an identifier is stopped or flagged when you save.
If you choose to keep a re-contact detail for a patient, it is stored apart from the case, can be seen only by you, and every read of it is written to an access log you can review.
The research assistant answers from aggregate numbers computed inside the database; the AI model never receives a patient's raw record, and groups smaller than five patients are hidden.
You: what we hold about your account
Your e-mail address, your name and profession as you entered them, your country, your language, your plan, and the dates you signed in. Payments are handled by Stripe; Tessera never sees your card number.
Your cases are visible only to you. Sharing a case with a colleague is read-only, shows only that case, and can be withdrawn by you at any time.
Where the data lives
Tessera runs on Vercel and stores data in a PostgreSQL database hosted by Supabase, with row-level access control so that every query is limited to the signed-in doctor. Connections are encrypted in transit.
Your rights and your controls
Export your cases at any time as a spreadsheet, as OMOP tables or as a FHIR bundle, from the Cases page. Turn on two-step sign-in, change your details, or delete your account — and every case with it — from Settings. Deletion is immediate and cannot be undone.
Questions about privacy, or a request we can act on for you: write to the support address at the foot of this page.