Plain-language explanation of how we protect, de-identify, and process your health data — and the controls you have over it.
For legal terms, see our Privacy Policy and Terms of Service.
Secure & encrypted
All data in transit is protected by HTTPS/TLS. Stored records are encrypted at rest.
What reaches the AI
Your report is read once to pull out the numbers. The analysis is then written from those numbers alone — never from the document.
Anonymised Before AI
Our PHI Scrubber automatically strips names, dates of birth, addresses, and IDs before every AI call.
Privacy-first by design
You control your data — export, delete, or withdraw AI consent at any time.
Your data is stored in encrypted databases on secure cloud infrastructure. All data in transit is protected by HTTPS/TLS encryption, and stored records are encrypted at rest.
Access to sensitive systems is restricted to the systems and processes needed to run the platform. Changes to your privacy settings and administrative actions on your account are recorded in an audit trail. No third party has open access to your health records.
AI providers receive only anonymised health-related data required for analysis. Personal identifiers such as names, addresses, and contact details are removed before processing.
The following anonymised clinical data may be sent:
Analysing a report takes two separate steps, and they are given different things.
Reading it. The document or photograph you upload is read once, to pull the results off the page. Text is redacted before it is sent. A photograph cannot be redacted — nothing can edit the words inside a picture — so an image is read as supplied. It is deleted from our servers once it has been read.
Explaining it. The written analysis is produced from the extracted results alone — the analyte names, values, units, reference ranges and flags, plus an age band and sex at birth. The document and the photograph are not sent to this step at all. If nothing could be read from your upload, no analysis is written; we tell you instead of guessing.
This is why a clear photograph matters, and why a report that shows only your results — rather than a page carrying your name and NHS number — is always the safer thing to upload.
Before every AI call, text passes through our PHI Scrubber — a server-side pre-processing layer that automatically redacts identifying information.
Input (never sent to AI)
"Name: John Smith, DOB: 12/01/1990, NHS: 485 777 3456, SW1A 1AA, symptoms include headache"
After scrubbing (sent to AI)
"[NAME_REMOVED], age_band: 30_39, [NHS_REMOVED], [POSTCODE_REMOVED], symptoms include headache"
Names
Labeled prefix patterns (Name:, Patient:) and clinician title patterns (Dr., Prof.)
Dates of birth
Full dates replaced with age band — computed server-side
Contact details
Emails, UK/US/international phone numbers removed
Addresses & postcodes
Street addresses, UK postcodes (SW1A 2AA), US ZIPs removed
NHS / NI / SSN numbers
National ID patterns detected and removed across UK and US formats
Clinician names
Dr., Prof., Consultant, Radiologist title patterns removed
Hard gate
After scrubbing, a residual PHI check runs — if any PHI is still found, the AI call is blocked entirely
Allowlist schema
Each AI call uses a typed allowlist — only permitted fields can reach the AI model
Known limitation: Standalone names typed without a label prefix (e.g. "my friend John Smith") cannot be removed by pattern matching alone. Our consent notice asks users not to include personal names in symptom descriptions.
A text scrubber cannot reach inside a picture, so a photograph is handled differently from a PDF.
Crop first. When you choose a photograph of a report or a scan, we ask you to crop it to the results. Only what is inside the box is uploaded; anything outside it — your name, date of birth, NHS number, address, the clinic — never leaves your phone and never reaches us. A lab photo opens with the header already outside the box, so this happens even if you tap straight through.
Saved as a plain JPEG. Whichever you choose — the crop or the full photo — it is re-drawn on your device and saved as a fresh JPEG before anything is sent. The details a camera writes into a photo file, such as where it was taken and on which device, are not carried across. This is also what lets an iPhone's HEIC photo be read at all.
If you skip the crop. The reading step is instructed to transcribe results only, never patient details. Everything it writes down is then passed through the same scrubber our text path uses, and any line that still contains an identifier is discarded before it is stored or analysed.
Always. The photo itself is deleted from our servers once it has been read. It is not kept.
You can connect the health app on your phone so your own day-to-day readings sit alongside your reports. Apple Health is supported today; Google Health Connect is built and will follow on Android. What is written here applies to any source we add.
We read, we never write. Healio360 asks for read access only. It cannot add, change or delete anything in your health app — the write permission list in our app is empty, and iOS shows you this when it asks.
What is read. Resting heart rate, walking heart rate average, heart rate variability, sleep, blood oxygen, respiratory rate, steps, exercise time, active and resting energy, workouts and mindfulness sessions (used only to exclude those minutes from your HRV baseline; they are not stored), VO₂ max, and body measurements (weight, BMI, body fat, lean mass). Nothing else — not your location, not your medical ID, not anything you have logged in other apps unless it appears in one of those categories.
Sleep includes the times, not only the total. As well as how long you slept, we read when your main sleep period began and ended, so we can show whether your schedule holds steady from night to night. That is a genuinely different thing from how long you sleep, and it cannot be worked out from a total. Only the longest sleep of each day is used, so an afternoon nap is not mistaken for a bedtime. We store these as a clock time on your own local clock, never a location.
Where it goes. Readings sync to your encrypted record on our servers. Your trends, your usual ranges, and the Health Intelligence signals are all calculated there, by our own code — no AI provider is involved in producing them.
The one exception. The short written sleep-and-recovery note is produced by an AI provider. It receives that day’s figures only — hours slept, sleep efficiency, your seven-night average, heart rate variability, resting heart rate, stress and recovery scores — as numbers, with no name, date of birth or account attached. It is the only place any wearable reading leaves our servers.
Turning it off. On iPhone, Settings → Privacy & Security → Health → Healio360, and switch off whatever you choose; syncing stops immediately. Readings already synced stay in your record until you remove them, which you can do at any time from Settings → Privacy, along with everything else.
All AI requests are routed through our Safe AI Gateway — a centralized server-side service that enforces PHI scrubbing and allowlist schemas before every call. No route or page can call AI providers directly.
OpenAI (GPT-4o / GPT-4o-mini)
Blood test analysis, imaging analysis, skin assessment, AI Health Assistant chat, treatment guidance
Google Gemini (2.5 Flash)
Health trend narratives, AI Health Assistant (fallback), comprehensive health analysis
View your data
All reports and health history in your account
Download reports
Export your analysis reports in PDF format
Delete uploads
Remove individual reports and extracted data from Health History
Withdraw AI consent
Disable AI processing at any time via Settings
Delete your account
Request full deletion of your account and data
Contact us
support@healio360.com — we respond within 5 business days
You remain in control of your personal health data at all times.
Healio360 allows you to access, export, correct, or request deletion of your data through your account settings or by contacting our support team at support@healio360.com. We will respond to all data requests within 30 days in accordance with applicable data protection law.
Healio360 is operated from the United Kingdom and is designed with privacy, security, and data protection principles aligned with UK GDPR and the Data Protection Act 2018. As a UK-operated platform, our primary data protection framework is UK GDPR and ICO expectations.
Healio360 may serve users internationally, including in the United States, and is designed with privacy and security principles suitable for an international health information platform. For users in the United States, Healio360 aims to follow privacy and security practices aligned with relevant US healthcare privacy expectations where applicable.
Healio360 is currently positioned as an educational health information and health intelligence platform — not a diagnostic medical device. It is not currently FDA-cleared or FDA-approved and is not intended to diagnose, treat, cure, or prevent disease. If functionality evolves toward regulated medical-device software, MHRA requirements will be reviewed.
Healio360 is UK-operated. If you are in the UK, EU, or EEA, you have the following rights over your personal data. Users in other regions, including the United States, are also entitled to these protections where applicable. Contact us to exercise any of them.
Right to Access
Request a copy of the personal data we hold about you
Right to Rectification
Ask us to correct inaccurate data
Right to Erasure
Request deletion of your personal data ('right to be forgotten')
Right to Portability
Receive your data in a structured, machine-readable format
Right to Restriction
Ask us to restrict processing in certain circumstances
Right to Objection
Object to processing based on legitimate interests
How to make a request
Email support@healio360.com with subject line "GDPR Rights Request". We will respond within 30 days.
We process health data under Article 9(2)(a) UK GDPR and GDPR — your explicit consent, which you provide before using AI features. You can withdraw this consent at any time via Settings.
Privacy and security approach (UK and Europe)
Healio360 is operated from the United Kingdom under UK GDPR and the Data Protection Act 2018. We process health data under Article 9(2)(a) — your explicit consent, given before any AI feature runs and withdrawable at any time in Settings. Security measures include encryption in transit and at rest, strict access controls, and removal of personal identifiers before AI processing. Healio360 is not a substitute for medical care and provides informational and educational support only.
Privacy and security approach (United States)
Not a HIPAA-covered entity. Healio360 is a direct-to-consumer health platform. We are not a healthcare provider, health plan, or healthcare clearinghouse, and we do not process data on behalf of one. HIPAA therefore does not apply to us, and we make no HIPAA claim.
FTC Health Breach Notification Rule. As a health application that is not covered by HIPAA, we are subject to the Federal Trade Commission's Health Breach Notification Rule. If unsecured identifiable health information we hold is acquired without authorisation, we will notify the individuals affected and the Federal Trade Commission without unreasonable delay and no later than 60 calendar days after discovery, and will provide media notice where 500 or more people are affected. Unauthorised disclosure to a third party counts as a breach under this rule, whether or not there was an intrusion.
Washington My Health My Data Act. For Washington residents, we treat the data described on this page as consumer health data. We collect it only with your consent, we do not sell it, and you may withdraw consent and request deletion at any time using the contact route below.
California. Under the CCPA as amended by the CPRA, health information is sensitive personal information. We do not sell your personal information and we do not share it for cross-context behavioural advertising. California residents may request access, correction, deletion, or limits on the use of sensitive personal information using the contact route below; we will not discriminate against you for exercising these rights.
Not FDA-cleared. Healio360 is a general-wellness and educational platform. It is not a medical device, is not cleared or approved by the Food and Drug Administration, and is not intended to diagnose, treat, cure, or prevent any disease.
Not a medical diagnosis service
Healio360 provides educational health summaries to help you understand your results and prepare questions for your clinician. It does not provide clinical diagnoses. If you have urgent symptoms, seek emergency care immediately.
Legal documents
For full legal terms, see our linked documents.
Healio360 provides AI-assisted health insights for educational and informational purposes only and does not replace professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional for any medical concern.
Last updated: 2026-09-06