♥ How healthpanel handles your data
Operators: this is a plain-language template, not legal advice. Review it with counsel for your jurisdiction (e.g. GDPR special-category health data, the US FTC Health Breach Notification Rule, Washington's My Health My Data Act) before opening sign-ups.
What we store
- Your email address, to sign you in.
- The Apple Health records you upload or sync: samples such as heart rate, HRV, steps, sleep stages and workouts, with the names of the apps and devices that recorded them, plus the daily panel computed from them.
- Your uploaded
export.zip, each sync delivery and each emailed attachment only until they've been imported. Then we delete them. Emails pass through our mail provider (Resend), which keeps its own copy for a limited time.
Who can see it
- Only you, after signing in with a link sent to your email. Each account's data is kept in a separate database.
- Your private sync URL and private email address let you add data. They can't be used to read anything.
- Email sent to the shared import address is added to an account only when it comes from that account's sign-in address and carries a valid DKIM signature from that address's mail domain, so a forged sender can't add data to your account.
- The server's administrators can technically access stored data. We don't sell it or share it for advertising.
The AI analyst (ask)
When you use ask, the questions you type and the aggregated numbers needed to answer them (daily metrics, correlations, summaries; never your raw export) are sent to Anthropic's API, which runs the Claude model. Anthropic processes it under its commercial terms. If you don't want that, don't use ask. All other commands run only on our server.
Your controls
- Download your daily panel as CSV at any time.
- Delete your health data, or your whole account, from the Account tab. Deletion takes effect immediately on the live system.
- To stop syncing, disable the automation in Health Auto Export or generate a new sync URL.