Privacy Policy
Finesis LLC
Chatbot.health
Last Updated: August 16, 2026
IMPORTANT NOTICE FOR U.S. USERS
Finesis LLC operates Chatbot.health as a consumer health, wellness, fitness, and personal-data platform. Chatbot.health is not a healthcare provider, does not provide medical care, and is not intended to diagnose, treat, cure, mitigate, or prevent disease.
Finesis LLC is not a HIPAA Covered Entity solely by operating Chatbot.health. The fact that information is health-related does not, by itself, make Finesis LLC a HIPAA Covered Entity or Business Associate. However, health and wellness information is highly sensitive, and its collection and use may be subject to federal and state privacy, consumer-protection, breach-notification, and other applicable laws.
Where applicable, Finesis LLC will comply with the requirements of the Federal Trade Commission’s Health Breach Notification Rule and other laws governing the protection of personal and health information.
1. Scope of This Privacy Policy
This Privacy Policy describes how Finesis LLC (“Finesis,” “Company,” “we,” “us,” or “our”) collects, receives, uses, stores, shares, and protects information when you use Chatbot.health, including:
- the Chatbot.health website;
- the Chatbot.health iOS application;
- the Chatbot.health Android application;
- connected wearable devices and sensors;
- integrations with Apple Health / HealthKit and Android Health Connect;
- features that allow you to connect with family members, caregivers, friends, or other people;
- automated notifications and communications;
- AI-powered summaries, insights, and wellness functionality; and
- other services, software, APIs, and functionality provided by Finesis.
This Privacy Policy applies to information collected through these services and does not apply to third-party websites, devices, applications, or services that Finesis does not control.
2. Information We Collect
We collect information that is necessary to provide the Service, information you voluntarily provide, and information that you explicitly authorize us to receive from connected devices and platforms.
The categories of information may include the following.
2.1 Account and Authentication Information
When you create or access an account, we may collect:
- email address and/or username;
- password credentials as necessary to authenticate your account;
- authentication and session information;
- account identifiers;
- date of birth or age information;
- access and refresh tokens or similar authentication credentials necessary to maintain your session; and
- information necessary to secure, administer, and support your account.
Authentication may be provided through third-party identity and authentication services, including Amazon Cognito.
Passwords are handled through the applicable authentication system and are not retained by the mobile application as ordinary readable password data.
2.2 Health and Fitness Information
If you authorize access to a connected health platform, device, or wearable, we may receive health and fitness information that you have chosen to make available to Chatbot.health.
Depending on the permissions you grant and the connected source, this may include:
- step count;
- heart rate;
- blood pressure, including systolic and diastolic measurements;
- blood oxygen saturation (SpO₂);
- blood glucose and continuous glucose monitoring (CGM) readings;
- body weight or body mass;
- associated timestamps;
- other supported health or fitness measurements that you expressly authorize the Service to access.
The availability of particular data types depends on your device, operating system, connected platform, permissions, and the capabilities of the source device or service.
For example, health information may be received through Apple Health / HealthKit or Android Health Connect.
You control whether and which health information you authorize the Service to access through the applicable operating system or platform permissions.
2.3 Connected Wearable and Ring Data
If you connect a supported wearable device or ring directly to Chatbot.health, we may collect information transmitted by that device, including:
- real-time heart rate;
- oxygen saturation (SpO₂);
- systolic and diastolic blood pressure measurements, where provided by the device;
- raw photoplethysmography (PPG) waveform samples;
- three-axis accelerometer data;
- device firmware version;
- device operating mode;
- device storage status;
- battery status; and
- other technical or physiological data transmitted by the connected device and made available to the Service.
The Service does not represent that every connected wearable is a medical device or that information obtained from a wearable constitutes a medical measurement or diagnosis.
Where a wearable provides physiological measurements, the availability, accuracy, and characteristics of those measurements depend on the device and its manufacturer.
2.4 Nutrition Information
If you use nutrition or food logging functionality, we may collect:
- free-text descriptions of food or beverages consumed;
- portion size information, such as small, medium, or large; and
- associated dates and times or other information necessary to organize your nutrition records.
Free-text information may contain health-related or other sensitive information if you choose to enter it.
2.5 Medication and Intervention Information
If you voluntarily record medications, drugs, interventions, or similar information through the Service, we may collect:
- medication or drug names;
- dosage information, including whether a whole or partial unit was taken;
- dates and times associated with entries; and
- other information you voluntarily enter in connection with such records.
Medication information is sensitive personal information. You should not enter information that you do not want processed through the Service.
2.6 Chronic Conditions and Health Profile Information
The Service may allow you to voluntarily provide or designate information concerning chronic health conditions.
This may include indicators relating to conditions such as:
- diabetes;
- hypertension;
- heart disease;
- peripheral artery disease (PAD);
- asthma;
- chronic obstructive pulmonary disease (COPD);
- dementia;
- neuropathy;
- kidney disease; and
- liver disease.
You control whether you provide this information and, where supported, whether you share it with other users through the Service.
3. Information About Other People and Connections
Chatbot.health may allow you to establish connections with other users, including family members, caregivers, friends, or other people you choose.
When you invite or connect with another person, we may collect and process:
- the person’s name;
- email address;
- relationship or connection type;
- connection status;
- permissions and authorization scopes associated with the connection; and
- information necessary to administer the connection.
Depending on the permissions selected by the users involved, connected users may be able to access information from one another’s profiles.
Available permission categories may include:
- Vitals;
- Live Vitals;
- Alerts;
- Warnings;
- Actuators;
- Statistics or Stats;
- Drugs;
- Chronic Conditions;
- Composer; and
- Full Profile.
The information actually shared depends on the permissions authorized by the applicable users.
For example, where authorized, information displayed to a connected user may include:
- profile photograph;
- age;
- sex;
- average systolic blood pressure;
- average diastolic blood pressure;
- average step count; and
- other information included within the authorization scope selected by the user.
You are responsible for selecting appropriate people and permissions when sharing your information through the Service.
4. QR Code Guest Access
Chatbot.health may provide functionality allowing you to generate a QR code or similar sharing mechanism.
A generated QR code may contain or encode a URL incorporating your username or another account identifier and may allow a person who scans the code to obtain temporary guest access to information you have chosen to share.
For example, the Service may provide a guest access period of approximately one hour.
You are responsible for controlling access to any QR code you generate. Anyone who obtains an active sharing code may be able to access the information associated with that code during its authorized period.
Do not distribute a QR code to anyone to whom you do not intend to provide access.
5. Notifications and Communications
The Service may provide push notifications, in-app notifications, alerts, warnings, and other communications.
We may process:
- device or push-notification tokens;
- notification preferences;
- notification delivery status;
- notification content;
- connection requests;
- health or wellness messages generated or configured through the Service; and
- other information necessary to deliver notifications.
Push notification functionality may be provided using third-party services such as Firebase Cloud Messaging.
Notifications may be generated by user-configured rules, Service functionality, connection activity, or other events.
Where the Service allows you to configure automated notifications or messages, you may select recipients, conditions, thresholds, permissions, or other parameters. You are responsible for configuring those settings appropriately.
Notifications are not guaranteed to be delivered immediately or at all. Delivery may be affected by device settings, operating system restrictions, connectivity, battery-saving features, notification permissions, third-party services, and other factors outside our control.
6. Device, Application, and Diagnostic Information
When you use the Service, we may collect technical information necessary to operate, secure, troubleshoot, and improve the Service.
This may include:
- device model;
- operating system and operating system version;
- application version;
- firmware information for connected devices;
- device and application identifiers;
- authentication/session identifiers;
- background synchronization activity;
- synchronization status and event logs;
- crash reports;
- error reports;
- diagnostic information;
- performance information;
- network or connectivity information;
- battery or power-saving status where necessary for functionality; and
- other technical information generated through use of the Service.
For example, the Service may use Firebase Crashlytics to collect crash and diagnostic information together with an identifier associated with the user or installation.
Certain device information may be processed only locally and may not be transmitted to Finesis. For example, a mobile application may read a device’s low-power or battery-saver state locally in order to display a warning without transmitting the device’s geographic location.
7. Android Permissions and Bluetooth
The Android application may request permissions necessary to provide particular functionality.
Depending on the version of Android and the functionality you use, these may include:
- Bluetooth scanning;
- Bluetooth connection;
- coarse location permission;
- fine location permission; and
- notification permission.
Certain Android versions require location-related permissions for Bluetooth Low Energy scanning even when the application does not use the permission to determine or store your geographic location.
Finesis does not use Bluetooth scanning permissions for the purpose of determining your geographic location merely because Android requires such permission for Bluetooth functionality.
Permissions are controlled through your device’s operating system and may be changed by you at any time, subject to operating-system functionality.
8. How We Use Information
We use information collected through the Service for purposes including:
Providing the Service
- creating and administering accounts;
- authenticating users;
- displaying health, fitness, nutrition, medication, and wellness information;
- synchronizing information from connected platforms and devices;
- providing dashboards and other user-requested functionality;
- maintaining user connections and permissions;
- providing notifications and communications;
- operating user-configured automation and communication features; and
- providing customer support.
Wellness and Data Analysis
We may use information to:
- generate wellness summaries;
- identify trends and patterns;
- calculate statistics and derived metrics;
- generate personalized wellness insights;
- provide fitness-related information;
- organize and aggregate information from multiple sources;
- provide AI-powered summaries and responses; and
- develop and improve features of the Service.
The Service is intended to help users understand and organize their personal information. It does not provide medical diagnosis or treatment.
Security and Operations
We may use information to:
- authenticate and secure accounts;
- detect, investigate, and prevent unauthorized access;
- detect fraud, abuse, or misuse;
- maintain system security;
- troubleshoot errors;
- analyze application performance;
- investigate crashes;
- maintain backups;
- operate infrastructure; and
- comply with legal obligations.
Product Development and Research
Subject to applicable law and applicable platform requirements, we may use information in de-identified, aggregated, or otherwise appropriately protected form for:
- health and wellness trend analysis;
- statistical analysis;
- product development;
- research;
- machine-learning model development and evaluation;
- quality assurance;
- service improvement; and
- other lawful business and analytical purposes.
9. Artificial Intelligence
Chatbot.health may use artificial intelligence and machine-learning technologies to generate summaries, responses, insights, classifications, recommendations concerning general wellness activities, and other functionality requested or enabled by the user.
Depending on the feature, information submitted to or processed by an AI system may include information contained in your account or information you have authorized the Service to use.
We may use third-party AI service providers to process information on our behalf.
AI-generated content may be incomplete, inaccurate, outdated, or inappropriate and should not be relied upon as a substitute for professional medical advice, diagnosis, or treatment.
Finesis does not represent that an AI-generated response constitutes a medical determination.
10. Data Sharing
We do not sell your directly identifiable account credentials, such as your password, for advertising or marketing purposes.
We may disclose personal information as necessary to provide and operate the Service, including to service providers that process information on our behalf.
These disclosures may include the following categories of providers:
- cloud hosting and infrastructure providers;
- authentication providers;
- database providers;
- analytics and diagnostics providers;
- crash-reporting providers;
- notification providers;
- AI and machine-learning service providers;
- security providers;
- communications providers;
- technical support providers; and
- other vendors necessary to provide the Service.
Service providers may process information on our behalf and may be located in the United States or other jurisdictions.
We may also disclose information:
- when you direct us to do so;
- when you authorize sharing through the Service;
- to people you designate through connection or sharing functionality;
- to comply with law, regulation, legal process, or governmental requests;
- to protect the rights, safety, property, or security of Finesis, users, or others;
- to investigate fraud, abuse, security incidents, or violations of our terms;
- in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar corporate transaction; or
- where otherwise permitted or required by applicable law.
11. De-Identified and Aggregated Information
We may create information that is de-identified, aggregated, anonymized, statistical, or otherwise modified so that it is not reasonably capable of being associated with an identifiable individual, subject to applicable law.
We may use such information for lawful purposes including:
- population-level health and wellness analysis;
- statistical analysis;
- research;
- product development;
- service improvement;
- machine-learning development and evaluation;
- benchmarking;
- business analysis; and
- other lawful commercial purposes.
Where permitted by applicable law, we may license, disclose, or otherwise commercialize appropriately de-identified or aggregated information.
We will not represent information as de-identified if applicable law requires a higher standard of de-identification and that standard has not been met.
We do not use de-identification as a substitute for obtaining permission where applicable law or a third-party platform’s rules require user permission for a particular use.
12. Health Data and Third-Party Platform Requirements
Health and fitness information is particularly sensitive.
When you connect Apple Health / HealthKit, Android Health Connect, or another health platform, the information we receive is subject to the permissions you grant through that platform.
Third-party platforms may impose additional requirements concerning how health information may be accessed, used, disclosed, or retained.
We do not use health information obtained through Apple Health / HealthKit for advertising or targeted marketing.
We do not use HealthKit information to build advertising profiles or for use-based advertising or marketing.
Where third-party platform policies impose additional restrictions on the use or disclosure of health information, those restrictions apply to our use of information obtained through the applicable platform.
Apple Health / HealthKit, Android Health Connect, wearable devices, and other third-party health platforms are independently operated services. Finesis does not control their privacy practices, availability, accuracy, or continued operation.
13. No Sale of Directly Identifiable Health Information for Advertising
We do not sell directly identifiable health information to advertising networks or data brokers for targeted advertising.
We do not use health information obtained from Apple Health / HealthKit for targeted advertising or marketing.
We may use information to provide functionality directly to you, including personalized wellness information and service functionality.
We may also use appropriately de-identified or aggregated information for lawful purposes as described above.
14. International and Cross-Border Processing
Finesis and its service providers may process, store, or access information in countries other than the country in which you reside.
Those jurisdictions may have privacy laws that differ from those in your jurisdiction.
Where required by applicable law, we will implement appropriate safeguards for international transfers and processing.
15. Data Retention
We retain information for as long as reasonably necessary to:
- provide the Service;
- maintain your account;
- provide requested functionality;
- comply with legal, regulatory, tax, accounting, or security requirements;
- resolve disputes;
- enforce agreements;
- prevent fraud or abuse; and
- maintain necessary business and technical records.
Different categories of information may be retained for different periods.
Information that is no longer required for these purposes may be deleted, anonymized, or de-identified, subject to applicable law and legitimate retention requirements.
16. Account Deletion and Data Deletion
You may request deletion of your Chatbot.health account and associated personal information through the Service or by contacting Finesis.
When you request deletion, we will delete or de-identify personal information from our active systems within a reasonable period, subject to:
- legal and regulatory retention requirements;
- legitimate security requirements;
- fraud-prevention requirements;
- dispute resolution;
- enforcement of agreements;
- backup and disaster-recovery systems; and
- other lawful retention obligations.
Deletion from active systems may not result in immediate deletion from all backup systems. Backup copies may be retained for a limited period until they are overwritten or securely deleted in accordance with our backup procedures.
Disconnecting Apple Health / HealthKit or Android Health Connect prevents future access to data for which permission has been revoked, but does not necessarily delete information that was previously transferred to and stored by Finesis.
You may manage health-data permissions through the applicable device or platform privacy settings.
17. Your Rights and Privacy Choices
Depending on where you live and the laws applicable to you, you may have rights concerning your personal information, which may include rights to:
- access personal information;
- request correction of inaccurate information;
- request deletion;
- obtain information concerning our processing of personal information;
- withdraw certain permissions;
- object to or restrict certain processing;
- receive a portable copy of certain information; and
- appeal certain privacy decisions.
The availability and scope of these rights vary by jurisdiction and may be subject to legal exceptions.
You may also control certain information directly through:
- your account settings;
- device privacy settings;
- Apple Health / HealthKit permissions;
- Android Health Connect permissions;
- Bluetooth permissions;
- notification permissions; and
- connection and sharing settings within Chatbot.health.
To exercise a privacy right or request deletion, contact Finesis through the administrative contact mechanism provided on Chatbot.health.
We may need to verify your identity before fulfilling certain requests.
18. Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, alteration, disclosure, destruction, or loss.
Depending on the system and function, these safeguards may include:
- encryption of data in transit;
- encryption or other protection of data at rest;
- authentication and access controls;
- role-based access restrictions;
- logging and monitoring;
- security controls for cloud infrastructure;
- software and infrastructure maintenance;
- backup and recovery mechanisms; and
- security and incident-response procedures.
No system or method of transmitting information over the Internet can be guaranteed to be completely secure.
Accordingly, while we take reasonable measures to protect information, we cannot guarantee absolute security.
You are responsible for protecting your account credentials, mobile device, authentication information, and other access mechanisms.
19. Security Incidents and the FTC Health Breach Notification Rule
Finesis operates a consumer health and wellness service that may receive identifiable health information from multiple sources, including connected health platforms and devices.
Where applicable, Finesis will comply with the Federal Trade Commission’s Health Breach Notification Rule and other applicable breach-notification laws.
The FTC’s Health Breach Notification Rule applies to certain vendors of personal health records and related entities that are not covered by HIPAA and requires notification following certain breaches involving unsecured personally identifiable health information. The FTC’s 2024 amendments expressly clarified the Rule’s application to many health applications and connected technologies.
If a legally reportable security incident occurs, we will provide notices required by applicable law within the applicable legally required timeframes.
20. Third-Party Services
The Service depends on third-party services and infrastructure.
These may include, depending on the functionality you use:
- Apple Health / HealthKit;
- Android Health Connect;
- Amazon Cognito;
- Firebase Cloud Messaging;
- Firebase Crashlytics;
- cloud hosting providers;
- AI providers;
- wearable-device manufacturers;
- telecommunications and Internet providers; and
- other third-party infrastructure and technology providers.
Third-party services have their own privacy policies and terms.
Finesis is not responsible for the privacy practices of third parties that independently control information collected by their own services.
Your use of a connected third-party service may therefore be subject to that provider’s own terms and privacy policy.
21. Children’s Privacy
Chatbot.health is not intended for use by children where such use is prohibited by applicable law.
We do not knowingly collect personal information from children in circumstances where applicable law requires parental consent without obtaining the required consent.
If you believe that a child has provided personal information to us in violation of applicable law, please contact us so that we can investigate and take appropriate action.
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
- the Service;
- our data practices;
- technology;
- applicable laws or regulations;
- third-party platform requirements; or
- our business operations.
When we make material changes, we may provide notice through the Service, by email, or by other appropriate means.
The “Last Updated” date at the beginning of this Privacy Policy indicates when the policy was most recently revised.
Your continued use of the Service following the effective date of an updated Privacy Policy constitutes acceptance of the updated policy to the extent permitted by applicable law.
23. Contact Us
For privacy questions, requests to exercise privacy rights, or requests to delete your information, please contact Finesis LLC through the administrative contact mechanism available at Chatbot.health.
Finesis LLC
United States
Summary of the Information We Handle
For transparency, Chatbot.health may process the following categories of information depending on the functionality you use and the permissions you grant:
| Category | Examples |
|---|---|
| Account | Email, username, date of birth, authentication/session information |
| Health & fitness | Steps, heart rate, blood pressure, SpO₂, glucose/CGM, weight |
| Wearable data | Heart rate, SpO₂, BP, PPG, accelerometer, firmware, battery/device status |
| Nutrition | Food/drink descriptions, portion sizes |
| Medication | Medication names and doses |
| Health profile | Chronic-condition information |
| Connections | Names, emails, relationship type, permissions and shared profile information |
| Notifications | Push tokens, notification content, connection requests, health/wellness messages |
| Device/diagnostics | Device/app information, crash reports, error reports, sync logs |
| Sharing | QR-code/temporary guest-access information |
| AI processing | Information necessary to provide requested AI summaries, insights, and responses |
Not every user will provide or connect all of these categories. The information processed for a particular user depends on the features used, permissions granted, devices connected, and information voluntarily provided.
