HealthAPI

Privacy Policy

Last Updated: May 16, 2025

Privacy First: HealthAPI is built on a fundamental principle: your health data belongs to you. We are committed to protecting your privacy and giving you complete control over your information.

1. Introduction

This Privacy Policy describes how HealthAPI ("we," "us," or "our") collects, uses, stores, and protects your personal information and health data when you use our mobile application and API services.

By using HealthAPI, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

2.1 Health and Fitness Data

We collect health and fitness data that you choose to sync from Apple Health, including but not limited to:

2.2 Account Information

2.3 Usage Data

3. How We Use Your Information

We use your information solely for the following purposes:

We DO NOT:

  • Sell your health data to third parties
  • Share your data with advertisers
  • Use your health data for marketing purposes
  • Share your data with health insurance companies
  • Use your data for research without explicit consent

4. Data Storage and Security

4.1 Storage Location

Your health data is stored on secure servers located in compliance with applicable data protection regulations. Data is encrypted both in transit (using TLS/SSL) and at rest (using AES-256 encryption).

4.2 Security Measures

4.3 Data Retention

We retain your health data for as long as your account is active or as needed to provide you services. You can request deletion of your data at any time through the app or API.

5. Data Sharing and Disclosure

5.1 Third-Party Services

We do not share your health data with third parties except in the following limited circumstances:

5.2 API Access

Your health data is accessible only through your personal API key. You are responsible for keeping your API key secure and for any access granted using your credentials.

6. Your Rights and Choices

6.1 Access and Control

You have the following rights regarding your data:

6.2 Exercising Your Rights

To exercise any of these rights, you can:

7. HIPAA Compliance

While HealthAPI handles personal health information, we are not a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA) as we do not conduct healthcare transactions or interact with healthcare providers on your behalf.

However, we implement security and privacy safeguards that meet or exceed HIPAA standards, including:

8. Children's Privacy

HealthAPI is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@healthapi.app.

9. Cookies and Tracking

Our website uses minimal cookies necessary for basic functionality. We do not use tracking cookies or third-party analytics on our landing page. Our API does not use cookies but relies on API key authentication.

10. International Data Transfers

If you are accessing HealthAPI from outside the United States, please be aware that your data may be transferred to, stored, and processed in the United States or other countries where our service providers operate. We ensure that all such transfers comply with applicable data protection laws.

11. Data Breach Notification

In the unlikely event of a data breach that affects your personal information, we will:

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

Your continued use of HealthAPI after such changes constitutes acceptance of the updated policy.

13. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

To exercise these rights, contact us at privacy@healthapi.app.

14. European Union Users (GDPR)

If you are located in the European Union, you have rights under the General Data Protection Regulation (GDPR), including:

Our legal basis for processing your data is your explicit consent when you create an account and choose to sync your health data.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We will respond to all legitimate requests within 30 days.

Your Privacy Matters: At HealthAPI, we believe your health data is yours. We're committed to transparency, security, and giving you complete control over your information. If you have any questions or concerns, we're here to help.