Privacy Policy
Last updated: October 2, 2026
Health Nexus, a dba of FollowThatPatient.com (“Health Nexus,” “we,” “us”), respects your privacy. This Privacy Policy explains what information we collect, how we use and share it, how we protect it, and the choices and rights you have. It applies to health-nexus.com, our member portal at portal.health-nexus.com, the Health Nexus mobile app for iOS and Android, and related services (the “Services”). Our Terms of Service govern your use of the Services, and this Policy forms part of them.
Privacy at a glance
- What we collect: your account details, your health records and results, information from devices you choose to connect, and basic technical information.
- How AI is used: your health information is analyzed by Claude, an AI model by Anthropic, running in our own Amazon Web Services account under a HIPAA Business Associate Agreement. It is not used to train AI models.
- Who can see it: you, your clinic’s care team, authorized Health Nexus staff, and the service providers that help us run the Services.
- What we never do: sell your personal information, or use your health information — including Apple Health data — for advertising.
- Your choices: access, correct, download, or delete your information by emailing Support@health-nexus.com.
1. Information we collect
1.1 Information you provide
- Account and identity information: name, email, date of birth, sex, phone number, shipping and billing address, and the clinic location you choose when you sign up.
- Consent and signature records: when you accept our Terms or other consents, the name you type as your signature, the date and time, your IP address, and your device or browser information.
- Health information: laboratory results, biomarkers, uploaded medical records (such as imaging reports, DEXA scans, and clinician notes), intake responses and questionnaire answers, and information you share with our care team.
- AI health assistant conversations: the questions you ask in chat and the answers you receive.
- Payment information: processed by Stripe, Inc. We receive limited details such as the last four digits, card brand, and subscription status. We do not store full card numbers.
- Communications: emails, support requests, and messages you send us.
1.2 Information from your devices and connected services
Only with your permission:
- Apple Health: activity, heart, sleep, and body measurement data you allow the app to read (Section 4).
- Wearable devices: data from watches, rings, scales, glucose monitors, and other devices you connect through Junction (Section 4).
- Body scans: a camera recording of a guided scan, together with your height, weight, sex, and birth date, processed by Prism Labs (Section 5).
1.3 Information from your clinic, laboratories, and partners
- laboratory results and reports sent to your account by laboratories working with your clinic;
- clinician notes and documents your clinic adds to your account;
- body measurements, body-composition estimates, and a 3D body model returned by Prism Labs after a scan;
- device data delivered through Junction.
1.4 Information we generate
Results extracted from documents you upload; health, category, and vitality scores; biological age estimates; AI-generated summaries, insights, and protocols (recommendations and action items); and records of the notifications we send you.
1.5 Technical information
- IP address, device and browser type, pages viewed, referring pages, and approximate location derived from IP;
- in the mobile app, your device’s push-notification token, app version, and operating system.
1.6 Device permissions the mobile app asks for
| Permission | Why we ask | When |
|---|---|---|
| Camera | To record a body scan | Only when you start a body scan |
| Motion sensors | To keep your phone level and steady during a body scan; never used to track your activity | During a body scan |
| Apple Health (read) | To show your activity, heart, sleep, and body data and personalize your insights | When you connect Apple Health |
| Notifications | To tell you when your results or your protocol are ready | When you allow notifications |
iOS also lists an Apple Health “write” permission and Face ID for the app because of software libraries the app includes. Health Nexus never writes to Apple Health and never turns on Face ID.
1.7 What we do not collect
The mobile app does not access your precise (GPS) location, contacts, photo library, or microphone. It does not use advertising identifiers or track you across other companies’ apps and websites. Documents you upload are files you choose yourself.
2. How we use information
- To provide memberships, testing, results, protocols, and clinician access;
- To create and maintain your account and Digital Health Vault;
- To process payments, renewals, refunds, and fulfillment;
- To generate personalized insights, including via automated and AI-assisted analysis (Section 3);
- To read the documents you upload and extract your results;
- To calculate your health scores and biological age and to create your protocol;
- To answer your questions in the AI health assistant;
- To sync and display Apple Health and device data, and to perform body scans;
- To send notifications you rely on, such as when new results or your protocol are ready;
- To record your consents and agreements;
- To secure the Services, prevent fraud, and debug problems;
- To communicate service updates and, with your consent, marketing;
- To comply with legal obligations and enforce our Terms.
We do not sell your personal information, and we do not sell or share your health information for advertising or cross-context behavioral advertising. Information you provide is not used by our AI provider to train AI models, and we do not use your identifiable information to train AI models.
3. How we use artificial intelligence
3.1 What the AI does
We use AI to read the lab reports and documents you upload and extract your results; to write your health summaries, insights, and protocol; and to answer your questions in the AI health assistant.
3.2 Who processes it
Our AI features are powered by Claude, an AI model developed by Anthropic, PBC, which we access through Amazon Bedrock within our own Amazon Web Services (“AWS”) account in the United States. AWS processes this information on our behalf under a HIPAA Business Associate Agreement. Your information is not made available to Anthropic, and it is not used to train AI models by AWS or Anthropic. No other AI service receives your health information.
3.3 What the AI receives
Only the information needed for the feature you are using. Depending on the feature, this may include your lab reports and results, uploaded documents, questionnaire answers, Apple Health and wearable data, other health information in your account, and your chat messages.
3.4 Web lookups for general health information
The AI health assistant may look up general medical information on public websites through our search provider, Tavily, preferring trusted sources such as the National Institutes of Health, the Centers for Disease Control and Prevention, and Mayo Clinic. Only the search terms are sent — never your name, contact details, or account information.
3.5 Your consent
Before we process your information with AI, we ask for your affirmative consent. The consent screen shown when you first sign in names our AI provider and describes what it receives, and the app shows a one-time notice before your first lab-report upload and before you first connect a device. The app’s “AI & Your Data” page (Profile → About & Legal) explains all of this in plain language. Because the Services are built on AI analysis, they cannot be used without this consent. You can withdraw your consent at any time by emailing Support@health-nexus.com; withdrawing ends your use of the Services.
3.6 Human review
Your clinic’s care team can see AI-generated outputs and may review or adjust your recommendations. Authorized Health Nexus staff may review AI chat conversations for quality and support.
3.7 Accuracy and sources
AI can make mistakes. AI-generated summaries, recommendations, and answers are for your information only and are not medical advice. The app shows where its health information comes from on its Health Information Sources page and in “Sources” links next to medical information.
4. Apple Health and connected devices
4.1 What we read
With your permission, the app reads activity, heart, sleep, and body measurement data from Apple Health (HealthKit). Access is read-only — Health Nexus never writes to Apple Health — and you choose which data types to share. You can also connect other devices, such as watches, rings, scales, and glucose monitors, through Junction’s secure connection page. Depending on what you allow, this may include steps, activity, workouts, sleep, heart rate, heart-rate variability, blood oxygen, respiratory rate, VO2 max, body measurements, blood pressure, glucose, and temperature.
4.2 How we use it
To show your device data in the app and member portal, calculate your scores, and personalize your insights, including the AI analysis described in Section 3.
4.3 How it is shared
Device data, including Apple Health data, is synced through Junction, our health-data integration partner, to our servers on AWS. It is visible to you and to your clinic’s care team.
4.4 Our commitments for Apple Health data
- It is never used for advertising, marketing, or data mining for those purposes.
- It is never sold, and never shared with advertising platforms, data brokers, or information resellers.
- It is shared with third parties only to provide the Services (Junction and AWS), with your consent (such as with your care team), or where required by law.
- It is not stored in iCloud.
4.5 Your controls
You can stop sharing Apple Health data at any time in the Health app or in your iPhone settings, and you can disconnect any device from the Data tab in the app. Disconnecting stops new data from syncing; to delete data already synced, contact us (Section 11).
5. Body scans
5.1 How scans work
Body scans are optional and require your consent to the scanning terms. During a scan, the app uses your phone’s camera to record a guided scan and its motion sensors to keep the phone level and steady.
5.2 What we share with Prism Labs
The scan recording and the details the scan needs — your height, weight, sex, birth date, and region — under a random identifier rather than your name or email address.
5.3 What we receive and keep
Body measurements, body-composition estimates, and a 3D body model, which we keep in your account to show your digital twin and track changes over time.
5.4 Limits on use
We instruct Prism Labs not to use your scans for research. We do not use body scans to identify you, and we do not sell body-scan data. Where state law treats body-scan data as biometric information, we handle it as that law requires. Prism Labs processes scans under its own privacy policy: https://www.prismlabs.tech/privacy-policy.
Because 3D scans include rough measurements of face geometry, some scan data may be considered “biometric identifiers” under laws such as the Illinois Biometric Information Privacy Act (BIPA). For known residents of Illinois, subject to any applicable exception under BIPA, scans of face geometry are permanently destroyed when the purpose for collecting them has been satisfied or three years have passed since your last interaction with Health Nexus, whichever comes first. You can delete a scan from the app at any time, which removes it from Prism Labs and from our systems.
6. How we share information
- Your clinic and care team: your clinic’s care team can see your information to support your care.
- Clinical partners: CLIA-certified laboratories, independent ordering physicians, phlebotomy providers, and clinicians involved in your care.
- Service providers: hosting, database, email, analytics, customer support, and shipping vendors, bound by contract to protect your information and use it only for us, including the providers listed in Section 7.
- AI processing: Claude by Anthropic, through Amazon Bedrock in our AWS account, as described in Section 3.
- Payment processing: Stripe, under its own privacy policy.
- Legal and safety: when required by law, subpoena, or to protect rights, safety, or prevent fraud.
- Business transfers: in connection with a merger, financing, acquisition, or sale of assets, subject to this Policy.
- With your direction: when you ask us to send records to a provider or third party.
Authorized Health Nexus staff can access your information only as needed to operate, support, and secure the Services.
We do not sell your personal information, and we do not sell or share your health information for advertising or cross-context behavioral advertising.
7. Our service providers
These are the principal service providers that process personal information for us. Each is bound by contract to protect it and to use it only to provide services to us.
| Provider | What they do for us | Information involved |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, file storage, and AI processing through Amazon Bedrock, under a HIPAA Business Associate Agreement | The information needed to run the Services |
| Anthropic (Claude), through Amazon Bedrock | The AI model behind document reading, summaries, protocols, and chat. It runs inside our AWS account. | None — Anthropic does not receive your information |
| Junction (formerly Vital) | Syncing Apple Health and wearable devices | Device data and an account identifier |
| Prism Labs | Body scans | Scan recording, height, weight, sex, birth date, and region, under a random identifier |
| Google Firebase Cloud Messaging and Apple Push Notification service | Delivering push notifications | Device push token and notification text |
| Twilio SendGrid | Sending email | Email address, name, and email content |
| Tavily | Web search for general health information in AI chat | Search terms only |
| Stripe, Inc. | Payment processing for purchases on our website | Payment details |
| Laboratories and clinical partners | Laboratory testing and clinical services | The information needed for your tests and care |
8. Health information and HIPAA
Some of the information we handle is protected health information created or received in connection with clinical services. Where we act as a business associate of a covered entity, or where a covered entity relationship exists, that information is handled in accordance with HIPAA and applicable business associate agreements. Information you upload voluntarily that is not created through a covered clinical encounter is protected under this Policy and applicable state health-privacy laws, including the California Confidentiality of Medical Information Act and the Washington My Health My Data Act where applicable.
We maintain business associate agreements with the service providers that process protected health information for us, including Amazon Web Services, which hosts the Services and runs our AI processing.
9. Security
We use encryption in transit and at rest, role-based access controls, row-level database security, audit logging, least-privilege administration, and vendor security review. No system is perfectly secure; we cannot guarantee absolute security, and you share information at your own risk. If a breach affecting your information occurs, we will notify you as required by law.
In the mobile app, your sign-in is kept in your device’s secure storage (such as the iOS Keychain), and documents you open are cached temporarily on your device and removed when you sign out.
10. Retention
Health Nexus is a software company, not a healthcare provider. Lab results and other records that come from your clinic, laboratory, or care team may also be held by those providers, who keep them for the periods required by HIPAA and state medical-records laws; deleting your Health Nexus account does not delete the copies they hold.
We keep your information for as long as your account is active and afterward as needed to meet legal, clinical recordkeeping, tax, and accounting obligations — typically at least seven years for records associated with laboratory testing. We then delete or de-identify it.
- Consent and signature records: for as long as your account is active and at least three years after it is closed.
- AI chat conversations, device data, and body-scan results: kept with your account and handled under the same rules.
- Copies cached on your phone: removed when you sign out of the app.
- When you close your account: we stop actively processing your health information within 30 days and delete or de-identify your information within 90 days, except records we must keep for the legal and clinical recordkeeping obligations above.
11. Your rights and choices
- Access, correct, or download a copy of your information;
- Request deletion of your account and information, subject to legal retention;
- Withdraw consent for optional processing and for AI-assisted analysis — because the Services are built on AI analysis, withdrawing that consent ends your use of the Services;
- Opt out of marketing email at any time via the unsubscribe link;
- Limit cookies through our cookie banner and browser settings;
- Turn off push notifications in your device settings;
- Stop sharing Apple Health data or disconnect devices (Section 4.5);
- Appeal a denied request, and (California residents) exercise rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
To exercise any right, email Support@health-nexus.com from the email address on your account. We will verify your identity and respond within the time required by law (generally 45 days). You may also use an authorized agent; we will verify the agent’s authority before acting.
12. U.S. state privacy rights
12.1 California
If you live in California, the CCPA/CPRA gives you the right to know what personal information we collect and how we use and disclose it; to access, correct, and delete it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell or share personal information, and we use sensitive personal information (such as health information) only to provide the Services and for other purposes the law permits.
In the past 12 months we have collected the following categories of personal information, from the sources and for the purposes described in this Policy, and disclosed them for business purposes to the recipients described in Sections 6 and 7:
| Category | Examples |
|---|---|
| Identifiers | Name, email, phone number, postal address, IP address, account and device identifiers |
| Customer records | Billing and shipping address, limited payment details |
| Protected classification characteristics | Date of birth (age), sex |
| Commercial information | Membership and purchase history |
| Internet or network activity | Pages viewed, referring pages, device and browser type |
| Geolocation | Approximate location derived from IP address (not precise location) |
| Sensitive personal information | Health information, body-scan data, account login credentials |
| Inferences | Health scores, biological age estimates, AI-generated insights |
Medical information of California residents is also protected under the California Confidentiality of Medical Information Act.
12.2 Washington, Nevada, and other consumer health data laws
Where the Washington My Health My Data Act, Nevada Senate Bill 370, or similar laws apply, we collect and share consumer health data only with your consent or as necessary to provide the Services you request, and we never sell it. You may confirm whether we collect your consumer health data and access it, including a list of the third parties and affiliates with which we have shared it; request its deletion; withdraw your consent; and appeal a denied request, by emailing Support@health-nexus.com.
12.3 Other states
Residents of other states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Texas, and Oregon) may have similar rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not engage in targeted advertising, sell personal data, or use profiling to make decisions that produce legal or similarly significant effects about you. To exercise your rights or appeal a decision, email Support@health-nexus.com.
13. Cookies and similar technologies
Our website uses cookies and similar technologies as described in our Cookie Policy at health-nexus.com/cookies. You can limit cookies through our cookie banner and your browser settings. Our member portal and mobile app use only the storage needed to sign you in, keep you signed in, and run the Services. The mobile app does not use advertising identifiers or track you across other companies’ apps and websites. Because we do not sell personal information or share it for cross-context behavioral advertising, there is nothing for a browser “Do Not Track” or Global Privacy Control signal to opt you out of.
14. Legal bases (EEA/UK visitors)
Where GDPR applies, we process personal data on the bases of contract performance, your explicit consent (for health data), our legitimate interests in operating and securing the Services, and compliance with legal obligations.
15. Children
The Services are not directed to anyone under 18, and we do not knowingly collect information from children. If we learn we have, we will delete it.
16. International transfers
We operate in the United States. If you access the Services from outside the U.S., your information will be transferred to and processed in the U.S. under appropriate safeguards.
17. Changes to this Policy
We may update this Policy. Material changes will be posted here with a new “Last updated” date and, where required, emailed to you or shown in the Services for your review.
18. Contact us
For questions about this Policy or to make a privacy request, contact us at (for requests, include “Privacy Request” in the subject line):
Health Nexus, a dba of FollowThatPatient.com
P.O. Box 4199, Malibu, CA 90264
Support@health-nexus.com