Privacy

Your data stays under your control

Every account has its own data boundary. Access, correction, export and deletion are normal parts of the product lifecycle.

01

One account, one boundary

Persistent records are tied to an internal owner identifier. The personal space never selects another owner from a free URL parameter.

02

Access and correction

The My data center lets you review account information, update it and revoke other sessions.

03

Export

You can export what the server holds for your account. Encrypted health payloads are not decrypted by administration.

04

Seven-day deletion window

A deletion request starts a seven-day safety window that can be cancelled before a private worker performs the purge.

05

Photos and OCR

Photo reading is assisted. Human confirmation remains mandatory before a detected value is stored.

06

Contact

Messages are encrypted before storage and the notification email does not repeat the message body.

07

Separate administration

Account, access, security and privacy workflows stay separate from decrypted health measurements.

08

No third-party telemetry

The public runtime includes no advertising tracker or external analytics platform.

09

Documented limits

Technical limits are stated without absolute promises, especially for backups and devices that remain offline.