Privacy Policy
This Privacy Policy explains how HumOS Inc. ("Humos," "we," "us") collects, uses, and protects your information when you use our websites, applications, and services (the "Service"). Health information is sensitive, and we treat it that way.
1. Information we collect
- Account information you provide, such as name, email, and settings.
- Health and wellness data you connect or enter. This can include wearable and sleep metrics, heart-rate variability and resting heart rate, workouts and activity, nutrition and meals, body measurements, lab and biomarker results, continuous glucose data, symptoms and how you feel, and — because the Service screens for interactions — the medications, supplements, and peptides you take.
- Photos you take of meals, if you use photo logging, so the Service can identify what you ate. If you scan a product barcode we do not already hold, we look that barcode up in a public food database — the lookup carries the barcode and nothing that identifies you.
- Lab documents you upload. Humos does not order lab tests. When you have results from your own provider, you can upload the document and the Service extracts the biomarker values from it.
- Approximate location, if you enable it — city-level only, used to fetch weather and air quality for outdoor-training guidance. Humos does not track or store precise location or GPS routes.
- Data from third parties you connect, with your authorization: wearables and devices through our aggregation partner, Apple Health on iOS, and your Google Calendar. Each is optional and separately revocable.
- Device and push data, such as a push notification token if you enable notifications.
- Usage and device data, such as app interactions, log data, and general device information, used to operate and improve the Service.
- Waitlist email. If you request access on our website before you have an account, we collect only your email address and which form you used, so we can tell you when access opens.
2. How we use your information
We use your information to build your personal model, generate your daily plan and guidance, run your N-of-1 experiments, keep the Service safe (including drug and supplement interaction checks), provide support, and improve the Service. We do not sell your personal information, we do not use it for advertising, and we do not use your health data to train third-party AI models. Your model is not the product.
3. Automated processing and AI
Humos uses AI models to generate your daily plan, coaching, and experiment analysis, to recognize meals from photos, and to extract values from lab documents you upload. To do that, relevant parts of your health context are sent to our AI provider for processing on our behalf, under contract, and are not used to train their models. We send the context a task needs, not your whole record. Guidance is generated automatically and is not reviewed by a clinician before you see it. Safety checks — including drug and supplement interaction screening — are applied as deterministic rules, not left to model judgment. You are always free to disregard guidance, and you should consult a qualified healthcare provider before acting on it.
4. How we share information
We share information only as needed to run the Service: with the service providers (processors) listed below, who act on our instructions under contract and may not use your data for their own purposes; with people you explicitly grant access to (see section 5); to comply with law or protect rights and safety; and in a business transfer, subject to this Policy. We do not share your health data for advertising, and we do not sell it.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and file storage. Row-level security isolates each user. | Account and health data |
| Vercel | Application and website hosting. | Request and log data |
| Terra | Wearable and device data aggregation. | Wearable metrics |
| Anthropic | AI model that generates your plan, coaching, experiment analysis, meal-photo recognition, and lab-document parsing. | Health context, meal photos, and lab documents sent per request |
| Voyage AI | Text embeddings used for retrieval within your own record. | Derived text vectors |
| Calendar integration, when you connect it. See the Google user data section below. | Calendar events and account email | |
| Apple | HealthKit, when you use the iOS app. Read on your device with your permission. App Store billing. | Health metrics; subscription status |
| RevenueCat | Subscription management and billing. | Subscription status |
| OneSignal | Push notifications and waitlist email. Message content is generic by policy — never a metric, dose, or diagnosis. | Device push token, account identifier, email address |
| Upstash | Rate limiting, so the Service stays available and abuse is contained. | Short-lived request counters keyed to an account or address |
| WeatherAPI | Weather and air-quality conditions for training guidance, when you enable location. | Approximate location (city-level) |
| Open Food Facts | Public food database, queried when you scan a barcode we do not already have. No account identifier is sent. | The scanned barcode |
| Sentry | Error monitoring, so failures get fixed. | Diagnostic and log data |
| Mixpanel | Product analytics — how features are used, not what your health data says. | Usage events |
This list reflects the providers in use as of the date above. We will update it as it changes.
5. Sharing with a coach or practitioner
If you invite a coach, trainer, or practitioner to your team, you choose what they can see, scope by scope, and you can change or revoke that access at any time from your settings. Nobody sees your data because of a default — every grant is an action you took. Revoking a grant ends their access immediately.
6. Google user data
When you choose to connect your Google Calendar, Humos requests read-only access to your Google Calendar events (calendar.events.readonly) and your basic Google account identity (openid, email).
What we access. From your primary Google Calendar only, and only for a rolling 7-day window going forward, we read each event's title, location, start and end times, all-day flag, and status. From your Google account we read your email address to identify the connected account. We never access past events, secondary calendars, or any other Google service, and we never write to, modify, or delete anything in your calendar.
How we use it. Your calendar events are used solely to build your daily plan around your real commitments — Humos schedules training, meals, and recovery around your meetings and travel — and to display those events back to you inside the app. Classification is done by deterministic software; your Google Calendar data is never used to train any AI or machine-learning model.
How we store and protect it. Access and refresh tokens are stored in our database, encrypted at rest, in a table that is accessible only to backend service processes and is never exposed to your browser or device. Event data is stored only to power the features above.
What we do not do. We do not sell your Google user data, do not use it for advertising, and do not share it with third parties. No human reads your calendar data; it is processed only by automated systems.
Your control. You can disconnect Google Calendar at any time from Settings → Data connections. Disconnecting immediately revokes our access, deletes the stored tokens, deletes all imported calendar events, and removes the associated consent record. You may also revoke access directly at myaccount.google.com/permissions.
Limited Use. Humos's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Apple Health (HealthKit)
On iOS, Humos can read from and write to Apple Health, only with the permissions you grant in the Health app. Permissions are granular: you choose each data type, and you can change or revoke any of them at any time in Settings → Health → Data Access & Devices on your iPhone. Humos works without HealthKit; the plan is simply built on less signal.
What we read. Only the types you approve, which can include sleep analysis, heart rate and heart-rate variability, resting heart rate, respiratory rate, blood oxygen, wrist temperature, steps and distance, active and basal energy, exercise and stand time, flights climbed, VO₂ max, workouts, body mass and body-fat percentage, height, walking steadiness, speed and gait metrics, time in daylight, mindful sessions, and dietary water and caffeine.
What we write. Only what you log in Humos: workouts, water, caffeine, weight, and breathwork sessions, so your other health apps stay in sync. Nothing else is written back.
How HealthKit data is handled. HealthKit data is read on your device with your permission and synced to your Humos account to power your plan. Consistent with Apple's requirements, we never use HealthKit data for advertising, marketing, or data mining, we never sell it, and we never disclose it to third parties except the processors listed above who operate the Service on our behalf. Deleting your Humos account removes the HealthKit-derived data we hold; it does not delete anything in Apple Health itself, which stays under your control on your device.
8. How we protect your data
We apply security controls appropriate to the sensitivity of the data, including row-level access controls that isolate each user's data at the database layer, encryption in transit (TLS) and at rest, access limited to what is necessary to operate the Service, and an audit trail for access to health information. No system is perfectly secure, but we hold health data to a clinical bar. See Security for detail.
9. Your choices and rights
You can access, correct, export, or delete your data, and disconnect any third-party source, from your account settings at any time. Export produces a machine-readable copy of your record. Deleting your account removes your health record from the Service — see Account deletion for exactly what is removed and what is retained.
If you are in the EU, EEA, UK, or Switzerland (GDPR). You have the right to access your data, correct it, erase it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time without affecting processing already carried out. Our legal bases are: performance of a contract for operating your account and delivering the Service; your explicit consent for processing health data and for each optional connection you authorize; legitimate interests for security, abuse prevention, and improving the Service; and legal obligation where law requires. You have the right to lodge a complaint with your local supervisory authority.
If you are in California (CCPA/CPRA) or another US state with a privacy law. You have the right to know what personal information we collect and how it is used, to access and delete it, to correct it, to obtain it in a portable format, and to limit the use of sensitive personal information. Health data is treated as sensitive personal information and is used only to provide the Service you asked for. We do not sell or share personal information as those terms are defined under the CPRA, and we have not done so in the preceding twelve months. We will not discriminate against you for exercising any of these rights.
How to make a request. Most requests are fastest to satisfy yourself in the app, under Settings. Otherwise, email privacy@joinhumos.com from the address on your account. We will verify your identity against that account, respond within 30 days (45 for California requests, extendable once with notice), and tell you if we need more time. There is no charge, unless a request is manifestly unfounded or repetitive.
10. Data retention
We keep your information for as long as your account is active. When you delete your account, your health record is deleted immediately and permanently from the live Service; encrypted infrastructure backups age out on our provider's rolling cycle and are not used to restore deleted accounts. Waitlist emails are kept until you unsubscribe or ask us to remove them. Diagnostic and analytics data is retained on our providers' standard schedules — 90 days for error diagnostics.
One exception is deliberate: the audit log of access to health information is retained after account deletion, because its purpose is to record who accessed what and when. It contains no health data and cannot be used to reconstruct your record. We may also retain billing and transaction records where tax or accounting law requires.
11. Service limits and fair use
To keep the Service available and to contain abuse, we apply rate limits to our API and usage limits to certain features by plan. These limits are enforced with short-lived request counters keyed to your account or address, which are not part of your health record. We also respect the rate limits of the third-party services you connect, and sync incrementally rather than re-pulling your history.
12. Children
The Service is not intended for anyone under 18, we do not knowingly collect data from children, and we do not knowingly sell or share the personal information of anyone under 16. If we learn that we have collected data from someone under 18, we will delete it. If you believe a child has provided us data, contact privacy@joinhumos.com.
13. International users
Humos is operated from the United States, and your information is processed in the United States and in other countries where our providers operate. These countries may have different data-protection laws than your own. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) with the providers listed in section 4. You can request a copy of the relevant safeguards at privacy@joinhumos.com.
14. Changes to this Policy
We may update this Policy. If changes are material, we will notify you by email or in the app before they take effect. The "last updated" date reflects the current version.
15. Contact
Questions, privacy requests, or to reach the person responsible for data protection at Humos: privacy@joinhumos.com, HumOS Inc., 251 Little Falls Dr, Wilmington, DE 19808.