Legal
Privacy Policy
Effective 2026-09-24. Voyage is operated by Sherlock Health, Inc.. This policy says what we collect, why, who sees it, how long we keep it, and how to ask us to delete it.
Who we are
Sherlock Health, Inc. (“Sherlock Health,” “we”) operates Voyage at trueknee.com/voyage and also operates OpenDoc. You sign in with a TrueKnee account: the TrueKnee website holds your verified mobile number, display name and roles and passes them to Voyage under a signed request each time you open it, so Voyage can show you your own record. This policy covers trueknee.com/voyage and the text messages and emails it sends. OpenDoc has its own policy, which applies when you are on OpenDoc. Voyage is operated independently of any surgical practice.
Write to us at privacy@sherlockhealth.ai. That mailbox is monitored, and it is the one place every request about your information goes.
What we collect
Before you sign in. The Fit Score and the Readiness Score run in your browser and on our servers without a record. Nothing you answer is kept unless you sign in, with three exceptions: an X-ray, blood-panel or EKG upload you make anonymously is stored under a case reference for 30 days and then deleted; a request to share a report with a provider is stored so the request can be fulfilled; and a request for a surgeon’s opinion or surgery made from a surgeon’s page before you sign in is stored with the contact details you typed, and sent to OpenDoc as described below.
Your record, once you sign in. Your phone number or email address; your name, date of birth, sex and ZIP code when you provide them; your Medicare status; your answers; files you upload (X-rays, imaging reports, laboratory results, EKGs, clearance letters); your medications and medical history; your home support arrangements; your chosen surgeon and surgery date; daily check-ins and outcome questionnaires; and consents and authorizations, each with the version of the wording you agreed to. Nothing is entered on your behalf: a clinician you authorize reads your record and writes their own notes, reviews and opinions on it, and does not message you through Voyage.
Physician accounts. A physician’s name, email, NPI, practice, the cell phone number they verified and the status of their identity verification, the registry account identifier they choose to enter, and the clinical notes, reviews and opinions they write on cases patients have authorized.
Surgeon records. The public surgeon record pages are compiled from public sources about physicians (Medicare claims, the AAHKS member directory, and pages that state a physician’s training). They are described under Surgeon record pages below.
Technical. Our hosting provider records the network address and request details of every visit for security and reliability. We keep a per-address rate limit for a short period, as a hash rather than an address. We count how many people reach each step of the preparation guide, by day, with no identity attached. If you arrive from a partner practice’s website that has turned on visit measurement, that site sends us which sections of its own pages you read and for how long, under a random visit identifier it assigns; the identifier is joined to your record only once you sign in here, so the practice can see that visits like yours led to a record, never which record. Those visits are deleted after 90 days. We run no advertising pixels, session-replay tools or third-party analytics on trueknee.com/voyage.
How we use it
Guide coordination (added September 25, 2026). My Voyage saves your preferred name, communication method, availability, language, personal goal and practical requests. When you enable Guide sharing and request a connection, your assigned Guide and their registered backup can see these details and write practical updates. This permission does not open your clinical record or enroll you in research. You can turn Guide sharing off in My Voyage; withdrawing the connection also stops access. Withdrawal stops future access but does not erase earlier records or information already received. Verified practice contacts are shown to you only when sharing is authorized. Guide access and contact changes are logged. These coordination records are removed with an approved deletion of your patient record; the existing security and legally required retention exceptions still apply.
Optional replacement research (added September 12, 2026). My replacements keeps separate records for joints, sides, and operations, including patient-reported procedure details, health factors, and dated follow-up. Research sharing is off until you opt in for that replacement. With that separate permission, authorized Voyage researchers can review the record and the documents and questionnaires you explicitly link to it. Restricted research exports use coded identifiers and omit names, contact details, exact dates, documents, and free text; coded data are not anonymous. Turning sharing off excludes that replacement from future exports while keeping your personal record. Prior exports and completed analyses cannot be recalled automatically. This does not authorize outside records retrieval or publication of individual records. Read the collection methods.
- To provide the service: your scores, your record, your preparation pathway, your recovery check-ins, and the reports you generate.
- To text or email you, as described under Text messages below.
- To give a clinician access to your record when, and only when, you authorize that clinician by name.
- To build the de-identified preoperative registry, only from records whose owner has turned research consent on, and only as counts, never free text or dates. The registry report is shown to every physician whose identity we have verified; any count below eleven patients is withheld.
- To validate our own scores against outcomes, as our operating data, under the plan published at /methodology. That analysis carries no name or contact detail.
- To keep the service secure, to enforce our terms, and to meet legal obligations.
We do not sell personal information, and we do not share it for targeted advertising.
Who we share it with
Clinicians you authorize. Nothing in your record reaches a clinician unless you authorize that clinician by name. Each authorization is recorded with the version of its wording and the date, and you can revoke it from your record. A clinician who has already signed a note, review or opinion keeps a copy of what they signed.
OpenDoc. When you ask for a surgeon’s written opinion or a surgery request, we send OpenDoc your phone number, your state, the dates you gave as available, the surgeon’s name and NPI, and which of the two you asked for, under a versioned authorization you see and accept first. That request is itself a fact about your health, which is why it needs your authorization. Your scores, your answers, your joint, your diagnosis and your date of birth do not go with it. When a page lists what a surgeon offers through OpenDoc, we tell OpenDoc your state and whether you said you are on Medicare, and nothing else. OpenDoc collects the payment and handles the surgeon’s side under its own terms and policy.
Planning programs. Some surgeons’ pages link to a planning technology’s own request form on that vendor’s site. Following the link is your choice, and Voyage sends the vendor nothing; what you type there is governed by the vendor’s policy.
Service providers. Cloudflare hosts the site, its database and its file storage. Telnyx delivers our text messages and, where a practice turns on the TrueKnee phone line, its calls. Resend delivers our emails. Stripe processes optional program payments on its own hosted checkout page; Stripe receives a case reference and the amount, never your name, phone, answers or record. Spruce Health, where a practice connects its Spruce inbox, supplies the practice’s messages with you so they appear in your communication history. Each acts on our instructions under a written agreement that binds it to protect the information.
Automated drafting. If you turn on AI drafting for your Guide, the practical details of a coordination task (its title, status, due date and the Guide’s note) are sent to OpenAI to draft an update that a person reviews before it is sent to you. The request is not stored by OpenAI for training or retention. Your answers, scores, images, record and contact details are not sent. You can turn this off at any time and it is off unless you turn it on.
On-device image analysis. The X-ray severity estimate runs inside your own browser. The image is not sent to any other company for that estimate; only the estimate and the crop are saved with your record, labelled as not clinician-reviewed.
Registries. A surgeon you have authorized may submit your case to the American Joint Replacement Registry from their own registry account, using the identifying details the registry requires. That submission is the surgeon’s, under their own obligations.
Legal. We disclose information when the law requires it, to protect the safety of a person, or to enforce our terms.
A consumer health app, and HIPAA
Voyage is a consumer health app. The information in your record is entered by you, belongs to you, and is not a medical record. HIPAA governs health care providers and the companies that work for them; Voyage is neither, so your information here is protected instead by this policy, by the Federal Trade Commission’s Health Breach Notification Rule, and by state consumer health data laws where they apply.
When you authorize a clinician to read your record, or buy a written opinion from a surgeon, what that clinician receives and writes is theirs to hold under their own professional and legal obligations, including HIPAA where it applies to them; their own Notice of Privacy Practices governs what they do with it. We hold your information to the same standard either way: encrypted in transit and at rest, reachable only through your sign-in, shared only on your authorization, and every clinician read written to an access log.
Text messages
Signing in with a phone number gives us that number, and we use it for one-time sign-in codes and for the notifications your record generates: preparation reminders before a surgery date, a daily recovery check-in for two weeks after surgery and weekly to ninety days, and outcome questionnaires at their windows. At most one scheduled notification a day, plus a text when a surgeon signs a written opinion you asked for. No text contains health information; each says something is waiting and links to a page that asks you to sign in.
The one exception is a medication reminder that names the medication, which we send only if you have separately consented to it, having read that text messages are not encrypted. You can withdraw that consent at any time from your record.
Reply STOP to any message to stop all texts from Voyage, including sign-in codes; reply START to resume; reply HELP for help. Message and data rates may apply. Your carrier is not responsible for delayed or undelivered messages.
Cookies and storage on your device
We set one cookie for everyone who signs in, which holds your signed-in session. It is not readable by scripts and is not shared with anyone. If you arrive from a partner practice’s website, two more cookies hold, for 30 days, which practice sent you and the random visit identifier described under Technical above. If you arrive through Your Joint Options, a separate source cookie lasts up to 30 days and contains only the source flag, with no visitor identifier or health answers. After sign-in and acceptance of the record agreement, we associate that source with your account and count assessment starts and saved Fit Scores in a restricted aggregate referral report. We honor Do Not Track and Global Privacy Control for this attribution. We set no advertising cookies.
While you take the Fit Score or the Readiness Score, your answers are kept in your own browser’s storage for 24 hours so that closing the tab does not lose them, and are cleared when you finish or sign out. A caregiver’s or driver’s name and phone, and anything you type in your own words, are kept only for the open tab and disappear when it closes. On a shared device, anyone using that browser within the day could open the questionnaire answers, and after sign-in we ask you to confirm that saved answers are yours before adding them to your record. A report you build for a provider is held in the tab only until it is delivered.
Education pages show a video from YouTube only after you press play; until then nothing is requested from YouTube. Playing one is subject to Google’s policy.
Security
Connections are encrypted, and stored data is encrypted at rest by our hosting provider. There are no passwords to leak: sign-in is a one-time code sent to your phone or email. A clinician sees your record only by your named authorization, only after we have verified their identity, and every clinician read of a case or a file is written to an access log. Uploaded files are served only through an authenticated request; they have no public address. No security is perfect; if we learn of a breach affecting your information we will notify you and the authorities the law requires, within the time it requires.
How long we keep it
- Your record, including everything you uploaded: for as long as it is active, and until you ask us to delete it. Deletion removes the record, its files and every note, review and opinion written on it, in one action; the clinician who signed a note keeps their own copy under their own obligations.
- Anonymous imaging uploads: 30 days, then deleted automatically, files and all.
- A request to share a report with a provider, or a request for a surgeon’s opinion or surgery made before you sign in: until it is fulfilled, and until you ask us to delete it.
- The access log, the record of your STOP, and security records: kept after deletion, because they hold identifiers rather than your information and exist to answer questions about who read what and who asked not to be texted.
- Sign-in codes: ten minutes. The record of a texted one-tap link: 30 days after the link expires. Rate-limit records: two days. Partner-website visits: 90 days.
Your choices and rights
- See and export. Your record shows everything it holds and where each piece came from, and your Joint Report exports it as a PDF or JSON at any time.
- Correct. Every field in your record is yours to change.
- Withdraw. Each authorization and consent can be withdrawn from your record, and the withdrawal is recorded.
- Delete. Write to privacy@sherlockhealth.ai from the email or phone your record uses, or tell us which it is so we can verify you. We will delete your record within 30 days and confirm, keeping only the access log, the record of a STOP you sent, and anything the law requires us to keep, which we will tell you.
- Ask. You may ask what we hold about you and how it has been shared, and we will answer within 30 days.
Residents of California, Washington, and other states with consumer privacy or consumer health data laws have the rights those laws give, including the right to know, to delete, to withdraw consent, and not to be treated differently for exercising them. If we decline a request we will say why, and you may appeal by replying to our answer. An authorized agent may act for you with your written permission. We will not discriminate against you for exercising any right.
Children
Voyage is for adults. It is not directed to anyone under 18, and we do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it.
Surgeon record pages
The pages at /surgeons are compiled from public sources about physicians, and each fact names its source and the date it was read. They are documented records, not ratings or recommendations. A physician may correct their own page after we verify their identity, or ask for it to come down. Anyone may report an error from the page itself or by writing to privacy@sherlockhealth.ai; a person reads every report and checks it against a source before the page changes.
Changes
When this policy changes, the effective date at the top moves and the change is recorded in the site’s changelog. A change that affects how your information is used will be shown to you in your record before it applies to you. Consents you have already given keep the wording you agreed to.
Contact
Sherlock Health, Inc., at privacy@sherlockhealth.ai. The terms of service, governed by the law of Delaware, set out the rest of the agreement between us.
Effective 2026-09-24.