Privacy Policy
Last updated: 2026-09-04
1. Who we are
saviorofhealth (the "Service") is an AI-assisted health-tracking application. It is operated by the saviorofhealth team ("we", "us"). Contact: official@saviorofhealth.app.
2. What we collect
- Account & identity: wallet address, optional display name, optional age / height / weight, chronic conditions you select.
- Daily logs you create: water, meals (descriptions + AI-estimated nutrition), exercise, sleep, mood, meditation sessions, community posts.
- Conversations: messages exchanged with the AI agents (stored to provide cross-session memory).
- Push subscriptions: the browser push endpoint and keys, only when you opt in.
- Operational data: request timestamps and, for login and consent records, a basic user-agent string.
- IP addresses: not stored in your account. They appear in server access logs kept for up to 48 days for security and abuse investigation, and login records keep only a salted one-way hash of the address, which cannot be reversed to the IP.
- What we do NOT collect: emails (unless you give one as a partner contact), phone numbers, contacts, or any government identifiers. Your wallet address is your only account identifier.
3. How we use it
- Provide the AI agents (Nurse, Gatekeeper, Nutritionist, MindCare) with the context needed to give personalized guidance.
- Calculate streaks, daily progress, and reward eligibility.
- Send the notifications you have enabled in Notifications.
- Diagnose abuse, billing, and security issues.
4. Third-party services
- OpenAI (API): when you talk to an AI agent or log a meal in chat, the message text plus minimal context (your display name if you set one, age group, BMI, chronic conditions, recent conversation topics) is sent to OpenAI to generate the reply and estimate nutrition. Your exact age, height, weight and wallet address are never sent. API data is not used to train OpenAI models and is retained for up to 30 days for abuse monitoring, then deleted. openai.com/enterprise-privacy.
- Amazon Web Services (Seoul region): the application and our own PostgreSQL database run on AWS servers we operate. AWS provides the infrastructure and does not access your data. aws.amazon.com/privacy.
- X (Twitter) follow verification: if you connect your X account for a mission, your public X user id may be sent to a third-party X data API (via RapidAPI) to read your public following list. No message content or health data is shared.
- Cloudflare Turnstile: if our anti-abuse checks limit your account, the verification widget at /verify sends browser signals and your IP address to Cloudflare to tell people from scripts. cloudflare.com/privacypolicy.
- Browser push services (FCM / APNs / Mozilla) deliver the actual push payloads to your device.
5. Storage & security
- Data is stored in a PostgreSQL database we operate ourselves on AWS (Seoul). The database is not reachable from the internet; only the application server can connect. All traffic to the site is TLS-encrypted.
- Sessions use a signed token kept in an HttpOnly, Secure cookie so page scripts cannot read it. Conversation messages and other sensitive fields are encrypted at the application layer (AES-256-GCM) with a key not stored in the database.
- We do not sell your data. We do not run third-party advertising trackers.
6. Your rights
- Access / export: contact us and we will return all data tied to your account.
- Deletion: contact us to delete your account and all associated logs. Push subscriptions and notification preferences are removable from /notifications.
- Correction: edit logs (e.g. meals) inline in each tracker, or contact us.
- Withdraw consent: withdrawing consent stops new processing but does not affect lawful processing already done.
7. Retention
We retain logs and conversations for as long as your account is active. On account deletion we remove personal data within 30 days (longer only when legally required, e.g. anti-fraud audit logs).
8. Children
saviorofhealth is not directed at users under 16. Do not create an account if you are under 16.
9. Aggregate data licensing (disclosure)
We license anonymized, aggregated statistics (survey answer distributions, cohort averages, symptom trends) to approved organizations via partner dashboards and a Data API.
- Aggregates only. Never your identity, wallet address, or raw records.
- k-anonymity: any slice with fewer than 5 respondents is suppressed automatically.
- Reporting windows are fixed (7 / 30 / 90 / 365 days) and cohort sizes are rounded, so overlapping queries cannot be differenced down to one person.
- Buyers are manually approved, usage-metered, and contractually barred from re-identification.
- You can opt out of contributing by not answering surveys; existing aggregates cannot be reversed to individuals.
10. Changes
If we materially change this policy we will surface a notice in-app before continuing to process data under the new terms.