Privacy Policy

Last Updated: April 18, 2026

1. Introduction

Ai1Health ("we," "our," or "us") is committed to protecting your privacy and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered health and fitness application (the "Service"). We follow strict security protocols to protect your health information.

2. Information We Collect

2.1 Health Information

We collect health-related information you provide, including:

  • Body measurements (height, weight, body composition)
  • Fitness activities and workout logs
  • Nutrition data (food intake, dietary preferences, allergies)
  • Medical conditions, medications, and injury history
  • Progress photos and body measurements
  • Health goals and preferences

2.2 Account Information

  • Name, email address, phone number
  • Date of birth and gender
  • Account credentials and preferences
  • Payment information (processed by Stripe)

2.3 Usage Data

  • Device information and IP address
  • App usage patterns and interaction data
  • AI chat conversations and coaching interactions

3. How We Use Your Information

We use your information to:

  • Provide AI Coaching: Generate personalized meal plans, workout programs, and health recommendations
  • Track Progress: Monitor your fitness journey and provide insights
  • Improve Service: Enhance our AI algorithms and user experience
  • Safety & Support: Ensure appropriate use and provide customer support
  • Communications: Send important updates, security alerts, and feature announcements
  • Compliance: Meet legal and regulatory requirements

4. Health Data Safeguards

We implement the following safeguards to protect your health information:

  • Encryption: All PHI is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Strict authentication and role-based access controls
  • Audit Logs: Comprehensive logging of all PHI access and modifications
  • Vendor Agreements: Third-party services that process your data are bound by contractual data-protection terms
  • Minimum Necessary: We only access the minimum PHI necessary to provide services
  • Breach Notification: We will notify you within 60 days of any data breach affecting your PHI

5. Information Sharing

We do NOT sell your health information. We only share information in these limited circumstances:

  • With Your Consent: When you explicitly authorize sharing (e.g., with accountability partners, or when you accept AI data sharing)
  • Service Providers: Partners who help operate our service (AI providers, hosting, payment processing) — see Section 5A below for details
  • Legal Requirements: When required by law, court order, or to protect safety
  • Business Transfers: In the event of a merger or acquisition (with continued privacy protections)

5A. Third-Party AI Services

When you accept AI data sharing (via the in-app consent prompt), the following data is sent to third-party AI services to power AI features:

Google Gemini API (Gemini 2.5 Flash Lite, Gemini 2.0 Flash)

  • Receives: Food photos you capture or upload, nutrition label images
  • Models: Gemini 2.5 Flash Lite and Gemini 2.0 Flash, accessed through the Google Gemini API (generativelanguage.googleapis.com)
  • Purpose: food photo identification, nutrition label OCR, and barcode digit extraction. Food images captured via the in-app camera are sent to the Google Gemini API for processing.
  • Training and retention: governed by the Gemini API Terms of Service and the data-use terms of our API tier. See Google's policies linked below for current details.
  • Opt-out: users may decline AI features at any time via Profile → Privacy. Declining disables food photo scanning, nutrition label OCR, and barcode AI lookup but does not affect other app functionality.
  • Google Privacy Policy →
  • Gemini API Terms of Service →

OpenAI (GPT-4o, GPT-4o-mini, TTS-1, TTS-1-HD)

  • Receives: Aggregated nutrition, fitness, and wellbeing statistics; chat messages to AI Health Assistant; fitness goals and preferences; health profile details used for plan personalization (medical conditions, allergies, injuries, medications context, body metrics such as age, weight, and height, and your name); meditation script generation requests
  • Purpose: Personalized coaching insights, plan adaptations, progress report generation, conversational health coaching, text-to-speech for guided meditation
  • OpenAI Privacy Policy →

Base44 (InvokeLLM)

  • Receives: Food photo classification requests, chat messages, health prediction queries, and plan-generation requests that may include health profile details (medical conditions, allergies, injuries, body metrics, and your name)
  • Purpose: Food photo routing, AI assistant responses, predictive health analytics
  • Base44 Privacy Policy →

Sentry (Error Monitoring)

  • Receives: Error metadata with PHI redaction (emails replaced with [EMAIL], health metrics replaced with [METRIC], request data redacted). Session replay uses maskAllText and blockAllMedia to limit what session replays can capture.
  • Purpose: Application error tracking and performance monitoring
  • Sentry Privacy Policy →

Google, OpenAI, Base44, and Sentry process this data under their respective terms of service and privacy policies, linked above. We do not sell your health information.

5B. Opt-Out of AI Data Sharing

You can decline AI data sharing at any time from the in-app consent banner (shown on first use of an AI feature) or from Profile → Privacy. Declining disables all AI-powered features including:

  • Food photo scanning and nutrition label scanning
  • AI Health Assistant (conversational coaching)
  • Proactive health insights and wellbeing analysis
  • AI-generated meal and workout plan adaptations
  • Guided meditation session generation (text-to-speech)
  • Predictive health outcomes and progress report AI summaries

Declining does not affect your ability to use other app features such as manual food logging, workout tracking, water logging, goal setting, community features, or wearable data sync. Your current AI consent status is stored on our servers as part of your account record.

6. Your Privacy Rights (including AI Opt-Out)

You have the following rights regarding your data:

  • Access: View all your personal and health data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your data (subject to legal requirements)
  • Export: Download your data in a portable format
  • Restriction: Limit how we process your data
  • Objection: Object to certain processing activities
  • Revoke Consent: Withdraw consent for data processing

To exercise these rights, visit your Privacy Dashboard or contact us at privacy@allin1health.app

7. Data Retention

We retain your health data for as long as your account is active. After account deletion, we retain data for 90 days (for recovery purposes) before permanent deletion. Some data may be retained longer if required by law or for legitimate business purposes (e.g., audit logs for 7 years).

8. Security Measures

We implement industry-leading security measures:

  • Data encrypted in transit (HTTPS/TLS) and stored securely on our hosting platform
  • Multi-factor authentication options
  • Regular security audits and penetration testing
  • Intrusion detection and prevention systems
  • Secure data centers with physical access controls
  • Employee security training and background checks
  • Incident response procedures

9. International Users (GDPR Compliance)

If you're in the European Economic Area (EEA), you have additional rights under GDPR. We process your data based on your consent, contractual necessity, or legitimate interests. You can lodge a complaint with your local data protection authority if you believe we've violated your rights.

10. California Privacy Rights (CCPA)

California residents have additional rights including the right to know what information we collect, the right to delete, and the right to opt-out of sale (we don't sell data). Contact us to exercise these rights.

11. Children's Privacy

Our Service is not intended for users under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us immediately.

12. Cookies and Tracking

We use essential cookies for authentication and security. Optional cookies may be used for analytics (with your consent). You can manage cookie preferences in your browser or app settings.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We'll notify you of significant changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us:

Ai1Health Privacy Team

Email: privacy@allin1health.app

Data Protection Officer: dpo@allin1health.app

⚠️ Important Note

This privacy policy is designed to be comprehensive and to describe our data practices clearly. It should be reviewed by a qualified attorney before final deployment. We recommend consulting with a healthcare privacy attorney to ensure full compliance with all applicable laws and regulations.

All-in-1Health · privacy@allin1health.app