Methodology & Data Ethics

How we build community-powered pediatric health intelligence

The rules we hold ourselves to, the math behind our numbers, and the boundaries we will not cross. Written so you can bring it to your district, clinic, or IRB conversation as-is.

Last updated: June 27, 2026

K-anonymity threshold (n ≥ 5)

No bucket smaller than 5 reports is ever surfaced as a count, in any public surface, export, or API response. Below the threshold, the bucket is shown as 'suppressed' so consumers can see what's missing — never the count.

Suppression rules

We suppress whenever k-anonymity would be violated, when geographic resolution would identify a single family, or when an illness category combined with a small school's enrollment would re-identify a child. Free-text and ages are never included in institutional exports.

Retention windows

Identifiable symptom logs are kept for 24 months for parent-facing personal history, then aggregated and the row-level record is purged. Aggregated, suppressed institutional data is retained for up to 5 years for trend continuity.

No-resale pledge

We do not sell personal health information to data brokers, ad networks, insurers, or pharmaceutical marketers. Institutional customers receive aggregated, suppressed data under a contract that forbids re-identification and onward sale.

Confidence over precision

Every surface that shows a signal also shows confidence — based on sample size, recency, and whether participating families are checking in 'all healthy.' We would rather say 'we don't know yet' than print a misleading number.

Methodology in the open

This page is the source of truth and is versioned with the product. Material changes are dated and explained, not silently revised. Bring this document to your data review.

Frequently asked

Where does the data come from?

Parents voluntarily log symptoms their kids had at home and (optionally) attribute them to a school or daycare they follow. Schools that claim their profile can also post health reviews. We do not pull data from EHRs, attendance systems, or insurance claims.

How do you prevent a single family from being identified?

Three layers: k-anonymity (n ≥ 5 before any count is shown), geographic suppression (we don't surface single-ZIP signals below threshold), and free-text exclusion in institutional exports. School-level reports under threshold are aggregated up to the 3-digit ZIP area or suppressed entirely.

What's in the Schools Insights export?

Per-school, per-illness, per-ISO-week counts. No names, no ages, no free text, no household identifiers. Buckets under 5 are returned with the count blanked and a 'suppressed=1' flag so consumers can see the bucket exists without learning the small count.

How long do you keep data?

Identifiable symptom rows: 24 months, then row-level deletion. Aggregated, suppressed institutional data: up to 5 years for trend continuity. Account data: deleted within 30 days of an account deletion request.

Do you sell data?

No. Institutional customers receive aggregated, suppressed data under a written agreement that prohibits re-identification and onward sale or transfer.

How do you handle COPPA?

We do not knowingly collect personal information directly from children under 13. Parents log on behalf of their family. No advertising trackers, no behavioral profiling of minors.

Are reports medically confirmed?

Some are. Parents can mark a report as a confirmed diagnosis when a doctor, urgent care, or test confirmed it, and confirmed reports are labeled as such everywhere and weighted more heavily in alerts and digests. Unconfirmed reports are always labeled as symptoms, never as a diagnosis. Parents choose from a fixed illness taxonomy rather than free text, so 'flu' and 'bad cold' are not conflated.

What location data do you collect?

ZIP code and school level only. No street address, no GPS coordinates, no precise home location. If a parent taps 'use my location,' the coordinates are converted to a ZIP and discarded.

Are reports tied to a parent's identity?

A report is linked to the reporting account so the parent can view and edit their own family history. It is never shown to another parent, school, or partner with identity attached, and all shared views are aggregated with the n ≥ 5 suppression rule applied.

Can I delete my account and data?

Yes, from inside the app, with no email request needed. Identifiable data is deleted within 30 days. Anonymized aggregate counts that can no longer be traced to you may remain in trend history.

What happens when a school has too few reports?

We show 'quiet here' or 'not enough reports yet' rather than a zero that reads like good news, and every signal carries a plain-language confidence level based on sample size and recency. We would rather show nothing than manufacture a trend.

Talk to us

If you're at a district, clinic, health system, public health department, or research group and want to evaluate our data against your own standards, we'll walk you through it.