Legal
Data collection notice
This notice is generated alongside a machine-readable inventory in governance/data-inventory.json. The generated public page must be regenerated in CI whenever the inventory or notice changes.
Default local mode
No account is required. Health records and preferences are stored in browser IndexedDB. Once installed/cached, core logging, charts, history, export and cached guidance can work offline.
Optional services
- Encrypted sync account: random account/authentication metadata plus ciphertext. The recovery secret remains on the user's side.
- Web Push: push endpoint, timezone and chosen reminder times. Notifications are generic and do not contain medication/readings.
- Anonymous statistics: allow-listed event names with screen size, installed or browser, build and day, counted as daily totals with no identifier; on by default with a one-time notice in GB, US, CA, AU and NZ, off until chosen elsewhere; off with Global Privacy Control or Do Not Track. The site also counts app update checks and guidance pack fetches, which happen anyway, even when the switch is off. It never counts them when the browser sends Global Privacy Control or Do Not Track, and they carry no identifier. Settings > Privacy lists exactly what is sent.
- Third-party health integrations: separate, explicit, revocable connection and permission scopes. Data exchange occurs only for the integration the user chooses.
Hosting metadata
Like any web host, Cloudflare may process network/HTTP metadata needed to deliver the site and secure the service. The production deployment must configure logging, retention, locality and subprocessors deliberately and describe the actual setup in the final privacy notice.