Privacy Policy
This Privacy Policy explains how [LEGAL ENTITY NAME] (“Omni Health System,” “we,” “us”) collects, uses, shares, and protects information when you use omnihealthsystem.com, the Omni application, and related services (together, the “Services”).
The short version. You choose which devices, apps, and labs to connect. We use that data to build your health record and to give you guidance. We do not sell your personal information. You can disconnect a data source or delete your account at any time.
1. Who this policy covers
This policy covers information we handle as a business operating the Services. Some information you provide is instead handled as protected health information (PHI) under HIPAA — specifically, information created or received in connection with physician-led care, prescriptions, and telehealth encounters. That information is governed by our Notice of Privacy Practices, which controls where the two documents differ.
2. Information we collect
Information you give us
- Account information — name, email address, password, and date of birth.
- Profile and goal information — height, weight, sex assigned at birth, activity level, health goals, and anything else you choose to enter.
- Health intake and clinical information — medical history, medications, symptoms, and answers to clinical questionnaires, where you engage with a program or provider.
- Payment information — processed by our payment provider. We receive confirmation and the last four digits of the card; we do not store full card numbers.
- Communications — messages you send to support, a coach, or a provider.
Information from sources you connect
When you authorize a connection, we receive data from that source. Depending on the source, this may include activity, heart rate, heart rate variability, ECG, sleep, temperature, training load, recovery, strain, body composition, nutrition, and laboratory or biomarker results. Connected sources currently include Apple Health, Google/Android Health, Strava, Oura, Whoop, Hume, Cronometer, and laboratory partners.
We request the narrowest scopes we can. You control every connection and can revoke it at any time, in the app or with the source itself. Revoking stops future collection; it does not automatically delete data already in your record, which you can delete separately.
Information collected automatically
- Device and usage data — device type, operating system, app version, IP address, and how you use the Services.
- Cookies and similar technologies — see Section 8.
3. How we use information
- To build and maintain your unified health record.
- To generate insights, trends, and guidance, and to adapt your plan over time.
- To provide coaching, and to support physician-led care where you have engaged it.
- To fulfil orders for supplements and, where clinically appropriate and prescribed, therapeutics.
- To operate, secure, debug, and improve the Services.
- To communicate with you about your account, your plan, and service changes.
- To comply with legal obligations and to enforce our Terms.
Advertising. The free plan is supported by occasional in-app ads. [CONFIRM: whether ads are contextual only, and whether any advertising SDK receives device identifiers — this determines CCPA/CPRA “sharing” disclosures and opt-out obligations.] We do not use health data or PHI to target advertising.
4. How we share information
We do not sell your personal information. We share it only as described here:
- With providers and pharmacies — when you engage clinical care, with the licensed providers involved in your care and, for prescriptions, with the dispensing pharmacy.
- With service providers — hosting, storage, analytics, payment processing, communications, and fulfilment vendors, bound by contract to use the data only for us. Vendors handling PHI sign Business Associate Agreements.
- For legal reasons — to comply with law, valid legal process, or to protect rights, safety, and the integrity of the Services.
- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this policy.
- With your direction — when you ask us to share with someone else.
De-identified data. We may create and use de-identified or aggregated data that cannot reasonably identify you. [CONFIRM: whether de-identified data is shared externally or used for research, and under what standard — HIPAA Safe Harbor or Expert Determination.]
5. Your choices and rights
- Access and export — get a copy of your health record.
- Correction — fix inaccurate information.
- Deletion — delete your account and associated data, subject to records we must retain by law (clinical and prescription records in particular have mandatory retention periods).
- Disconnect a source — at any time, without losing access to the rest of the Services.
- Marketing opt-out — unsubscribe from marketing email; we will still send essential service messages.
Depending on where you live, you may have additional rights (for example under the California Consumer Privacy Act as amended, or comparable state laws). To exercise any right, contact us using Section 10. We will not discriminate against you for exercising a privacy right.
6. Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, role-based access controls, audit logging, and least-privilege access for staff. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your information, we will notify you as required by law.
7. Retention
We keep information for as long as your account is active and as needed to provide the Services. After deletion, we remove or de-identify data within [N DAYS], except where longer retention is required — most notably clinical records, which are retained per the applicable state medical record retention period. [CONFIRM retention schedule with counsel.]
8. Cookies
We use cookies and similar technologies for authentication, preferences, security, and to understand how the Services are used. You can control cookies in your browser settings; disabling some cookies will break parts of the Services. [CONFIRM: whether a consent banner is required for your analytics and advertising stack, and in which jurisdictions.]
9. Children
The Services are not directed to children under 18, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
10. Contact us
Privacy questions
privacy@omnihealthsystem.com
Mail
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
11. Changes to this policy
We may update this policy. If changes are material, we will notify you in the app or by email before they take effect, and we will update the “Last updated” date above.