What we collect

Health documents you upload (PDFs, images, pathology results, letters).

Supplement and medication details and photos you enter.

Personal notes and symptom logs you create.

Cycle data if you use the cycle tracking feature.

Subscription status only (active/inactive) — no payment details.

Anonymised analytics about feature usage, only with your consent.

We do not collect your name, email, location, or any account credentials.


How your health data is processed

All health data is stored on your device only. HealthLens does not maintain a server-side database of your records.

When you upload a document or generate an AI summary, your document content is sent over encrypted HTTPS to our processing server in Australia, then forwarded to Anthropic (United States) for AI analysis using Claude. The result is returned to your device and stored locally. No health data is retained on our servers after processing.


AI processing & third-party services

Anthropic processes your document content solely to generate AI analysis. Anthropic does not use API content to train its models by default. Anthropic retains API request logs for up to 30 days for safety monitoring, then deletes them.

Subscription billing is handled by Apple or Google depending on your platform. No health data is shared with billing or payment providers.


Data storage & security

Your health data is stored in an encrypted database on your device. All transmissions use TLS (HTTPS). Our server does not store health data after processing. Your device passcode and biometric lock protect your local data.

Device backups (iCloud / Google Backup) may include HealthLens data under Apple's and Google's policies. Use Settings → Export to create your own portable backup.


Your rights

Australia (Privacy Act 1988)

Access, correct, or complain about your personal information. Contact support@health-lens.com. Unresolved complaints: Office of the Australian Information Commissioner (oaic.gov.au).

New Zealand (Privacy Act 2020)

Access, correct, or complain. Contact support@health-lens.com. Unresolved: Office of the Privacy Commissioner NZ (privacy.org.nz).

United States

We are not a HIPAA-covered entity. Subject to FTC Act Section 5 and the FTC Health Breach Notification Rule. In the event of a breach we will notify affected individuals within 60 days. Contact support@health-lens.com.

Canada (PIPEDA)

Access, correct, or withdraw consent. Contact support@health-lens.com. Unresolved: Privacy Commissioner of Canada. Quebec residents: Law 25 rights apply.


Contact

support@health-lens.com