optiHealth
Privacy Policy
Last updated: August 7, 2026 · Contact: antonix@devpins.org
optiHealth ("we", "the service") is an N-of-1 health analytics platform operated by Anton Ivanov. This policy explains in plain language what data we collect, what we do with it, and the controls you have. The short version: your data produces your insights, and it also trains the statistical and neural models that generate those insights for everyone — that is how the analysis exists at all, and it is part of what you agree to when you create an account. We never sell your data, never use it for advertising, and the models never leave optiHealth. By using the service you accept this policy and the Terms of Service. The service is for people aged 16 and over.
1. What we collect
- Account data — email address, authentication identifiers (email/password or Google / X sign-in, managed by Supabase Auth), and your timezone.
- Health & activity data you choose to sync or log — sleep stages and sessions, heart rate, resting heart rate, HRV, SpO2, respiratory rate, skin/body temperature, ECG recordings (waveform samples plus the recording device's model and the provider's classification), workouts, exercise GPS routes, steps, VO2 max, blood pressure, glucose, nutrition, hydration, EEG-derived cognitive metrics (Neiry), and derived circadian features. Sources: the Android app (Health Connect), a connected WHOOP account, a connected Fitbit account (via the Google Health API), or manual entry.
- Context you add — feelings logs (a fixed emotion vocabulary with optional context tags and a free-text note, plus when you were prompted and answered), day tags (e.g. "sauna", "fasting"), journal notes, goals, and supplement logs (products, doses, intake times).
- Optional phone & environment signals — if you enable them in the Android app: screen time and per-app usage durations, ambient light (luminance), and location samples. Raw GPS points are kept for a maximum of 21 days, then automatically deleted; only derived daily features (e.g. time at your anchors, location entropy) and the anchor places discovered by clustering remain. Recent coordinates are also used to attach local weather (pressure, UV) to your days.
- Media you submit for extraction — voice dictation audio (uploaded to our server and transcribed; we keep the text, not the audio) and supplement bottle photos (processed to pre-fill product details).
- Technical data — standard server logs (IP, user agent, timestamps) kept for security and debugging.
- Product usage — once you are signed in, we record which screens you open and which features you use (for example: a provider connect button was pressed, an insight was opened, a dose was logged), together with your browser, operating system and country. This runs on our own server — the software is self-hosted and no third-party analytics company receives any of it.
Usage events carry only short labels and counts, never your data: no measurement values, no journal or note text, no place names, no email addresses. Values longer than 32 characters are discarded before storage, so free text cannot reach this store even by accident.
We do not run this on our public pages, do not record your screen or mouse movements, and use none of it for advertising.
2. How your data is used
- Your personal analytics. The analysis engine computes correlations, lagged and partial correlations, regime-shift detection, intervention-effect estimates, anomaly detection, clustering, forecasting and tag/supplement impact — all scoped to your account, to produce the insights you see on your dashboard.
- Training the engine that produces those insights. optiHealth's output is generated by statistical and neural models that learn from the data they analyze. Cross-account baselines are what make your percentiles, priors and comparisons meaningful — they cannot be computed from a single account, and without them the engine cannot tell an unusual night from an ordinary one. Training and improving these models is therefore not an optional extra: it is the mechanism by which the service works, and it applies to every account.
Training sets contain numeric time-series, tags and feelings-vocabulary entries, with account identifiers replaced by random codes. Email addresses, names, free-text notes, photos, audio and precise coordinates are excluded. No human reads individual user data; all processing is automated.
The models never leave optiHealth. They are not sold, licensed, published, shared with third parties, or used for any purpose other than powering optiHealth's own analysis — and neither is the data behind them, in raw, aggregated or anonymized form. If you no longer want to contribute, you can delete individual data or your entire account at any time; deleted data leaves the training sets at the next rebuild. - AI-assisted features. When you use voice tagging or dictation, the audio and its transcribed text (plus the names of your existing tags) are processed by a large-language-model API (currently Google Gemini) to transcribe and propose tags; bottle photos are processed the same way to recognize products. We keep only the extracted text and fields. Health and fitness measurements — including everything synced from Google Health / Fitbit, WHOOP or Health Connect — are never sent to Gemini or to any other external model provider. Because analysis involves statistical and machine-learning models, outputs are estimates and can be wrong — they are informational, not medical advice.
- Service operation — authentication, sync scheduling, debugging, abuse prevention.
3. What we never do
- We never sell your data — including in aggregated or anonymized form.
- We never use your data for advertising.
- We never transfer your data to advertising platforms, data brokers or information resellers, and never use it for credit-worthiness or lending decisions.
- We never share identifiable health data with third parties except the processors listed below, or if required by law.
- We never publish, license or hand over the trained models, or use them outside optiHealth.
4. Data from Google Health (Fitbit)
If you connect a Fitbit or Google Health account, we read — with your explicit authorization, one permission category at a time — your profile, activity and fitness, health metrics and measurements, sleep, nutrition, exercise location (GPS recorded during a workout) and ECG recordings. Each category is requested because it enters the same statistical model: an unobserved variable does not merely remove a chart, it turns into an uncontrolled confounder and biases the conclusions the app shows you.
- Google Health data is used only to provide and improve the optiHealth features that are visible in the app: your charts, your data explorer, and the analysis engine that generates your insights.
- It is never sold, never transferred to third parties, never used for advertising, and never sent to an external model provider.
- No human reads it. Access is limited to automated processing, to security investigations, to what applicable law requires, and to aggregated and anonymized internal operations.
- Exercise GPS is used to draw the route of the workout itself and to derive elevation- and terrain-adjusted training load. It never leaves your account.
- ECG recordings are displayed and summarized for information only. optiHealth is not a medical device: it performs no diagnosis and no interpretation of arrhythmia, and only repeats the classification your recording device already produced.
- You can disconnect at any time in Settings — this revokes and deletes the OAuth tokens — and you can also revoke access from your Google Account. Deleting your optiHealth account deletes the synced data.
The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.
5. Processors & storage
- Hetzner (Finland) — the application server, the database and the analysis worker all run on hardware we rent here. The database is PostgreSQL (self-hosted Supabase) operated by us on that same infrastructure, not a managed third-party cloud database. All health rows are protected by row-level security: only your authenticated session can read them.
- Google — the Gemini API processes dictation audio, tag-matching text, and bottle photos when you use those features (see section 2: health measurements are never sent to it); the Google Health API syncs your Fitbit data if you connect a Fitbit account.
- WHOOP — if you connect it, we access your WHOOP data via their official API using OAuth tokens stored server-side only, encrypted at rest, never exposed to browsers or apps.
- Open-Meteo — receives recent coordinates from your location samples (no account identifiers) to fetch local weather.
- OpenStreetMap — map tiles on the Places pages load directly in your browser from OpenStreetMap's servers, which therefore see your IP address and the map area you view (© OpenStreetMap contributors).
- iHerb — supplement product searches send your search terms (proxied through our server, not your IP) to iHerb.
- GitHub — hosts the Android APK downloads; GitHub sees standard download-request metadata.
6. Shared insight links
If you create a share link for an insight, a frozen snapshot of that insight (and a preview image) becomes visible to anyone with the URL — including link-preview crawlers of platforms you post it to. Shared pages are excluded from search-engine indexing and contain no live data; you can revoke a link at any time, which takes the snapshot offline.
7. Cross-source deduplication
When two sources report the same metric for the same day (e.g. Health Connect and WHOOP both report sleep), we keep the first source's values and skip duplicates. This is a data-quality measure; both raw sources may be retained in your account's raw data.
8. Retention & deletion
- Your data is retained while your account is active so the engine can analyze long windows (this is the core value of the product). Raw GPS points are the exception: deleted after 21 days.
- Dictation audio is processed transiently and not stored after transcription.
- You can delete individual data points, disconnect sources, wipe all location data with one control, or delete your entire account — deletion cascades through all your health rows, tags, logs and OAuth tokens.
- Training sets are rebuilt periodically from live data; data deleted from your account leaves them at the next rebuild. Models trained before that rebuild are not individually reversible — no model contains or can reproduce your records, and no output identifies you.
9. Your rights and the legal basis
We process your health data on the basis of your explicit consent (GDPR art. 9(2)(a)), given when you create an account, and to perform the agreement between us (art. 6(1)(b)). That consent covers the uses in section 2, including model training, which is inseparable from the service itself: it cannot be switched off while the account exists, because there is no version of the engine that runs without it.
You may request access, correction, export, or erasure of your data (GDPR arts. 15–20). You can withdraw consent at any time by deleting your data or your account, which ends all further processing and removes you from future training sets. Email antonix@devpins.org — we respond within 30 days. You can also export any metric as CSV directly from the data explorer.
10. Where data lives
The service runs on EU infrastructure (Finland, listed above). As a small operation, service administration may occasionally happen from outside the EU/EEA; such access is to the systems rather than to individual users' health rows, uses the same encrypted, access-controlled paths described in this policy, and is limited to what operating the service requires.
11. Security
TLS everywhere; encryption at rest; row-level security on all user tables; device and provider OAuth tokens live in a backend-only table with deny-all RLS and are never shipped to clients. No system is perfectly secure — report vulnerabilities to the contact above.
12. Changes
We'll update this page and bump the date above when the policy changes. Material changes (e.g. new processors, new data uses) will be announced in-app before they take effect.