Account & data deletion
How to request deletion of your VynMed (Android app) account, or specific data within it.
Delete your entire account
To request deletion of your VynMed account, send an email to [email protected] with the subject line:
Account Deletion Request
Include in the body:
- The email address associated with your VynMed account
- A short statement that you are requesting deletion (e.g., "Please delete my VynMed account and associated profile data.")
We confirm receipt within 2 business days and complete the deletion within 14 business days of confirmation.
Delete specific data without deleting your account
If you only want to remove certain information (e.g., your saved name or phone number) but keep your sign-in credentials active, you have two options:
- In-app: open the VynMed app, go to Profile, clear the relevant fields, tap Save profile. Local profile changes propagate immediately.
- By email: send a request to [email protected] with subject
Partial Data Deletion Request, listing which fields or data types you want removed. We respond within 2 business days.
What gets deleted
When you delete your account, the following are removed:
- Your Cognito sign-in record (email + authentication credentials)
- Profile fields you set (name, phone, role display)
- Local mobile-app data (cached profile, preferences, biometric-enable flag)
- Active session tokens (you are signed out everywhere)
What is retained, and why
VynMed Inc. is built to operate as a HIPAA Business Associate and signs a Business Associate Agreement with each skilled-nursing facility before handling its data. Certain records are retained for compliance and legal-defensibility reasons even after account deletion:
- Captured test images (the controlled-lighting photograph of each test cassette, taken as evidence that the test was performed) are retained for 7 years from capture in tamper-evident, write-once storage (S3 Object Lock COMPLIANCE). VynMed never asks for or records patient names or dates of birth, so an image is not filed under a person's name.
- Test session metadata (session id, test type, device id, facility id, timestamp, capture status, and the evidence hash) is retained for 7 years in the same storage, as required for healthcare audit trails. Your facility may choose to attach its own reference to a session, such as an accession, chart number or MRN; where it does, that value is encrypted with your facility's own key before it is stored, so VynMed cannot read it.
- Audit log entries (which user took which administrative action) are retained for 7 years in the same tamper-evident store, also for HIPAA chain-of-custody compliance.
- Billing records (subscription history, invoice metadata) are retained for 7 years per IRS requirements for business records.
These retained records are encrypted at rest with KMS-managed keys, and are accessible only to authorized VynMed staff for legal, regulatory, or audit-response purposes.
Why the retained records cannot be deleted early
Images, session metadata and audit entries are written under S3 Object Lock in COMPLIANCE mode with a seven-year retention period that starts when the record is written. In that mode no one can delete a record or shorten its retention before it expires, including VynMed staff and including the owner of the underlying AWS account. This is deliberate: a record of a test that the Company could quietly delete or alter would not serve as evidence that the test happened.
So the honest answer to a deletion request has two halves:
- What we can do. Delete your sign-in record and profile fields, sign you out everywhere, and stop any further collection about you. A facility ending its contract also has its access revoked and its directory records purged on written request.
- What we cannot do. Destroy images, session metadata or audit entries already written to write-once storage before their seven-year retention expires. Once it expires, those records are deleted.
VynMed's Business Associate Agreement states this at section 7.3, relying on the exception at 45 CFR 164.504(e)(2)(ii)(J) for protected health information whose return or destruction is not feasible. The protections of that agreement continue to apply to the retained records for the rest of the retention period. Section 5 of the Privacy Policy says the same thing in full.
Response timeline
- Account deletion request: 2 business days to confirm, 14 business days to complete.
- Partial data deletion request: 2 business days to respond.
- Verification: we may ask you to confirm your request from the email address on file before proceeding, to prevent unauthorized deletions.
Contact
Questions about deletion or what data is retained:
- Email: [email protected]
- Phone: (702) 900-8503
- Mail: VynMed Inc., Wilmington, DE
Last updated: 2026-08-12