What this covers
Third Genome builds private, local-first health software. healthBot is a health assistant that reads and explains your health records; the Third Genome Wearable Sync app is the Android bridge that brings wearable data into healthBot. This policy explains what data these products handle, where it lives, and how it is protected.
What data we collect (and how)
Wearable/health data you choose to share:
We do not "collect" your health data: the server is a private bridge and archive for your own data, isolated per user, on our own self-hosted infrastructure. It is never sold, shared, or used for anything other than serving you.
- With the Wearable Sync app you can connect your phone’s Health Connect (on Android, the system health-data hub fed by apps like Samsung Health, Google Fit, and watch apps). With your explicit permission, the app reads the data types you grant: activity/steps, sleep, heart rate & HRV, workouts, blood oxygen, and body measurements. Summaries of this data are synced to your private Open Wearables account on our self-hosted server.
- In healthBot, data you import or sync (labs, genotypes, vitals, wearable summaries) is stored in your on-device vault, protected by a passcode you create. Only you can decrypt it.
- Technical usage data: standard app/server logs (timestamps, error signatures) and, ONLY if you opt in, debug telemetry to help us fix issues. No health contents are included in debug telemetry.
Where your data lives
- Your device: your healthBot vault (encrypted at rest, passcode-only).
- Our self-hosted server (your Open Wearables account): daily wearable summaries, encrypted in transit (TLS). We do not use third-party cloud health storage.
- AI providers: to answer your questions, healthBot sends the context you authorize to the AI provider you select from Settings. You control this; the de-identified context note is shown in the app.
How we use it — and don’t
- Used to provide, personalize, and improve our products (your summaries power healthBot’s answers to you).
- Never sold. Never shared with advertisers. Not used to build profiles for anyone else.
- Shared only: (a) with the AI provider you choose (as above), (b) if you ask us to export/restore your vault, (c) where the law requires.
Security
- healthBot: your vault decrypts with your passcode only — we never see or store your passcode or your decrypted data.
- Wearable Sync app: connect codes are single-use, short-lived, and per-account; the app stores no Open Wearables credentials.
- Transmission: TLS everywhere.
- Access: your Open Wearables data is isolated per account.
Your controls & rights
- Permissions: grant or revoke wearable data access at any time in your phone’s Health Connect settings or in the Wearable Sync app.
- Delete: you can wipe your healthBot vault in-app; you can request removal of stored Open Wearables account data by contacting us.
- Retention: per-user retention controls (including an option to automatically purge wearable data from the server once healthBot has imported it) are planned; we will announce them here when available.
- Access, correction, portability: request a copy or correction of your data at the contact below; backups you create (encrypted vault exports) are yours.
Children, changes, contact
- Our products are intended for adults; we do not knowingly collect children’s data.
- We may update this policy; significant changes will be announced in-product.
- Contact: pro-support@third-genome.com
Third Genome — health data stays yours.