One account, one boundary
Persistent records are tied to an internal owner identifier. The personal space never selects another owner from a free URL parameter.
Every account has its own data boundary. Access, correction, export and deletion are normal parts of the product lifecycle.
Persistent records are tied to an internal owner identifier. The personal space never selects another owner from a free URL parameter.
The My data center lets you review account information, update it and revoke other sessions.
You can export what the server holds for your account. Encrypted health payloads are not decrypted by administration.
A deletion request starts a seven-day safety window that can be cancelled before a private worker performs the purge.
Photo reading is assisted. Human confirmation remains mandatory before a detected value is stored.
Messages are encrypted before storage and the notification email does not repeat the message body.
Account, access, security and privacy workflows stay separate from decrypted health measurements.
The public runtime includes no advertising tracker or external analytics platform.
Technical limits are stated without absolute promises, especially for backups and devices that remain offline.