HealthidiaYour Health. Organized. Secure. Accessible.

Privacy Policy

Last updated: 6 August 2026

Healthidia holds some of the most sensitive information about you. We never sell it, never share it for advertising, and never use it to train public AI models. Your records are visible only to you.

1. Who we are

Healthidia ("we", "us") provides the Healthidia personal health record platform. We are an early-stage venture and not yet incorporated as a company; the operator of the service acts as the data controller for the personal data described here. Contact: support@healthidia.com. We will update this page with full corporate and, where required, EU/UK representative details on incorporation.

2. What we collect

Account data

  • Full name, email address, and mobile number, provided at sign-up.
  • Password (stored only as a one-way hash) and, if you enable it, passkey credentials.
  • Timestamps recording your acceptance of the disclaimer, marketing consent, and device consent.

Health data (special category data)

  • Blood glucose and blood pressure readings, including context and notes.
  • Vitals and body metrics: weight, height, BMI, oxygen saturation, heart rate, sleep, steps, energy.
  • Laboratory reports and extracted parameters, values, units, and reference ranges.
  • Medications, prescriptions, and dose logs.
  • Medical history: conditions, allergies, surgeries, family history.
  • Radiology and cardiology reports, including findings and impressions.
  • Files you upload: lab PDFs, prescription images, imaging reports, and photos of device displays.

Device and technical data

  • Connected device details (manufacturer, model, nickname, firmware, battery, sync status) and encrypted access tokens for connected health platforms.
  • Synchronisation history and audit log entries for sensitive actions.
  • Authentication tokens and basic browser/device information needed to run and secure the app, plus error diagnostics.

We do not collect payment data — Healthidia does not currently charge for anything — and we run no advertising or analytics trackers.

3. Why we process it, and our legal basis

  • To provide the service (storing and displaying your records, exports, device sync) — performance of a contract with you. For health data specifically, we rely on your explicit consent, given at sign-up and again at the disclaimer, device-connection, and summary-export consent gates.
  • AI extraction of your documents — your explicit consent, exercised each time you choose to use an AI feature. You can always enter data manually instead.
  • Account security, abuse prevention, audit logging — our legitimate interest in keeping the service and your data safe, and compliance with law.
  • Service and update emails you asked for — consent, withdrawable at any time.
  • Emailing your summary to a recipient you choose — your explicit, per-export consent, recorded with the exact wording you agreed to.

4. Who can see your data

Your records are visible only to you inside the app. Access is enforced by database row-level security that scopes every row to the account that owns it. There is no clinician, clinic, or administrator console that can browse your records.

We do not sell, rent, or share your personal data with third parties for their own purposes. Data leaves our systems only to the processors listed below, acting on our instructions, or to a recipient you personally choose when exporting or emailing a summary.

5. Processors we use

  • Managed cloud backend — database, authentication, and private file storage for your records and uploads.
  • Application hosting / edge network — serves the app and runs server-side functions.
  • AI processing gateway (Google Gemini models) — receives only the document image or text you submit to an AI feature, to return an extraction result.
  • Transactional email delivery — sends verification, password reset, and summary emails you request.

Each processor is bound by a data processing agreement and may only act on our instructions.

Automated processing. AI extraction is fully automated: the result you see is generated by artificial intelligence, and no doctor or other healthcare professional reviews your documents, your records, or the AI output. Nothing is saved without your review, and the processing has no legal or similarly significant effect on you — you can always enter data by hand instead. See the AI Medical Disclaimer.

Only for the service. We use your personal information solely to provide, secure, and improve Healthidia — never for advertising, profiling for third parties, or sale.

6. International transfers

Healthidia serves users globally and our processors operate infrastructure in multiple regions, including the United States. Where data is transferred out of the EEA or UK, it is covered by the European Commission's Standard Contractual Clauses (and the UK Addendum) together with the technical measures described in our Security Policy.

7. How long we keep it

For as long as your account exists, so your history stays useful over time. Full periods and the deletion process are in the Data Retention Policy.

8. Your rights

Wherever you live, we apply these rights to everyone. Under GDPR/UK GDPR you have the right to:

  • Access — get a copy of the data we hold about you.
  • Rectification — correct anything inaccurate; you can edit records and your profile directly in the app.
  • Erasure — have your account and records deleted.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — at any time, without affecting processing already carried out.
  • Complain — to your local data protection authority.

Exercise any right by emailing support@healthidia.com from your registered address. We respond within 30 days and never charge for a first request. We do not carry out automated decision-making that produces legal or similarly significant effects.

9. Health information and HIPAA

Healthidia is a consumer-controlled personal health record. It is not a covered entity or a business associate under HIPAA, we have no HIPAA certification, and we make no compliance claim. Data you enter is your own personal health information, held under your control. If a clinician or organisation ever wants to use Healthidia with patient data, a Business Associate Agreement would be required first — contact us.

10. Security

Encryption in transit and at rest, hashed passwords, passkey sign-in, row-level access control, private storage buckets, and audit logging. Details and current limitations are in the Security Policy. No system is perfect; keep your original medical documents.

11. Cookies

Only essential storage plus optional functional preferences — no advertising or analytics trackers. See the Cookie Policy, and use "Cookie Settings" in the footer to change your choice at any time.

12. Children

Healthidia is not intended for children under 16 to use independently. A parent or guardian may maintain records on behalf of a child in their care.

13. Breach notification

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and inform affected users without undue delay.

14. Changes

We may update this policy. Material changes will be announced in the app and take effect on the date shown above.

15. Contact

Privacy questions, data requests, and deletion requests: support@healthidia.com or via our Contact page.