Privacy Policy

Your health data is yours. Here's exactly what we collect and why.

Last updated: July 2026

Health Partner ("the app") is developed and operated by Shreyansh Jain ("we", "us"). This policy explains what data the app collects, how it's used, who it's shared with, and how you can delete it.

1. Information We Collect

  • Account information: name, email address, password (stored as a salted hash, never in plain text), date of birth, gender, and dietary preference.
  • Health & activity logs you enter or sync: food entries, workouts, sleep sessions, water intake, body measurements, lab/health values, daily activity (steps, active minutes, distance, calories) synced from Apple Health (iOS) or Google Health Connect (Android) with your permission, and your personal goals.
  • Photos you attach: food photos, workout screenshots, medical report images, and your profile photo — stored in a private cloud bucket (AWS S3), never made public.
  • Mind journal entries: encrypted on your device before they're ever sent to our server — see Section 3.
  • Reading activity: the books you add, your progress, and any notes you write in the Books tab.
  • Push notification token: a device identifier used only to deliver reminders to your device.
  • Technical data: IP address, request timestamps, and basic device metadata, logged for security and debugging.

2. How We Use This Information

  • To show you your own activity, history, and trends inside the app.
  • To schedule and deliver your hourly walk reminders and other notifications.
  • To calculate your daily health score against the goals you set.
  • To keep your account secure (login, single active session enforcement).
  • To let you optionally connect your account to Claude or another MCP-compatible AI client so it can read or log entries on your behalf — see Section 4.

We do not run ads, do not use third-party analytics or ad-tracking SDKs, and do not use your data to train any model.

3. The Mind Journal Is Encrypted End-to-End

Mind entries are protected by a passphrase you choose, which is separate from your account password and never leaves your device. Your device derives an encryption key from that passphrase and uses it to encrypt every entry with AES-256-GCM before syncing it. Our server only ever stores the resulting ciphertext — we have no technical ability to read your journal, even if compelled to try. If you forget your passphrase and don't have your recovery key, those entries cannot be recovered by us or anyone else.

4. Who We Share Data With

We do not sell your data, and we do not share it with advertisers. Data is only shared with:

  • Amazon Web Services (S3): stores your uploaded photos and journal ciphertext, in a private bucket we control.
  • Google Firebase Cloud Messaging: delivers push notifications to your device using your device's push token. Firebase does not receive your health data — only the token and notification text.
  • An AI client you connect via MCP — only if you turn this on: the app speaks MCP (Model Context Protocol), an open standard, so you can optionally connect your account to Claude or any other MCP-compatible AI client to read or log your health data through an OAuth connection you explicitly authorize. If you never set this up, no data is ever shared this way. You can revoke access at any time by changing your password, which invalidates the connection.
  • Legal requirements: if required by law, court order, or to protect against fraud or abuse.

5. Data Retention

We keep your data for as long as your account exists, so the app can show you meaningful history and trends. If you don't use the app, your data is simply kept as-is — we don't auto-delete inactive accounts.

6. Deleting Your Account and Data

You are always in control of deletion:

  • In the app: go to Profile → Delete My Account, confirm your password, and your account plus every record tied to it (food, workouts, sleep, water, physical data, lab values, goals, journal entries, books, photos, push tokens, and your profile) is permanently and irreversibly deleted within seconds.
  • Without the app installed: see healthpartner.shrynshjn.com/delete-account for how to request deletion by email.
Deletion is permanent. There is no recovery window and no backup copy kept for restoration purposes.

7. Security

  • Passwords are hashed with bcrypt and never stored or logged in plain text.
  • All API traffic is authenticated with short-lived JWTs; a new login on another device invalidates the previous session's token.
  • Photos and files are stored in a private S3 bucket, never publicly listable.
  • Mind journal content is end-to-end encrypted as described in Section 3.

8. Children's Privacy

Health Partner is not directed at, and should not be used by, children under 13. We do not knowingly collect data from children under 13.

9. Changes to This Policy

If this policy changes materially, we'll update the "Last updated" date above and, where appropriate, notify you in the app.

10. Contact Us

Questions about this policy or your data: privacy@healthpartner.shrynshjn.com

© Health Partner. Made by Shreyansh Jain.
Home Blog AI Terms of Service Contact Delete My Account