Legal

Privacy Policy

Effective [EFFECTIVE DATE]  ·  Last updated [DATE]

This Privacy Policy explains how [LEGAL ENTITY NAME] (“Omni Health System,” “we,” “us”) collects, uses, shares, and protects information when you use omnihealthsystem.com, the Omni application, and related services (together, the “Services”).

The short version. You choose which devices, apps, and labs to connect. We use that data to build your health record and to give you guidance. We do not sell your personal information. You can disconnect a data source or delete your account at any time.

1. Who this policy covers

This policy covers information we handle as a business operating the Services. Some information you provide is instead handled as protected health information (PHI) under HIPAA — specifically, information created or received in connection with physician-led care, prescriptions, and telehealth encounters. That information is governed by our Notice of Privacy Practices, which controls where the two documents differ.

2. Information we collect

Information you give us

Information from sources you connect

When you authorize a connection, we receive data from that source. Depending on the source, this may include activity, heart rate, heart rate variability, ECG, sleep, temperature, training load, recovery, strain, body composition, nutrition, and laboratory or biomarker results. Connected sources currently include Apple Health, Google/Android Health, Strava, Oura, Whoop, Hume, Cronometer, and laboratory partners.

We request the narrowest scopes we can. You control every connection and can revoke it at any time, in the app or with the source itself. Revoking stops future collection; it does not automatically delete data already in your record, which you can delete separately.

Information collected automatically

3. How we use information

Advertising. The free plan is supported by occasional in-app ads. [CONFIRM: whether ads are contextual only, and whether any advertising SDK receives device identifiers — this determines CCPA/CPRA “sharing” disclosures and opt-out obligations.] We do not use health data or PHI to target advertising.

4. How we share information

We do not sell your personal information. We share it only as described here:

De-identified data. We may create and use de-identified or aggregated data that cannot reasonably identify you. [CONFIRM: whether de-identified data is shared externally or used for research, and under what standard — HIPAA Safe Harbor or Expert Determination.]

5. Your choices and rights

Depending on where you live, you may have additional rights (for example under the California Consumer Privacy Act as amended, or comparable state laws). To exercise any right, contact us using Section 10. We will not discriminate against you for exercising a privacy right.

6. Security

We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, role-based access controls, audit logging, and least-privilege access for staff. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your information, we will notify you as required by law.

7. Retention

We keep information for as long as your account is active and as needed to provide the Services. After deletion, we remove or de-identify data within [N DAYS], except where longer retention is required — most notably clinical records, which are retained per the applicable state medical record retention period. [CONFIRM retention schedule with counsel.]

8. Cookies

We use cookies and similar technologies for authentication, preferences, security, and to understand how the Services are used. You can control cookies in your browser settings; disabling some cookies will break parts of the Services. [CONFIRM: whether a consent banner is required for your analytics and advertising stack, and in which jurisdictions.]

9. Children

The Services are not directed to children under 18, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.

10. Contact us

Privacy questions
privacy@omnihealthsystem.com

Mail
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]

11. Changes to this policy

We may update this policy. If changes are material, we will notify you in the app or by email before they take effect, and we will update the “Last updated” date above.