# I don't want to know my user's email so my app would be able to record de-identified data and not need to be HIPAA compliant

**URL:** <https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237>\
**Category:** Ask for Help\
**Created:** [April 30, 2021, 7:05pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237 "2021-04-30T19:05:08Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kate\_Thomas](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kate_thomas/32/22042_2.png) [@Kate\_Thomas](https://community.glideapps.com/u/Kate_Thomas)\
**Post date:** [April 30, 2021, 7:05pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/1 "2021-04-30T19:05:08Z")

</div>

Is there a way to identify a user with a text field instead of an email? I would like to use user specific columns, and have users sign is with a username and password, but no email address so they aren’t worried about correlating data.

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [April 30, 2021, 7:11pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/2 "2021-04-30T19:11:59Z")

</div>

User email addresses are anonymised by default.

[https://docs.glideapps.com/all/reference/security-and-per-user-data/email-anonymization](https://docs.glideapps.com/all/reference/security-and-per-user-data/email-anonymization)

---

<div class="post-metadata">

**Author:** ![Kate\_Thomas](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kate_thomas/32/22042_2.png) [@Kate\_Thomas](https://community.glideapps.com/u/Kate_Thomas)\
**Post date:** [April 30, 2021, 7:13pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/3 "2021-04-30T19:13:55Z")

</div>

Thank you for answering, I would like to ask a medical question and can’t have any PHI for HIPAA reasons

---

<div class="post-metadata">

**Author:** ![Kate\_Thomas](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kate_thomas/32/22042_2.png) [@Kate\_Thomas](https://community.glideapps.com/u/Kate_Thomas)\
**Post date:** [April 30, 2021, 7:14pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/4 "2021-04-30T19:14:53Z")

</div>

The username would be randomly generated

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [April 30, 2021, 7:19pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/5 "2021-04-30T19:19:30Z")

</div>

If the user email addresses are anonymised, then it is not possible to connect responses to your questions to any individual (unless you’re collecting other identifying information).

Does that not meet your requirement?

---

<div class="post-metadata">

**Author:** ![Kate\_Thomas](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kate_thomas/32/22042_2.png) [@Kate\_Thomas](https://community.glideapps.com/u/Kate_Thomas)\
**Post date:** [April 30, 2021, 7:21pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/6 "2021-04-30T19:21:43Z")

</div>

If you know their email address, then no. I’d have to ask you to sign a BAA in order to use your service (which wouldn’t happen). I understand it won’t be in my records by theory (though it seems like it could slip through).

---

<div class="post-metadata">

**Author:** ![Kate\_Thomas](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kate_thomas/32/22042_2.png) [@Kate\_Thomas](https://community.glideapps.com/u/Kate_Thomas)\
**Post date:** [April 30, 2021, 7:23pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/7 "2021-04-30T19:23:45Z")

</div>

Though I’ve just realized you’ll know their IP address, and could have analytics on them in the background so maybe it’s a moot point.

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [April 30, 2021, 7:27pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/8 "2021-04-30T19:27:11Z")

</div>

Sorry, I’m a bit lost. Who is the “you” that you are referring to?

Once again, if your requirement (as per your original question) is not to know your users email addresses - or have any way to find out - then email anonymisation achieves that goal.

---

<div class="post-metadata">

**Author:** ![david](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/david/32/62831_2.png) [@david](https://community.glideapps.com/u/david)\
**Post date:** [April 30, 2021, 7:28pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/9 "2021-04-30T19:28:23Z")

</div>

> [@Kate\_Thomas](#):
>
> HIPAA

Glide is not HIPAA compliant. Using Glide where HIPAA is a requirement is also prohibited: [User Data Rules and Restrictions | Glide](https://www.glideapps.com/legal/user-data)

---

<div class="post-metadata">

**Author:** ![Kate\_Thomas](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kate_thomas/32/22042_2.png) [@Kate\_Thomas](https://community.glideapps.com/u/Kate_Thomas)\
**Post date:** [April 30, 2021, 7:29pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/10 "2021-04-30T19:29:57Z")

</div>

I was originally asking if I could identify a user with a text field instead of an email, and I wanted to do that so I could use your service without needing HIPAA compliance. But in asking the question I realized that you know their IP address and the data they submit is viewable by you so it wasn’t going to make a difference anyways. You being Glide. Thank you for responding so quickly. Kate

---

<div class="post-metadata">

**Author:** ![Kate\_Thomas](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kate_thomas/32/22042_2.png) [@Kate\_Thomas](https://community.glideapps.com/u/Kate_Thomas)\
**Post date:** [April 30, 2021, 7:31pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/11 "2021-04-30T19:31:10Z")

</div>

Thank you, I didn’t see that!

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [April 30, 2021, 7:34pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/12 "2021-04-30T19:34:05Z")

</div>

> [@Kate\_Thomas](#):
>
> I was originally asking if I could identify a user with a text field instead of an email, and I wanted to do that so I could use your service without needing HIPAA compliance. But in asking the question I realized that you know their IP address and the data they submit is viewable by you so it wasn’t going to make a difference anyways. You being Glide. Thank you for responding so quickly. Kate

Ah, okay. But I’m not Glide - I’m just a user, like you 🙂

---

<div class="post-metadata">

**Author:** ![Kate\_Thomas](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kate_thomas/32/22042_2.png) [@Kate\_Thomas](https://community.glideapps.com/u/Kate_Thomas)\
**Post date:** [April 30, 2021, 7:34pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/13 "2021-04-30T19:34:41Z")

</div>

Thank you even more then! 😀

---

<div class="post-metadata">

**Author:** ![Mark\_Turrell](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/mark_turrell/32/26605_2.png) [@Mark\_Turrell](https://community.glideapps.com/u/Mark_Turrell)\
**Post date:** [April 30, 2021, 11:56pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/14 "2021-04-30T23:56:20Z")

</div>

It is worth noting that these anonymous emails are not aliases. They are just bits of text that do nothing, apart from not being actual email addresses. I realized this when I first started using Glide again … I imagined that users would get sent a message, that it would resolve ‘anonymous-puppy-catfish7@glide.com’ … but no.

---

<div class="post-metadata">

**Author:** ![Eden](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/eden/32/18651_2.png) [@Eden](https://community.glideapps.com/u/Eden)\
**Post date:** [September 12, 2023, 5:54am UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/15 "2023-09-12T05:54:02Z")

</div>

What about using the fetch JSON column to display data?

This does not store it on glide servers, correct? Essentially I’d only be using glide to make the API call on the users end- which is secure.

@Darren_Murphy any thoughts on this?

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [September 12, 2023, 10:40am UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/16 "2023-09-12T10:40:02Z")

</div>

I know nothing about HIPAA, so I’ll stay out of this one 🙂

---

<div class="post-metadata">

**Author:** ![Eden](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/eden/32/18651_2.png) [@Eden](https://community.glideapps.com/u/Eden)\
**Post date:** [September 12, 2023, 4:00pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/17 "2023-09-12T16:00:27Z")

</div>

Fair!

From your experience- does any of the data of the fetch JSON hit the glide servers in any way or does it appear directly on the users device only?

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [September 12, 2023, 4:16pm UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/18 "2023-09-12T16:16:15Z")

</div>

Fetch JSON would still be exposing API keys to the user, but it’s ran locally.

Call API would not expose keys, but you are still running data through glide servers.

---

<div class="post-metadata">

**Author:** ![Eden](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/eden/32/18651_2.png) [@Eden](https://community.glideapps.com/u/Eden)\
**Post date:** [September 16, 2023, 2:36am UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/19 "2023-09-16T02:36:01Z")

</div>

Yes, but if I use the hash256 function in Glide and use an intermediary such as [make.com](http://make.com) I should be totally fine, no?

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [September 16, 2023, 3:13am UTC](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237/20 "2023-09-16T03:13:40Z")

</div>

Hash256 cant be decrypted. It’s a one way encryption, so I’m not sure how you would use it to transfer data in an encrypted way that is hidden from Glide. You could probably use some other form of encryption, but the keys would still be exposed to the end user, so not exactly secure.

[Next page](https://community.glideapps.com/t/i-dont-want-to-know-my-users-email-so-my-app-would-be-able-to-record-de-identified-data-and-not-need-to-be-hipaa-compliant/26237.md?page=2)
