Privacy, explained.
Control, made clearer.
Understand what happens to your vaccination records, who processes them and how to ask for help. Clear information before you upload.
Private record access
Records are reached through a private check link with ownership and expiry checks. They are excluded from the public directory, sitemap and AI-discovery pages. Protect the link like a password.
Used for your check
Your records support the check you request. VacciFly does not sell vaccination records or use them for targeted advertising. The website has no advertising trackers.
Deleted after download
After your browser receives the PDF, your check closes and its records, extracted data and report are automatically deleted from active VacciFly storage. Save your copy securely. Payment records and separately submitted feedback remain separate.
The journey your data takes
Your vaccination records are processed by our servers and configured AI providers to prepare the report. Temporary storage supports processing and delivery; completed downloads trigger automatic cleanup.
- 01 · You choose
Add the correct traveler and relevant records, with authority to process them.
- 02 · Providers read
Our AI processing services read and cross-check document evidence.
- 03 · You review
Compare extracted details with the originals. Uncertainty stays visible before assessment.
- 04 · You keep control
Save your PDF securely. Your completed check closes and its records enter automatic deletion. Interrupted transfers have a recovery window; see the privacy notice for details and provider retention.
Encryption and secure hosting
- Hosted startup checks require database settings that enforce encryption and certificate verification. The live database and network still need deployment verification.
- Private file storage supports the hosting provider's encryption policy or customer-managed AWS KMS keys. Conflicting encryption settings are rejected.
- Hosting can use temporary AWS role credentials. The application does not require long-lived storage keys to be saved in its code.
- Hosted report delivery requires an encrypted, certificate-verified connection to the email provider. This does not encrypt copies after a recipient downloads or forwards them.
- AI extraction requests disable optional response storage and document debug logging. Provider abuse monitoring, caching and account-level retention remain separate.
Use the HTTPS website for encrypted transport between your browser and the service. The production environment also needs verified database, file, object-storage and backup encryption, restricted access and protected keys. These hosting controls must be checked in the deployed environment.
AI providers need readable document content to extract the record. This workflow is therefore not end-to-end encrypted from those processors. Encryption helps protect information; it does not remove provider-processing or retention obligations.
For healthcare organisations
VacciFly supports privacy principles including limited access, transparency and data minimisation. HIPAA and GDPR obligations depend on the organisation, purpose, provider agreements and live configuration. The service does not claim HIPAA certification or blanket GDPR compliance.
Before submitting patient information subject to HIPAA or another organisational restriction, confirm the necessary agreements, permitted providers, processing locations and safeguards with your organisation and VacciFly. Contact info@vaccifly.com.
Small habits that protect your records
- Upload only the relevant traveler's documents and keep family records separate.
- Keep private links out of public posts, shared devices and online chatbots.
- Store downloaded reports securely and share them only with your intended recipient.
- Report a lost link, suspected disclosure or privacy concern to support@vaccifly.com. Leave medical attachments out of the first message.
