← health

Privacy Policy

Last updated: 2026-09-09

01

Privacy Policy

health is a private health and performance application. It brings together data from wearables, training platforms and manually entered health results, and turns them into personal trends, baselines and a daily health State. This policy explains which personal data health processes, why, where it is stored, and how you can remove it.

health is not a medical device. It does not provide diagnoses, treatment or medical advice.

02

Data Controller

The party responsible for processing personal data in health is:

[Data Controller Name]
[Address]
[Postal Code, City]
[Country]
[Privacy Contact Email]

Values shown in brackets are placeholders and are maintained in one central configuration file of the application.

03

Data We Process

  • Account data: email address, authentication identifiers, sign-in metadata.
  • Profile data: first name, birth date, sex, height, units, timezone, language, goals.
  • Connected third-party health and fitness data (see sections 4–6).
  • Manually entered weight measurements, including date, time and optional note.
  • Manually entered or uploaded blood test results and their extracted values.
  • Manually entered or uploaded performance and lactate diagnostics.
  • Technical and log data: synchronisation events, import timestamps, error messages, and standard server request data required to operate the service.
04

Connected Services

health only accesses a third-party service after you have explicitly authorised it through that provider's own OAuth consent screen. No data is retrieved before you grant access, and only the permissions health actually needs are requested. You can withdraw the authorisation at any time, in health and in the provider's own account settings.

05

WHOOP Data

If you connect WHOOP, health may process the following data, depending on the permissions you grant:

  • Recovery data
  • Heart rate variability (HRV)
  • Resting heart rate
  • Cycle data (daily physiological data)
  • Strain
  • Sleep data, including sleep stages, efficiency and respiratory rate
  • Workout data
  • Profile data used to identify your WHOOP account
  • Body measurements such as height, weight and maximum heart rate

The permissions requested are: read:recovery, read:cycles, read:sleep, read:workout, read:profile and read:body_measurement. WHOOP remains the source of the data; health stores an imported copy so it can calculate trends and personal baselines over time.

06

Strava Data

If you connect Strava, health may process:

  • Activities such as runs and rides
  • Distance, pace, duration and elevation
  • Heart rate recorded during activities
  • Power data where available
  • Route data where available
  • Historical activity data used for training and performance trends
07

Manual Health Data

Weight entries, blood test results and performance or lactate diagnostics are processed only because you enter or upload them yourself. Uploaded documents and any values extracted from them are treated as health data and are visible only to your own account.

08

Purpose of Processing

  • Personal health and performance visualisation
  • Trend analysis over time
  • Calculation of personal baselines instead of population averages
  • health State calculations
  • Personalised, explainable insights
  • AI-assisted interpretation, where you enable it
  • Operating, securing and troubleshooting the service

Health data is processed on the basis of your explicit consent, which you give by creating an account, connecting a service or entering data, and which you can withdraw at any time.

09

Data Storage

Data is stored in the managed cloud database and storage backing health. Access is restricted per user at the database level, so one account can never read another account's data. Provider access and refresh tokens are stored server-side only and are never sent to the browser or kept in browser storage.

10

AI Processing

Where you use AI-assisted interpretation, the relevant subset of your data may be sent to a model provider to generate an explanation. This happens only for features you actively use. AI output is an interpretation aid, not a medical statement, and the deterministic health State calculation itself does not depend on a model.

11

Data Sharing

health does not sell personal data and does not share it for advertising. Data is disclosed only to the technical service providers required to run the application (hosting, database, authentication, and — where you use those features — the AI provider), and to the third-party services you have connected, for the purpose of retrieving your own data.

12

Data Retention

Data is retained while your account exists, so that long-term trends and baselines remain meaningful. Technical logs are kept for a limited period for operational and security reasons. When you delete data or your account, it is removed from the production database.

13

Security

Traffic is encrypted in transit. Access to your rows is enforced per user at the database level. Provider credentials and webhook secrets exist only in server-side configuration. OAuth flows are protected with a signed, time-limited state value to prevent cross-site request forgery. No online service can be guaranteed to be absolutely secure.

14

Disconnecting Integrations

You can disconnect WHOOP or Strava at any time on the Sources page. Disconnecting removes the stored credentials from health and stops all further data retrieval, and the authorisation is revoked at the provider where technically supported. Disconnecting alone does not delete data that has already been imported — that stays available for your history until you ask for it to be deleted.

15

Deleting Data

You can delete individual entries, such as weight measurements or uploaded documents, in the application. To delete imported provider data or your entire account, contact [Privacy Contact Email]. Deletion requests are carried out without undue delay.

16

User Rights

Subject to applicable law, you have the right to access your data, to have inaccurate data corrected, to have data deleted, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent at any time with effect for the future. You also have the right to lodge a complaint with your competent supervisory authority.

17

Contact

For any privacy question or request, contact [Data Controller Name] at [Privacy Contact Email].

18

Changes to This Policy

This policy may be updated as health evolves or as new data sources are added. The current version is always available at https://your-body-signal.lovable.app/privacy, with the date of the last update shown at the top of this page.