Privacy
Biological Data Privacy Policy
Your biological data belongs entirely to you. We do not sell, license, or monetize your health information. All data is encrypted using end-to-end zero-knowledge protocols.
Zero-Knowledge Storage
HealthOS utilizes end-to-end encryption keys generated directly on your mobile device. Our server nodes process correlations in sandboxed memory containers, meaning our engineering team cannot view your raw biomodality streams without explicit, time-locked authorization.
Global Compliance Standards
Our infrastructure is strictly engineered to align with regional standards: HIPAA compliance in the United States, GDPR data control standards in Europe, and national healthcare data localization rules in Saudi Arabia.
Full Data Portability
You are never locked into our ecosystem. You can request a complete, standardized export of your raw biological data (glucose logs, heart rate variability, genomic variants) at any time. A single tap allows you to download your history or permanently delete your account.
No Ads. No Data Brokers.
Our business model is simple: you pay for the hardware and the subscription. We do not monetize your data by selling it to third-party brokers, advertisers, or insurance companies. Your health profile is used solely to generate your personalized insights.
The free tools on this website
Our free blood-work interpreter works differently from the app, and the zero-knowledge model described above does not apply to it — there is no account and no device key, so there is nothing to encrypt against. Here is exactly what happens instead:
- Your file is not kept. The report you upload is read in memory to extract the numbers, then discarded. We never write the document to disk.
- To read it, we send it to Google. Extraction uses Google’s Gemini API, so the contents of your report are transmitted to Google as a data processor. If you ask our assistant a question, your results and question are sent there too.
- We keep the anonymous results. The extracted values, their reference bands, and the answers you gave (biological sex, age range, fasting status) are stored so we can measure demand and — more usefully — find which biomarkers and units our reader fails on, which is how it improves.
- Those results are not linked to you. No name, no account, and no email unless you volunteer one. We store the country your request came from, never the IP address itself.
- It is not medical advice. Reference ranges are educational guidance, not a diagnosis, and our assistant will not diagnose, prescribe, or recommend a dose.
Because these records carry no identifier, we cannot look yours up on request. If you would like a submission removed, email support@healthosx.com with the approximate date and we will delete the matching records.
Your DNA on this website
The free DNA tool at /dna works differently again. Here is exactly what happens to your genome:
- Your file is read in your browser. By default it never leaves your device — the report is computed on it.
- Ancestry sends a marker extract, then deletes it. A compact list of rsIDs and genotypes is sent for the ancestry analysis and deleted when the run finishes.
- Ask your DNA sends your question and your results — not the file. Answers are generated with Anthropic’s Claude API, acting as our data processor. Conversations are stored linked to the email you gave, so you can sign back in with a one-time code and continue.
- Storing your file is your choice. Only if you tick the consent do we store your DNA file and the results computed from it, to answer your questions in more depth. The file is encrypted at rest with its own key, linked to your email, and used for nothing else.
- A relative’s file needs their agreement. If you add a relative’s file to compare with yours, you confirm they agreed. It is used only for that comparison and deleted together with yours.
- Delete it whenever you like. “Delete my DNA and chats” removes the stored file, its results and the linked conversation straight away. Genetic data is special-category data under GDPR, and you can also ask us by email.