Quietport
An embeddable employee-directed portability and erasure workflow for wellness vendors that authenticates requests, inventories data and retention duties, delivers encrypted exports to the worker, tracks deletion across processors, and issues scoped receipts with exceptions and correction.
The research confirms general data-subject-request specifications, signing primitives, a draft compliance-receipt format, and enterprise privacy workflow vendors. It did not find a wellness-exit product. Two of four referenced interfaces remain unverified and no structural incumbent copying cost is evidenced.
Quietport must not promise that a signed deletion receipt proves all individual data is gone. Vendors may have backups, immutable logs, billing and fraud records, legal holds, clinical or professional records, safety obligations, insurance, litigation, subpoenas, processor copies, and retention required by law or contract. A cryptographic receipt proves only the statements, systems, time, issuer, and scope it names.
The employee controls request and export. Employers must not receive wellness history, request contents, diagnoses, notes, utilization, portability files, or person-level deletion status. If the employer has a legitimate program-governance role, it receives only privacy-reviewed aggregate or contract-level completion metrics. Portability does not guarantee another provider can interpret or accept the data, and architecture cannot prevent lawful court-ordered disclosure of retained records.
Wellness, EAP, and benefits-platform vendors that need an employee-controlled portability and erasure workflow with scoped processor evidence and employer privacy boundaries.
Employer-funded access must coexist with strict worker control and employer blindness.
A live privacy dispute and active standards work create urgency.
Several wellness, reverse-data, vault, and receipt neighbors support the direction.
The vendor buyer, worker-controlled request, live privacy standards, processor chain, scoped receipt, and employer boundary are concrete.
Two interfaces are unverified, no structural moat is shown, deletion cannot be absolute, wellness data is extremely sensitive, and legal retention and portability vary.
Discussion
No comments yet — be the first to weigh in.
