Health Data Privacy

Your health data is yours.
Completely.

Last updated: March 20, 2026Effective: March 20, 2026

This Health Data Privacy Policy supplements the alaivOS Privacy Policy and specifically addresses how alaivOS handles health, wellness, fitness, and biometric data. Health data deserves heightened protection, and our architecture reflects that.

Core Principle

Device-Only Architecture

All health data processed by alaivOS is stored exclusively on your device. It is never transmitted to our servers, never shared with third parties for any purpose, and we have no technical ability to access it. This is not a policy choice — it is an architectural guarantee.

What Health Data We Access

When you grant permission, alaivOS may read the following data from Apple Health (iOS) or Health Connect (Android):

Activity
Steps, distance, active energy, workouts, exercise minutes
Heart
Heart rate, resting heart rate, heart rate variability
Sleep
Sleep duration, sleep stages, sleep analysis
Body
Weight, BMI, body fat percentage, height
Nutrition
Dietary energy, macronutrients (when logged)
Vitals
Blood oxygen, respiratory rate, temperature

This integration is read-only. alaivOS never writes data back to Apple Health or Health Connect.

Where Your Health Data Is Stored

Health data imported into alaivOS is stored in a local SQLite database on your device. This database is encrypted at rest by the operating system. If you enable cloud sync, your health data is not included in the sync — health data always remains device-only.

When you log health information manually in alaivOS (mood, meals, medications, symptoms), that data is treated identically — local only, never transmitted.

What We Never Do With Health Data

  • We never transmit your health data to our servers
  • We never share health data with advertisers, data brokers, or third parties
  • We never use health data to train AI models
  • We never sell health data under any circumstances
  • We never use health data for profiling or behavioral targeting
  • We never perform geofencing around healthcare facilities
  • We cannot respond to law enforcement requests for health data we do not possess

Your Consent

Before alaivOS accesses any health data, you will be shown a consent screen explaining exactly what data will be accessed and how it will be used. You may then be prompted by your operating system (iOS or Android) to grant or deny the permission.

You can revoke health data permissions at any time through your device settings (Settings → Privacy → Health on iOS; or the Health Connect app on Android). Revoking permission stops any future data access and does not affect data already stored locally on your device.

Washington My Health My Data Act Compliance

For users in Washington State, alaivOS complies with the My Health My Data Act (MHMD). Our device-only architecture satisfies the Act's requirements by design:

  • Health data is not collected by Citerius Holdings LLC — it remains on your device
  • No health data is shared with third parties
  • No geofencing related to healthcare facilities
  • Explicit opt-in consent is obtained before any health data is accessed

To submit a consumer health data request under MHMD, contact us at support@alaivos.com.

Deleting Your Health Data

Because your health data lives on your device, you control deletion entirely:

  • Delete specific entries — within the alaivOS app, you can delete any logged health entry
  • Delete all health data — go to Settings → Privacy → Clear Health Data in the app
  • Delete everything — uninstalling alaivOS removes all locally stored data including all health data

We have no health data on our servers to delete. There is nothing for us to erase on our end.

Contact

For health data privacy inquiries:

CompanyCiterius Holdings LLC
Address30 N Gould St Ste R, Sheridan, WY 82801