Legal
Last updated: December 4, 2024
Your privacy matters to us. This policy explains how we collect, use, and protect your personal and health information in plain language.
Here's the short version of what you need to know about your data:
We Protect Your Data
All your health information is encrypted using AES-256 encryption, both in transit and at rest.
We Never Sell Your Data
Your personal and health information is never sold to third parties. Period.
You're In Control
Access, download, or delete your data anytime. It's your information.
We Follow The Rules
We comply with GDPR, HIPAA, and other privacy regulations to keep you protected.
We collect information you provide directly and data from connected services to power your personalized wellness experience.
To provide personalized insights, we collect health data including:
When you connect third-party services, we receive data from:
We use your information to provide, personalize, and improve your wellness experience:
We only share your data in these specific circumstances:
We work with trusted partners who help us operate the platform:
All service providers operate under strict agreements and use data only for authorized purposes.
We may disclose information when required by law, court order, or to protect health and safety in emergencies.
We implement industry-leading security measures to keep your health information safe:
Encryption
AES-256 encryption at rest and TLS 1.3 in transit protects all your data.
Access Controls
Role-based permissions and multi-factor authentication keep access secure.
Audit Logging
All data access is logged with timestamps, providing a complete audit trail.
Regular Testing
Quarterly security audits and penetration testing ensure ongoing protection.
You have full control over your personal data. Here's what you can do:
Request a complete copy of all personal data we hold about you.
Fix any inaccuracies in your personal information.
Request deletion of your account and associated data.
Download your data in machine-readable formats (JSON, CSV, PDF).
Limit how we use your data while we address your concerns.
Opt out of certain data uses including marketing.
Change your mind about data processing at any time.
We keep your data only as long as necessary to provide our services:
We retain all your health data to power your personalized experience.
After account deletion, data is retained for 30 days in case you change your mind.
After 30 days, all personal data is permanently deleted. Encrypted backups are purged within 90 days.
Anonymized audit logs are retained for 6 years for HIPAA compliance.
Your data is primarily stored and processed in the United States through our cloud infrastructure providers (Vercel, AWS).
Questions about this Privacy Policy or your data? We're here to help.
privacy@optimal-os.co
support@optimal-os.co
Optimal Health Ltd.
Privacy Office
London, UK
We may update this Privacy Policy from time to time. When we make material changes, we'll notify you via email and with a prominent notice in the app. Your continued use after changes become effective constitutes acceptance of the updated policy.
Was this page helpful?