What Actually Happens When You Share a Result

Every time someone asks whether Protecht is end-to-end encrypted, the honest answer needs two sentences, not one. It depends on how the share happens. We’d rather explain both paths than round up to a word that doesn’t quite fit either of them.

Receipts, not promises means telling you exactly what happens to your data, not the version that sounds best. So here’s what actually happens when you share a result, both ways it can go.

When you’re both in the app, nothing touches our servers

If the person you’re sharing with has Protecht open on their phone, the results travel straight from your device to theirs over a direct connection, encrypted the whole way. Our servers are never part of that path. This is the one case where “end-to-end” is the accurate word, and we use it here on purpose.

When they don’t have the app yet

If you’re sharing with someone who doesn’t have Protecht, we fall back to a link. Your results are encrypted on your phone before anything leaves it, and the key that unlocks them is locked with our public key and sent separately. When the link is opened, the encrypted result passes through our server for a moment as part of loading the page, then the server sends back the key and deletes its copy. None of it is ever written to our database. The whole thing is built to work once: the link’s key is single-use and expires within an hour whether or not anyone opens it.

Why we’re not calling this one “end-to-end”

For a few seconds while that link is open, our server technically holds enough to read the result, the encrypted data and the key that unlocks it, even though it never stores either one and never looks. That distinction is small in practice and real on paper, and “end-to-end encrypted” glosses over it. We’d rather say the precise thing than the reassuring thing. No upload path, no PHI in our database, and a key that expires in an hour either way.

See exactly what’s stored

The full breakdown of both sharing paths, in plain language.

Read how sharing works

We checked the parts you can’t see, too

The claims above are only as good as the infrastructure behind them, so we went back and checked it directly: the request logs and backups that sit underneath the app don’t retain share links either. It’s not a glamorous thing to verify, but it’s the same principle as everything else here. Say what’s actually true, then go check that it still is.

Ready to bring your own?

Download Protecht and share verified status in seconds, not screenshots.

Get Protecht on the App Store

What a Real Result Has That a Screenshot Doesn’t

A live result and a screenshot of one can say the exact same word. “Negative,” the same date, the same provider name. On screen, they’re identical. The difference is entirely in what doesn’t survive the trip from one to the other.

The instinct to go to the source instead of a screenshot is already common. In a January 2025 study of 2,601 gay and bisexual men published in the International Journal of STD & AIDS, 18% had already used a patient portal to show a partner a result live, rising to 30% among men who tested nine or more times a year and 24% among PrEP users. That’s the right instinct, done by hand. Here’s what it’s actually protecting.

Five things a screenshot can’t carry

An authenticated origin. A live result arrived through a login to the provider’s system. A screenshot arrived through a camera roll. Nothing about a JPEG can tell you where it came from, no matter how official it looks.

Structured fields, not pixels. The provider name, the lab, each test, its method, its result, the collection date and the result date are separate data fields attributed to the source in a live result. In a screenshot they’re just shapes on a picture. Any of them can be repainted, and there’s no way to tell which ones were.

Dates set by the lab, not typed by the sender. Collection date and result date come from the provider’s record in a live result. In a screenshot, the date is whatever the sender put there.

No edit path. A result pulled directly from a provider can’t be changed, cropped, or re-saved by the person sharing it. A screenshot is edited in the same app it was taken in.

A view that ends. A provider-sourced share can be read-only and time-limited, attributed to the provider by name, then gone. A screenshot sits on someone else’s phone for as long as they keep it, with no way to take it back.

See the difference for yourself

Protecht pulls results straight from your provider, so nothing has to travel as a picture.

See how verification works

So what do you actually ask for

Not “is this real,” since nobody can answer that by looking at a picture. Ask to see it live instead, in the portal or through an app that pulls it from the provider. That single request does more work than any amount of scrutinizing a photo, because it moves the result out of the one format that can’t prove anything about itself.

Sources

Ready to bring your own?

Download Protecht and share verified status in seconds, not screenshots.

Get Protecht on the App Store

Can You Trust a Partner’s STD Test Result?

Can you trust a partner’s STD test result?

Short answer: only as much as you can trust where it came from. A result you type in yourself, or one shown as a screenshot, tells you what someone wants you to know. A result pulled directly from a provider’s system, or shown to you live in a portal, tells you what the lab actually found. The trust isn’t in the number. It’s in the path the number took to reach you.

Why the same word, “negative,” can mean two different things

A self-reported status and a provider-verified one can read identically on a screen. The difference is entirely in what’s behind them. Self-reported means someone typed it in, the same way a dating profile field works. Provider-verified means it came through an authenticated connection to the lab or clinic that ran the test, with no step where a person could type in something different from what was found. Neither is a lie by default. But only one of them can’t become one.

The one question that actually settles it

Not “do you trust them,” but “can I see where this came from.” A screenshot answers “no,” because a picture carries no record of its own origin. A live view in a patient portal, or a share from an app that pulls the result from a provider, answers “yes,” because the result is still connected to the system that produced it. Ask to see it that way. It’s not an accusation, it’s the same request you’d make of any document that mattered.

People already do this, they just haven’t had the words for it

In a January 2025 study of 2,601 gay and bisexual men published in the International Journal of STD & AIDS, 18% had already used a patient portal to show a partner a result live, rising to 30% among men who tested nine or more times a year and 24% among PrEP users. The instinct to go to the source instead of a screenshot is already common. It just hasn’t been standard.

See the difference for yourself

Protecht pulls results straight from your provider, so there’s no upload step and nothing to edit.

See how verification works

What actually makes a screenshot unreliable

Not that most people send fake ones. Most don’t. It’s that a screenshot carries no way to check, and the ones that are edited are indistinguishable from the ones that aren’t. Any photo-editing tool can change a date, a name, or a result, and there is nothing in the image itself that reveals it. That’s not a reason to assume the worst about someone. It’s a reason to ask for the version that can’t be edited when it matters.

Frequently asked questions

Is a screenshot of a test result ever enough? For a low-stakes, established relationship, plenty of people treat it as enough. For anything where the stakes are higher, ask to see the result live in a portal or through an app that pulls it from the provider directly.

What does “verified” actually mean for a result like this? It means the result reached you through a connection to the system that produced it, not through a document someone could have altered before sending it.

Is asking to verify a result rude? Framed as “can I see it live, and I’ll show you mine too,” it reads as a habit, not a test. Most people say yes.

Sources

Ready to bring your own?

Download Protecht and share verified status in seconds, not screenshots.

Get Protecht on the App Store

Apps That Let You Share STD Test Results, Compared (2026)

Comparison

Apps that let you share STD test results, compared

Most articles about this are from 2014 and describe apps that no longer exist. Here is what is actually available in 2026, compared on the three things that matter: where the result comes from, how long a partner can see it, and what gets stored where.

The three questions to ask any of these

Where does the result come from? There are only three answers. The user typed it in (self-reported). The user uploaded a file (a screenshot or PDF, which is easy to edit). Or the app pulled it from the provider’s system through an authenticated connection (provider-sourced). Only the third one is proof.

How long can a partner see it? A link that lives for a day can be forwarded for a day. A view that lasts a minute can’t.

Where is it stored? A vendor cloud, a clinic’s system, or your own phone. This is your health record. It’s worth knowing who holds a copy.

Side by side

App Where the result comes from How the partner sees it How long Where it’s stored Cost
Protecht (iPhone) Pulled automatically from your provider through Apple Health (Epic, Kaiser, Quest and other connected systems). No upload button. In person, phone to phone. A web viewer works with no app installed. 60 seconds, read-only, then gone Encrypted on your phone. Nothing in a vendor cloud. Free to download and to receive. Sharing HIV status is free. Protecht+ for other conditions.
Zults (UK) You upload a PDF of your result; a human reviews it (features). A shareable link, plus a wallet card Links last 24 hours Zults’ service Free tier; premium £14.99/year (pricing)
IntimID (iPhone) You enter your own status. No verification (App Store listing). A QR code 48 hours On your device See listing
Healthvana Delivered by a clinic that uses Healthvana; you can’t sign up on your own (FAQ). Depends on the clinic’s setup Not a time-limited share Healthvana, on the clinic’s behalf Paid for by the clinic
Grindr health fields Self-reported profile fields and filters (Grindr, Sept 2025). On your profile Until you change it Grindr’s servers Included in the app
Epic Share Everywhere (MyChart) Your real chart, from your Epic provider (FAQ). A one-time code you give to a clinician, who views your record on their end 60 minutes Your provider’s Epic system Free with MyChart
Apple Health sharing Your Health app data, including records from connected providers (Apple). An ongoing feed to a person you choose; both of you need an iPhone Until you stop sharing iCloud, end-to-end encrypted Free

Details are limited to what each company’s own page says as of September 2026. Prices and features change; check the linked pages.

What each one is actually for

Zults: verified by a person, shared by link

Zults is the closest thing to Protecht in intent. You upload a PDF, someone at Zults checks it, and you get a link and a wallet card to show partners. The human review is a real step up from a raw screenshot. The tradeoffs are that it is upload-based (the review is checking a document, not the source), the link is good for 24 hours, and it is built for the UK.

IntimID: a tidy way to say it yourself

IntimID keeps everything on your device and shares a QR code that lasts 48 hours. It is honest about what it is: you enter your own status, and there is no verification. Treat it as a nicer version of telling someone.

Healthvana: great if your clinic uses it

Healthvana delivers results from clinics to patients. The result is real because it came from the clinic. You can’t sign up on your own, and it isn’t designed around a partner-facing, time-limited share.

Grindr health fields: a filter, not a result

Grindr added profile fields and filters for things like testing and PrEP in September 2025. They help people find each other. They are self-reported, so they tell you what someone chose to display, not what a lab found.

Epic Share Everywhere: for your doctor, not your date

If your provider uses Epic, Share Everywhere lets you generate a code so a clinician can see your chart for 60 minutes. It is the real record. It is also your whole record, and it’s designed for a clinician at a desk, not a partner at a bar.

Apple Health sharing: an open door, not a moment

Apple lets you share Health app data with someone on an ongoing basis. It’s built for a caregiver or a family member. Both people need an iPhone, the share stays open until you close it, and it isn’t limited to sexual health results.

Protecht: the provider’s result, for 60 seconds, in person

Protecht pulls your STI and HIV results from your provider through Apple Health, so there is nothing to upload and nothing to edit. You show a partner in person, they see a read-only view for 60 seconds, and then it’s gone. A web viewer means they don’t need the app. Your results are encrypted on your phone and never sit in our cloud. The security page explains the whole path.

Which one should you use?

  • You want to prove a result to a partner: a provider-sourced share (Protecht) or, if you’re in the UK and fine with a document review, Zults.
  • You want to state your status in your dating profile: Grindr’s fields, or IntimID’s QR, knowing neither is verified.
  • You want a clinician to see your chart: Epic Share Everywhere.
  • You want a partner or caregiver to follow your health data over time: Apple Health sharing.

Whichever you pick, the conversation still matters, and so does knowing what a real result looks like.

Questions people ask

Is there an app that verifies STD test results?

Two approaches exist. Zults has a person review a PDF you upload. Protecht skips the upload entirely and pulls the result from your provider through Apple Health, so the result is verified by where it came from rather than by someone checking a document.

Does my partner need the app to see my results?

With Protecht, no. A web viewer shows the 60-second read-only view without an install. With Apple Health sharing, both people need an iPhone. Zults uses a link, and IntimID uses a QR code.

Can I just use MyChart to show a partner my results?

You can open the portal and hand over your phone, and plenty of people do. You’re also handing over your whole record. Epic’s Share Everywhere is built for clinicians, with a 60-minute window, not for a partner.

Are Grindr’s health fields verified?

No. They are profile fields you fill in yourself, plus filters so people can search on them. Useful for finding people who share your approach, not evidence of a result.

Which of these store my results in the cloud?

Zults holds what you upload. Healthvana holds results on the clinic’s behalf. Grindr holds your profile fields. Epic keeps the record in your provider’s system. Apple Health data lives in iCloud with end-to-end encryption. Protecht keeps results encrypted on your phone and doesn’t store them in a vendor cloud.

Is Protecht available on Android?

Not yet. Protecht is iPhone-only today, and an Android version is in development with no release date. A partner on Android can still see your share through the web viewer.

Skip the upload. Show the source.

Results from your provider, on your phone, visible to a partner for 60 seconds. Free to download. Sharing your HIV status is always free.

Get Protecht on the App Store

 

How to Spot a Doctored STI Test Screenshot

Someone sends you a screenshot of a negative test result. It looks real. The font matches, the logo is in the right place, the date lines up. But “looks real” and “is real” are not the same thing, and there is no way to tell the difference by squinting at a photo on your phone.

That is not a reason to assume the worst about anyone. Most people sharing a screenshot are telling the truth. The problem is structural, not personal: a photo of a document was never designed to prove anything. Anyone with a basic photo editor, a PDF form filler, or even a messaging app’s markup tool can change a date, a name, or a result in a few minutes.

The red flags worth noticing

If you are looking at a screenshot, a few things are worth a second look: a font that shifts partway through the document, margins or spacing that do not match the rest of the page, a crop that conveniently cuts off a header or footer, or a file name that does not match the lab or clinic it is supposed to be from. None of these prove anything either way. A genuine result can look slightly off because of how it was screenshotted, and a doctored one can look flawless. That is the real issue: visual inspection was never a reliable test.

Why “trust me” isn’t a system

In a 2026 survey of nearly 7,900 U.S. adults by Testing.com, 45% of people diagnosed with an STI said they had withheld their status from a sexual partner at least once, and 59% of that group also had unprotected sex without saying anything. Most of that is not malice. It is shame, timing, or the assumption that it will not matter. But it means that even well-intentioned self-reporting has a real gap between what people say and what is true.

A screenshot does not close that gap. It just adds a layer that feels more official without actually being verifiable. Asking someone to prove their status with a photo puts the burden on trust and editing software, not on an actual system.

Receipts, not promises

The fix is not asking better questions about a screenshot. It is removing the screenshot from the process entirely. Protecht does not have an upload button, because a result you can upload is a result you can edit. Instead, it connects directly to your healthcare provider through Apple Health and pulls your result straight from the source, read-only, with nothing for anyone to fake and nothing stored on Protecht’s servers beyond the coordination needed to make the share happen.

Sources

Ready to bring your own?

Download Protecht and share verified status in seconds, not screenshots.

Get Protecht on the App Store

Your Results Stay On Your Phone. Not Our Servers.

Here’s a question worth asking about any app that touches your health data: where does it actually live?

For Protecht, the answer is simple: on your device, and nowhere else. When you connect your provider through Apple Health, your verified test results are pulled down and encrypted locally using AES-256, with the key in your iPhone’s Keychain. Protecht doesn’t store your results. There’s no central database of test results to breach, because there isn’t a central database at all.

A deliberate architecture choice

That’s a deliberate architecture choice, not a marketing line. A lot of health apps promise “bank-level security” while still holding a copy of everything you’ve ever told them, sitting on a server, one misconfiguration away from exposure. We didn’t want to make that promise and hope we kept it. We wanted to make it structurally impossible to break.

What happens when you share

When you choose to share a result with someone, that sharing happens directly, through a consent-controlled link, not through us. We coordinate the permission and the timing. Protecht doesn’t store the result.

A guarantee, not a promise

Privacy shouldn’t be something you have to trust a company to protect. It should be something the architecture guarantees.

Ready to bring your own?

Download Protecht and share verified status in seconds, not screenshots.

Get Protecht on the App Store