Last updated: 18 August 2026
This policy is issued by AIHealth Labs for the AIHealth Chat web application and WhatsApp channel at https://aihealthchat.qzz.io.
We use this data to run the assistant, optional tracker logging, SOAP visit summaries, and account security (rate limits, webhook signatures). We do not sell, rent, or trade your personal or health data.
Prompts and, when you attach a photo, image data are sent to providers so we can generate a reply or a report. Current subprocessors:
chat-images bucket).Gemini is not in the live provider chain. Paid API terms for Groq, OpenRouter, and Mistral provide that API content is not used to train their public models. We do not sell your health content.
If you create a share link, the secret is a cryptographically random token in the URL fragment (/report#token), not the path. Recipients do not need an account. Public share pages do not embed original chat photos; they may include text findings. You can expire or revoke links in the app.
Data in transit uses TLS. Access to chats, reports, and metrics is enforced with RLS: you only read your own rows. SOAP reports are minted by our API after authentication and quota checks; browsers cannot insert fabricated reports. Chat images are private; signed URLs are short-lived and scoped to your session.
Inbound webhooks are verified with HMAC-SHA256. Metrics are extracted from WhatsApp only for a linked number and only if you have enabled “Log health data mentioned in chat.” Unlinked WhatsApp data is purged after 30 days of inactivity.
You can unlink WhatsApp, delete tracker rows and reports, and permanently delete your account from Settings → Delete my account (type DELETE). That removes profile, chats, reports, tracker entries, uploaded photos, and any WhatsApp link.
Privacy questions: info@aihealthchat.qzz.io