Legal

Privacy Policy

What Homeostat collects, why, who else can see it, and how to take it back. Health data is the most sensitive category of personal information there is, and this policy is written to be specific rather than reassuring.

Effective
August 23, 2026
Last updated
August 23, 2026

The short version

A plain-language orientation only. The numbered sections below are the binding text.

  • Your health records are visible to you alone. We do not browse them, and no other user can reach them.
  • We do not sell your data, share it for advertising, or train AI models on it — and we do not let our providers train on it either.
  • Sending documents to an AI model and syncing a connected source are both opt-in and off by default.
  • You can export everything as JSON, or delete everything permanently, from Settings — no request, no waiting.
  • HIPAA does not apply to a consumer app like this one. Other law does, and this policy is binding on us.
  • No aggregate or cross-user analysis of your data is running today, and none will start without asking you.

1Who we are and what this covers

Homeostat Health LLC, a Utah limited liability company (“Homeostat”, “we”, “us”), operates the Homeostat website and application. This policy explains what personal information we collect, why, who else touches it, how long we keep it, and the control you have over it. For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), we are the data controller.

It covers the Homeostat Service. It does not cover third-party services you connect — Whoop, Apple Health, MyFitnessPal, and the like — which are governed by their own policies, or any external site we cite or link to.

This policy is part of our Terms of Service.

2Health data is sensitive, and we treat it that way

Almost everything you store in Homeostat — biomarkers, medications and doses, body composition, sleep, imaging results, nutrition — is health data. Under the GDPR this is a “special category” of personal data (Article 9), and under several US state laws it is “sensitive personal information”. We apply three rules to it.

  • Your record is yours alone. Every health record is scoped to your account. No other user can read it, and we do not browse it. Our staff access individual records only where you have asked for support and access is necessary to provide it, or where the law compels us.
  • Sensitive processing is opt-in. Sending documents to an AI model and pulling data from a connected provider are each off by default. You turn them on, and you can turn them off.
  • Privacy wins conflicts. Where a feature cannot be built without weakening these commitments, we do not build it that way.

3HIPAA, and what actually applies

Homeostat is not a HIPAA covered entity.

HIPAA applies to healthcare providers, health plans, and clearinghouses, and to their business associates. Homeostat is a direct-to-consumer tool that you use on your own behalf, so the health information you store here is generally not protected health information under HIPAA, and HIPAA does not give you rights against us.

That is a statement about which statute governs, not a lower standard of care. Other law does apply to us, and we hold ourselves to the commitments in this policy either way:

  • the FTC Health Breach Notification Rule, which requires consumer health apps outside HIPAA to notify affected users, the FTC, and in some cases the media following a breach of unsecured identifiable health information;
  • the GDPR and UK GDPR, including the Article 9 conditions for processing health data, where you are in the EEA or UK;
  • US state privacy laws — including the California Consumer Privacy Act as amended (“CCPA/CPRA”) and comparable laws in other states — which treat health data as sensitive and restrict its use; and
  • Section 5 of the FTC Act, which makes the promises in this policy enforceable against us.

If you obtained a lab report or scan from a provider, that provider remains bound by HIPAA for its own copy. Uploading it here moves a copy outside that framework and into this one.

4Information we collect

Information you give us

  • Account information. Your email address and password. Accounts and credentials are handled by our managed authentication provider — we never store your password, and we cannot read it.
  • Health metrics you enter. Readings with their value, unit, date, and source, across activity, sleep, vitals, body composition, nutrition, imaging, and biomarkers.
  • Protocol records. Administered doses, infusion sessions, imaging studies, and blood panels with their individual results, including any notes you add.
  • Documents and images you upload. Lab reports, scan reports, and photographs of results, stored as private files that are not publicly reachable.
  • Contributions. Research citations, compound information, and corrections you submit for editorial review, plus your own additions to the treatment, facility, and compound catalogs.
  • Correspondence. What you send us by email or through a support request.

Information from sources you connect

  • Connected provider data. When you connect Whoop, we retrieve recovery, strain, sleep, and heart-rate data within the scopes you approve.
  • Access credentials. The access and refresh tokens for a connected account, encrypted at rest with AES-256-GCM and never included in a data export.
  • Imported export files. The contents of files you import from Apple Health, MyFitnessPal, smart scales, body-scan reports, or smart garments.
  • Sync records. When a sync ran, what it covered, and whether it succeeded — kept so a failure is visible to you rather than silent.

Information collected automatically

  • Consent records. Which privacy consents you have granted or revoked, and when. We keep these as proof that sensitive processing was authorized.
  • Server and security logs. IP address, user agent, timestamps, and request outcomes, generated by our hosting provider and used for security, abuse prevention, and debugging.
  • Aggregate usage analytics. Page views and coarse device and referrer information, measured without cookies and without cross-site identifiers. This is not joined to your health record.

We do not collect precise geolocation, we do not read your device contacts or photo library, and we do not use advertising or social media tracking pixels.

5Cookies

We use only the cookies the Service needs to function. We set no advertising, profiling, or cross-site tracking cookies, which is why you are not asked to accept a tracking banner.

  • Session cookie. Keeps you signed in. It is HTTP-only, marked Secure, and signed. Without it, the Service cannot authenticate you.
  • Connection-security cookie. A short-lived, single-use value written when you begin connecting a third-party account, used to verify that the returning authorization is genuinely yours. It is deleted as soon as the connection completes.

6How we use information, and our legal bases

Where the GDPR applies, we rely on the bases below. Because health data is a special category, processing it also depends on your explicit consent under Article 9(2)(a), given when you create a record or enable a feature — or, where relevant, on Article 9(2)(f) for the establishment or defence of legal claims.

  • To provide the Service — storing your records, showing your current status and trends, running the features you use. Basis: performance of our contract with you, and your explicit consent for health data.
  • To extract metrics from documents you upload. Basis: your consent, which you can withdraw at any time.
  • To sync connected sources and process imports. Basis: your consent.
  • To authenticate you and secure the Service — preventing abuse, investigating incidents, enforcing our Terms. Basis: our legitimate interest in a secure service, and our legal obligation to protect personal data.
  • To understand aggregate usage and improve the product. Basis: legitimate interest, using data that is aggregated and not health data.
  • To review and publish Contributions. Basis: performance of our contract and our legitimate interest in maintaining an accurate research record.
  • To communicate with you about your account, security, or material changes to this policy. Basis: contract and legal obligation.
  • To comply with law and respond to lawful requests. Basis: legal obligation.

We do not use your health data for advertising, for profiling that produces legal effects, or to make decisions about you.

7Your privacy controls

Three switches under Privacy consents in Settings govern optional processing. All three default to off, and each is enforced on our servers — not merely hidden in the interface — so turning one off actually stops the processing.

AI document processing

Allow uploaded lab reports and photos to be sent to an AI model to extract metrics. Turning this off disables the upload-extraction feature.

Third-party data sources

Allow connected sources like Whoop, and imported exports from Apple Health or MyFitnessPal, to write readings into your timeline. Turning this off stops all syncing and blocks new imports; data already saved is kept until you delete it.

Extended data retention

Keep your historical readings indefinitely so long-term trends stay available. With this off, you are responsible for exporting data you want to keep.

Storing the records you deliberately enter is not gated by a consent switch, because it is the thing the Service does. Your control over that data is to edit or delete it.

Withdrawing a consent stops the processing going forward. It does not undo processing already lawfully carried out, and it does not by itself delete data already saved — delete that separately if you want it gone.

8AI processing

With AI document processing enabled, the contents of a document you upload are sent to a third-party large language model, which returns the metrics it identified. We use Google’s Gemini models, reached through our AI gateway provider.

  • Only what you submit is sent. We do not send your stored history, your other records, or your identity — the request carries the document and the instruction to extract from it.
  • Nothing is trained on your data. We do not train models on your data, and we use these services under terms that do not permit our provider to train on it either.
  • Output is reviewed by you. Extracted values are presented for confirmation or correction before they enter your record. Extraction failures are surfaced to you rather than discarded quietly.
  • Turning the consent off disables the feature and stops any further transmission.

9Aggregate and anonymized research

We may in future offer aggregate comparisons — how a goal or activity level compares across users. If we do, it will operate under rules fixed in advance:

  • participation will be strictly opt-in, through a separate consent that defaults to off, and users who do not opt in will be excluded entirely;
  • all identifiers will be removed or irreversibly de-identified before data enters aggregate processing, and no aggregate output will identify anyone;
  • results will be reported only at thresholds large enough that an individual cannot be singled out; and
  • withdrawing consent will stop further contribution immediately.

No such program is running today. Your data is not being pooled, aggregated, or analyzed alongside other users’ data, and we will not begin without asking you first.

10Who we share information with

We do not sell your personal information, and we do not share it for advertising. We disclose it only to the service providers that run the Service, each bound by contract to process it only on our instructions and to protect it.

ProviderPurposeData involvedLocation
NeonManaged Postgres database and authentication service (Neon Auth)Account identifiers and credentials, and every health record you saveUnited States
VercelApplication hosting, serverless compute, and private file storage (Vercel Blob)Request metadata, server logs, and uploaded documents and imagesUnited States (global edge network)
Vercel AnalyticsAggregate traffic measurementPage views and coarse device and referrer information, without cookies or cross-site identifiersUnited States
Google (Gemini, via our AI gateway provider)AI extraction of metrics from documents you uploadOnly the contents of documents you submit for extraction, and only while the AI document processing consent is enabledUnited States
WhoopWearable data sourceRecovery, strain, sleep, and heart-rate data pulled on your behalf — only after you connect the accountUnited States

We may also disclose information:

  • When you direct us to — for example, by connecting an account or exporting your data.
  • To comply with law — in response to a subpoena, court order, or other valid legal process. We assess each request, disclose no more than is required, and will notify you unless we are legally prohibited from doing so.
  • To protect people — where disclosure is necessary to prevent imminent harm, fraud, or a serious security threat.
  • In a corporate transaction — if we are involved in a merger, acquisition, or asset sale, your data may transfer, but it remains subject to this policy and we will notify you before any change takes effect.

11What we will not do

Commitments, not aspirations.

  • We will not sell or rent your personal information, and we will not “share” it for cross-context behavioural advertising as CCPA/CPRA defines those terms.
  • We will not disclose your health data to advertisers, data brokers, employers, insurers, or credit-reference agencies.
  • We will not use your health data to target advertising to you, anywhere.
  • We will not train AI models on your health data, or allow our providers to.
  • We will not add a new use of your health data without a lawful basis and, where consent is required, without asking you first.

12International data transfers

Our infrastructure and providers are located in the United States, so if you use the Service from outside the US your information is transferred to and processed there. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), together with the encryption and access controls described below. You may request details of the safeguards in place by writing to legal@homeostat.health.

13How long we keep information

  • Your health records and uploads are kept until you delete them or delete your account. Keeping full history indefinitely is what the extended data retention consent governs; with it off, you are responsible for exporting anything you want to preserve long term.
  • Connected-source credentials are kept until you disconnect the source or delete your account.
  • Consent records are kept for as long as needed to demonstrate that processing was authorized, and for a reasonable period afterwards.
  • Security and server logs are retained on a short rolling window by our hosting provider, then discarded.
  • Published Contributions may remain part of the research record after your account is deleted, since they concern published science rather than you. They carry no personal information.

When you delete your data we remove it from our live systems, including the underlying stored files. Residual copies may persist briefly in encrypted backups before being overwritten on their ordinary cycle. We may retain the minimum necessary where the law requires it or to resolve a live dispute.

14How we protect information

  • Encryption in transit. All traffic is served over HTTPS, with HTTP Strict Transport Security enforced.
  • Encryption at rest. Our database and file storage are encrypted at rest. Third-party access tokens receive a second, application-level layer of authenticated AES-256-GCM encryption, so a database disclosure alone does not yield working credentials.
  • Per-user isolation. Every read and write of health data is filtered by the authenticated user’s identity, and privileged editorial checks fail closed — an unreachable database denies access rather than granting it.
  • Private file storage. Uploaded documents are stored privately, are not publicly enumerable, and their storage URLs are withheld even from your own data export.
  • Credential handling. Passwords are held and hashed by our managed authentication provider; we never see or store them.
  • Hardened responses. We set strict transport, content-type, referrer, and permissions policies, and deny browser access to camera, microphone, and location.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your unsecured identifiable health information, we will notify you without undue delay — within 72 hours of becoming aware where the GDPR applies — and will notify regulators as required, including under the FTC Health Breach Notification Rule.

To report a vulnerability, write to legal@homeostat.health. We will not pursue good-faith security research conducted without accessing other users’ data.

15Your rights

Everyone

  • Export. Download a complete, machine-readable copy of everything stored for you — every user-scoped record, not a subset.
  • Delete. Permanently erase your records, uploads, connected sources, and consents.
  • Correct. Edit or remove any individual reading or record.
  • Withdraw consent. Turn off any optional processing at any time.

EEA, UK, and Switzerland

You have the rights to access, rectification, erasure, restriction of processing, portability, and objection (including to processing based on legitimate interests), and the right to withdraw consent at any time without affecting the lawfulness of prior processing. You may lodge a complaint with your national supervisory authority — or, in the UK, with the Information Commissioner’s Office — and you may do so without contacting us first, though we would like the chance to help.

California

You have the right to know what personal information we collect and disclose, to delete it, to correct it, to limit our use and disclosure of sensitive personal information, and to opt out of its sale or sharing. We do not sell or share personal information, so there is nothing to opt out of; we use sensitive personal information only to provide the Service you requested, which is a permitted purpose, so no additional limitation is required. We will not discriminate against you for exercising any right, and we do not offer financial incentives for your data. You may use an authorized agent, with proof of authority.

Other US states

If you live in a state with a comprehensive privacy law — including Utah, Colorado, Connecticut, Virginia, Texas, Oregon, and others — you have comparable rights to access, correct, delete, and obtain a portable copy of your data, to opt out of targeted advertising, sale, and profiling (none of which we do), and to appeal a refused request. Because these laws treat health data as sensitive, we process it only with your consent.

16How to exercise your rights

The fastest route is built into the Service, and needs no request or waiting period:

You can also write to legal@homeostat.health. We will verify your identity through your account email before acting on a request about health data, and we will respond within 30 days (extendable to 90 where the law permits and the request is complex, with notice to you). Exercising these rights is free, unless a request is manifestly unfounded or excessive. If we refuse a request, we will explain why and how to appeal or complain.

17Children

The Service is intended for adults and requires you to be at least 18. We do not knowingly collect personal information from children. If we learn that we hold information from someone under 18, we will delete it. A parent or guardian who believes a child has provided us information should write to legal@homeostat.health and we will act promptly.

18Automated decision-making

We do not make decisions about you that produce legal effects or similarly significant consequences by automated means alone. AI extraction reads documents and proposes values for your confirmation; it does not decide anything about you, and a human — you — remains in the loop. Trends, charts, and any future insights are descriptive summaries of data you supplied, not determinations about you.

19Changes to this policy

We will update this policy as the Service changes. If a change materially affects how we handle your personal data, we will give reasonable advance notice — by email, or by a prominent notice in the Service — and update the “Last updated” date above. Where a change requires your consent under applicable law, we will ask for it before the new processing begins, rather than treating continued use as agreement. Previous versions are available on request.

20Contact us

Homeostat is operated by Homeostat Health LLC, a Utah limited liability company, which is the controller of the personal data described in this policy.

For any privacy question, to exercise a right, or for any other legal matter, contact legal@homeostat.health.

We will respond to privacy enquiries within 30 days. If you are in the EEA or UK and are unsatisfied with our response, you may complain to your local supervisory authority.