Skip to content

Privacy Policy — MyHealth

Version (policy_version): 3.17 Last updated: August 1, 2026 Effective: August 1, 2026. Changes (3.17, 2026-08-08): This version brings one optional addition and no other change to how we handle your data. Up to 3.16 we did not store the trace (waveform) of your watch's electrocardiogram — only the classification and metadata. A new option appears, "Store my ECG trace" (Profile › Privacy), which starts off: while it is off, nothing changes. If you turn it on, we import and store the trace so you can take it to your doctor — and, even when on, the trace is never interpreted by us, never sent to the artificial intelligence, never altered, does not enter family sharing or notifications, and turning it off deletes the traces already imported. We ask for a separate authorisation because the Apple Health permission does not distinguish "see the classification" from "store the trace". No new subprocessor, no new international transfer. The Terms also changed in this version (liability cap, §14.3).

Changes (3.16, 2026-08-01): This version describes what already happened and changes nothing about how we handle your data: no new data, no new purpose, no new subprocessor, no change of legal basis. The Policy gains §12.3, on deleting a specific exam from your health record — the two options the app offers and the difference between them, what goes immediately, what remains on purpose (the appointment you have already attended and the symptom you have already confirmed), how the AI analysis stops resting on the removed exam, and what we keep of the act: a receipt with counts only, never the title or the content. The former §12.3 and following were renumbered.

Changes (3.15, 2026-07-25): This version amends the Terms of Use (§12.1) and changes nothing about how we handle your data. We removed from the contract the monetary amounts quoted "for reference" for the subscription and the add-on packs. Why: MyHealth's price varies by country — the App Store sets its own amount for each market where the app is sold — so a contract quoting a fixed amount, even as a reference, is wrong for most readers and goes stale when the price changes; one of the quoted amounts was in fact below what the App Store charged. The Terms now state what has always applied in practice and still applies: the prices and quotas in force are always those displayed at the time of purchase. The quotas are unchanged (40 pages and 12 interactions per month; 480 and 144 per year; packs of 50/150 pages and 20/50 interactions) — what you are entitled to use is exactly the same. No new data, no new subprocessor, no new transfer. Changes (3.14, 2026-07-25): A stress transparency round — three points: one new, one in your favor, and one honest correction of our earlier text. (A) Your ring's stress index is now shown TO YOU (§3.2 and Sections 4, 6.8 and 8): in the "Today's readiness" card, on the Routine tab, next to your readiness, we show the label Oura itself publishes for the day (restful / normal / stressful), exactly as the brand publishes it and always with the date it refers tono translation into a scale of ours, no severity color, no severity ordering of ours, and no calculation of ours: MyHealth never computes a "stress index" from your signals. This is not new data: collection already happens under the consent you granted when you connected Oura (revocable), and "stress" has been listed among the daily scores we declare we collect since version 3.9 — what was missing was declaring that we give that data back to you, on screen. Everything that already applied still applies: this index is NEVER sent to the AI (the exclusion is applied in the database query itself, in both the analysis and the chat, and reaches the stress sub-score embedded in Oura's resilience "contributors" — it is not merely an instruction to the model), never enters the PDF Health Report, never becomes a notification and never appears on a dependent's or a minor's profile. Legal basis unchanged, no new purpose: performing the service you signed up for (seeing your own organized data) over sensitive data already consented to (LGPD Art. 7, V and Art. 11, II, "a"; GDPR Art. 6(1)(b) and Art. 9(2)(a)); the change is one of transparency (LGPD Art. 6, VI and Art. 9; GDPR Art. 5(1)(a) and Art. 12–13). No new data, no new subprocessor, no new international transfer. (B) A new control: "What appears in the app" (§3.2 and Sections 4 and 5): in Profile › Privacy & consents you can now turn off the display of sensitive categories, one by one — Ring stress, Menstrual cycle and Mental health — effective on tap and across all your devices. Read carefully what this switch does and what it does NOT do: it hides that content from the app's screens, for you — and that is all. It does not disconnect your ring or Apple Health, does not withdraw consent, does not delete data, does not stop collection and does not change what the AI receives; collection and use are still governed by your consent. We only offer the switch for a category you actually have on that profile; it does not exist on a dependent's profile or in read-only access; and when you hide Menstrual cycle, it also stops being offered in the PDF Report (the PDF goes to third parties — offering to send data you chose not to see would be the opposite of what you asked for). It is extra control for you, with no new legal basis: minimization and privacy by default (LGPD Art. 6, III; GDPR Art. 5(1)(c) and Art. 25(2)). (C) Correction: the daily check-in's "Stress" axis IS sent to the AI analysis — and our text said it was not (§3.2 and Sections 6.1, 6.8 and 9). The "How are you today?" check-in has evolved: where there used to be a single mood answer, there are now four axes that you yourself answer on three levelsenergy, mood, stress and (only when the app does not receive sleep from your wearable) sleep. The stress axis is your own self-report and is part of the context sent to the AI, only as a weekly average, under the Clinical processing, AI processing and International transfer consents you already granted, with a hard instruction to the model: a descriptive reading of what you reported, never a diagnosis of anxiety, depression or a "stress disorder", never treated as a clinical instrument, never treatment advice. Our earlier text, written before the check-in gained axes, said that "point-in-time stress… stays out of the AI" and described the check-in as being mood only — a reasonable reader would conclude that no self-reported stress reaches the AI, and one does. We corrected the affected paragraphs to say plainly what goes and what does not: the check-in axis goes (weekly average, three levels); the sensitive Health Diary entries (alcohol and stress/evening context, under their own consent) do not, the ring's stress index does not, and the GAD-7/PHQ-9 questionnaires do not. Legal basis — the same one already operating, now described correctly: specific and prominent consent for sensitive data (LGPD Art. 7, I and Art. 11, I; GDPR Art. 6(1)(a) and Art. 9(2)(a)) + international transfer (LGPD Art. 33; GDPR Art. 44–49); for Washington (USA) residents, the per-purpose consent under MHMDA, reaffirmed over the corrected text. That is why this version asks you to accept again: because the earlier description was incomplete on a special-category point, we ask you to confirm you have read the corrected Policy, so that your consent record points to the right text. This update triggers re-consent (the acceptance screen reappears). Also in this version (Section 13): we now record the install source when you download the app after seeing one of our App Store ads (Apple Search Ads / AdServices) — campaign data, no IDFA, no iOS tracking permission (ATT) and no third party: it is Apple reporting on our own campaign to our own server. It exists so we can tell which ads bring people who actually use the app. Legal basis: legitimate interest (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).

Changes (3.13, 2026-07-25): The come-back invitation may now also be delivered by remote push (Section 12-A). The neutral invitation to return to the app after a stretch without use already existed and keeps the same purpose, the same trigger and the same legal basis: what triggers it is still only the time since you last opened the app — an app-usage signal, never a reading or inference about your health. What changes is only the delivery method: it used to be assembled exclusively on your device (a local notification); now it may also be sent from our server (remote push, APNs). Why: a local notification is only scheduled when the app is opened — so someone who went a long time without opening it, or switched devices, simply never received the invitation. The body stays identical and neutral: no health data, no number, no comparison, no judgment, no urgency and no blame (e.g., "Your data misses you — the portrait is still here, just as you left it."). The cap of one interruptive notice per day, your quiet-hours window, the cancellation as soon as you open the app, and the individual toggle in Profile › Notifications all still apply. Dependent and managed profiles remain excluded. Remote delivery uses the same technical delivery token already described in Section 3.4 — no new data is collected and no new subprocessor is involved. Legal basis unchanged: performing the service/legitimate interest, with easy opt-out (LGPD Art. 7, V and IX; GDPR Art. 6(1)(b) and (f)). This update triggers re-consent (the acceptance screen reappears).

Changes (3.12, 2026-07-19): Personalized notifications with your own data (Section 12-A). By founder directive (sole Controller/DPO, 2026-07-19), MyHealth notifications may now include, in the body, a summary of your own health data — for example, the duration and efficiency of last night's sleep (and deep sleep) and how it compares to your own average; your daily glucose average and time in range (descriptive, never an alarm or clinical threshold); your activity versus your average and milestones reached; the name of a lab marker and how it changed over time; a weekly or monthly summary with real numbers; and the analysis-ready notice (a push about your own record) may name the analysis theme/panel, in your language. Previously the body was kept generic (no health values). This is a change in how data you already share is DISPLAYED to you, on your own devicenot a new data category collected, and not new sharing with third parties. Four controls: (a) iOS hides previews on the lock screen until you unlock the device (default "Show Previews: When Unlocked"; you can also choose "Never"), so a glance at a locked phone does not reveal the content; (b) each category has its own toggle in Profile › Notifications — the non-sensitive personalized summaries are on by default and each can be turned off (granular opt-out); (c) they are for you, the adult account holder, on your device onlyminor and managed profiles never carry health data in the notice body; (d) the notices stay descriptive and factualnever a diagnosis, a medical judgment or opinion, a cause, an efficacy claim, or urgency. Sensitive domains (mental health, cycle/reproductive, substance, medication adherence) stay off by default and would only ever appear in a notification if you had both opted into that data category (the dedicated consent that enables it — e.g., the Health Diary, Mental health, cycle) and turned on that category's notification toggle; today, mental-health and cycle/reproductive content remain entirely out of any notification, and medication notices never frame a missed or late dose (adherence memory, never surveillance). Legal basis: for the personalized service notices derived from your own data and delivered to your own device, performance of the service you configured, with granular opt-out (LGPD Art. 7, V and IX; GDPR Art. 6(1)(b) and (f)); for the sensitive (special-category) ones, explicit consent (LGPD Art. 11, I; GDPR Art. 9(2)(a); Washington MHMDA). This update triggers re-acceptance (the acceptance screen reappears). Changes (3.11, 2026-07-19): Two Apple Health-related additions, published together — a minor bump, with re-acceptance. (A) Observed medication adherence (§3.2, Sections 4, 6, and 9; requires iOS 26 or later): if you log that you took a medication dose in Apple Health, MyHealth can import only the doses marked as taken into your record, matched to a medication you have already registered in the app (we never create a new medication from Apple Health). Only a factual aggregate goes to the AI — how many days, within a 30-day window, had a dose logged — never a percentage, never a judgment, never a causal claim. There is no surveillance: the app never sends a "missed dose" or "forgotten dose" notification — the absence of a log is never treated as a failure. This import uses the clinical-processing and AI consents you have already granted (it is a new source for a routine medication data point you already share, not a new category); unavailable to minors and managed profiles. (B) Clinical Records (United States only) — honest conditional note (§3.2, Section 8, and Sections 4, 6, and 9): we have built, and will make available once Apple grants the required authorization (an external process, outside our control, that can take weeks), the read-only import of your own structured clinical records from Apple Health (via FHIR) — lab results (matched via the international LOINC standard), immunizations, medications, conditions/diagnoses already recorded by clinicians, procedures, and allergies — directly into your record, with the same protections as any other data of yours. Free-text clinical notes and insurance/coverage records are never imported. Available only for US accounts; until Apple grants the authorization, the feature stays invisible. No new subprocessor and no new international transfer in either addition. This update triggers re-acceptance (the acceptance screen reappears). Changes (3.10, 2026-07-19): Two new optional, special-category areas (mental health and a reproductive complement), each under its own separate consent — a dedicated bump, with re-acceptance. (A) Mental health from Apple Health (§3.2, Sections 4, 6, and 9): if you log your mood (State of Mind) or answer well-being questionnaires (GAD-7 for anxiety, PHQ-9 for depression) in Apple Health, you may bring them into your record only by turning on a dedicated, separate consent ("Mental health from Apple Health," mind_import, off by default, outside "Accept and continue"). We keep only the daily mood average (a −1 to +1 score; we discard the item-by-item emotions and associations) and, for the questionnaires, only the total score and Apple Health's own classification (we discard the question-by-question answers). This data lives in your record, with a home in the Journal and the "Mental health" system — never on the home screen. Only the weekly mood trend (average and number of days) goes to the AI, descriptively, and only if you have also enabled the Health Diary (daily_journal_ai) — a double consent. The GAD-7/PHQ-9 questionnaires and the ring's stress index are NEVER sent to the AI. No mental-health content appears in notifications. Unavailable to minors and managed profiles. When you revoke, we delete everything (mood and questionnaires). Basis: LGPD Art. 7, I + Art. 11, I; GDPR Art. 6(1)(a) + 9(2)(a); Washington MHMDA (per-category consent); requires iOS 18+. (B) Cycle/reproductive complement (§3.2 and Sections 6.10 and 9): the contraceptive (in use) and lactation states can now contextualize the educational reading of your labs (they shift reference ranges, as pregnancy and menopause already did). They follow exactly the same design as pregnancy: they stay only on your device (Keychain, outside iCloud and backups), are never written to any table of ours nor synced, and go to the AI only transiently, at the moment you run the analysis, to calibrate the reading — they are not stored by us and the AI does not record them as a condition. In addition, cycle deviations from Apple Health (infrequent/irregular cycles, persistent intermenstrual bleeding, prolonged periods) appear as descriptive findings within cycle tracking (under the cycle opt-in you already control), always suggesting a conversation with your gynecologist, without alarm. As already applies to the cycle, the AI chat does not receive cycle data, and none of this becomes a notification. The app still does not import the Apple Health "pregnancy test" and does not import sexual activity. Basis: LGPD Art. 7, I + Art. 11, I + Art. 33; GDPR Art. 6(1)(a) + 9(2)(a) + 44–49; Washington MHMDA. No new subprocessor and no new international transfer. This update triggers re-acceptance (the acceptance screen reappears). Changes (3.9, 2026-07-19): A transparency update (a minor bump, with re-acceptance — anyone who already accepted 3.8 simply confirms they have read this update): we enumerate the new Apple Health and wearable data categories we now import, all under the consents you already granted (clinical + AI + international transfer) — no new subprocessor, no new international transfer. (1) New device/Apple Health data (§3.2): a possible sleep-apnea event and high sound-exposure alerts; home spirometry (FVC/FEV₁/peak flow) and inhaler use; the Oura ring's hypnogram and ideal sleep window; symptoms imported from Apple Health; nutrition data (water, caffeine, energy, macro- and micronutrients); gait (asymmetry, support, step length, stair speed); audiogram (it becomes an audiometry exam in your health record, with no file upload); eyeglass/lens prescription (display only); insulin and alcoholic beverages (display only, never sent to the AI); the ring's vascular age, pulse-wave velocity, and temperature deviation; and standing time, stairs climbed, effort, wheelchair pushes, and the activity's intensity/quality. (2) Oura ring annotations (§3.2 and Section 8) — a correction and clarification: the free text (custom name and comment) is discarded at import and never gets stored; we keep only the standardized category code (e.g., "coffee", "alcohol"), which — aggregated by week and never as free textmay be part of the context sent to the AI when you keep the Health Diary (daily_journal) on. (3) Retention (Section 12.1): we detail that the condensation of daily wearable series (weekly summaries after 13 months; monthly after 36 months) covers the continuous activity, sleep, and environment metrics and the daily continuous-glucose-monitor aggregates — but never manually recorded measurements, point clinical measurements (weight, capillary glucose, blood pressure), nor insulin, alcohol, spirometry, and inhaler use. (4) The nightly sleep reminder may cite the ideal window suggested by Oura, always attributed to Oura (the brand's recommendation, never our advice). (5) We now store a pseudonymous identifier of your WHOOP profile (just a number, never a name or email) to receive real-time update/deletion notices (Section 9). Legal bases indicated in each section. This update triggers re-acceptance (the acceptance screen reappears): anyone who already accepted 3.8 simply confirms they have read it — there is no new mandatory affirmative consent (no new special category, no new subprocessor, no new international transfer). Changes (3.8, 2026-07-18): Consolidated round with six changes. (1) Educational, age-based screening reminders (Section 4): we now use your date of birth and sex at birth — data you already provided at sign-up — to show, as an in-app card (never as a notification), educational reminders about health screenings that population guidelines commonly suggest for your age group; they are generated on your device, by fixed age/sex rules — without using your test results, conditions, or any individual risk assessment —, dismissible one by one and can be turned off. (2) Care team in the analysis (Section 6.11): the context we send to the AI when analyzing your record now includes the name and specialty (and, when you provide them, the institution and the reason) of your Care Team professionals — never phone, email, address, or registration number —, as already happened in chat. (3) Continuous glucose monitor (CGM) glucose (§3.2 and Sections 6 and 8): continuous-monitor days imported from Apple Health are stored only as daily aggregates — mean, minimum, maximum, variability (CV), and the percentage of the day within the 70–180 mg/dL range of the industry display standard (AGP) — and the raw continuous readings are never stored by us; spot/capillary measurements continue as normal measurements; only the aggregates enter the AI context. (4) Oura ring annotations (§3.2 and Section 8): we import the annotations you record in the Oura app (type, custom name, and a free-text comment) under the maximum protection of sensitive data — visible only to you, never sent to the AI, and always deleted when you disconnect Oura; they require an additional Oura permission ("tag" scope): older connections need to be reconnected. (5) AI-generated educational library (Section 6.12): the generic educational content shown in the app may be generated by AI (Anthropic) in a population-level way — one text per topic and language, the same for everyone; the generation receives no data of yours, and the choice of what to show happens on your device. (6) Condensation of wearable series (Section 12.1): raw daily wearable metric series may be condensed after 13 months into weekly summaries (minimum/mean/maximum/count) and, after 36 months, into monthly summaries — a minimization policy; manually entered measurements and clinical measurements (weight, glucose, blood pressure) are never condensed. Legal bases indicated in each section. Triggers re-consent for everyone. Changes (3.7, 2026-07-18): New optional feature for adult female account holdersPregnancy state (§3.2, the Section 4 table, and Sections 6.10 and 9). You declare only your trimester (not pregnant / 1st / 2nd / 3rd / postpartum, with "prefer not to say"); never the date of your last menstrual period (LMP) nor the estimated due date (EDD). The state stays only on your device (Keychain, outside iCloud Keychain and backups), is never written to any table of ours and never synced, expires in about 40 weeks, and is erasable in one tap. It goes to the AI (Anthropic, USA) only transiently, in the request body, when YOU run an analysis or the chat, to calibrate the reading of your labs by the reference ranges specific to pregnancy and lactation — it is not stored by us, and the AI never records it as a condition, alert, or diagnosis. Unavailable to minors and managed profiles. Specific, prominent consent (pregnancy-state-1.0), separate from the clinical consent, covering the international transfer under the DPA/SCC in effect; revocable in Profile › Privacy. Also in this version: the app stopped importing and storing "pregnancy tests" from Apple Health (§3.2 and Section 8) — the mention was removed. Legal basis: LGPD Art. 7, I + Art. 11, I + Art. 33; GDPR Art. 6(1)(a) + 9(2)(a) + 44–49. Triggers re-consent for everyone. Changes (3.6, 2026-07-18): Adjustments to reminders and notices (Section 12-A), with no new data collection: (1) the invitation to come back to the app after a stretch without use (for example, around one and three weeks) now belongs to the neutral service reminders (group 1, pre-enabled) rather than the inference-based group — because what triggers it is only the time since you last opened the app (an app-usage signal, not a reading about your health); the body is neutral, with no health data and no blame, and the reminder remains toggleable in Profile › Notifications. (2) In the Question of the Day (under the "Daily headline", optional), the notice body may become the question itself when it comes from a closed list of everyday, non-sensitive questions (coffee, energy, hydration, a change in routine, how your body responded to yesterday's workout in a generic way) — fixed phrases, the same for everyone, with none of your data, value, or judgment; sensitive questions (alcohol, night context, stress), symptom questions, or ones that would involve medication/appointments or an inference about your data are never shown in full. (3) The analysis-ready notice may state how many exams were organized (a count), never the name or value of any of them; plus new neutral wording in existing reminders. Legal basis for the service items: performing the service/legitimate interest (LGPD Art. 7, V and IX; GDPR Art. 6(1)(b) and (f)); for the inference-based notices: specific consent (LGPD Art. 7, I and Art. 11, I; GDPR Art. 6(1)(a) and Art. 9(2)(a)). Triggers re-consent for everyone. Changes (3.5, 2026-07-17): New optional agenda feature (Section 12-A) — and the first feature in the app that uses your location: with "Alert me when it's time to leave" on, on the day of an appointment that has a time and address, the app estimates your travel time (via Apple Maps, on your device) and alerts you "Time to leave" so you arrive on time. Location is requested only when you turn the option on (iOS "While Using the App" permission), used 100% on your device for the calculation, and never stored, never sent to our servers, and never sent to the AI. Opt-in per device, off by default, revocable in the app or in your iPhone Settings; dependent and managed profiles are excluded; the calculation and the alert are 100% on your device. Legal basis: specific, explicit consent (LGPD Art. 7, I and Art. 11, I; GDPR Art. 6(1)(a) and Art. 9(2)(a)). Triggers re-consent for everyone. Changes (3.4, 2026-07-17): New optional exception to the neutral body of agenda reminders (Section 12-A): the adult account holder may enable, for their own appointments and follow-ups, showing on the lock screen the professional, the time, and a short address they entered themselves (with a map of the destination) — never the specialty, the reason, or a diagnosis. Opt-in per device, off by default, revocable with immediate effect; dependent and managed profiles are excluded; 100% on your device (nothing travels over push). Legal basis: specific, explicit consent (LGPD Art. 7, I and Art. 11, I; GDPR Art. 6(1)(a) and Art. 9(2)(a)). Triggers re-consent for everyone. Changes (3.1, 2026-07-16): AI-assisted support is now active (to draft and translate replies). For logged-in users, it runs only under a new, dedicated, unbundled consent — "Share my support messages with AI assistance" (support_ai_share) — separate from the general AI Processing consent, off by default, refusable on its own (the paid product works fully without it), together with the existing International transfer consent (intl_transfer); a human reviews every draft/translation before it is sent, the support text is best-effort minimized before sending (not de-identification, not a guarantee of complete removal), and your health record is never sent. For people who write to support without an account, it is consent-first: no message goes to AI until the sender grants two separate consents (to process the message, and to transfer it to Anthropic (Claude), in the United States); otherwise a human replies with no AI. The transfer is covered by our existing DPA + EU SCC with Anthropic — the same terms governing record analysis, extraction, and chat — with no new subprocessor. Triggers in-app re-consent. Changes (3.0, 2026-07-15): New optional exception to the neutral notice body (Section 12-A): with the "Daily headline" on, the adult account holder may include, in notices derived from their own data, a small detail of the data — e.g., minutes left to their activity goal, or that they slept above their usual (no "below" variant exists). Closed list of phrases — never a diagnosis, lab value, judgment, or urgency. Opt-in per device, off by default, revocable with immediate effect; dependents/managed profiles are excluded. Also in this version: new closed-list domain headlines (sleep, activity goal, new lab result, partial week, consistency), an appointment-eve notice with the prep summary ready, and a technical sensor-quiet notice. Legal basis: specific, explicit consent (LGPD Art. 7, I and Art. 11, I; GDPR Art. 6(1)(a) and Art. 9(2)(a)). Triggers re-consent for everyone.


In short (read this first)

MyHealth is an iPhone app that helps you organize your own health record, with an artificial intelligence (AI) assistant that reads the documents and photos you upload to extract and fill in records (which you confirm before saving) and offers a supportive educational reading. You bring together your lab results, conditions, medications, vaccines, appointments, measurements, and documents in a single place, and the app builds a timeline of your health to prepare you for the conversation with your doctor.

The most important points:

The full text below details all of this and describes your legal rights.


1. Who we are (the Controller) and the DPO

The party responsible for processing your personal data ("Controller" under the LGPD; "Controller" under the GDPR) is:

BAS AI — BAS ARTIFICIAL INTELLIGENCE LTDA
CNPJ: 64.106.409/0001-70
Website: www.bas-ai.com
Address: Rua Gomes de Carvalho, 911, Vila Olímpia, São Paulo/SP, ZIP 04547-003, Brazil

In this document, "MyHealth", "we", or "the app" refer to this Controller.

Data Protection Officer (DPO)

For any privacy and data protection matter, contact our Officer (LGPD Art. 41 / Data Protection Officer, GDPR Art. 37):

Email: dpo@bas-ai.com
Officer's name: Guilherme Kaschny Bastian
Mailing address: Rua Gomes de Carvalho, 911, Vila Olímpia, São Paulo/SP, ZIP 04547-003, Brazil

We adopt the GDPR standard as our global baseline of protection (the most protective standard, applied to all users), even though the launch does not offer the service in the European Union/EEA or in the United Kingdom.


2. To whom this Policy applies

This Policy applies to everyone who uses the MyHealth app, in any country. The app is global and multi-language (Portuguese, English, and Spanish).

The initial launch focuses on Brazil, but, where the law of your country is more protective, it prevails. We treat the LGPD (Law No. 13.709/2018, Brazil) and the GDPR (Regulation (EU) 2016/679) as our minimum standard of protection everywhere, applied to all users. The app is distributed worldwide, except in the European Union/EEA and the United Kingdom, which are outside the launch.

Users in the United States: US-specific supplementary disclosures — the California Privacy Notice (CCPA/CPRA) and the Washington Consumer Health Data Disclosure (My Health My Data Act) — form part of this Policy as supplementary documents, published at https://www.bas-ai.com/myhealth/legal and prevailing, for residents of those jurisdictions, where they are more specific.

Children and adolescents: self-registration is intended for people 18 or older. Data of minors may only be included by a legal guardian, who manages the dependent's profile (see Section 11).


3. What data we collect

We collect only what is necessary for the app to work (the minimization principle). Below is what we collect and where it is stored.

3.1 Identity data (PII) — encrypted in a vault

The following data identifies you directly and is stored in an identity vault (identity_vault), encrypted field by field with authenticated (AEAD), deterministic encryption (the pgsodium library, AES-256), physically separated from the clinical tables. It is decrypted only by a secure function, under your own identity:

The clinical tables do not contain this data — they refer to you only by a profile code (pseudonym). In the pseudonymized profile we keep only the clinical-demographic minimum needed to interpret the data correctly (for example, biological sex and date of birth/age, important for lab reference ranges).

3.2 Health / sensitive data (PHI)

This is sensitive personal data (health) and receives maximum protection. We collect, as you record or import it:

Electrocardiogram trace (waveform) — optional, only if you turn it on

Up to version 3.16 of this Policy, we did not store your ECG trace: only the classification and the metadata. That changes in this version, and it changes only for those who turn the feature on.

If — and only if — you turn on "Store my ECG trace" (Profile › Privacy), we begin importing from Apple Health, alongside the classification, the trace of the exam: the sequence of voltage measurements your watch recorded. The option starts off; while it is off, nothing changes.

Why we offer it. The trace is what your doctor reads. The classification says "sinus rhythm" or "atrial fibrillation"; the trace is the exam. Storing it lets you take it to your appointment, including an older trace, without depending on still having the same device.

What we do NOT do with it:

For how long. As long as your account exists and you want it — an older exam matters because it allows comparison. The control is yours and it is granular: on the event's record you can delete only the trace and keep the entry (classification, heart rate and date). Turning the option off deletes the traces already imported. When you disconnect Apple Health, the traces are deleted by default. The trace is never summarised or condensed over time.

Why we ask for a separate authorisation. Because the permission you already gave Apple Health does not distinguish "see the classification" from "store the trace" — it is a single authorisation, and it is Apple's, not ours. Data like this does not enter your health record riding on an authorisation given for something else. Turning it off does not disconnect Apple Health.

Daily records of sensitive habits (special category). Beyond what you submit, the app may ask, occasionally and optionally, about habits that devices do not measure: a day's alcohol drinks (substance-use data) and what shaped a shorter night — including the options "Stress" (mental-health data) and "Alcohol". Because they involve a substance and a mental state, we treat these records as sensitive / special-category personal data. This is different from the weekly range of smoking/alcohol you declare at registration (the "Lifestyle habits you provide" item, above), which is part of the AI context when you authorize it: here we mean the daily, point-in-time records, which stay on your device and in your health record and are not sent to the AI.

We only collect them after YOUR specific and prominent consent (the daily_journal purpose, which you turn on in Profile › Privacy & consents), separate from accepting the Terms and from the general clinical consent. It is OFF by default — nothing is recorded until you turn it on —, it is blocked on the server until the consent exists, and it is UNAVAILABLE on minors' profiles and managed profiles (blocked in the app and on the server). Declining it does not reduce any other feature of the app.

Well-being check-in distinction (energy, mood, stress and sleep). The "How are you today?" check-in is handled separately, as health data under the general clinical consent (it does not fall into the sensitive-habit category above). It has four axes that you yourself answer, each on three levels (1 = worse · 2 = average · 3 = better): energy, mood, stress and — only when the app does not receive sleep from your wearablesleep. Like the rest of the health record, these axes may be part of the context sent to the AI under that same clinical consent (together with AI Processing and International Transfer), only as a weekly average per axisnever a single day's answer, never free text. This includes the stress axis, and we want to be explicit: it is your own self-report, of low granularity (three levels), aggregated by week, sent so that the educational reading can cross how you feel with your sleep, your activity and your lab results — always descriptive. The AI is instructed hard: never diagnose anxiety, depression or a "stress disorder", never treat this axis as a clinical instrument, never advise treatment. What does NOT go to the AI, and still does not: entries in the sensitive Health Diary (alcohol doses and stress/evening context, under the separate consent described above) — dated sensitive self-observation entries, more stigmatizing, which is why they have their own consent; your ring's stress index (Oura); and the GAD-7/PHQ-9 questionnaires from Apple Health. The distinction in one line: the check-in axis is an answer of yours, on three levels, that the analysis reads as the week's average; the sensitive Diary is a daily record of substance use and evening context that stays between you and your health record.

What changed in this description (3.14). Up to version 3.13 this paragraph said that "point-in-time stress" stayed out of the AI and described the check-in as being mood only — text written before the check-in gained its own axes. A reasonable reader would conclude that no self-reported stress reached the AI, and the check-in axis did, as a weekly average. The text above is the correct description; the correction is one of the reasons for the re-acceptance in version 3.14.

Other non-sensitive daily contexts. Occasionally and optionally, the app may also ask about lifestyle and wellness contexts that devices don't measure — for example coffee/caffeine, energy levels, hydration, how your workout felt (light/normal/hard), and routine changes during the week (e.g., travel, a new workout, changes in diet or sleep). Like the mood check-in, these are health data under the general clinical consent and are stored in your health record. When you authorize AI Processing and International Transfer (Sections 6 and 9), these contexts are included in the context sent to our AI provider (Anthropic, USA — Section 9) only in weekly aggregated form, as day counts — for example, "low hydration on 3 days of the week" or "3+ coffees on 2 days"; for routine changes, only the category you reported that week (e.g., "travel") — never the individual daily entry, never free text, limited to recent weeks. The sole purpose is to correlate, in an educational and descriptive way, your habits with your sleep, activity, and exam data — never diagnosis or treatment. Entries in the sensitive health diary (alcohol and stress/evening context) are not included: they remain outside the context sent to the AI and under their own separate consent, and any future AI use of them would require new explicit consent.

Your ring's stress index: you see it, the AI does not. If you connect an Oura ring, the daily scores we import (Section 8) include the day's stress index. We show it to you in the "Today's readiness" card, on the Routine tab, in the most conservative way possible: we display the label Oura itself publishes for that day (for example, restful, normal or stressful), exactly as the brand publishes it, always with the date it refers tono translation into a scale of ours, no severity color, no severity ordering, and no calculation of ours: MyHealth never computes a "stress index" from your physiological signals. This index is never sent to our AI provider — not in the analysis, not in the chat, and not inside Oura's resilience sub-scores (the exclusion is applied in the database query itself, not merely as an instruction to the model) —, never enters the PDF Health Report you hand to third parties, never becomes a notification and never appears on a dependent's or a minor's profile. Collection of this index happens under the consent you granted when you connected Oura, revocable at any time (Section 8).

"What appears in the app" — hiding from the screen is different from withdrawing consent. In Profile › Privacy & consents there is a card called "What appears in the app", with one switch per sensitive category you actually have on that profile: Ring stress (your ring's index), Menstrual cycle and Mental health. Turning one off hides that content from the app's screens — and that is all —, with immediate effect and across all your devices (the choice travels with you, not with the device). To leave no doubt: hiding does not disconnect your ring or Apple Health, does not withdraw any consent, does not delete any data, does not stop collection and does not change what our AI provider receives. Collection and use are governed by your consent — the two controls sit on the same screen on purpose, but they are different controls with different effects: if what you want is to stop collection or use, use consent withdrawal (Section 5) or disconnect the source (Section 8). When you hide Menstrual cycle, it also stops being offered in the PDF Health Report — the PDF goes to third parties, and offering to send data you chose not to see would be the opposite of what you asked for. This control does not exist on a dependent's profile or in read-only access. The Ring stress switch hides the line with the ring's index; the "Stress" axis of the check-in (which is your self-report, not the ring's reading) and Oura's Resilience index remain visible — which is why the label names the ring.

When this data refers to a minor in your care, the same protections apply (see Section 11).

3.3 Locality and language (optional, in clear text)

Optionally, to adapt the experience and prepare future features (such as recommending professionals by city), we may store country, state/province, city, and the preferred language. We do not collect a full address, latitude/longitude, or precise location. These locality fields are kept in clear text because the "city" granularity is not, in itself, sensitive data, and they are protected by the same access rules as your account. When you authorize AI Processing (Section 6), your profile's country is part of the context sent to the AI, only to regionalize, in an educational way, emergency guidance and vaccination-calendar guidance (state/province and city are not sent to the AI).

3.4 Account, session, and security data

3.5 De-identified usage data

We collect minimal stability and diagnostics data (telemetry) — crashes, errors, performance — in a de-identified way and without any health content, to keep the app safe and working (see Section 13). This is internal processing: we do not use analytics SDKs or third-party tracking. As a self-limited minimization measure, we retain this telemetry for up to about 12 months (see Sections 12 and 13).

3.6 What we DO NOT collect / DO NOT do


4. Purposes and legal bases

Every processing activity has a legal basis. Because we process sensitive health data, we are especially rigorous: each sensitive purpose is recorded in our consent record with the corresponding legal basis and Policy version.

PurposeWhat it isLegal basis — LGPDLegal basis — GDPR
Clinical processing (clinical_processing)Organize your documents, structure values, build the health record's timeline and trendsPrimary basis: Art. 7, II and Art. 11, II, "a" (specific and prominent consent for sensitive data). Subsidiary basis (only for security, integrity, compliance with a legal obligation, and operating deletion): Art. 7, II and Art. 10. We do not invoke health protection (Art. 11, II, "f")Primary basis: Art. 6(1)(a) + Art. 9(2)(a) (explicit consent for health data). Subsidiary basis (security, integrity, legal obligation, and deletion): Art. 6(1)(c) and (f). We do not invoke Art. 9(2)(h): Art. 9(3) would require a health professional bound by confidentiality in the flow, and there is no doctor in the loop
AI processing (ai_processing)Send the pseudonymized clinical content (without direct identifiers) to the AI (Anthropic) to read the documents and photos you upload and from them extract and fill in records (lab results, medications, vaccines, measurements, professionals — which you confirm before saving), structure the health record, and generate a supportive educational reading (assistant, never diagnostic — see Section 6)Art. 7, I and Art. 11, I (specific consent)Art. 6(1)(a) + Art. 9(2)(a)
Progress reports and follow-up decisionsRecord, in your health record, your own reports about the evolution of a tracked item (report text, keep/close decision, date, and version of the confirmed text), in an immutable trail, and send them to the AI as context marked as your report (see Section 6.9). Operates under the already-active consents (clinical_processing + ai_processing/intl_transfer) — it is not a new consentArt. 7, II and Art. 11, II, "a" (same consent as the clinical core)Art. 6(1)(a) + Art. 9(2)(a)
Sensitive health journal (daily_journal)Collect your daily sensitive self-observation records — alcohol (substance) and stress/what shaped the night (mental health) — as dated points that make up your time series (§3.2). Opt-in, off by default, blocked on the server until the consent exists, unavailable on minors' profiles. These records are not sent to the AI (see Section 6)Art. 7, I and Art. 11, I (specific and prominent consent for sensitive data)Art. 6(1)(a) + Art. 9(2)(a) (explicit consent for a special category)
Pregnancy state (pregnancy-state-1.0)Keep, only on your device (Keychain, outside iCloud and backups), the trimester you declare (adult female account holder), and send it transiently to the AI (Anthropic, USA) only when YOU trigger an analysis or the chat, to calibrate the reading of your labs by pregnancy/lactation ranges. On-device, never written to any table of ours nor to lifestyle_facts, not synced; expires ~40 weeks; erasable in one tap; unavailable to minors/managed profiles; never written as a condition/diagnosis (see §3.2 and Sections 6.10 and 9)Art. 7, I and Art. 11, I (specific and prominent consent) + Art. 33 (international transfer)Art. 6(1)(a) + Art. 9(2)(a) (explicit consent) + Art. 44–49 (transfer)
Contraceptive state (contraceptive-state-1.0)Keep, only on your device (Keychain, outside iCloud and backups), whether you use a contraceptive method and the type (hormonal/non-hormonal) you declare (adult female account holder), and send it transiently to the AI (Anthropic, USA) only when YOU trigger an analysis or the chat, to calibrate the reading of your labs by contraceptive-use ranges. On-device, never written to any table of ours nor to lifestyle_facts, not synced; expires ~24 months; erasable in one tap; unavailable to minors/managed profiles; never written as a condition/diagnosis (see §3.2 and Sections 6.10 and 9)Art. 7, I and Art. 11, I (specific and prominent consent) + Art. 33 (international transfer)Art. 6(1)(a) + Art. 9(2)(a) (explicit consent) + Art. 44–49 (transfer)
International transfer (intl_transfer)When, and only when, necessary, process de-identified data outside Brazil (see Section 9)Art. 7, I; Art. 11, I; Art. 33 (international transfer)Art. 6(1)(a) + Art. 9(2)(a); Art. 44–49
Family sharing (family_sharing)You authorize a family member to read your health record, in a revocable way (see Section 7)Art. 7, I and Art. 11, I (consent)Art. 6(1)(a) + Art. 9(2)(a)
Data of minors in your careOrganize a dependent's health recordArt. 14 (best interest of the child/adolescent; consent of at least one parent or legal guardian)Art. 8 + Art. 9(2)(a), exercised by the legal guardian
Age attestation (age_attestation)You declare you are 18+; registration of a minor under 18 is blocked and the attestation is recorded immutably, with the server's date/timeArt. 14 + Law 15.211/2025 (Digital ECA)Art. 8
Security, fraud prevention, and auditAccess logs, defense against attacks, compliance with legal record-keeping obligationsArt. 7, II (compliance with a legal obligation) and Art. 10 (legitimate interest, limited)Art. 6(1)(c) (legal obligation) and Art. 6(1)(f) (legitimate interest)
App notifications — delivery tokenStore a technical delivery token (push/APNs) and send generic, no-health-data notices (e.g., "your analysis is ready"); operational consent via the iOS notification permissionArt. 7, IX (legitimate interest)Art. 6(1)(f) (legitimate interest)
SENSITIVE-domain notices and manual lock-screen detail (optional — notices derived from a sensitive domain: mental health, cycle/reproductive, substance, medication adherence; and the detail exceptions you enable: medication name, vaccine detail, appointment detail, "time to leave")Decide when to send, or include a detail, from a sensitive domain of your data, or display a specific clinical detail on the lock screen. These run under their own consent, off by default (see Section 12-A), never legitimate interestArt. 11, I (specific, highlighted consent)Art. 9(2)(a) (explicit consent) + Art. 6(1)(a)
SERVICE reminders and summaries (medication/dose, wellbeing check-in, weekly check-in, schedule eve, stock refill, suggested follow-up, come-back invitation after a stretch without using the app; and — since 3.12 — the non-sensitive personalized summaries of your own data: sleep, glucose and time in range, activity, a marker's evolution, the weekly/monthly summary, and the "Daily headline")Deliver, on your device, a neutral (PHI-free) reminder of the service you set up or a descriptive summary of your own health data (never a diagnosis, judgment, cause, efficacy claim, or urgency). Pre-enabled once you allow notifications on iOS; disable-able per type/category in Profile › Notifications (granular opt-out). The decision to deliver rests on performance of the service / legitimate interest; the underlying health data is already processed under your clinical consent (see Section 12-A)Art. 7, V (performance) and IX (legitimate interest), with granular opt-outArt. 6(1)(b)/(f); underlying health data under Art. 6(1)(a) + 9(2)(a) already consented
Technical telemetry / stabilityCrash diagnostics, without health data, in internal processing (no analytics SDK or third-party tracking)Art. 7, IX (legitimate interest), with self-limited minimization (Art. 6, III)Art. 6(1)(f) (legitimate interest)
Account, subscription, and packsMaintain the account and process subscriptions and AI usage packs (measured in pages and prompts). A minor's AI consumption is charged to the guardianArt. 7, VArt. 6(1)(b)
Support and assistanceReceive and reply to the messages you send through the app's support channel (free text that may contain health data you include). AI-assisted drafting/translation of the reply runs only under the dedicated, unbundled "Share my support messages with AI assistance" consent (support_ai_share) — separate from the general AI Processing consent — together with International transfer (intl_transfer), with a human reviewing before sending (see Section 6.7)Art. 7, V (performance of the contract) + Art. 11, I / II, "a" (consent for any health data you include, and the dedicated support_ai_share consent for AI-assisted drafting/translation); retention: as long as the account exists, erased upon deletionArt. 6(1)(b) + Art. 9(2)(a)
Pseudonymized research (opt-in at deletion)Pseudonymized research cohort (only sex, age range, and year, in random cohorts, without profile_id, without free text, and without an exact date) that you may authorize at the moment of deleting your account (see Section 12)Art. 7, II and Art. 11, II, "a" (specific consent); pseudonymized data, not irreversibly anonymous dataArt. 6(1)(a) + Art. 9(2)(a) (explicit consent); cf. Art. 9(2)(j) (research purposes)

Legal basis of the clinical core — clarification. The primary basis for processing your health record is your specific and prominent consent (LGPD Art. 11, II, "a" / GDPR Art. 9(2)(a)), consistent with the "sovereign health record" positioning: you authorize, and you may revoke. We reserve a subsidiary basis only for what consent does not cover — information security, data integrity, compliance with a legal obligation, and the very operation of account deletion —, supported by LGPD Art. 7, II and Art. 10 and by GDPR Art. 6(1)(c) and (f). We do not adopt the health protection ground (LGPD Art. 11, II, "f" / GDPR Art. 9(2)(h)): under the GDPR, Art. 9(3) conditions this ground on the presence, in the flow, of a health professional bound by a duty of confidentiality, and there is no doctor in the loop of MyHealth.

Educational, age-based screening reminders. We use your date of birth and sex at birth — data you already provided in your profile — to show, inside the app, educational reminders about health screenings that international population guidelines commonly suggest for your age group (for example, mammography or periodic blood pressure checks). These reminders are generated on your own device by fixed age/sex rules; we do not use your test results, conditions, or any individual risk assessment to generate them, and they are not delivered as notifications. They are educational content, not medical advice — any decision about testing is always yours and your doctor's. Legal basis: performance of the contract (delivery of the app's educational feature) and, for the use of the already-collected health datum (sex at birth), your consent to clinical processing (LGPD art. 7(V) and art. 11(I); GDPR art. 6(1)(b) and art. 9(2)(a)). You can dismiss each reminder or turn this reminder surface off at any time in your preferences — with no impact on the rest of the app.


5. Consent and how to revoke it

When you authorize a sensitive purpose, that consent is:

Our system only executes an operation if the corresponding consent is active. For example: if you do not authorize "AI Processing", the app does not send anything to the AI — this check happens automatically, on the server (the has_active_consent function), on every operation.

How the record works: each authorization or revocation is recorded as an immutable event in our consent record (consent_events), with the purpose, the legal basis, the language, and the Policy version in effect. Revoking does not erase the consent history — it records a new event that halts future processing of that purpose.

Revocation does not make unlawful processing already lawfully carried out, but it halts the future use of that purpose. You do not lose access to the health record you had already organized.

Sensitive health journal. The daily sensitive collection (alcohol, stress/what shaped the night) has its own consent (daily_journal), off by default: nothing is recorded until you turn it on, and the server blocks writes of these items without the consent active. You may withdraw at any time, just as easily, in Profile › Privacy & consents. When you withdraw: (1) we immediately stop collecting new records; and (2) we delete the alcohol/stress records already collected in those categories.

Hiding ≠ withdrawing. On the same screen as the consents there is a card called "What appears in the app" (§3.2), which hides from the screens the ring's stress, the menstrual cycle or mental health. It is a display preference: it does not withdraw consent, does not stop collection, does not delete data and does not change what the AI receives. To stop the processing, use the withdrawal described in this Section; to cut off the source, disconnect the wearable or remove the permission in Apple Health (Section 8). The two controls sit side by side on purpose — and the screen says, in those words, what each one does.


6. How Artificial Intelligence (AI) processes your data

AI is a central piece of MyHealth (assistant and extraction of data from documents), so we explain it with full transparency. Our AI provider is Anthropic, which acts as a subprocessor.

6.1 The AI receives the clinical content of your health record, without your direct identifiers

6.2 We DO NOT use your data to train AI

6.3 Technical safeguards

6.4 Open standards and vocabularies (LOINC® / UCUM)

So that the same test coming from different laboratories (with different names, abbreviations, and languages) is recognized as a single parameter and produces a coherent timeline, MyHealth normalizes markers using the open vocabulary LOINC® (Logical Observation Identifiers Names and Codes) and standardizes units of measure based on UCUM. These standards are licensed reference content embedded in the app — they work like a dictionary and receive none of your personal data (Regenstrief Institute is not a sub-processor and nothing from your record is sent to it).

This product includes content from LOINC® (loinc.org). LOINC is copyright © 1995–2024, Regenstrief Institute, Inc. and the LOINC Committee, and is available at no cost under the LOINC license (loinc.org/license). LOINC® is a registered trademark of Regenstrief Institute, Inc.

6.5 Organizing medications and supplements (derived data, AI-assisted)

To organize your record, the AI may produce, from the medications and supplements you log, a derived organizational datum: the decomposed active ingredients (a compounded formula is split into its label ingredients) and a general category; the canonical vaccine, the disease prevented, and the dose in the series (consolidating the same vaccine under different names); and the normalized allergen and its class. This datum is generated from what you already provided (we collect nothing new from you) and serves to relate, for example, an active ingredient to the corresponding marker in your lab test. It is educational and AI-assisted — you can review and correct it, and it is not a clinical classification, a prescription, or interaction checking (see the Medical Notice, item 5.2). AI processing details follow Sections 6.1–6.3.

6.6 Document awaiting available quota/usage

When billing is active and you do not have enough available quota or usage at the moment of upload, a document already redacted (after the on-device redaction described in 6.1) may be stored, without analysis, until subscription quota or an add-on pack becomes available — and is then analyzed automatically. The document waits in your own health record, under the same security and access protections as your account; nothing is sent to the AI while the AI Processing consent (ai_processing) is not active and there is no available usage.

6.7 AI-assisted support

When you contact our support and an agent uses AI assistance to draft or translate the reply, the text of your support conversation — which may contain health data you write — may be sent to our AI provider (Anthropic (Claude), United States) only to prepare a draft reply or translate it, which a human agent always reviews before it is sent. The support AI never receives your health record (prontuário) — only the text of your support message.

For logged-in users (in-app support, Profile › Support). This happens only when you grant a new, dedicated consent — "Share my support messages with AI assistance" (support_ai_share), which is separate from, and additional to, the general AI Processing consent (ai_processing): it has its own request, is off by default, and can be refused or withdrawn on its own without affecting anything else — the paid product works fully if you decline. AI-assisted support runs only while both this consent and your International transfer (intl_transfer) consent are active; if either is off, an agent replies without any AI. Before your support text is sent, the app makes a best-effort attempt to minimize identifiers in it — this is not de-identification and not a guarantee of complete removal, so please still avoid including unnecessary data (name, ID document, contacts) in your support messages.

For people who write to support without a MyHealth account (external senders). We do not send your message to AI without your own consent. When you email support, you first receive an email asking for two separate consents: (1) to process your message to prepare a reply, and (2) to transfer it to Anthropic (Claude), in the United States — with a link to our Consumer Health Data Privacy Policy. Only after you grant both does the AI draft or translate a reply for your ticket, which a human reviews before it is sent. If you do not consent, a human replies to you with no AI involved.

Safeguards. The transfer to Anthropic (United States) is covered by our existing Data Processing Agreement and EU Standard Contractual Clauses (SCC) with Anthropic — the same terms that govern record analysis, document extraction, and chat, and that apply to all data we submit to Anthropic's API. Contractual non-training applies. Retention follows Anthropic's own contractual limit (as a rule about 30 days, subject to legal or abuse-prevention exceptions) — this is Anthropic's limit, not a deletion date we guarantee. This adds no new subprocessor: Anthropic is already listed in Section 9.

6.8 Stress and the AI: what goes and what doesn't

The Sensitive Health Journal is NOT sent to the artificial intelligence. Your alcohol and stress/what-shaped-the-night records (the Diary's own consent) stay on your device and in your health record and are not part of the context sent to our AI provider (Anthropic, United States). Any future use of these records by the AI would require a separate, explicit consent ("include my daily records in the AI analysis"), which does not exist in this version. This differs from the non-sensitive daily contexts (coffee/caffeine, energy levels, hydration, workout perception, and routine changes), which are part of the AI context only in weekly aggregated form — day counts and the routine-change category — as described in §3.2.

Your ring's stress index is also NOT sent to the AI. Oura's stress score is excluded in the database query itself, in both the health-record analysis and the chat (a single exclusion list serves both surfaces), and the exclusion also reaches the stress sub-score embedded in Oura's resilience "contributors" — the barrier does not depend on the AI obeying an instruction. It also does not enter the PDF Health Report (§3.2). The same applies to Apple Health's GAD-7/PHQ-9 questionnaires.

What IS sent: the well-being check-in's "stress" axis, as a weekly average. The "How are you today?" check-in — which you answer on three levels, across the energy, mood, stress and (only without wearable sleep) sleep axes — is part of the analysis context under the Clinical processing, AI processing and International transfer consents, only as a weekly average per axis, so that the educational reading can cross how you feel with your sleep, your activity and your lab results. It goes descriptive, with a hard instruction to the model: never a diagnosis of anxiety, depression or a "stress disorder", never a clinical instrument, never treatment advice. Up to version 3.13 this section did not say this — it said only that "point-in-time stress" stayed out of the AI, text that predates the check-in's axes. This is the correct description, and it is one of the reasons for the re-acceptance in version 3.14.

6.9 Progress reports and follow-up decisions

When you record the evolution of a tracked item as your own report (Terms, Section 9.7), we store in your health record the report text, the decision (keep or close follow-up), the date, and the version of the text you confirmed, in an immutable trail (correcting = a new entry). These reports become part of the context sent to the AI explicitly marked as a patient report — the AI is instructed to treat them as a report ("you reported that…"), never as a documented clinical fact, and it is technically prevented (server-side validation, not just an instruction) from closing or superseding an item based on a report without your express decision. All of this operates under the already-active Clinical Processing, AI Processing, and International Transfer consents; the copy sent to the AI follows the same identifier-redaction pipeline as the rest of your record.

Minimization: to record a report, professionals' names are optional — the report works equally well without identifying who made the assessment; we recommend including only what is necessary.

Export and deletion: reports and decisions are part of your health record — they are included in the export and erased upon account deletion, through the same dual-track process of Section 12.

Minors: on minors' profiles, entries are made by the legal guardian, in representation, and the entry identifies the guardian who made it; relevant closures are communicated to the other guardians linked to the profile.

6.10 Pregnancy and contraceptive state (transient, never recorded by the AI)

When you keep the pregnancy state on (§3.2) and trigger an analysis or the chat, the trimester you declared is attached to the body of that request, in memory, only so the AI can calibrate the reading of your labs by the reference ranges specific to pregnancy and lactation. It is not persisted by us in any table, and the AI is instructed — with deterministic server-side output filtering as a backstop (with a regression test) — to never record "pregnant", "expecting", or "breastfeeding" as a condition, alert, problem-list item, summary, or diagnosis in your health record. Automatic/proactive analyses and the large-record (batch) path do not receive this state — it accompanies only the analysis you start. The transfer to Anthropic (United States) is governed by the DPA/SCC already in effect (Section 9), under the pregnancy-state-1.0 consent (which covers the international transfer), and Anthropic retains the request for its own contractual limit (as a rule ~30 days — Section 6.2); we do not store this state.

The contraceptive state (§3.2), when you keep it on, follows the same transient design: it stays only on your device (Keychain, expires in ~24 months) and is attached to the request body, in memory, only when you trigger an analysis or the chat, under the contraceptive-state-1.0 consent (which covers the international transfer). It is not persisted by us in any table, does not go to automatic/proactive analyses nor to the large-record path, and the AI is instructed to never write it as a condition, alert, or diagnosis in your health record. The lactation / postpartum state is the "postpartum" stage of the pregnancy state, under the same treatment above.

6.11 Care team in the analysis context

If you add professionals to your Care Team (for example, the doctor who already follows you), those professionals' name and specialty — and, when you provide them, the institution and the reason for the follow-up — become part of the context we send to the AI when it analyzes your health record, so that the educational guidance can point to the professional you already registered (for example, "worth taking this to your cardiologist already on file") instead of a generic suggestion. We never send the professional's contact details (phone, email, or address) or registration number to the AI; those fields stay only in your record. This is the same handling that already happens when you chat with the AI. The legal basis and international transfer are the same as for the rest of the AI processing described in this section.

6.12 AI-generated educational library (generic, population-level content)

Beyond the personalized reading, the app shows a library of educational content about markers, measurements, and conditions (for example, "what ferritin is" or "what a value above the range usually means"). This content may be generated by AI — by the same provider (Anthropic) and with the same provenance as Sections 6.1–6.3 — but in a generic, population-level way: each text is produced once per topic and language and is the same for every user of that topic. The generation receives no data of yours: the AI receives only the abstract coordinate of the topic (the marker/measurement/condition name from our catalog and generic direction, range, and population-group categories) — never your value, your result, your dates, or any identifier. Personalization happens only in the selection: the app uses your data, on your device, solely to choose which generic texts from the library are relevant to show you. The content itself is not an individual analysis of your case — it is population-level educational material, available regardless of the AI Processing consent (which governs the personalized reading), and subject to the same non-diagnosis rule as the rest of the app (see the Medical Notice).


7. Family sharing (opt-in, read-only, revocable)

MyHealth lets you share your health record with a family member, in a controlled way:

The family member must also be a user of the app. This sharing is between you and the person you choose — it is not sharing with third parties or for commercial purposes.

7.1 Item-by-item sharing of hereditary conditions

In addition to the read-only link above, you may choose, item by item, to offer health conditions tracked in your record (for example, a diagnosis and its year of onset) to linked family members, so they can add them to their own family history. How it works:

Legal basis: processing based on your specific, highlighted consent (LGPD art. 11, II, "a"; GDPR art. 9(2)(a)) and, where applicable, upon a valid authorization under the My Health My Data Act (Washington/USA). The incorporated item is treated as sensitive data of the recipient themselves throughout the pipeline (including AI, export, and erasure), under the recipient's own active consents.

7.2 Manager authorized by you (delegation by an adult)

Upon your specific, highlighted consent (LGPD art. 7, I and art. 11, I; GDPR art. 9(2)(a); for Washington/USA residents, the separate consent required by the MHMDA), an adult you designate (the "Manager") may access and record data in your health record. How this processing works:


8. Apple Health (HealthKit)

MyHealth lets you import measurements from Apple Health (HealthKit) — weight, height, body composition, blood glucose, blood pressure, heart rate, saturation, and temperature, plus day-to-day metrics when your device offers them, such as sleep breathing disturbances, time in daylight, and mindfulness sessions — and, when you authorize them in the iOS permissions, also menstrual cycle and reproductive health data (menstrual flow, intermenstrual bleeding, ovulation tests, cervical mucus quality) into your health record. We do not import sexual activity records.

Continuous glucose monitor (CGM) glucose — daily aggregates only. When importing glucose from Apple Health, days with a continuous glucose monitor (hundreds of readings) are summarized on your own device and stored only as daily aggregates — mean, minimum, maximum, variability (CV), and the percentage of the day within the 70–180 mg/dL range of the industry display standard (AGP); the raw continuous readings are never stored by us. Spot measurements (capillary/manual) continue to be stored as normal measurements, with date and time (see §3.2).

Cycle patterns (its own opt-in, off by default). If you turn it on in Profile › Privacy, the app can show your logged cycle days alongside your charts (sleep, heart) and observe local, descriptive patterns (for example, how your sleep behaves on logged menstruation days). It is a composition, on your device, of data you already see: none of it becomes a notification, nothing is sent to the AI beyond what you already authorized, and the app never calculates or predicts fertility/ovulation. Unavailable on dependents' profiles; revocable at any time (the pattern simply stops being shown).

Medication adherence (iOS 26 or later). See the summary in §3.2 — the app can import, from Apple Health, medication doses marked as taken, matched to a medication you have already registered; it is adherence memory for you, never surveillance, and never generates a missed- or forgotten-dose notification.

Clinical Records (United States only, conditional availability). See the summary in §3.2 — the read-only import of your structured clinical records (lab results, immunizations, medications, conditions, procedures, and allergies) via FHIR depends on an authorization only Apple can grant and is available only for US accounts; until that authorization exists, the feature stays invisible and inactive in the app.

Connecting smart bands and rings (Oura and WHOOP)

In addition to Apple Health, you may, optionally and revocably, connect third-party wearables, with specific consent per provider (wearable_sync_oura, wearable_sync_whoop):

The authorization uses OAuth: the access tokens are encrypted (AES-256-GCM) on our server and are not accessible by the app. Oura operates in Finland (European Economic Area) and WHOOP in the United States; connecting these services involves an inbound international transfer, under the safeguards in Section 9.1. Oura and WHOOP act as data sources (independent controllers of their own platforms), not as our subprocessors, and do not receive data from your health record.

When you disconnect a wearable:

Data imported from wearables and from Apple Health is always recorded in your own health record (account holder) and never in a dependent's profile, even if you are viewing a minor's profile.


9. Subprocessors and international transfers

We do not sell your data. To operate the service, we use a minimal set of vendors ("subprocessors"/"processors"), each under a data processing agreement (DPA) in effect, confidentiality, and security, processing data only under our instructions. The three subprocessors below have DPAs/SCCs in effect: Supabase (signed 2026-06-18), Anthropic (via Commercial Terms, 2026-06-17), and Resend (via EU-US DPF + SCC, 2026-06-17).

SubprocessorWhat it doesWhat data it processesWhereSafeguards
SupabaseDatabase (PostgreSQL), authentication, document storage, and edge functionsPseudonymized clinical data; encrypted PII in the vault; encrypted documents; account metadataSão Paulo, Brazil (sa-east-1)DPA in effect (signed 2026-06-18; Supabase Pte. Ltd) — includes EU SCCs + transfer safeguards (UK/Switzerland); SOC 2 Type 2 + ISO 27001 (Supabase provider certifications); daily backups (14 days); 28-day log retention; encryption in transit (TLS) and at rest; additional field encryption under our key management; isolation via RLS; SCC for any transfers outside the EEA
Anthropic, PBCAnthropic's AI models for health-record analysis, document extraction, chat, and generation of the generic educational library (for the latter, it receives only the abstract topic coordinate — never data of yours; see Section 6.12)Pseudonymized clinical content (values, dates, notes, lifestyle habits, cycle, wearable aggregates — for continuous glucose monitoring, only the daily aggregates, never the raw readings —, the name and specialty (and, if provided, the institution and reason) of your Care Team professionals — never their contact details or registration number — and non-sensitive daily contexts in weekly aggregated form — day counts and routine-change categories, never the individual daily entry; the free text of your wearable annotations is discarded and never sent, and only their standardized category code — never free text, aggregated by week — may be sent when you keep the Health Diary (daily_journal) on — see §3.2) plus sex, age, country, and year of birth (without day/month)without direct identifiers and without emergency contacts — and, in document analysis, the redacted copy of the image/PDF (best-effort on-device redaction of printed identifiers, when located) — transiently; and, when an agent uses AI-assisted drafting in support, the text of your support conversation (never the health record); and, when YOU trigger an analysis or the chat with the pregnancy state on, the self-declared trimester (enum) you consented to (pregnancy-state-1.0) — and, likewise, the self-declared contraceptive state (enum) you consented to (contraceptive-state-1.0), when on — transiently, only in the request body, never stored by us (§3.2 and 6.10)United States (international transfer)DPA in effect (via Anthropic's Commercial Terms, 2026-06-17) + SCC; contractual non-training; limited retention (~30 days); TLS
ResendSending transactional emails (access code/OTP and account notices)Only your email address and the email body; no PHI / no health contentUS / globalDPA in effect (2026-06-17) via EU-US DPF + SCC; TLS. For those who choose "Hide My Email" in Sign in with Apple, transactional emails are delivered through Apple's private relay (@privaterelay.appleid.com) and we do not see your real email
Apple (App Store / In-App Purchase / HealthKit / push)Distribution, HealthKit, notifications, and payment processing for subscriptions and add-on packs as merchant of recordPurchase/receipt data; we do not receive your card data; no health content in the payment flowUS / globalApp Store Terms; Guideline 5.1.3

Oura and WHOOP do not appear in this table: they are data sources that you connect (Section 8), acting as independent controllers of their own platforms, and not as our subprocessors. Apple acts as an independent controller for distribution, HealthKit, push, and payments. The DPAs and Standard Contractual Clauses (SCC) of our three subprocessors (Supabase, Anthropic, and Resend) are in effect, as indicated in the "Safeguards" column. We maintain a public subprocessors page kept up to date at https://www.bas-ai.com/myhealth/legal/subprocessadores. We will give notice before adding a relevant new subprocessor.

9.1 International transfers

Your health record is stored in Brazil (São Paulo) — that is the rule. Transfers outside Brazil occur in a limited way and with your authorization (intl_transfer): in AI processing (Anthropic, United States — Section 6), in which we send the clinical content without your direct identifiers (in document extraction, the file itself — after a best-effort on-device automatic redaction that attempts to cover name, tax ID, email, and phone; identifiers not located may remain in the file); in the connection of wearables (Oura, in Finland/EEA; WHOOP, in the United States — Section 8); and in distribution by Apple (United States). When there is an international transfer, we adopt the required safeguards:

We may also disclose data when required by law (court order or competent authority), always limited to what is strictly necessary and, where legally permitted, notifying you.


10. Information security

The confidentiality of your health data is our number one control. The main measures:

We seek alignment with the best international practices for health information security. No system is 100% immune; that is why we maintain incident response plans (see Section 14).


11. Data of children and adolescents (minors)

The protection of children and adolescents follows the Statute of the Child and Adolescent (Law 8.069/1990), Law 15.211/2025 (Digital ECA), Art. 14 of the LGPD, and Art. 8 of the GDPR (EEA).

We adopt, in any country, a single 18-year-old threshold for a self-owned account. This requirement refers to account ownership and is not to be confused with the GDPR's age of autonomous digital consent (Art. 8, between 13 and 16 years old depending on the country). Below 18, data processing only occurs through a profile managed by an adult guardian.

Users in the United States (COPPA): MyHealth does not offer accounts to minors and does not collect data directly from children. Any minor's data is entered and controlled by a responsible adult, who exercises verifiable parental consent.

Sensitive journal unavailable to minors. The daily sensitive collection (alcohol, stress) is not performed on minors' profiles or on profiles managed by a guardian — blocked on the client and on the server. It is a feature exclusive to adult account holders (18+). Under no circumstances do we collect alcohol/stress records from minors.


12. Retention and disposal

We adopt the minimization principle: we keep each category of data only for as long as needed for its purpose or required by law. Because MyHealth is distributed worldwide, we apply the most protective standard among the applicable laws: by default, deletion erases your identity and health record, and retention is the exception, triggered only when a concrete law requires it or to enable fraud prevention and response to authorities. The only exception that survives deletion for every account is a minimum forensic index — search identifiers as irreversible codes (HMAC) + recent IPs, with no health data —, described in 12.2.

12.1 Retention periods

CategoryPeriodWhy
Health record and identity vault (clinical data + PII)As long as your account exists; removed upon account deletion (see 12.2)You keep the health record organized for as long as you want
Daily wearable / Apple Health series (daily imported metrics — e.g., steps, SpO₂, walking heart rate, activity and environment, nutrition data, gait, and the daily continuous-glucose-monitor (CGM) aggregates; never manually recorded measurements, point clinical measurements — weight, capillary/spot glucose, blood pressure —, nor insulin, alcohol, spirometry, or inhaler use)Daily detail for 13 months; after that, the daily points may be condensed into weekly summaries (minimum, mean, maximum, and count) and, once older than 36 months, into monthly summaries — a granularity exception to the row above: the history remains in your record as a summaryMinimization / storage limitation (LGPD Art. 6, III; GDPR Art. 5(1)(c) and (e)) — our own minimization policy, not a legal deadline
Access / audit logs (access_log — date/time, source IP, action; never clinical content)6 monthsSecurity and detection of fraud/abuse (a proportionate measure — legitimate interest, GDPR Art. 6(1)(f); LGPD Art. 7, IX). In Brazil, it also meets the floor of the Internet Civil Framework (Law 12.965/2014, Art. 15) for an application provider. The log (date/time + IP) is not health data and the IP is never used to infer a health condition
Minimum identity retained upon deletion (encrypted name + encrypted email + creation date + last access date)Only where there was a transaction (subscription or packs purchased); for the tax period of your jurisdiction (Brazil, United States, and other countries: 5 years; United Kingdom and Canada: 6 years; European Union: 10 years), with automatic purging at the end. For anyone who never transacted: none of this is retained — the identity is erased upon deletionTo comply with a tax/accounting obligation that arises only from a real transaction (Brazil: Tax Code (CTN), Arts. 173 and 174; United States: IRS rules; European Union: the Member State's period; United Kingdom: Limitation Act 1980 / HMRC; Canada: Income Tax Act s. 230). Without a transaction, there is no legal obligation that justifies keeping the identity
Billing and tax data (receipts, subscription and pack movements)Tax period of the jurisdiction (Brazil: 5 years) — only for those who transactedTax periods (Brazil: Tax Code (CTN), Arts. 173 and 174; or the applicable local tax law)
De-identified technical telemetryUp to about 12 monthsInternal minimization policy (LGPD Art. 6, III) — not a legal period
Consent records (consent_events, de-linked / pseudonymized from your profile upon deletion — the identifier is replaced by an HMAC code whose key is kept outside the database)Kept as proof of lawfulness for the applicable limitation periodTo prove lawfulness and the authorizations granted/revoked (accountability — GDPR Art. 5(2)/7(1); LGPD Art. 8/6, X)
Minimum forensic index retained upon deletion (account_forensic_hold — search identifiers as an irreversible HMAC code — email, Sign in with Apple identifier, phone, national ID — + recent IPs; never readable name/email or clinical content)Applicable limitation period for exercising/defending rights and responding to authorities — set by default, as a proportionate measure, to the same duration as the fiscal retention period (5 years Brazil/US/others; 6 years United Kingdom/Canada; 10 years European Union), with automatic purging at the endFraud prevention and response to a request from a competent authority within the period — legal obligation and exercise of rights (LGPD Art. 16, I — legal obligation to comply with an order/authority —, Art. 7 VI — defense in proceedings — and Art. 7 IX — fraud prevention, secondary use under an LIA; GDPR Art. 6(1)(f) and Art. 17(3)(e)). Break-glass access restricted to the top responsible person, with a mandatory reason and immutable audit

How identity is protected when retained: when there is a transaction and tax law requires retention, we keep the name and email encrypted (the same protection as the identity vault), in an isolated table, accessible only by the internal service (RLS, no user access), and we delete it automatically at the end of the period. We do not keep your email in readable text.

Retention of the sensitive journal. While the consent is active and the account exists, the Sensitive Health Journal records (alcohol, stress/what shaped the night) remain in your health record. When you withdraw the consent, they are deleted; when you delete the account, they follow the dual-track deletion (Section 12). There is no tax retention of this data.

12.2 Permanent account deletion (right to erasure — LGPD Art. 18, VI / GDPR Art. 17 / local equivalents)

Deletion is available directly in the app, under Profile › Privacy › Delete my account (an Apple requirement). Upon confirmation, we execute the permanent cascade removal — an immediate operation — of all of your clinical health record (lab results, conditions, medications, vaccines, documents, measurements, history, appointments, conversations with the AI, wearable data) and of the files in storage, we revoke the wearable connections, and we close your access account.

Managed dependents and guardianship migration. Deleting your account also erases the data and files of the dependents you manage (minor profiles in your care). Before completing, if a minor has another guardian already linked, the app offers to migrate that minor's guardianship to the existing co-guardian — so the minor's profile survives with them, instead of being erased. If you choose not to migrate, the dependent's profile is removed together with your account. In any case, we never retain the minor's name or email for tax reasons (see below).

The backups may, for a short period, still contain data already deleted: they are overwritten in our processor's normal cycle (Supabase, around 14 days — well within the 6 months), and the data processing agreements (DPAs) with Supabase and Anthropic govern the disposal of any residual copies. (We do not claim "key destruction" or instant backup purging.)

The deletion of your identity depends on whether or not you made a purchase:

Deletion receipt (accountability — LGPD Art. 6, X): we can confirm the completion of the deletion upon request to the DPO. The deletion is not total — the minimum records below remain, by legal requirement.

Minimum forensic index that survives deletion (all accounts). At the moment of deletion, and for any account — including minors' profiles and deletions you perform yourself —, we keep a minimized forensic index, in an isolated, shielded table (no user access and no access by ordinary operations staff), containing at most: (a) irreversible codes (HMAC) of your search identifiers — email, Sign in with Apple identifier, phone, and national ID — which do not allow recovering the original value and serve only to confirm an exact match when an identifier is presented to us; (b) the IP addresses of your recent accesses; and (c) the pseudonymous account identifier (account_ref) and minimal retention metadata (creation/deletion dates, jurisdiction, and period). This index contains no health data, no readable name or email, and no content from your health record. It is pseudonymized data — it remains personal data (LGPD Art. 12 and 13), retained on the basis of Art. 16, I; we do not invoke anonymization (Art. 16, IV). Purpose: fraud prevention and response to a request from a competent authority — for example, answering "which accounts were associated with this email, Apple ID, or IP" — within the period. Legal basis: compliance with a legal obligation and exercise of rights (LGPD Art. 16, I — legal obligation to comply with an order/authority — as the primary basis for survival, Art. 7 VI — defense in proceedings — and Art. 7 IX — fraud prevention, secondary use under an LIA; GDPR Art. 6(1)(f) and Art. 17(3)(e)). Period: the applicable limitation period for exercising/defending rights and responding to authorities — set by default, as a proportionate measure, to the same duration as the fiscal retention period (5 years Brazil/US/others; 6 years United Kingdom/Canada; 10 years European Union) —, with automatic purging at the end. Access: restricted, "break-glass" type, reserved for BAS AI's top responsible person (owner), always with a mandatory reason and an immutable (tamper-evident) record of each lookup; the key that generates the HMAC codes is kept in a vault (Vault), encrypted by a root key managed outside the database, and never exposed. Accounts deleted before this version took effect do not have this index.

What always remains after deletion, for any user:

Dependent profiles (minors): when deleting a minor's profile, we never retain the minor's name or email for tax reasons — the tax obligation, if any, belongs to the paying guardian, not to the minor's profile. For the minor, erasure of the identity is the rule; only the minimum deletion record by irreversible code and the minimum forensic index (search identifiers as irreversible HMAC codes + recent IPs, with no health data of the minor) remain, retained for a reduced period, proportionate to the fraud-prevention purpose (never the fiscal period, which does not apply to a minor who does not transact), subject to a proportionality assessment and to the best interests of the child, under the same audited break-glass access — and subject to DPO sign-off.

Users in jurisdictions with a reinforced right to deletion (e.g., Washington — My Health My Data Act): we treat the request as deletion of consumer health data — we erase the identity and all consumer health data (without invoking the tax period against anyone who did not transact), and the disposal of residual copies at the processors occurs within 6 months, in accordance with the respective data processing agreements (DPAs). The minimum forensic index above is not consumer health data: it holds only account identifiers as irreversible codes (HMAC) and IPs, for fraud prevention and response to authorities — a distinct purpose and category from the health data, which is erased.

12.3 Deleting an exam from your health record (right to erasure, item by item)

In addition to deleting the entire account (12.2), you can remove a specific exam at any time, on the document's own screen. The app offers two options, and the difference matters:

Under either option, the readings our AI had written from that exam are deleted, and the follow-ups that were born from it are closed — the follow-up entry remains, recorded as closed and with the reason, so that your history does not lose the thread.

What happens to the file and to the record. The exam record is deleted from the database immediately and in a single operation — the entry ceases to exist; it is not a "hidden" flag. The file is removed from storage: the app removes it immediately and, if that removal fails for any reason, the server repeats it on its own, in sweeps every 15 minutes, until it is done. The file name does not survive either: it is replaced by an irreversible code, because the name is chosen by you and can, on its own, reveal the finding. (There is a distinct case: a document the app could not prepare may be deleted in a way that is reversible for a period — when that is the case, the screen itself says so in those words. The deletion described here, performed on the exam's screen, is permanent.)

The analysis of your health record stops resting on the removed exam. The next analysis is redone without the memory of the previous one: it rebuilds the conclusions from what the remaining record supports — otherwise, a finding from the deleted exam could be restated indefinitely. This rebuild is prioritized: removing an exam counts as a relevant change and enters the next sweep, which happens every few minutes; in exceptional situations (for example, when your plan's daily processing limit has already been reached) it may be postponed by a few hours. We record the moment the redone analysis is published.

Two honest caveats about that interval. First: until the new analysis is ready, the text of the previous analysis remains displayed, and it may still mention the removed exam — the file and the record, however, were gone from the very first moment. Second: if the rebuild returns no conclusions, we prefer to keep the previous reading rather than empty your health record; in that case it may reflect the removed exam until a later analysis replaces it. Earlier conversations with the assistant also remain in your conversation history until you delete them.

What remains, and why. We keep the act, never the content: the record that a removal occurred, when, who requested it, and which of the two options was chosen, with a receipt that keeps counts only — how many markers, medications, vaccines, measurements, professionals, appointments, and follow-ups were affected. We do not keep the title, the date, or any content of the removed exam, for the obvious reason that a title is already health data. This is what lets us explain the effect of the removal to you without retaining what you told us to delete (accountability — LGPD Art. 6, X; GDPR Art. 5(2)). If the exam was still being processed when you removed it, the working data from that preparation is discarded automatically within 24 hours — 30 days when the processing had ended in error, so that the failure can be investigated. The access logs — date/time, action and, when available, the IP address — never keep the exam's content and follow the period in Section 12.1.

Backups: the same conditions as Section 12.2 apply — the copies are overwritten in the processor's normal cycle and the data processing agreements govern the disposal of residual copies.

12.4 Death of the data subject

The LGPD and the GDPR protect living persons and, as a rule, do not reach the deceased (ANPD, Technical Note No. 3/2023; GDPR, Recital 27). Even so, a deceased person's health record involves personality rights that survive death (Civil Code, Art. 12, sole paragraph) and matters of succession.


12-A. Notifications and reminders (opt-in)

MyHealth may send reminders on your iPhone — about medication, a wellbeing check-in, a weekly check-in (optional, once a week — a neutral, fixed-text invitation to log what the app can't see on its own, such as activity, symptoms, or energy; it never carries health data or inference; you can turn it off whenever you like), your schedule (appointments/tests/follow-ups/vaccines), an invitation to come back to the app after a stretch without use, and a few server-side notices (when an analysis is ready, when one of your exams is updated, when a follow-up appointment is approaching, when support replies to your message, and — optional, off by default — when your data — e.g., sleep, resting heart rate — brings something new). Since version 3.12, these notices may also carry, in the body, a summary of your own health data (for example, last night's sleep and how it compares to your average, your glucose average and time in range, your activity and milestones, a lab marker's evolution, or a weekly/monthly summary) — always descriptive, on your own device, and disable-able category by category (see "Personalized summaries of your data"). Key points:

13. Cookies, telemetry, and tracking

MyHealth is a native iPhone app (not a website), so it does not use browsing cookies in the traditional sense.

Today we do not use any third-party analytics or tracking tool; if that changes, we will update this Policy and the subprocessors page before activation, with a new notice — also reviewing the App Store privacy labels and the need (or not) for App Tracking Transparency (ATT).


14. Security incidents and notification

We maintain incident response plans. In the event of a security incident that may create relevant risk to you:


15. Your rights

You are the owner of your data and have rights guaranteed by the LGPD (Art. 18) and the GDPR (Chapter III):

RightWhat it meansHow to exercise it in MyHealth
Access / confirmationTo know what data we hold and obtain a copy (LGPD Art. 18, I–II; GDPR Art. 15)View the full health record in the app; export it
CorrectionTo correct incomplete or wrong data (LGPD Art. 18, III; GDPR Art. 16)You review and edit the data directly
Deletion / erasureTo delete your data and account (LGPD Art. 18, VI; GDPR Art. 17)Delete account / data in the app (see Section 12)
PortabilityTo take your data in a structured, interoperable format (LGPD Art. 18, V; GDPR Art. 20)Export in FHIR R4 and as PDF
Consent revocationTo withdraw an authorization (LGPD Art. 8, §5; GDPR Art. 7(3))Turn off a purpose (e.g., "AI Processing") in the settings (see Section 5)
Information on sharingTo know with whom we share (LGPD Art. 18, VII)This Policy (Section 9) and the subprocessors page
Objection / restrictionTo object to a processing or request its restriction (LGPD Art. 18, §2; GDPR Art. 18 and 21)Contact the DPO
No subjection to automated decision / reviewThe AI does not decide anything on its own (LGPD Art. 20; GDPR Art. 22)You always review and confirm (see Section 6.3)
View the access historyTransparency about who accessed whatYour access log is available
Petition to the authority (ANPD)To petition against the controller before the national authority (LGPD Art. 18, §1)Contact us (Section 1) and/or the ANPD — see "Complaints" below

How to exercise: many rights are exercised directly in the app (review, export, delete, revoke consent). For the others, or if something does not work, write to our DPO (Section 1). We respond within the legal period (as a rule, up to 15 days for confirmation of existence or access, under the LGPD; up to 30 days under the GDPR, extendable where the law permits).

Complaints: if you believe we process your data improperly, you can complain to the competent authority — in Brazil, the ANPD (https://www.gov.br/anpd); in Europe, the data protection authority of your country. We ask, however, that you talk to our DPO first — we want to resolve it directly with you.


16. MyHealth is NOT a medical service


17. Changes to this Policy and versioning

We may update this Policy to reflect changes in the app, in vendors, or in the law. The Policy has a version (policy_version):

The version history is published at https://www.bas-ai.com/myhealth/legal/versoes; each accepted version remains archived.


18. Contact us

Questions, requests, or complaints about your data:


MyHealth — your health record, sovereign and private. This Policy was drafted in Portuguese as the basis for translation into the app's other languages (at least PT/EN/ES). In case of divergence between versions, the Portuguese prevails.