Every consequential decision in your care rests on information: what you have been diagnosed with, what you take, what you have tried, and how your body responded. That information exists. It is just not where you need it, when you need it, in a form you can use.
How we got here
Medical records grew up around institutions. Each hospital, clinic, and health system built its own record for its own purposes: documentation, billing, administration. The patient portal came later, as a small window onto one institution's slice. The result is an arrangement nobody would design on purpose: the story of one body, scattered across many systems, each holding a fragment under its own rules.
People live with the consequences daily. Histories re-told from memory at every new front desk. Results explained by a search engine at midnight because the report arrived without context. Records lost when a clinic closes, a system migrates, or a family moves countries. Errors written once and repeated for years, because downstream care builds on whatever was written upstream. And for the person coordinating a parent's care, all of it multiplied across another person's logins.
None of this is anyone's malice. It is what happens when the record is organized around the places care happens instead of the person it happens to.
The principle
One record per person, held by the person.
Today there is a login for every provider. We believe the center of gravity should move: a single lifelong record that belongs to the patient, that providers, systems, and apps connect to on the patient's terms. Where you are treated changes over a lifetime. That you are treated does not, and the one party present at every visit, in every system, in every country, is you.
This changes where the record lives and who answers for it. Completeness becomes your right, access becomes your decision, and continuity stops depending on any institution's lifespan.
What becomes possible
For one person, the change is practical and immediate. Every visit can start from the full picture instead of a fresh retelling. A result can arrive with explanation and context from your own history. Trends invisible inside any single system become plain across years and providers. Preparing for an appointment becomes reading a summary, and helping a parent stops meaning a drawer of borrowed passwords.
At scale, the implications reach further. Care informed by complete histories stands to mean fewer repeated tests, fewer decisions made on partial information, and fewer errors carried silently from record to record. Second opinions become cheap to seek, because the full history travels in minutes. Moving between cities, systems, and countries stops meaning starting over. And a generation of people gains something they have never had: the ability to actually use their own health data, with tools they choose, for their own benefit.
We are deliberate about the order here. Ametti's job is to make each of these real for one person at a time, starting with the people who need it most: those with complex histories and those caring for someone who has one. The larger change follows from many individual records becoming whole, owned, and useful.
Why trust has to be built in
A record this complete is powerful, which is exactly why it cannot be built casually. Two requirements are structural, and we treat them as product decisions rather than policy promises.
Only you can read it
Your record is encrypted on your device, with keys only you hold. The systems that sync it store data they cannot read. This is a stronger arrangement than a privacy policy, because it does not depend on anyone's continued good behavior: the architecture itself keeps your record yours. And our business is simple on purpose. You pay for Ametti; your data is never sold, shared, or monetized.
Everyone can trust what it says
A record that future doctors rely on must be verifiable. In Ametti, original records are preserved exactly as their authors wrote them, with their source attached. When you add context or correct an error, your note lives alongside the original, clearly yours, clearly dated. Every fact shows how it entered the record: fetched from a provider system, extracted from a document with the original attached, or noted by you. A doctor reading a shared record always knows what came from where.
Looking further ahead, we are designing for corrections that can graduate: a clinician reviews a patient note and confirms it, and the confirmation becomes part of the record's provenance. That step is direction, and we will always be explicit about what is shipped and what is ahead.
Where we start
Grand visions in health tend to fail by starting grand. We start small and concrete: a private vault on your own device, your existing records brought in from papers, files, and portal downloads, organized into one clear timeline you can understand and search. That path works wherever your care happens, and direct portal connections grow region by region from there.
From that foundation, the record grows outward: more sources, richer understanding, sharing, and family care, in that order, each step arriving when it meets the bar the record deserves. Ametti is in early private testing today, and we would rather grow deliberately than promise casually.
If this is the direction you want your health data to go, join the waitlist and be part of the early group shaping it.