Skip to content

Privacy Policy — MyHealth

Version (policy_version): 2.9 Last updated: July 14, 2026 Effective: July 14, 2026. Changes (2.9, 2026-07-14): Optional lock-screen detail (off by default): the adult account holder may enable, on their own records, (a) the medication name and dosage in medication reminders, chosen separately per device; and (b) the vaccine name and dose in vaccine reminders — always as a factual echo of what you recorded, never the purpose, drug class, due-date calculation, booster recommendation, or urgency (Section 12-A). Minor and managed profiles are excluded: a dependent's notice always stays generic ("Reminder for a dependent"). Also in this version: a new refill / low-stock reminder (opt-in, neutral fixed body, under the same consent as medication notifications) and the Section 4 table extended. Legal basis: specific, explicit consent (LGPD Art. 7, I and Art. 11, I; GDPR Art. 6(1)(a) and Art. 9(2)(a)). Triggers re-consent for everyone. Changes (2.7, 2026-07-13): New Data manager (Section 7.2): upon your specific, highlighted consent (LGPD art. 7, I and art. 11, I; GDPR art. 9(2)(a); for Washington/USA residents, the separate consent required by the MHMDA), collected on your device with reinforced identity confirmation, an adult you designate may access and record data in your health record. Revocable at any time, in one tap, with immediate effect. Strictly personal acts (consents, account deletion, links, credentials, purchases, bulk export) are technically blocked for the Manager (on the server and in the app). We keep an audit trail of all the Manager's acts and show it to you, plus an in-app activity summary the Manager cannot turn off. Minors cannot appoint a Manager. Changes (2.6, 2026-07-13): New family sharing of hereditary conditions (Section 7.1), opt-in and item by item: the source enables a tracked diagnosis and linked family members may incorporate it into their own family history through express, item-by-item acceptance. It transmits only the condition, year of onset, and status (minimization locked in code); a permanence notice at the moment of the toggle; one-tap revocation (ex nunc); the recipient may delete the incorporated item at any time; erasure of the source's data de-identifies the origin in the recipient's record. Legal basis: specific, highlighted consent (LGPD art. 11, II, "a"; GDPR art. 9(2)(a)) and, where applicable, a valid authorization under the My Health My Data Act (Washington/USA). Minors' profiles do not participate as a source by their own decision. Changes (2.5, 2026-07-13): Non-sensitive daily contexts (coffee/caffeine, energy levels, hydration, workout perception, and routine changes) become part of the context sent to the AI only in weekly aggregated form (day counts and routine-change category — never the individual daily entry, never free text), under the AI Processing and International Transfer consents (§3.2 and Sections 6 and 9). The Sensitive Health Journal (alcohol, stress/what shaped the night) remains outside the AI. Changes (2026-07-05): in-app support channel (Profile › Support); account number (account_ref); AI-assisted support under consent; support-reply notification (push); email delivery via Apple Private Relay for those who use "Hide My Email". Changes (2.4, 2026-07-05): Sensitive Health Journal — opt-in collection (daily_journal) of daily records of alcohol and of stress/what shaped the night as sensitive data, with its own, prominent consent (off by default, revocable, blocked on the server, unavailable on minors' profiles); these records stay on your device/health record and are not sent to the AI. The mood check-in remains under the general clinical consent.


In short (read this first)

MyHealth is an iPhone app that helps you organize your own health record, with an artificial intelligence (AI) assistant that reads the documents and photos you upload to extract and fill in records (which you confirm before saving) and offers a supportive educational reading. You bring together your lab results, conditions, medications, vaccines, appointments, measurements, and documents in a single place, and the app builds a timeline of your health to prepare you for the conversation with your doctor.

The most important points:

The full text below details all of this and describes your legal rights.


1. Who we are (the Controller) and the DPO

The party responsible for processing your personal data ("Controller" under the LGPD; "Controller" under the GDPR) is:

BAS AI — BAS ARTIFICIAL INTELLIGENCE LTDA
CNPJ: 64.106.409/0001-70
Website: www.bas-ai.com
Address: Rua Gomes de Carvalho, 911, Vila Olímpia, São Paulo/SP, ZIP 04547-003, Brazil

In this document, "MyHealth", "we", or "the app" refer to this Controller.

Data Protection Officer (DPO)

For any privacy and data protection matter, contact our Officer (LGPD Art. 41 / Data Protection Officer, GDPR Art. 37):

Email: dpo@bas-ai.com
Officer's name: Guilherme Kaschny Bastian
Mailing address: Rua Gomes de Carvalho, 911, Vila Olímpia, São Paulo/SP, ZIP 04547-003, Brazil

We adopt the GDPR standard as our global baseline of protection (the most protective standard, applied to all users), even though the launch does not offer the service in the European Union/EEA or in the United Kingdom.


2. To whom this Policy applies

This Policy applies to everyone who uses the MyHealth app, in any country. The app is global and multi-language (Portuguese, English, and Spanish).

The initial launch focuses on Brazil, but, where the law of your country is more protective, it prevails. We treat the LGPD (Law No. 13.709/2018, Brazil) and the GDPR (Regulation (EU) 2016/679) as our minimum standard of protection everywhere, applied to all users. The app is distributed worldwide, except in the European Union/EEA and the United Kingdom, which are outside the launch.

Users in the United States: US-specific supplementary disclosures — the California Privacy Notice (CCPA/CPRA) and the Washington Consumer Health Data Disclosure (My Health My Data Act) — form part of this Policy as supplementary documents, published at https://www.bas-ai.com/myhealth/legal and prevailing, for residents of those jurisdictions, where they are more specific.

Children and adolescents: self-registration is intended for people 18 or older. Data of minors may only be included by a legal guardian, who manages the dependent's profile (see Section 11).


3. What data we collect

We collect only what is necessary for the app to work (the minimization principle). Below is what we collect and where it is stored.

3.1 Identity data (PII) — encrypted in a vault

The following data identifies you directly and is stored in an identity vault (identity_vault), encrypted field by field with authenticated (AEAD), deterministic encryption (the pgsodium library, AES-256), physically separated from the clinical tables. It is decrypted only by a secure function, under your own identity:

The clinical tables do not contain this data — they refer to you only by a profile code (pseudonym). In the pseudonymized profile we keep only the clinical-demographic minimum needed to interpret the data correctly (for example, biological sex and date of birth/age, important for lab reference ranges).

3.2 Health / sensitive data (PHI)

This is sensitive personal data (health) and receives maximum protection. We collect, as you record or import it:

Daily records of sensitive habits (special category). Beyond what you submit, the app may ask, occasionally and optionally, about habits that devices do not measure: a day's alcohol drinks (substance-use data) and what shaped a shorter night — including the options "Stress" (mental-health data) and "Alcohol". Because they involve a substance and a mental state, we treat these records as sensitive / special-category personal data. This is different from the weekly range of smoking/alcohol you declare at registration (the "Lifestyle habits you provide" item, above), which is part of the AI context when you authorize it: here we mean the daily, point-in-time records, which stay on your device and in your health record and are not sent to the AI.

We only collect them after YOUR specific and prominent consent (the daily_journal purpose, which you turn on in Profile › Privacy & consents), separate from accepting the Terms and from the general clinical consent. It is OFF by default — nothing is recorded until you turn it on —, it is blocked on the server until the consent exists, and it is UNAVAILABLE on minors' profiles and managed profiles (blocked in the app and on the server). Declining it does not reduce any other feature of the app.

Mood/wellbeing distinction. The mood check-in ("how you woke up") is handled separately, as health data under the general clinical consent (it does not fall into the sensitive-habit category above) and — like the rest of the health record — may be part of the context sent to the AI under that same clinical consent. The distinction: a day's alcohol drinks and point-in-time stress carry greater stigma and so receive their own consent and stay out of the AI; the mood, a low-granularity aggregated self-report (1–3), follows the general clinical treatment.

Other non-sensitive daily contexts. Occasionally and optionally, the app may also ask about lifestyle and wellness contexts that devices don't measure — for example coffee/caffeine, energy levels, hydration, how your workout felt (light/normal/hard), and routine changes during the week (e.g., travel, a new workout, changes in diet or sleep). Like the mood check-in, these are health data under the general clinical consent and are stored in your health record. When you authorize AI Processing and International Transfer (Sections 6 and 9), these contexts are included in the context sent to our AI provider (Anthropic, USA — Section 9) only in weekly aggregated form, as day counts — for example, "low hydration on 3 days of the week" or "3+ coffees on 2 days"; for routine changes, only the category you reported that week (e.g., "travel") — never the individual daily entry, never free text, limited to recent weeks. The sole purpose is to correlate, in an educational and descriptive way, your habits with your sleep, activity, and exam data — never diagnosis or treatment. Entries in the sensitive health diary (alcohol and stress/evening context) are not included: they remain outside the context sent to the AI and under their own separate consent, and any future AI use of them would require new explicit consent.

When this data refers to a minor in your care, the same protections apply (see Section 11).

3.3 Locality and language (optional, in clear text)

Optionally, to adapt the experience and prepare future features (such as recommending professionals by city), we may store country, state/province, city, and the preferred language. We do not collect a full address, latitude/longitude, or precise location. These locality fields are kept in clear text because the "city" granularity is not, in itself, sensitive data, and they are protected by the same access rules as your account. When you authorize AI Processing (Section 6), your profile's country is part of the context sent to the AI, only to regionalize, in an educational way, emergency guidance and vaccination-calendar guidance (state/province and city are not sent to the AI).

3.4 Account, session, and security data

3.5 De-identified usage data

We collect minimal stability and diagnostics data (telemetry) — crashes, errors, performance — in a de-identified way and without any health content, to keep the app safe and working (see Section 13). This is internal processing: we do not use analytics SDKs or third-party tracking. As a self-limited minimization measure, we retain this telemetry for up to about 12 months (see Sections 12 and 13).

3.6 What we DO NOT collect / DO NOT do


4. Purposes and legal bases

Every processing activity has a legal basis. Because we process sensitive health data, we are especially rigorous: each sensitive purpose is recorded in our consent record with the corresponding legal basis and Policy version.

PurposeWhat it isLegal basis — LGPDLegal basis — GDPR
Clinical processing (clinical_processing)Organize your documents, structure values, build the health record's timeline and trendsPrimary basis: Art. 7, II and Art. 11, II, "a" (specific and prominent consent for sensitive data). Subsidiary basis (only for security, integrity, compliance with a legal obligation, and operating deletion): Art. 7, II and Art. 10. We do not invoke health protection (Art. 11, II, "f")Primary basis: Art. 6(1)(a) + Art. 9(2)(a) (explicit consent for health data). Subsidiary basis (security, integrity, legal obligation, and deletion): Art. 6(1)(c) and (f). We do not invoke Art. 9(2)(h): Art. 9(3) would require a health professional bound by confidentiality in the flow, and there is no doctor in the loop
AI processing (ai_processing)Send the pseudonymized clinical content (without direct identifiers) to the AI (Anthropic) to read the documents and photos you upload and from them extract and fill in records (lab results, medications, vaccines, measurements, professionals — which you confirm before saving), structure the health record, and generate a supportive educational reading (assistant, never diagnostic — see Section 6)Art. 7, I and Art. 11, I (specific consent)Art. 6(1)(a) + Art. 9(2)(a)
Progress reports and follow-up decisionsRecord, in your health record, your own reports about the evolution of a tracked item (report text, keep/close decision, date, and version of the confirmed text), in an immutable trail, and send them to the AI as context marked as your report (see Section 6.9). Operates under the already-active consents (clinical_processing + ai_processing/intl_transfer) — it is not a new consentArt. 7, II and Art. 11, II, "a" (same consent as the clinical core)Art. 6(1)(a) + Art. 9(2)(a)
Sensitive health journal (daily_journal)Collect your daily sensitive self-observation records — alcohol (substance) and stress/what shaped the night (mental health) — as dated points that make up your time series (§3.2). Opt-in, off by default, blocked on the server until the consent exists, unavailable on minors' profiles. These records are not sent to the AI (see Section 6)Art. 7, I and Art. 11, I (specific and prominent consent for sensitive data)Art. 6(1)(a) + Art. 9(2)(a) (explicit consent for a special category)
International transfer (intl_transfer)When, and only when, necessary, process de-identified data outside Brazil (see Section 9)Art. 7, I; Art. 11, I; Art. 33 (international transfer)Art. 6(1)(a) + Art. 9(2)(a); Art. 44–49
Family sharing (family_sharing)You authorize a family member to read your health record, in a revocable way (see Section 7)Art. 7, I and Art. 11, I (consent)Art. 6(1)(a) + Art. 9(2)(a)
Data of minors in your careOrganize a dependent's health recordArt. 14 (best interest of the child/adolescent; consent of at least one parent or legal guardian)Art. 8 + Art. 9(2)(a), exercised by the legal guardian
Age attestation (age_attestation)You declare you are 18+; registration of a minor under 18 is blocked and the attestation is recorded immutably, with the server's date/timeArt. 14 + Law 15.211/2025 (Digital ECA)Art. 8
Security, fraud prevention, and auditAccess logs, defense against attacks, compliance with legal record-keeping obligationsArt. 7, II (compliance with a legal obligation) and Art. 10 (legitimate interest, limited)Art. 6(1)(c) (legal obligation) and Art. 6(1)(f) (legitimate interest)
App notifications — delivery tokenStore a technical delivery token (push/APNs) and send generic, no-health-data notices (e.g., "your analysis is ready"); operational consent via the iOS notification permissionArt. 7, IX (legitimate interest)Art. 6(1)(f) (legitimate interest)
Notices DERIVED from health data (optional — "Something new in your data"; medication reminders; and stock refill)Decide when to send a notice from a signal derived from your health/wearable data. Even though the content is generic and PHI-free, the derivation is sensitive-data processing — so it runs under its own consent (see Section 12-A), never legitimate interestArt. 11, I (specific, highlighted consent)Art. 9(2)(a) (explicit consent) + Art. 6(1)(a)
Technical telemetry / stabilityCrash diagnostics, without health data, in internal processing (no analytics SDK or third-party tracking)Art. 7, IX (legitimate interest), with self-limited minimization (Art. 6, III)Art. 6(1)(f) (legitimate interest)
Account, subscription, and packsMaintain the account and process subscriptions and AI usage packs (measured in pages and prompts). A minor's AI consumption is charged to the guardianArt. 7, VArt. 6(1)(b)
Support and assistanceReceive and reply to the messages you send through the app's support channel (free text that may contain health data you include)Art. 7, V (performance of the contract) + Art. 11, I / II, "a" (consent for any health data you include); retention: as long as the account exists, erased upon deletionArt. 6(1)(b) + Art. 9(2)(a)
Pseudonymized research (opt-in at deletion)Pseudonymized research cohort (only sex, age range, and year, in random cohorts, without profile_id, without free text, and without an exact date) that you may authorize at the moment of deleting your account (see Section 12)Art. 7, II and Art. 11, II, "a" (specific consent); pseudonymized data, not irreversibly anonymous dataArt. 6(1)(a) + Art. 9(2)(a) (explicit consent); cf. Art. 9(2)(j) (research purposes)

Legal basis of the clinical core — clarification. The primary basis for processing your health record is your specific and prominent consent (LGPD Art. 11, II, "a" / GDPR Art. 9(2)(a)), consistent with the "sovereign health record" positioning: you authorize, and you may revoke. We reserve a subsidiary basis only for what consent does not cover — information security, data integrity, compliance with a legal obligation, and the very operation of account deletion —, supported by LGPD Art. 7, II and Art. 10 and by GDPR Art. 6(1)(c) and (f). We do not adopt the health protection ground (LGPD Art. 11, II, "f" / GDPR Art. 9(2)(h)): under the GDPR, Art. 9(3) conditions this ground on the presence, in the flow, of a health professional bound by a duty of confidentiality, and there is no doctor in the loop of MyHealth.


5. Consent and how to revoke it

When you authorize a sensitive purpose, that consent is:

Our system only executes an operation if the corresponding consent is active. For example: if you do not authorize "AI Processing", the app does not send anything to the AI — this check happens automatically, on the server (the has_active_consent function), on every operation.

How the record works: each authorization or revocation is recorded as an immutable event in our consent record (consent_events), with the purpose, the legal basis, the language, and the Policy version in effect. Revoking does not erase the consent history — it records a new event that halts future processing of that purpose.

Revocation does not make unlawful processing already lawfully carried out, but it halts the future use of that purpose. You do not lose access to the health record you had already organized.

Sensitive health journal. The daily sensitive collection (alcohol, stress/what shaped the night) has its own consent (daily_journal), off by default: nothing is recorded until you turn it on, and the server blocks writes of these items without the consent active. You may withdraw at any time, just as easily, in Profile › Privacy & consents. When you withdraw: (1) we immediately stop collecting new records; and (2) we delete the alcohol/stress records already collected in those categories.


6. How Artificial Intelligence (AI) processes your data

AI is a central piece of MyHealth (assistant and extraction of data from documents), so we explain it with full transparency. Our AI provider is Anthropic, which acts as a subprocessor.

6.1 The AI receives the clinical content of your health record, without your direct identifiers

6.2 We DO NOT use your data to train AI

6.3 Technical safeguards

6.4 Open standards and vocabularies (LOINC® / UCUM)

So that the same test coming from different laboratories (with different names, abbreviations, and languages) is recognized as a single parameter and produces a coherent timeline, MyHealth normalizes markers using the open vocabulary LOINC® (Logical Observation Identifiers Names and Codes) and standardizes units of measure based on UCUM. These standards are licensed reference content embedded in the app — they work like a dictionary and receive none of your personal data (Regenstrief Institute is not a sub-processor and nothing from your record is sent to it).

This product includes content from LOINC® (loinc.org). LOINC is copyright © 1995–2024, Regenstrief Institute, Inc. and the LOINC Committee, and is available at no cost under the LOINC license (loinc.org/license). LOINC® is a registered trademark of Regenstrief Institute, Inc.

6.5 Organizing medications and supplements (derived data, AI-assisted)

To organize your record, the AI may produce, from the medications and supplements you log, a derived organizational datum: the decomposed active ingredients (a compounded formula is split into its label ingredients) and a general category; the canonical vaccine, the disease prevented, and the dose in the series (consolidating the same vaccine under different names); and the normalized allergen and its class. This datum is generated from what you already provided (we collect nothing new from you) and serves to relate, for example, an active ingredient to the corresponding marker in your lab test. It is educational and AI-assisted — you can review and correct it, and it is not a clinical classification, a prescription, or interaction checking (see the Medical Notice, item 5.2). AI processing details follow Sections 6.1–6.3.

6.6 Document awaiting available quota/usage

When billing is active and you do not have enough available quota or usage at the moment of upload, a document already redacted (after the on-device redaction described in 6.1) may be stored, without analysis, until subscription quota or an add-on pack becomes available — and is then analyzed automatically. The document waits in your own health record, under the same security and access protections as your account; nothing is sent to the AI while the AI Processing consent (ai_processing) is not active and there is no available usage.

6.7 AI-assisted support

When you talk to our in-app support (Profile › Support) and an agent uses AI assistance to draft the reply, the text of your support conversation — which may contain health data you write — may be sent to the AI (Anthropic, United States) only to prepare a draft reply, which a human agent reviews before sending. The support AI does not access your health record. This sending occurs under the same safeguards as the rest of AI Processing (SCC/DPA, no use for training, retention of about 30 days) and only when your AI Processing (ai_processing) and International transfer (intl_transfer) consents are active — if they are not, the agent replies without AI assistance. Unlike documents, the support text is not redacted automatically — so avoid including unnecessary data (name, ID document, contacts) in your support messages.

6.8 The Sensitive Health Journal is NOT sent to the AI

The Sensitive Health Journal is NOT sent to the artificial intelligence. Your alcohol and stress/what-shaped-the-night records stay on your device and in your health record and are not part of the context sent to our AI provider (Anthropic, United States). Any future use of these records by the AI would require a separate, explicit consent ("include my daily records in the AI analysis"), which does not exist in this version. This differs from the non-sensitive daily contexts (coffee/caffeine, energy levels, hydration, workout perception, and routine changes), which are part of the AI context only in weekly aggregated form — day counts and the routine-change category — as described in §3.2.

6.9 Progress reports and follow-up decisions

When you record the evolution of a tracked item as your own report (Terms, Section 9.7), we store in your health record the report text, the decision (keep or close follow-up), the date, and the version of the text you confirmed, in an immutable trail (correcting = a new entry). These reports become part of the context sent to the AI explicitly marked as a patient report — the AI is instructed to treat them as a report ("you reported that…"), never as a documented clinical fact, and it is technically prevented (server-side validation, not just an instruction) from closing or superseding an item based on a report without your express decision. All of this operates under the already-active Clinical Processing, AI Processing, and International Transfer consents; the copy sent to the AI follows the same identifier-redaction pipeline as the rest of your record.

Minimization: to record a report, professionals' names are optional — the report works equally well without identifying who made the assessment; we recommend including only what is necessary.

Export and deletion: reports and decisions are part of your health record — they are included in the export and erased upon account deletion, through the same dual-track process of Section 12.

Minors: on minors' profiles, entries are made by the legal guardian, in representation, and the entry identifies the guardian who made it; relevant closures are communicated to the other guardians linked to the profile.


7. Family sharing (opt-in, read-only, revocable)

MyHealth lets you share your health record with a family member, in a controlled way:

The family member must also be a user of the app. This sharing is between you and the person you choose — it is not sharing with third parties or for commercial purposes.

7.1 Item-by-item sharing of hereditary conditions

In addition to the read-only link above, you may choose, item by item, to offer health conditions tracked in your record (for example, a diagnosis and its year of onset) to linked family members, so they can add them to their own family history. How it works:

Legal basis: processing based on your specific, highlighted consent (LGPD art. 11, II, "a"; GDPR art. 9(2)(a)) and, where applicable, upon a valid authorization under the My Health My Data Act (Washington/USA). The incorporated item is treated as sensitive data of the recipient themselves throughout the pipeline (including AI, export, and erasure), under the recipient's own active consents.

7.2 Manager authorized by you (delegation by an adult)

Upon your specific, highlighted consent (LGPD art. 7, I and art. 11, I; GDPR art. 9(2)(a); for Washington/USA residents, the separate consent required by the MHMDA), an adult you designate (the "Manager") may access and record data in your health record. How this processing works:


8. Apple Health (HealthKit)

MyHealth lets you import measurements from Apple Health (HealthKit) — weight, height, body composition, blood glucose, blood pressure, heart rate, saturation, and temperature, plus day-to-day metrics when your device offers them, such as sleep breathing disturbances, time in daylight, and mindfulness sessions — and, when you authorize them in the iOS permissions, also menstrual cycle and reproductive health data (menstrual flow, intermenstrual bleeding, ovulation tests, cervical mucus quality, and pregnancy tests) into your health record. We do not import sexual activity records.

Cycle patterns (its own opt-in, off by default). If you turn it on in Profile › Privacy, the app can show your logged cycle days alongside your charts (sleep, heart) and observe local, descriptive patterns (for example, how your sleep behaves on logged menstruation days). It is a composition, on your device, of data you already see: none of it becomes a notification, nothing is sent to the AI beyond what you already authorized, and the app never calculates or predicts fertility/ovulation. Unavailable on dependents' profiles; revocable at any time (the pattern simply stops being shown).

Connecting smart bands and rings (Oura and WHOOP)

In addition to Apple Health, you may, optionally and revocably, connect third-party wearables, with specific consent per provider (wearable_sync_oura, wearable_sync_whoop):

The authorization uses OAuth: the access tokens are encrypted (AES-256-GCM) on our server and are not accessible by the app. Oura operates in Finland (European Economic Area) and WHOOP in the United States; connecting these services involves an inbound international transfer, under the safeguards in Section 9.1. Oura and WHOOP act as data sources (independent controllers of their own platforms), not as our subprocessors, and do not receive data from your health record.

When you disconnect a wearable:

Data imported from wearables and from Apple Health is always recorded in your own health record (account holder) and never in a dependent's profile, even if you are viewing a minor's profile.


9. Subprocessors and international transfers

We do not sell your data. To operate the service, we use a minimal set of vendors ("subprocessors"/"processors"), each under a data processing agreement (DPA) in effect, confidentiality, and security, processing data only under our instructions. The three subprocessors below have DPAs/SCCs in effect: Supabase (signed 2026-06-18), Anthropic (via Commercial Terms, 2026-06-17), and Resend (via EU-US DPF + SCC, 2026-06-17).

SubprocessorWhat it doesWhat data it processesWhereSafeguards
SupabaseDatabase (PostgreSQL), authentication, document storage, and edge functionsPseudonymized clinical data; encrypted PII in the vault; encrypted documents; account metadataSão Paulo, Brazil (sa-east-1)DPA in effect (signed 2026-06-18; Supabase Pte. Ltd) — includes EU SCCs + transfer safeguards (UK/Switzerland); SOC 2 Type 2 + ISO 27001 (Supabase provider certifications); daily backups (14 days); 28-day log retention; encryption in transit (TLS) and at rest; additional field encryption under our key management; isolation via RLS; SCC for any transfers outside the EEA
Anthropic, PBCAnthropic's AI models for health-record analysis, document extraction, and chatPseudonymized clinical content (values, dates, notes, lifestyle habits, cycle, wearable aggregates, and non-sensitive daily contexts in weekly aggregated form — day counts and routine-change categories, never the individual daily entry) plus sex, age, country, and year of birth (without day/month)without direct identifiers and without emergency contacts — and, in document analysis, the redacted copy of the image/PDF (best-effort on-device redaction of printed identifiers, when located) — transiently; and, when an agent uses AI-assisted drafting in support, the text of your support conversation (never the health record)United States (international transfer)DPA in effect (via Anthropic's Commercial Terms, 2026-06-17) + SCC; contractual non-training; limited retention (~30 days); TLS
ResendSending transactional emails (access code/OTP and account notices)Only your email address and the email body; no PHI / no health contentUS / globalDPA in effect (2026-06-17) via EU-US DPF + SCC; TLS. For those who choose "Hide My Email" in Sign in with Apple, transactional emails are delivered through Apple's private relay (@privaterelay.appleid.com) and we do not see your real email
Apple (App Store / In-App Purchase / HealthKit / push)Distribution, HealthKit, notifications, and payment processing for subscriptions and add-on packs as merchant of recordPurchase/receipt data; we do not receive your card data; no health content in the payment flowUS / globalApp Store Terms; Guideline 5.1.3

Oura and WHOOP do not appear in this table: they are data sources that you connect (Section 8), acting as independent controllers of their own platforms, and not as our subprocessors. Apple acts as an independent controller for distribution, HealthKit, push, and payments. The DPAs and Standard Contractual Clauses (SCC) of our three subprocessors (Supabase, Anthropic, and Resend) are in effect, as indicated in the "Safeguards" column. We maintain a public subprocessors page kept up to date at https://www.bas-ai.com/myhealth/legal/subprocessadores. We will give notice before adding a relevant new subprocessor.

9.1 International transfers

Your health record is stored in Brazil (São Paulo) — that is the rule. Transfers outside Brazil occur in a limited way and with your authorization (intl_transfer): in AI processing (Anthropic, United States — Section 6), in which we send the clinical content without your direct identifiers (in document extraction, the file itself — after a best-effort on-device automatic redaction that attempts to cover name, tax ID, email, and phone; identifiers not located may remain in the file); in the connection of wearables (Oura, in Finland/EEA; WHOOP, in the United States — Section 8); and in distribution by Apple (United States). When there is an international transfer, we adopt the required safeguards:

We may also disclose data when required by law (court order or competent authority), always limited to what is strictly necessary and, where legally permitted, notifying you.


10. Information security

The confidentiality of your health data is our number one control. The main measures:

We seek alignment with the best international practices for health information security. No system is 100% immune; that is why we maintain incident response plans (see Section 14).


11. Data of children and adolescents (minors)

The protection of children and adolescents follows the Statute of the Child and Adolescent (Law 8.069/1990), Law 15.211/2025 (Digital ECA), Art. 14 of the LGPD, and Art. 8 of the GDPR (EEA).

We adopt, in any country, a single 18-year-old threshold for a self-owned account. This requirement refers to account ownership and is not to be confused with the GDPR's age of autonomous digital consent (Art. 8, between 13 and 16 years old depending on the country). Below 18, data processing only occurs through a profile managed by an adult guardian.

Users in the United States (COPPA): MyHealth does not offer accounts to minors and does not collect data directly from children. Any minor's data is entered and controlled by a responsible adult, who exercises verifiable parental consent.

Sensitive journal unavailable to minors. The daily sensitive collection (alcohol, stress) is not performed on minors' profiles or on profiles managed by a guardian — blocked on the client and on the server. It is a feature exclusive to adult account holders (18+). Under no circumstances do we collect alcohol/stress records from minors.


12. Retention and disposal

We adopt the minimization principle: we keep each category of data only for as long as needed for its purpose or required by law. Because MyHealth is distributed worldwide, we apply the most protective standard among the applicable laws: by default, deletion erases your identity, and retention is the exception, triggered only when a concrete law requires it.

12.1 Retention periods

CategoryPeriodWhy
Health record and identity vault (clinical data + PII)As long as your account exists; removed upon account deletion (see 12.2)You keep the health record organized for as long as you want
Access / audit logs (access_log — date/time, source IP, action; never clinical content)6 monthsSecurity and detection of fraud/abuse (a proportionate measure — legitimate interest, GDPR Art. 6(1)(f); LGPD Art. 7, IX). In Brazil, it also meets the floor of the Internet Civil Framework (Law 12.965/2014, Art. 15) for an application provider. The log (date/time + IP) is not health data and the IP is never used to infer a health condition
Minimum identity retained upon deletion (encrypted name + encrypted email + creation date + last access date)Only where there was a transaction (subscription or packs purchased); for the tax period of your jurisdiction (Brazil, United States, and other countries: 5 years; United Kingdom and Canada: 6 years; European Union: 10 years), with automatic purging at the end. For anyone who never transacted: none of this is retained — the identity is erased upon deletionTo comply with a tax/accounting obligation that arises only from a real transaction (Brazil: Tax Code (CTN), Arts. 173 and 174; United States: IRS rules; European Union: the Member State's period; United Kingdom: Limitation Act 1980 / HMRC; Canada: Income Tax Act s. 230). Without a transaction, there is no legal obligation that justifies keeping the identity
Billing and tax data (receipts, subscription and pack movements)Tax period of the jurisdiction (Brazil: 5 years) — only for those who transactedTax periods (Brazil: Tax Code (CTN), Arts. 173 and 174; or the applicable local tax law)
De-identified technical telemetryUp to about 12 monthsInternal minimization policy (LGPD Art. 6, III) — not a legal period
Consent records (consent_events, de-linked / pseudonymized from your profile upon deletion — the identifier is replaced by an HMAC code whose key is kept outside the database)Kept as proof of lawfulness for the applicable limitation periodTo prove lawfulness and the authorizations granted/revoked (accountability — GDPR Art. 5(2)/7(1); LGPD Art. 8/6, X)

How identity is protected when retained: when there is a transaction and tax law requires retention, we keep the name and email encrypted (the same protection as the identity vault), in an isolated table, accessible only by the internal service (RLS, no user access), and we delete it automatically at the end of the period. We do not keep your email in readable text.

Retention of the sensitive journal. While the consent is active and the account exists, the Sensitive Health Journal records (alcohol, stress/what shaped the night) remain in your health record. When you withdraw the consent, they are deleted; when you delete the account, they follow the dual-track deletion (Section 12). There is no tax retention of this data.

12.2 Permanent account deletion (right to erasure — LGPD Art. 18, VI / GDPR Art. 17 / local equivalents)

Deletion is available directly in the app, under Profile › Privacy › Delete my account (an Apple requirement). Upon confirmation, we execute the permanent cascade removal — an immediate operation — of all of your clinical health record (lab results, conditions, medications, vaccines, documents, measurements, history, appointments, conversations with the AI, wearable data) and of the files in storage, we revoke the wearable connections, and we close your access account.

Managed dependents and guardianship migration. Deleting your account also erases the data and files of the dependents you manage (minor profiles in your care). Before completing, if a minor has another guardian already linked, the app offers to migrate that minor's guardianship to the existing co-guardian — so the minor's profile survives with them, instead of being erased. If you choose not to migrate, the dependent's profile is removed together with your account. In any case, we never retain the minor's name or email for tax reasons (see below).

The backups may, for a short period, still contain data already deleted: they are overwritten in our processor's normal cycle (Supabase, around 14 days — well within the 6 months), and the data processing agreements (DPAs) with Supabase and Anthropic govern the disposal of any residual copies. (We do not claim "key destruction" or instant backup purging.)

The deletion of your identity depends on whether or not you made a purchase:

Deletion receipt (accountability — LGPD Art. 6, X): we can confirm the completion of the deletion upon request to the DPO. The deletion is not total — the minimum records below remain, by legal requirement.

What always remains after deletion, for any user:

Dependent profiles (minors): when deleting a minor's profile, we never retain the minor's name or email for tax reasons — the tax obligation, if any, belongs to the paying guardian, not to the minor's profile. For the minor, erasure of the identity is the rule; only the minimum deletion record by irreversible code remains.

Users in jurisdictions with a reinforced right to deletion (e.g., Washington — My Health My Data Act): we treat the request as deletion of consumer health data — we erase the identity (without invoking the tax period against anyone who did not transact), and the disposal of residual copies at the processors occurs within 6 months, in accordance with the respective data processing agreements (DPAs).

12.3 Death of the data subject

The LGPD and the GDPR protect living persons and, as a rule, do not reach the deceased (ANPD, Technical Note No. 3/2023; GDPR, Recital 27). Even so, a deceased person's health record involves personality rights that survive death (Civil Code, Art. 12, sole paragraph) and matters of succession.


12-A. Notifications and reminders (opt-in)

MyHealth may send reminders on your iPhone — about medication, a wellbeing check-in, a weekly check-in (optional, off by default, once a week — a neutral, fixed-text invitation to log what the app can't see on its own, such as activity, symptoms, or energy; it never carries health data or inference), your schedule (appointments/tests/follow-ups/vaccines), and a few server-side notices (when an analysis is ready, when one of your exams is updated, when a follow-up appointment is approaching, when support replies to your message, and when your data — e.g., sleep, resting heart rate — brings something new). Key points:

13. Cookies, telemetry, and tracking

MyHealth is a native iPhone app (not a website), so it does not use browsing cookies in the traditional sense.

Today we do not use any third-party analytics or tracking tool; if that changes, we will update this Policy and the subprocessors page before activation, with a new notice — also reviewing the App Store privacy labels and the need (or not) for App Tracking Transparency (ATT).


14. Security incidents and notification

We maintain incident response plans. In the event of a security incident that may create relevant risk to you:


15. Your rights

You are the owner of your data and have rights guaranteed by the LGPD (Art. 18) and the GDPR (Chapter III):

RightWhat it meansHow to exercise it in MyHealth
Access / confirmationTo know what data we hold and obtain a copy (LGPD Art. 18, I–II; GDPR Art. 15)View the full health record in the app; export it
CorrectionTo correct incomplete or wrong data (LGPD Art. 18, III; GDPR Art. 16)You review and edit the data directly
Deletion / erasureTo delete your data and account (LGPD Art. 18, VI; GDPR Art. 17)Delete account / data in the app (see Section 12)
PortabilityTo take your data in a structured, interoperable format (LGPD Art. 18, V; GDPR Art. 20)Export in FHIR R4 and as PDF
Consent revocationTo withdraw an authorization (LGPD Art. 8, §5; GDPR Art. 7(3))Turn off a purpose (e.g., "AI Processing") in the settings (see Section 5)
Information on sharingTo know with whom we share (LGPD Art. 18, VII)This Policy (Section 9) and the subprocessors page
Objection / restrictionTo object to a processing or request its restriction (LGPD Art. 18, §2; GDPR Art. 18 and 21)Contact the DPO
No subjection to automated decision / reviewThe AI does not decide anything on its own (LGPD Art. 20; GDPR Art. 22)You always review and confirm (see Section 6.3)
View the access historyTransparency about who accessed whatYour access log is available
Petition to the authority (ANPD)To petition against the controller before the national authority (LGPD Art. 18, §1)Contact us (Section 1) and/or the ANPD — see "Complaints" below

How to exercise: many rights are exercised directly in the app (review, export, delete, revoke consent). For the others, or if something does not work, write to our DPO (Section 1). We respond within the legal period (as a rule, up to 15 days for confirmation of existence or access, under the LGPD; up to 30 days under the GDPR, extendable where the law permits).

Complaints: if you believe we process your data improperly, you can complain to the competent authority — in Brazil, the ANPD (https://www.gov.br/anpd); in Europe, the data protection authority of your country. We ask, however, that you talk to our DPO first — we want to resolve it directly with you.


16. MyHealth is NOT a medical service


17. Changes to this Policy and versioning

We may update this Policy to reflect changes in the app, in vendors, or in the law. The Policy has a version (policy_version):

The version history is published at https://www.bas-ai.com/myhealth/legal/versoes; each accepted version remains archived.


18. Contact us

Questions, requests, or complaints about your data:


MyHealth — your health record, sovereign and private. This Policy was drafted in Portuguese as the basis for translation into the app's other languages (at least PT/EN/ES). In case of divergence between versions, the Portuguese prevails.