Privacy Policy
Last Updated: September 11, 2026
Teknical Solutionz LLC ("we," "us," or "our") operates the HealthCoach mobile application ("App"). This Privacy Policy explains how we collect, use, store, and protect your information when you use our App.
By using HealthCoach, you agree to the collection and use of information as described in this policy.
1. Information We Collect
1.1 Account Information
- Email address
- Display name
- Authentication identifiers (Apple Sign-In user ID or Microsoft Entra ID)
1.2 Health and Fitness Data
We collect health and biometric data that you choose to provide or sync, including:
- Heart rate variability (HRV)
- Resting heart rate (RHR)
- Sleep duration, stages, and quality scores
- Steps and active calories
- VO2 max estimates
- Blood oxygen saturation (SpO2)
- Respiratory rate
- Body temperature deviations
- Workout and exercise data (sets, reps, weight, RPE)
- Daily subjective check-ins (mood, energy, stress, soreness)
- Continuous glucose monitor (CGM) readings
- Blood pressure measurements
- Body composition data (DEXA scans)
- Fasting session records
- Thermal exposure sessions (sauna and cold exposure)
- Alcohol consumption records
- Habit completion records
- Health events you choose to log, such as a blood donation, vaccination, surgery, medication change, injury, or change in diet. These include the event type, date, and an optional title and notes, which are encrypted at rest. We use them to explain expected movement in your biomarkers over time.
1.3 Lab Results and Biomarkers
- Lab test results uploaded manually or extracted from PDF documents via AI processing. The uploaded document file itself is retained in our encrypted Azure Blob Storage so you can revisit the source of a result, and is deleted when you delete the document or your account.
- Biomarker values, units, test dates, and reference ranges
- Supplement and medication names, dosages, and schedules
- Genetic profile data from DNA report PDFs (interpreted phenotype summaries only — raw SNP data is never stored)
1.3.1 Viome Gut Microbiome Data
With your explicit action (PDF upload), we extract food classification data from Viome Gut Intelligence Test reports:
- Food recommendations classified as Superfood, Enjoy, Minimize, or Avoid
- Food category and serving size information
This data is used solely to personalize meal planning and provide food-specific guidance within the App. Viome data is encrypted at rest.
1.3.2 Food Reactions and Sensitivity Profile
If you record a reaction to something you ate, we collect:
- The food the reaction is linked to
- The symptoms you report (bloating, gas, nausea, fatigue, brain fog, skin reaction, headache, cramping, heartburn, diarrhea, or constipation)
- A severity rating from 1 to 5
Once you have logged enough reactions, we send the reaction history for AI analysis to identify candidate trigger ingredients, and we store the resulting sensitivity profile on your account. That profile is used to personalize meal planning and to flag foods when you log them. It is not a diagnosis and is not a substitute for allergy testing or medical advice.
1.4 Apple HealthKit Data
With your explicit permission, HealthCoach reads the following data from Apple HealthKit:
- Heart rate variability (SDNN)
- Resting heart rate
- Sleep analysis (duration, stages including deep, REM, and light sleep)
- Step count
- VO2 max
- Blood oxygen saturation
- Respiratory rate
- Active energy burned
- Workout sessions
- Blood glucose (from connected CGM devices)
HealthCoach may also write the following data to Apple HealthKit:
- Workout sessions
- Fitness and wellness metrics
We use HealthKit data solely to provide you with personalized health insights, recovery scores, training recommendations, and trend analysis within the App. HealthKit data is never used for advertising, sold to third parties, or shared with data brokers. HealthKit data is not used for purposes unrelated to health and fitness functionality.
1.5 Google Health Connect Data
On Android, with your explicit permission, HealthCoach reads the following data from Google Health Connect. We request read access only, and only to these six types:
- Weight
- Body fat percentage
- Blood glucose
- Resting heart rate
- Heart rate variability
- Step count
Each of these appears somewhere you can see it in the App: as a metric on the Dashboard or Health Data screens, in trend charts, and as context for the personalized plans and insights the App generates. We do not request data types the App has no feature for, and we never write data back to Health Connect.
Health Connect data is used solely to provide you with personalized health insights, recovery and readiness information, and trend analysis within the App. It is never used for advertising, sold to third parties, or shared with data brokers. You can review or revoke these permissions at any time in the Health Connect app on your device, and doing so stops further syncing immediately.
1.6 Wearable Device Data
With your authorization, we sync data from connected wearable devices:
- Oura Ring (sleep, activity, readiness, HRV, temperature)
- Apple Watch (via HealthKit as described above)
- Garmin (sleep, activity, body battery, stress, HRV)
- WHOOP (recovery, strain, sleep, HRV)
- Withings (body composition, blood pressure)
1.7 App Usage and Diagnostics
- Feature usage patterns (anonymized)
- Crash reports and error logs
- Device type, operating system version, and app version
1.8 Camera and Photos
HealthCoach uses your device camera and photo library in four distinct ways. They are handled differently, so we describe each separately.
Barcode and QR scanning
When you scan a barcode on supplement or food packaging, the camera frames are processed locally on your device in real time. No image is stored, uploaded, or transmitted to our servers. Only the decoded barcode number is sent, so that we can look up the product.
Food and nutrition label photos
If you photograph a meal or a nutrition label to estimate its contents, the image is transmitted to our Azure backend and forwarded to our AI vision provider for analysis. This is the only way the estimate can be produced. The image is held in memory for the duration of the analysis and is not written to our database or to file storage, and it is not retained by the AI provider for model training. What we keep is the resulting nutrition estimate, if you choose to save it as a food entry, and an audit record noting that an analysis took place. Please avoid capturing faces, documents, or other people in these photos, since the image is sent off your device.
Progress photos
Progress photos you take or select remain on your device only. They are stored in the App's private storage area, are never uploaded to our servers or to any third party, and are not included in AI analysis. Deleting a progress photo in the App removes it from your device. Because these photos are not on our servers, they are not part of a server-side data export and are removed when you uninstall the App.
Screenshots you attach to feedback
If you submit feedback or a bug report, you may optionally attach up to three images. These are uploaded to and stored in our Azure Blob Storage so that we can investigate the issue you reported. Attaching an image is entirely optional, and you choose which images to attach. Please avoid attaching screenshots containing health information you would rather not share with us.
1.9 Health Records from Your Healthcare Provider
If you choose to connect a patient portal account — such as Epic MyChart — HealthCoach imports clinical records directly from your healthcare provider. This connection is optional, is started only by you, and can be disconnected at any time from the Settings screen.
When connected, we import and store:
- Laboratory results — test names, values, units, reference ranges, and dates
- Medications — name, dose, frequency, prescribing dates, and whether the prescription is active
- Medical conditions and allergies, including their clinical and verification status
- Immunization records
- The health system you selected and your patient identifier at that organization
- Authorization tokens for the connection, so records can be refreshed without repeated sign-in
All imported clinical data and authorization tokens are encrypted at rest. We request read-only access — we never write to, alter, or delete anything in your medical record, and we cannot act on your behalf with your provider.
You can remove imported records at any time without disconnecting, and disconnecting asks whether you want them removed as well. Because records belonging to two different patients must never be combined in one account, HealthCoach supports one connected health system at a time — connecting a different patient's chart requires removing the previously imported records first.
1.10 Community Profile and Posts
HealthCoach includes an optional Community area. You are not required to use it, and no community profile exists until you create one.
If you set up a community profile and post, we collect and store:
- The display name and avatar image you choose, which do not have to be your real name or likeness
- Whether you have marked your profile as public
- The title and body of any post you publish, and any health metric you deliberately attach to it
- Comments you write, and the posts you like
- Any report you submit about another member's post, including the reason and your notes
Anything you publish in Community is visible to other HealthCoach users. Health information you attach to a post becomes visible to them as well, so please share only what you are comfortable making public. We do not publish any of your health data to Community automatically; a post is created only when you choose to create it.
You can delete your posts and comments, and deleting your account removes your community profile and content. Copies that other users have already seen, quoted, or screenshotted are outside our control.
2. How We Use Your Information
We use your information exclusively to:
- Provide personalized health insights, recovery scores, and training recommendations
- Generate AI-powered health plans and goal suggestions based on your biometric data
- Analyze trends in your health metrics over time
- Calculate correlations between your behaviors and health outcomes (N=1 analytics)
- Extract biomarkers from uploaded lab documents
- Estimate nutrition content from photos of meals and nutrition labels that you choose to capture
- Identify candidate trigger ingredients from food reactions you have logged
- Publish the community posts and comments you choose to share with other users
- Generate weekly health summaries and coaching recommendations
- Track supplement protocols and provide progress reports
- Estimate biological age and longevity metrics
- Deliver glucose intelligence and nutrition recommendations
- Send local notifications for protocol reminders and health nudges
- Improve app performance and fix bugs
We do NOT use your health data for:
- Advertising or marketing to you based on health conditions
- Selling to third parties or data brokers
- Sharing with employers, insurers, or any entity that could use it against you
- Any purpose unrelated to your direct health and fitness benefit
3. Authentication
HealthCoach offers the following sign-in methods:
- Sign in with Apple (Apple ID)
- Microsoft account (via Microsoft Entra External ID)
We receive only the minimal information needed to authenticate you (user identifier, email, and display name). We do not receive or store your password for any authentication provider.
4. Data Security and Encryption
We take the security of your health data seriously:
- All data in transit is encrypted using HTTPS/TLS
- Sensitive health data at rest (lab results, biomarker values, goal descriptions, plan details, supplement names) is encrypted using AES-256 encryption
- Encryption keys are managed through Azure Key Vault, a FIPS 140-2 compliant key management service
- Authentication tokens are stored in platform-secure storage (iOS Keychain, Android Keystore)
- Local app data is stored in an encrypted SQLite database on your device
- We maintain a complete audit trail of all data access for security monitoring
- Biometric authentication (Face ID, Touch ID, or fingerprint) is handled entirely by your device's operating system. HealthCoach never accesses, processes, or stores your biometric data. We only receive a pass/fail result from the operating system.
5. Data Storage and Retention
- Your data is stored on Microsoft Azure servers located in the United States
- We retain your data for as long as your account is active
- You may request deletion of your account and all associated data at any time
- Upon account deletion, all personal and health data is permanently removed from our servers within 30 days
- Anonymized, aggregated data that cannot be linked back to you may be retained for service improvement
6. In-App Subscriptions
HealthCoach offers optional subscription plans that unlock premium features. Subscription purchases are processed through Apple's App Store (iOS) or Google Play Store (Android). We do not directly collect or store your payment information (credit card numbers, billing address). Subscription status is verified through the respective platform's APIs to enable premium features.
7. Third-Party Services
We use the following third-party services:
- Microsoft Azure (cloud hosting and data storage)
- Azure Key Vault (encryption key management)
- OpenAI GPT-4o — AI-powered health plan generation, lab document parsing, and wellness insights. Your health data is routed through our Azure backend before being sent to OpenAI's API for processing. Only anonymized health context is sent — never your name, email, or account identifiers. Data is not retained by OpenAI for model training per our data processing agreement.
- Application Insights (anonymized crash reporting and performance monitoring)
- Azure Blob Storage (encrypted storage for uploaded lab documents, feedback screenshots, generated recipe images, and exported workout files)
- Open Food Facts (food and supplement barcode lookup — public database, no personal data sent)
- Nutritionix (food nutrition database lookup — food search queries only, no personal data sent)
- Kroger API (grocery ordering — with your authorization via OAuth, product searches and cart management for meal plan grocery lists)
- Instacart (grocery ordering — when you choose to send a grocery list, the item names from that list are sent to Instacart to build a shopping list. No health data, lab results, or account identifiers are sent.)
- OpenAI gpt-image-1 (recipe image generation — only recipe titles are sent, no personal data)
- Epic on FHIR (health record import from Epic MyChart — only if you connect a patient portal account. We send authorization tokens and your patient identifier to your health system in order to read your records; we request read-only access and send none of your HealthCoach data to them.)
- Veradigm FollowMyHealth (health record import from the FollowMyHealth patient portal, on the same read-only basis — not currently enabled)
We do not share your personally identifiable health data with any third-party service for purposes other than providing direct App functionality as described above.
8. AI Processing
HealthCoach uses AI to generate personalized health plans, extract biomarkers from lab documents, and provide wellness insights. When AI processing occurs, relevant portions of your health data are sent from our Azure Functions backend to OpenAI's API. Your data never leaves our Azure infrastructure directly from your device — it is first received and processed by our secure Azure servers, then forwarded to OpenAI's API for AI analysis.
Only the minimum health data necessary for the specific AI task is included (e.g., lab values, wearable trends, health profile context). Your name, email address, and other directly identifying information are never sent to OpenAI. This data is processed in real-time and is not retained by OpenAI for model training purposes per our data processing agreement.
Two AI tasks involve images rather than text. Lab documents you upload are parsed to extract biomarker values, and photos of meals or nutrition labels are analyzed to estimate nutrition content. In both cases the image is sent from our backend to the AI provider, processed in real time, and not stored by us or retained by the provider for model training. Progress photos are never sent for AI analysis.
9. Your Rights and Choices
You have the right to:
- Access all personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and all data
- Revoke HealthKit access at any time through iOS Settings
- Disconnect any wearable device integration at any time
- Opt out of optional notifications
- Export your health data (clinician reports, protocol reports)
- Delete your community profile, posts, and comments, or decline to use Community at all
- Disconnect a health system and remove imported clinical records at any time
To exercise any of these rights, contact us at the email address below.
10. Children's Privacy
HealthCoach is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that we have collected data from a child under 13, we will delete it promptly.
11. California Residents (CCPA)
If you are a California resident, you have the right to: request disclosure of the categories and specific pieces of personal information we have collected about you; request deletion of your personal information; and opt out of the sale of your personal information. HealthCoach does not sell, rent, or share your personal information with third parties for their marketing purposes. To exercise your rights, contact us at josephtoland@teknicalsolutionz.com or use the "Delete All My Data" option in the app's Settings.
12. European Residents (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases: consent (for HealthKit access and wearable device connections), contract performance (to provide the app's core functionality), and legitimate interest (for crash reporting and service improvement). You have the right to access, rectify, erase, restrict processing, and port your data. You also have the right to withdraw consent at any time and to lodge a complaint with your local data protection authority. To exercise your rights, contact us at josephtoland@teknicalsolutionz.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy within the App or sending a notification. Your continued use of the App after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions or concerns about this Privacy Policy or your data:
Email: josephtoland@teknicalsolutionz.com
Company: Teknical Solutionz LLC
Website: https://healthcoach.teknicalsolutionz.com