About this health data policy
This consumer health data privacy policy is provided by Insightfull Development LLC, a California limited liability company in the United States. It describes our handling of consumer health data, including for people covered by Washington’s My Health My Data Act or other applicable consumer health privacy laws.
It supplements our general privacy policy. Health-related data may be sensitive even when it is not a formal medical record or is not covered by HIPAA. Contact support@insightfull.app about this policy.
Categories and sources
- Information from you: diary entries and conversations about symptoms, mood, medication, food, sleep, and other health matters; goals and preferences; and health-related information included in feedback.
- Connected information: Apple Health categories you permit, including sleep, steps, weight, activity, exercise, resting heart rate, heart rate variability, respiratory rate, and blood oxygen. The app synchronizes daily summaries to its backend.
- Derived information: insight scores, trends, generated responses and reports, possible food or symptom associations, correlation confidence and evidence, and related alerts.
- Associated information: account identifiers, dates, and device or notification records when they are connected to the health information above.
The sources are you, Apple Health on your device, your paired devices, and processing of the information you provide. Current food photo auto-log analyzes the selected photo on your iPhone; saved meal text can become part of your synchronized diary and cloud analysis.
Why it is collected and used
We use consumer health data to save and synchronize your diary, display health trends, calculate scores, identify possible patterns, answer questions, generate reports, and provide watch summaries and notifications. We also use information you supply to handle support, privacy requests, and security or legal obligations.
These features provide personal wellness information. They do not diagnose or treat conditions and are not an emergency monitoring service. We do not send your diary contents or Apple Health records to our advertising SDK for targeting.
Collection, use, and sharing must have the permissions or other lawful basis required by applicable law. This policy does not itself provide consent for optional sharing.
Who receives health data
- Backend hosting and database providers process synchronized records, derived results, and operational information to run and store the service.
- OpenRouter and the model providers it routes to receive messages, conversation context, health summaries, and diary text for cloud chat and deep analysis. Selected providers may change with routing and fallback settings.
- External correlation-analysis services, when enabled, receive derived correlation evidence and confidence values to evaluate patterns. This can happen automatically after diary or health synchronization.
- Notification delivery providers process device tokens and notification content for push delivery. Alerts can include health-related titles and summaries. The iPhone also shares selected summaries with your paired watch.
- Support personnel and service providers may receive health information you include in a support request or that is necessary to resolve it.
We may disclose information where required by law or in other circumstances permitted by applicable consumer health privacy law. If you choose to share a report or other information with someone else, that recipient may handle it independently.
The website’s waitlist administration integration receives account and waitlist event information. It does not receive your app diary or Apple Health records. Our general policy describes that separate flow.
Permissions and their limits
Manage Apple Health permissions in Apple’s Health app or device settings. Revoking a permission stops future access through that connection; it does not remove information already synchronized.
The app’s AI category settings and Apple Health permissions are separate. Contextual chat excludes categories explicitly switched off and includes categories without a saved preference. The current health synchronization, deep-analysis, and automatic correlation paths do not use those category switches as a complete restriction. Cloud AI can process diary text and summaries as described above.
To withdraw consent or request restrictions on previously collected health data, contact support@insightfull.app. We will explain the effect on features that need the data. Consent withdrawal does not change the lawfulness of processing that occurred before withdrawal.
Access, deletion, and appeals
Where applicable law provides these rights, you can ask us to confirm whether we collect or share your consumer health data, access it, obtain information about its recipients, withdraw consent to collection or sharing, or delete it. You may also request the list of third parties and affiliates with whom it has been shared or sold and their contact information, as provided by applicable law.
Email support@insightfull.app from your account email where possible and describe the request. We may request information needed to verify your identity without collecting unnecessary health details. Requests apply to relevant copies held by us and to required downstream deletion instructions, subject to lawful exceptions.
In-app request submission does not confirm completed deletion. Deleting a single entry also does not automatically erase past reports or chat text. Ask support for confirmation and assistance with related records and device copies.
If we decline a request, reply with “consumer health data appeal” to seek a review. We will respond within the period required by the law that applies to your request and explain any applicable extension or exception. If an appeal is denied, you can contact the regulator responsible for your request. If your request is covered by Washington’s My Health My Data Act and your appeal is denied, you may submit a complaint to the Washington Attorney General.
Updates and contact
We will update the date on this page when this policy changes and provide further notice or obtain consent where required. For consumer health privacy questions, contact Insightfull Development LLC at support@insightfull.app.