Privacy Policy
health-os is personal software operated by Hakari AI for its operator and their household. It is not offered as a service to the public. This policy describes how it handles data for the small set of people who actually use it.
What data is collected
With the account holder's explicit authorization, health-os retrieves personal health and fitness data from third-party services through their official APIs — for example sleep, readiness, and heart-rate data from Oura, and workout data from Hevy. Users may also log data directly (for example, meals via a chat assistant).
Where data lives
All retrieved data is stored on private, self-hosted hardware operated by Hakari AI. There is no third-party cloud database, no third-party analytics, no advertising, and no error-tracking service that ships data off that hardware.
How data is used
Data is used solely to show users their own metrics, trends, and summaries, and to generate personal (non-medical) guidance for them. Limited, summarized excerpts may be processed by an AI model provider to generate those summaries; raw data exports are never shared.
What is never done with data
- Never sold, rented, or shared with third parties
- Never used for advertising or profiling
- Never combined across users
Access tokens
OAuth tokens for connected services are stored encrypted-at-rest on the same private hardware and used only to retrieve the authorizing user's own data. You can revoke health-os's access at any time from the connected service (for Oura: cloud.ouraring.com), which immediately stops all data retrieval.
Deletion
Any user can request complete deletion of their stored data at any time by contacting the operator; deletion is immediate and permanent.