01
Privacy by design
Your data lives on your device.
Your lab results, biomarker measurements, trends, health profile, and AI-generated insights are stored locally on your Mac. Nothing syncs to a cloud service, and we cannot access it remotely. If you use macOS FileVault, your entire disk, including Hemo's data, is encrypted at rest.
Your database is tied to your Apple ID, and each account gets its own separate data store. Signing out does not erase local data. Using Delete account removes your local Hemo data and the related backend account record.
AI requests are transient: process and forget.
When you use PDF extraction or AI insights, your Mac prepares the minimum data needed and sends it over HTTPS to Hemo's backend. The backend forwards the request to Azure OpenAI, then returns the response to your Mac, where it is saved locally.
Hemo deletes the temporary vector store immediately after the structured response is returned. Hemo's backend does not log or retain your PDF contents, biomarker values, prompts, or AI responses. Microsoft does not use customer prompts or completions to train its models.
We do not keep your health data on our servers.
Hemo does not run a database containing your lab results, biomarker values, or health history. Our backend handles authentication, usage limits, product feedback, compatibility information, and secure AI proxying.
Your data isn't our business model.
We don't sell your personal or health data, and we don't share it for advertising.
Authentication is handled by Apple.
Hemo uses Sign in with Apple. We never see or store your Apple ID password. Apple gives Hemo an anonymous user identifier, which we hash before storing. We do not receive your email unless you choose to share it, such as when submitting feedback.
02
What we collect
| Data | Where it lives | Purpose |
|---|---|---|
| Lab results, biomarkers, trends, insights | Your Mac only | Core app functionality |
| Health profile | Your Mac only | Personalizing AI insights |
| Hashed Apple user ID | Hemo backend | Authentication and usage limits |
| Usage counts | Hemo backend | Enforcing plan limits |
| App version, build, and OS version | Hemo backend | Compatibility and support |
| Registration and activity timestamps | Hemo backend | Support and aggregate usage analytics |
| Feedback and diagnostic metadata | Hemo backend | Responding to feedback and fixing issues |
| Email, only when you provide it | Hemo backend or Kit | Feedback replies, updates, and beta invitations |
03
AI processing details
Hemo uses Azure OpenAI, Microsoft's AI platform, for two types of work:
- PDF and image extraction: reading lab results from documents you choose to upload.
- Insights and action planning: analyzing relevant biomarkers, writing summaries, and suggesting possible next steps.
All AI requests go through Hemo's backend proxy over an encrypted TLS/HTTPS connection. Hemo deletes its temporary vector store immediately after returning the structured response and does not use your health data for model training.
04
Exporting and deleting your data
You can export or restore your Hemo data using a .hemobackup file. You can also delete your account from within the app. Account deletion permanently removes:
- Your local app data, including lab results, biomarkers, insights, and health profile.
- Your backend record, including the hashed user ID, usage counts, activity timestamps, and app or OS version.
After deletion, Hemo does not keep a backup of your user record.
05
Third-party services
| Service | What it does | What it receives |
|---|---|---|
| Apple | Authentication | Apple ID credentials handled by Apple, not Hemo |
| Azure OpenAI | AI processing | Request data needed for extraction or insights; not used for training; flagged abuse may be stored for authorized review |
| Vercel | Backend and website hosting | Hashed user ID, usage counts, and transient proxied requests |
| Kit | Email list management | The email address you submit on this website |
| Google Analytics | Aggregate website analytics | Page views, browser type, and IP-derived general region |
These services do not receive a stored copy of your health history from Hemo.
06
Website and marketing
Email collection
If you join the waitlist or subscribe to updates, we collect the email you provide. Signup is voluntary and double opt-in. We use your email for product updates and beta invitations. Kit manages the list under a data processing agreement. We do not sell your email, and you can unsubscribe anytime.
Cookies and analytics
We use analytics to understand page views, browser types, and general regions. We do not use website analytics to collect health information. You can opt out with the Google Analytics Opt-out Add-on.
Legal basis and retention
We process your email based on consent. Emails are retained until you unsubscribe. Analytics logs are retained for up to 14 months, then deleted or aggregated. We do not sell or share personal data for cross-context behavioral advertising.
International transfers and Do Not Track
Website data is stored on servers in the United States. By submitting your email, you consent to this transfer. The website currently does not respond to browser Do Not Track signals.
07
Your rights
Depending on where you live, you can request access to, correction of, deletion of, or export of your personal data. Send requests to hello@tryhemo.com.
08
Changes to this policy
We may update this policy as Hemo evolves. If we make significant changes, we will update the date above and provide notice through the app when appropriate.
09
Contact
Questions about privacy? Email hello@tryhemo.com.
