Privacy

Privacy Policy

Last updated 26 July 2026

HEALTHINGS.AI is local-first: your health data stays on your phone. Nothing reaches our server unless you choose it — by sharing with a linked clinic, or by turning on cloud backup — and you can end either at any time. You are always in control.

Summary

Healthings is an alpha wellness app — a personal metabolic coach for meals, glucose, and progress. It is not a medical device and does not diagnose or treat conditions. Do not use it for emergency medical decisions. Your health data stays on your device by default. It reaches our server only through choices you make: approving a clinic and sharing with it, or turning on cloud backup. Neither is on unless you switch it on, and you can end either at any time.

What stays on your device

By default, all of the following live only on your phone:

There are exactly two ways this data reaches our server, and you start both of them: clinic sharing and cloud backup. Neither is on by default, and you can end either one at any time. Everything else — exporting a backup to a file, importing a PDF, taking a meal photo — happens on the phone.

Your Withings login tokens are held in your phone's secure keystore and are never uploaded, even when you share or back up. The weight and activity values synced from Withings are ordinary health data and travel with the rest.

Optional clinic sharing (your choice)

Sharing with a clinic is entirely optional. Nothing is uploaded until you approve a clinic in Data sharing and tap Share (or respond to a refresh request while the app is open after you have already approved that clinic). You are always in control: you choose who to link, when to share, and you can revoke access at any time.

While a link is approved and you have shared, a copy of your current snapshot is stored on our server for that clinic to read — only the latest one, replaced each time you share, and never a permanent medical record. That snapshot carries meals, glucose, labs, body metrics, targets, rules and directives. Conversations with the AI coach are not included — they stay on your phone (and in your optional cloud backup) and are never shared with a clinic. Revoking removes that clinic's access immediately, and when your last clinic link ends we delete the snapshot along with the clinic's workspace data and rule history. The app works fully without any clinic link.

Clinic chat and rule suggestions (when enabled) apply only while you keep a clinic linked. They are workspace aids for your care team — not a copy of your full history on our servers.

Optional clinic sharing may be unavailable in your region if required by law or regulator guidance. The wellness app on your phone continues to work without clinic sharing.

We do not accept patient health exports by email. Do not send lab PDFs, glucose logs, or other health data to support@healthings.ai — use clinic sharing in the app instead.

Optional cloud backup (your choice)

Cloud backup is off unless you turn it on. When you do, the app uploads a copy of your app data so you can restore it on a new phone. We keep the current backup and the one before it, so a bad overwrite does not cost you your history. Once it is on, the app refreshes that copy in the background — that is the point of a backup — so treat turning it on as ongoing consent rather than a one-time upload.

Turning cloud backup off deletes both copies from our server. Your clinic snapshot, if you have one, is separate and unaffected — and the reverse is also true.

What we collect on our server

Always, because the account cannot work without it:

We email that address for: sign-in codes, account-deletion confirmation codes, and clinic invitations when a clinic enters your email in their portal. An invitation email does not include health data — nothing is shared until you approve in the app.

Only if you use the feature:

Retention. During the alpha we do not run automatic clean-up. Sign-in records, AI usage records and billing history are kept until you ask us to delete your account. Snapshots and clinic workspace data are deleted as described above. We will add scheduled expiry as the product leaves alpha and will say so here.

API host: api.healthings.ai (HTTPS).

Third-party services you choose to use

Permissions

Android also lists a microphone permission. It comes bundled with the photo-picker component and the app never records audio; we are removing it in a coming build. The app does not use location, and sends no notifications.

Children

Healthings is not directed at children under 13. We do not knowingly collect data from children.

How long we keep it

We do not run a deletion timer. What we hold on the server is kept for as long as your account exists, because each piece of it is doing a job while you use the product — your clinic can only read a snapshot that is still there. When you delete your account, it goes; see Account deletion.

Some things are shorter-lived than the account, and a few are capped by design:

Anything still on your phone follows your phone, not this policy. We cannot delete it and we cannot see it.

Account deletion

You can delete your account yourself, without asking us. Sign in at healthings.ai/account with the same email you use in the app and choose Delete my account. We email you a confirmation code first, so nobody using your browser can delete your account without access to your inbox.

Deletion is immediate and permanent. There is no grace period and no recovery — not by you, and not by us. It removes:

Your phone is not touched. Labs, meals, weight and glucose stay in the app, because that is where they live. Uninstall the app to remove those too — and export a backup first if you want to keep them.

Three things deliberately survive, and none of them can be traced back to a deleted account. If a clinician deletes their account, notes and rules they wrote for a patient stay with that patient, with the clinician's identity removed — your clinic history should not disappear because your clinician left. Billing and payment records are kept as required for accounting, also with the identity removed.

The third is the access log. We record when a clinician opens a patient's record, and those entries are kept even after the patient's account is deleted. An access log that erases itself is not a record of anything, and a patient asking "who saw my data?" deserves an answer that survives. What is left is a timestamp, an action, and identifiers that no longer resolve to a person — no name, no email, no health data.

If you cannot sign in, email support@healthings.ai from the address on the account and we will delete it for you.

Changes

We may update this policy as features evolve (e.g. optional clinic sync). Material changes will be reflected on this page with an updated date.

Contact

support@healthings.ai
Back to download page