Privacy Policy
What Grace Health collects, why, and who else can see it.
Draft — pending legal review
This document describes current system behaviour accurately, but it has not been reviewed by a qualified lawyer and is not yet a published legal notice. Items marked [requires confirmation] need a human answer before publication.
1. Who we are
Grace Health is an online service for medical weight management. You complete a health assessment, a licensed clinician reviews it, and — where clinically appropriate — treatment and ongoing care follow. Grace Health operates the platform; it is not itself the treating clinician.
2. What we collect
This is the complete list. We do not collect categories that are not named here.
Account details
Your email address, first, middle and last name, and date of birth. If you sign in with Google, we receive your email address and name from Google.
Health information from your assessment
The assessment asks for the information a clinician needs to judge whether treatment is appropriate:
- Height, weight and derived BMI
- Current medications
- Allergies
- Relevant medical history and existing conditions
- Previous weight-loss treatments
- Alcohol and substance use
- Your treatment goals
Messages you send the AI assistant
Anything you type into the assistant, and the replies it gives. See section 4 — these leave our systems.
Progress check-ins
Weight and progress updates you record during ongoing care.
What we do not collect
- Files of any kind. There is no upload feature. You cannot send us documents, lab reports, scans or photographs, and we have no file storage.
- Analytics or tracking. No analytics service, no tracking pixels, no advertising identifiers, no session recording, no third-party marketing tags.
- Advertising profiles. We do not sell or share your information with advertisers. There is no advertising on the service.
- Payment card details. These never reach our systems — see section 5.
3. Cookies and similar technologies
We do not use cookies for analytics, advertising or tracking. Signing in stores a session credential in your browser so you stay logged in between pages; that is set by Google Firebase Authentication and is required for the service to function. Clearing your browser storage signs you out.
4. Artificial intelligence
The service includes an AI assistant, and you are talking to software, not a person.
- Where your messages go. They are sent to OpenAI, which generates the reply. Up to your last ten exchanges are sent with each message so the assistant follows the conversation.
- What is sent. Your typed messages and that recent conversation history. Your stored assessment answers and clinical record are not attached to these requests.
- Retention and training by OpenAI. Governed by OpenAI's API terms rather than by us. [requires confirmation] — the exact retention period and training-exclusion status applicable to our account must be confirmed against our OpenAI agreement before this is stated as fact.
- It is not medical advice. The assistant cannot diagnose you, cannot prescribe, and can be wrong. It does not replace your clinician.
- Safety handling. Messages suggesting an emergency, self-harm, or requests to change medication or dosage are intercepted before reaching the assistant and answered with directions to real-world help instead. This is automated pattern matching, not a monitored crisis service — nobody is watching your conversation in real time, and the system cannot contact emergency services for you.
5. Who else processes your information
| Provider | What it does | What it receives |
|---|---|---|
| Google Firebase / Google Cloud | Sign-in, database, hosting, application backend | Everything in section 2. This is where your record lives. |
| OpenAI | Generates AI assistant replies | Your assistant messages and recent conversation history |
| Tebra | Medical billing system of record | Name, date of birth, email and gender, to create your billing record. Your assessment answers and clinical notes are not sent. |
| Mailgun | Delivers service email | Your email address and the message content |
| Google reCAPTCHA Enterprise | Confirms requests come from a real browser, not a bot | Device and browser signals, IP address |
Each of these has its own privacy terms. [requires confirmation] — the data-processing agreements in force with each provider need to be confirmed and summarised here.
Payment cards. Card details are handled by the payment provider, never by Grace Health. We hold only whether a payment succeeded, when, and for how much.
6. Who inside Grace Health can see your information
- You — your own record, and nobody else's.
- Clinicians — patient records and assessments, to carry out the review and provide care.
- Billing staff — billing and payment status. This is a separate permission from clinical access; billing staff cannot make clinical decisions and clinicians do not get financial access by default.
7. How long we keep it
Your account and health record are kept while your account exists, and are removed when you delete it (section 8).
[requires confirmation] — retention periods for clinical records after account closure, and for billing records, are set by medical-record and tax law in the jurisdictions Grace Health operates in. Those jurisdictions have not been fixed, so no period is stated here rather than stating one we cannot honour.
Backups: deleted data may persist in routine infrastructure backups for a period after deletion. We do not claim instant erasure from backups, because we cannot guarantee it. [requires confirmation] — actual backup retention window.
8. Deleting your account
You can delete your account from account settings. Deletion is immediate and cannot be undone. It removes your profile, your patient record, your assessment submissions and your sign-in credentials, and records that the deletion happened.
A record of the deletion event itself is retained so we can show that your request was carried out.
9. Your choices
- See your information — your assessment answers and profile are visible in the patient area.
- Correct it — name and date of birth are editable in your profile. To correct clinical information, contact your care team, because changing a clinical record needs clinician review.
- Delete it — see section 8.
[requires confirmation] — additional statutory rights (such as data export or objection to processing) depend on which jurisdictions Grace Health serves. This is unresolved, so no jurisdiction-specific rights are claimed here.
10. How your information is protected
- Traffic between your browser and the service is encrypted (HTTPS).
- Google Cloud encrypts stored data at rest as a property of the platform.
- Access is enforced by server-side rules, so one patient cannot read another patient's record.
- Clinical decisions and billing actions are recorded in an audit trail that cannot be edited from a browser.
- Sign-in is handled by Google Firebase Authentication. We never see or store your password.
We describe only controls that are actually implemented. We hold no security certification and make no claim to one.
11. Limits you should know about
Not HIPAA-covered
Grace Health does not operate as a HIPAA covered entity or business associate, and there is no Business Associate Agreement in place. Whether HIPAA ought to apply is a legal question that has not been settled. Your information is treated as confidential regardless, but do not assume HIPAA protections apply.
Not for emergencies
Grace Health is not monitored continuously and cannot respond to urgent medical situations. If you are in danger or need urgent care, call 911 or go to your nearest emergency department.
12. Where your information is held
The service runs on Google Cloud infrastructure in the United States, and the providers in section 5 are US-based. Your information is therefore processed in the United States.
13. Changes to this policy
If what we collect or who processes it changes, this page changes with it. Material changes will be communicated to account holders.
14. Contact
Questions about your information, or about this policy, go through the contact page.
[requires confirmation] — a dedicated privacy contact address and postal address must be established and published here. No address is printed above because none has been verified, and printing an unmonitored one would leave privacy requests unanswered.