Privacy
Privacy Policy
Last updated 26 July 2026
HEALTHINGS.AI is local-first: your health data stays on your phone. Nothing reaches our server unless you choose it — by sharing with a linked clinic, or by turning on cloud backup — and you can end either at any time. You are always in control.
Summary
Healthings is an alpha wellness app — a personal metabolic coach for meals, glucose, and progress. It is not a medical device and does not diagnose or treat conditions. Do not use it for emergency medical decisions. Your health data stays on your device by default. It reaches our server only through choices you make: approving a clinic and sharing with it, or turning on cloud backup. Neither is on unless you switch it on, and you can end either at any time.
What stays on your device
By default, all of the following live only on your phone:
- CGM / blood glucose readings (from Health Connect or Apple Health, when you grant permission)
- Steps, workouts, heart rate, and active calories
- Meals, macros, and food log, including any meal photos you take
- Lab results and nutritionist directives you import
- Personal rules, targets, and coach preferences
- Weight and body composition synced from Withings
There are exactly two ways this data reaches our server, and you start both of them: clinic sharing and cloud backup. Neither is on by default, and you can end either one at any time. Everything else — exporting a backup to a file, importing a PDF, taking a meal photo — happens on the phone.
Your Withings login tokens are held in your phone's secure keystore and are never uploaded, even when you share or back up. The weight and activity values synced from Withings are ordinary health data and travel with the rest.
Optional clinic sharing (your choice)
Sharing with a clinic is entirely optional. Nothing is uploaded until you approve a clinic in Data sharing and tap Share (or respond to a refresh request while the app is open after you have already approved that clinic). You are always in control: you choose who to link, when to share, and you can revoke access at any time.
While a link is approved and you have shared, a copy of your current snapshot is stored on our server for that clinic to read — only the latest one, replaced each time you share, and never a permanent medical record. That snapshot carries meals, glucose, labs, body metrics, targets, rules and directives. Conversations with the AI coach are not included — they stay on your phone (and in your optional cloud backup) and are never shared with a clinic. Revoking removes that clinic's access immediately, and when your last clinic link ends we delete the snapshot along with the clinic's workspace data and rule history. The app works fully without any clinic link.
Clinic chat and rule suggestions (when enabled) apply only while you keep a clinic linked. They are workspace aids for your care team — not a copy of your full history on our servers.
Optional clinic sharing may be unavailable in your region if required by law or regulator guidance. The wellness app on your phone continues to work without clinic sharing.
We do not accept patient health exports by email. Do not send lab PDFs, glucose logs, or other health data to support@healthings.ai — use clinic sharing in the app instead.
Optional cloud backup (your choice)
Cloud backup is off unless you turn it on. When you do, the app uploads a copy of your app data so you can restore it on a new phone. We keep the current backup and the one before it, so a bad overwrite does not cost you your history. Once it is on, the app refreshes that copy in the background — that is the point of a backup — so treat turning it on as ongoing consent rather than a one-time upload.
Turning cloud backup off deletes both copies from our server. Your clinic snapshot, if you have one, is separate and unaffected — and the reverse is also true.
What we collect on our server
Always, because the account cannot work without it:
- Email address — for sign-in with a one-time code (no password)
- Sign-in records — hashed one-time codes and hashed session tokens, with the times they were issued and revoked
- Display name and whether the account is a patient or a clinic
We email that address for: sign-in codes, account-deletion confirmation codes, and clinic invitations when a clinic enters your email in their portal. An invitation email does not include health data — nothing is shared until you approve in the app.
Only if you use the feature:
- Clinic links — which clinic accounts you approved, and the request, approval and revocation times
- Clinic snapshot — see clinic sharing above
- Clinic workspace — rules your clinic writes for you, their edit history, and clinic-side AI chat about your case. This is written by your clinic, not copied from your phone. If you link more than one clinic, each clinic sees only the rules it wrote, and AI chat stays private to the individual clinician who wrote it. A clinic's rules are deleted when you end your link with that clinic; the edit history ends with your last link
- Access log — when a clinician opens your record, we record who, which clinic, what they opened and when. It holds no health data. This exists so the question "who has looked at my data?" has an answer, and it is the one thing we keep after an account is deleted — see Account deletion
- Cloud backup — see cloud backup above
- AI usage records — one row per AI request, recording which account it was for, what kind of request it was (meal, chat, labs, coaching), and what it cost in tokens. The content of the request is not stored here
- Token balance and billing history — your AI token balance and the credits and debits behind it, plus which clinic is sponsoring your AI if one is
- Payment details — if you add a card, we store your payment processor's customer and payment-method identifiers along with the card brand and last four digits. We never see or store your full card number. Card payments are simulated during the alpha
Retention. During the alpha we do not run automatic clean-up. Sign-in records, AI usage records and billing history are kept until you ask us to delete your account. Snapshots and clinic workspace data are deleted as described above. We will add scheduled expiry as the product leaves alpha and will say so here.
API host: api.healthings.ai (HTTPS).
Third-party services you choose to use
- Google Gemini — health context is sent to Google’s API to generate responses, on two separate paths. When you use the AI coach or mentor chat, it is sent from your phone. When a clinic you have linked uses their chat about your case, it is sent from our server, drawn from the snapshot you shared — so this can happen as a result of your clinician’s action rather than your own. Either way it can include labs, glucose, meals, workouts, body measurements, and your rules and targets. See Google’s privacy policy.
- Withings — optional OAuth to sync weight and body composition. Your Withings login tokens stay in your phone’s secure keystore and are never uploaded to us. The synced values are health data like any other and travel in a clinic snapshot or cloud backup if you use those. See Withings privacy.
- Health Connect (Android) and Apple Health (iPhone) — optional read access to blood glucose, steps, workouts, heart rate and active calories. Reading is one-way: we never write anything back to your health records. This data is used for your charts and coaching on the phone, and travels onward only through clinic sharing or cloud backup.
Permissions
- Health Connect / Apple Health — read blood glucose, steps, workouts, heart rate and active calories, so your charts and coaching reflect what you actually did
- Camera and photos — optional, to photograph a meal for the AI to analyse or to attach an image in coach chat
- Files — optional, to import lab PDFs, nutritionist directives and CGM exports, and to save backups where you choose. We can only read the files you pick
- Biometric unlock — optional fingerprint or Face ID after first sign-in
- Internet and network state — sign-in, AI coach, optional Withings sync
- Vibration — feedback on taps and alerts
Android also lists a microphone permission. It comes bundled with the photo-picker component and the app never records audio; we are removing it in a coming build. The app does not use location, and sends no notifications.
Children
Healthings is not directed at children under 13. We do not knowingly collect data from children.
How long we keep it
We do not run a deletion timer. What we hold on the server is kept for as long as your account exists, because each piece of it is doing a job while you use the product — your clinic can only read a snapshot that is still there. When you delete your account, it goes; see Account deletion.
Some things are shorter-lived than the account, and a few are capped by design:
- Sign-in codes expire 10 minutes after we email them, and are single-use.
-
Sessions. The token your app or browser holds lasts
15 minutes and is renewed silently; the renewal itself expires after
30 days of not being used, and signing out revokes it. On the
clinic portal (and the patient web account page) that token is
stored in the browser’s
localStoragefor the site — convenient on a clinician workstation, but readable by any script that can run on healthings.ai, and there is not yet an idle auto-lock. Use Sign out on a shared computer. - Clinic snapshot — one copy, not a history. We keep exactly the current snapshot. Each upload from your app deletes the one before it, so there is no archive of earlier versions on the server.
- Cloud backup — current plus one. If you turn backup on, we keep the latest copy and the one before it, so a bad export cannot cost you your data. Older copies are not kept.
- AI usage records (how many tokens a coach reply used, and who paid) are kept while the account exists, because they are what a sponsoring clinic's balance is calculated from. They contain no message text.
- The access log outlives the account. Every entry above is deleted with your account; this one is not. Who opened a record, and when, has to remain answerable after the fact, so the entries stay with the identifiers stripped of any meaning — see Account deletion.
Anything still on your phone follows your phone, not this policy. We cannot delete it and we cannot see it.
Account deletion
You can delete your account yourself, without asking us. Sign in at healthings.ai/account with the same email you use in the app and choose Delete my account. We email you a confirmation code first, so nobody using your browser can delete your account without access to your inbox.
Deletion is immediate and permanent. There is no grace period and no recovery — not by you, and not by us. It removes:
- Any snapshot you shared with a clinic
- Your cloud backup, including the previous copy we keep
- Your clinic links — linked clinics lose access at once
- Pending clinic invitations addressed to your email
- Your email address, sign-in codes and sessions
Your phone is not touched. Labs, meals, weight and glucose stay in the app, because that is where they live. Uninstall the app to remove those too — and export a backup first if you want to keep them.
Three things deliberately survive, and none of them can be traced back to a deleted account. If a clinician deletes their account, notes and rules they wrote for a patient stay with that patient, with the clinician's identity removed — your clinic history should not disappear because your clinician left. Billing and payment records are kept as required for accounting, also with the identity removed.
The third is the access log. We record when a clinician opens a patient's record, and those entries are kept even after the patient's account is deleted. An access log that erases itself is not a record of anything, and a patient asking "who saw my data?" deserves an answer that survives. What is left is a timestamp, an action, and identifiers that no longer resolve to a person — no name, no email, no health data.
If you cannot sign in, email support@healthings.ai from the address on the account and we will delete it for you.
Changes
We may update this policy as features evolve (e.g. optional clinic sync). Material changes will be reflected on this page with an updated date.