HealthSource

HealthSource Privacy Policy

HealthSource connects to Oura or Withings only with explicit user authorization. It is designed as a read-only recovery and body-context service for approved HealthSource integrations.

Data We Access

Depending on granted Oura scopes, HealthSource may retrieve sleep, readiness, activity, workout, heart-rate-derived sleep metrics, HRV/RMSSD, resting heart rate, lowest heart rate, temperature deviation, SpO2, breathing disturbance, stress, resilience, rest mode, sessions, tags, cardiovascular age, VO2 max, and ring device information.

Depending on granted Withings scopes and connected devices, HealthSource may retrieve sleep summaries, nightly heart-rate and HRV fields when available, activity, workouts, weight, body composition, and device information. HealthSource does not use Withings clinical records such as ECG or blood-pressure data for its recovery product.

How We Use Data

Data is used only to provide user-requested, non-medical wellness, recovery, fitness, performance, and training-readiness context. HealthSource does not diagnose, treat, provide emergency support, or make medical claims.

HealthSource does not use wearable-derived data to train, fine-tune, develop, improve, evaluate, or benchmark AI models or AI platforms.

Approved AI Integrations

When a user invokes HealthSource inside an approved integration such as ChatGPT Health, HealthSource sends only the requested Daily Measurements, Daily Brief, Body Context, or Connection Status response to that integration at the user's direction. The integration provider processes that response under its own health-product privacy terms. HealthSource requires separate user authorization for its connector and does not authorize wearable-derived data for model training, advertising, or unrelated product improvement.

HealthSource minimizes each response to the requested workflow, labels its source and coverage, and keeps provider-specific diagnostic and raw-data tools off the public connector surface.

Sharing

HealthSource returns authorized wearable context only to the user-requested, approved HealthSource integration. It does not sell body data, use it for advertising, use third-party analytics SDKs, or expose provider-derived data as an unapproved provider-record pass-through. HealthSource does not send body data to contacts, employers, trainers, or other third parties.

Storage

Production stores encrypted OAuth tokens only while the user keeps a source connected so HealthSource can refresh access. Provider API records are not kept as a long-term warehouse. Tokens are not returned by MCP tools or API responses.

User Control

Users can revoke access in their provider account settings, disconnect a source from HealthSource, or ask HealthSource to delete stored connections and related retained data. HealthSource deletes user data after a deletion request within 72 hours where technically available.

Contact

Contact: support@healthsource.app

Sign in

Welcome to HealthSource.

Sign in to your account. No password needed.

By signing in, you agree to our Terms and Privacy Policy.