HealthStack is a personal, single-user health data application. It is operated by an individual for their own use and is not offered to the public. This policy describes how it handles data.
Operator and data controller: Ilya Laptev
Contact: health@mail.northaxis.me
HealthStack has exactly one user: its operator. It does not offer registration, does not accept sign-ups, and does not process data belonging to any other person. If this ever changes, this policy will be rewritten and reviewed by legal counsel before any third-party data is accepted.
No data is collected from anyone other than the operator, and no data is collected automatically from visitors to any HealthStack page.
Solely to display the operator's own health data to the operator and to identify patterns within it. HealthStack does not diagnose conditions, does not recommend treatment, and is not a medical device. There is no advertising, no profiling for commercial purposes, and no automated decision-making with legal or similarly significant effects.
Processing rests on the explicit consent of the sole data subject, who is also the operator (GDPR Art. 6(1)(a) and Art. 9(2)(a) for health and genetic data). Consent is given by connecting an account or uploading a file, and is withdrawn by disconnecting the account or deleting the data.
On a private server controlled by the operator, in an encrypted database on an encrypted disk. Access requires the operator's credentials. Backups are encrypted before leaving the server. OAuth tokens are encrypted at the application layer in addition to disk encryption.
Health data is not sold, rented, shared, or disclosed to any third party.
One limited exception, disclosed for transparency: to phrase observations in readable language, the application may send already-computed summary findings — such as "resting heart rate rose from 52 to 61 bpm over 18 days" — to the Anthropic API. Raw records, genetic data, laboratory files, and identifying information are never sent. This processing can be disabled in configuration, in which case findings are displayed without narrative text.
No analytics, tracking, advertising, or telemetry services are used.
Data is retained while the operator finds it useful and is deleted on request. Because there is a single user, deletion is immediate and total: disconnecting a service revokes its tokens, and deleting the account removes every associated record, including raw imported files. Full export of all stored data is available at any time.
WHOOP data is accessed only with scopes the operator explicitly grants during the OAuth flow, is used only within this application, and is never shared onward. Authorization can be revoked at any time from WHOOP account settings, which immediately ends HealthStack's access. On revocation, previously retrieved WHOOP data is deleted from HealthStack on request.
The sole data subject is the operator, who holds direct administrative access to the database and can exercise access, rectification, erasure, portability, and withdrawal of consent at any time without a request procedure.
Material changes are recorded by updating the date at the top of this document. The document is version-controlled, and its full history is available on request.
Questions about this policy: health@mail.northaxis.me