Plain-language privacy
Privacy
MyBPStory stores the information needed to keep your blood pressure log private to your account and useful for reports.
Last updated: August 8, 2026
What MyBPStory stores
MyBPStory stores your email address, a protected password hash, account preferences, timezone, and the readings you enter or send from the Android app.
Readings can include blood pressure, heart rate, symptoms, notes, timestamps, source, and a device event id used to avoid duplicate app saves.
The service also keeps limited security, access, and email-delivery records used to prevent abuse and diagnose account problems. These records can include the request time, requested path, response status, IP address or a protected hash derived from it, and basic browser or app request information. An IP address can imply an approximate location, but MyBPStory does not request GPS or precise location. It does not store your email password or authenticator codes.
Public pages keep anonymous daily totals for homepage visits, guide visits, and the two main action buttons. To avoid repeatedly counting the same browser in one day, your browser stores only the date of its last counted visit for each page type. These totals do not include an IP address, account, email, health information, referral source, or browsing history.
How the information is used
Your information is used to sign you in, reset passwords, sync the Android app, show your dashboard, create reports, generate PDFs, prevent duplicate readings, and maintain backups.
The Android app temporarily stores readings on your phone until they sync. Android cloud backup is disabled for MyBPStory account and health data.
MyBPStory does not use your readings to diagnose you, treat you, or replace a clinician.
Sharing
MyBPStory does not sell your personal information. Your GP or clinician does not automatically receive anything from MyBPStory.
You choose when to share a PDF report or show your account to someone else.
Security and retention
Passwords are stored as hashes, not plain text. Website sessions expire after inactivity. The Android app signs out when it closes unless you choose to keep that phone signed in.
Website and Android traffic uses encrypted HTTPS. Access is limited to operating the service, security review, backup, and recovery.
Your readings stay in your account until you remove them. Deleting an account removes its live account and readings immediately. Encrypted recovery copies age out under the backup schedule: up to 60 days on the VPS and up to 365 days in the offsite archive.
Your choices
You can export your readings, delete individual readings, or permanently delete your account and data from the dashboard.
See the MyBPStory account deletion page for the website and Android deletion path.
Questions or account help
For MyBPStory account help, email support@mybpstory.ca.
Do not email urgent symptoms or emergency information. Use your local emergency or clinical care instructions for anything urgent.