health-os · a Hakari AI project
Effective September 21, 2026

Privacy Policy

health-os is personal software operated by Hakari AI for its operator and their household. It is not offered as a service to the public. This policy describes how it handles data for the small set of people who actually use it.

What data is collected

With the account holder's explicit authorization, health-os retrieves personal health and fitness data from third-party services through their official APIs — for example sleep, readiness, and heart-rate data from Oura, recovery, strain, and sleep data from Whoop, and workout data from Hevy. Users may also log data directly (for example, meals via a chat assistant).

Where data lives

Each person's data is stored in its own database, inside a single self-contained application that is run either on private hardware operated by Hakari AI or on a dedicated cloud application provisioned for one household on Fly.io, with the databases held on an encrypted persistent disk in the region chosen for that household. One application per household means no database is ever shared across households. There is no third-party cloud database, no third-party analytics, no advertising, and no error-tracking service that ships data off that application.

How access is controlled

Each person has their own access token. A token can reach only that person's database — no request can name another person, and there is no combined view across people.

How data is used

Data is used solely to show users their own metrics, trends, and summaries, and to generate personal (non-medical) guidance for them. Limited, summarized excerpts may be processed by an AI model provider to generate those summaries; raw data exports are never shared.

What is never done with data

Access tokens

OAuth tokens for connected services are stored encrypted-at-rest on the same disk as that person's database, and used only to retrieve the authorizing user's own data. You can revoke health-os's access at any time from the connected service (for Oura: cloud.ouraring.com; for Whoop: the privacy settings in your WHOOP app), which immediately stops all data retrieval.

Deletion

Any user can request complete deletion of their stored data at any time by contacting the operator; deletion is immediate and permanent.

Contact

hello@hakari.ai