Scope and responsibility
This policy applies to Anistratenco websites, direct-to-user accounts, HealthOS, chat, research, projects, voice, files, billing, shared plans, and support. Anistratenco determines the purposes and means of processing for those direct services unless a separate signed agreement identifies a different controller or processor relationship.
A payment processor, connected service, app store, model provider, or other independent service may process information under its own notice when you choose that service. A feature-specific disclosure shown at collection supplements this policy and controls if it gives you a more specific choice.
Information and sources
We receive information directly from you, from the device and browser you use, from people who invite you to a shared plan, from services you connect, from payment and identity providers, and from security or anti-abuse signals generated when the Service is used.
- Account, contact, age-confirmation, authentication, profile, support, and shared-plan details.
- Health context you choose to provide, including symptoms, routines, medications, biomarkers, laboratory results, family history, or genetic context.
- Prompts, conversations, projects, feedback, files, images, audio, documents, generated outputs, and tool instructions.
- Plan, invoice, transaction, gift, balance, tax, and usage records. Raw payment credentials are handled by the payment processor.
- Device, browser, session, security, quota, route, model, tool, latency, cost, consent, and fault metadata.
Consumer health data notice
Depending on what you submit, HealthOS may handle consumer health data that identifies or can reasonably be linked to you. Categories can include health conditions and symptoms, medication and treatment context, measurements and laboratory information, reproductive or mental-health context, sleep and activity information, nutrition, family history, and inferences generated from those inputs.
We collect this information from you and from files, images, devices, or services you intentionally connect. We use it only to provide the requested feature, maintain your chosen context, secure and support the Service, comply with law, and establish or defend legal claims. We disclose it only to service providers needed for those purposes, to a recipient you direct, or where law, safety, fraud prevention, or a corporate transaction lawfully requires disclosure.
We do not sell consumer health data or use raw health conversations, health profiles, or health files for cross-context behavioral advertising. Where applicable law requires consent for collection or sharing, the relevant feature will request it. You may withdraw consent for future processing and request deletion through account controls or the contact method below, subject to permitted exceptions and appeal rights.
If we introduce a separately identified regulated clinical offering, its activation will include feature-specific privacy notices and disclosures describing purpose, legal basis, clinical or professional recipients, retention, consent, and applicable rights. Unless and until you activate such an available mode, the current consumer-mode practices described in this Policy apply; product plans or prototypes do not imply that a regulated offering is active.
Purposes and legal bases
We process information to provide requested features, authenticate users, preserve user settings, enforce plan limits, process confirmed transactions, answer support requests, prevent abuse, maintain reliability, investigate incidents, satisfy legal duties, and establish or defend claims.
The legal basis depends on the activity and jurisdiction. It may be performance of a contract, steps you request before a contract, legitimate interests in operating and securing the Service, consent, vital interests, or a legal obligation. When we rely on legitimate interests, we assess necessity and the effect on your rights. When we rely on consent, you may withdraw it for future processing without affecting earlier lawful processing.
In the EEA and United Kingdom, health or genetic information may be special-category data and requires both an ordinary processing basis and an applicable special-category condition. A feature-specific notice will identify that condition at collection. Accepting the Terms or acknowledging this Policy is not treated as consent to every health-data practice. Where explicit consent is the applicable condition, managed processing must not begin until a separate, specific choice is recorded.
Local-first and managed data
Supported health-profile fields and conversation state are browser-local by default. They leave the device only when you choose a feature that requires encrypted server processing, synchronization, managed storage, sharing, or export. Clearing browser storage, using private browsing, changing profiles, or losing a device can remove local information; keep an export when continuity matters.
Synchronized files are encrypted and decrypted by trusted browsers. The managed storage provider receives ciphertext, while the service retains the minimum account-scoped metadata needed to locate, meter, and delete each encrypted object.
Attachments promoted to managed workflows are encrypted before storage receives their bytes. Authorized processing may require transient decryption for extraction, preview, analysis, recovery, or export. Encryption protects content boundaries but does not remove the need for authorization metadata, object references, expiry records, or provider processing requested by the user.
AI processing, training, and human review
A request can be processed by model, search, speech, extraction, or tool providers. We limit transmitted content to what the selected feature needs and request no storage where the provider supports that option. Bootstrap providers otherwise process requests under their ordinary published retention and training terms; we do not represent those routes as zero-data-retention or contractually no-training.
Different rules can apply to a user-selected integration, a separately disclosed workflow, de-identified operational measurement, or feedback you voluntarily submit. We will not use raw health conversations or files to train an Anistratenco model without a separate, affirmative choice where required. A future restricted provider mode will require current signed evidence and fail closed when that evidence is missing or stale.
Automated systems handle most processing. Limited authorized personnel or providers may review information when you request support, submit feedback, report abuse, appeal a decision, or when access is reasonably necessary to investigate security, fraud, illegal use, or a legal obligation. Access is purpose-limited and does not create permission for unrelated use.
Providers and other disclosures
We use categories of providers for hosting, storage, model inference, search, speech, document extraction, payments, email, authentication, security, analytics, observability, and support. They receive only information reasonably necessary for their assigned purpose and are subject to contractual or equivalent restrictions appropriate to their role.
We may also disclose information to professional advisers; to a shared-plan owner only for billing, seats, and plan administration; to a recipient you choose; to authorities or other parties when reasonably necessary for law, safety, fraud, or security; and in a financing, merger, reorganization, or asset transfer subject to applicable notice and safeguards. Shared-plan membership does not authorize access to another member’s private content.
Advertising, sale, and consequential profiling
We do not sell personal information or share raw health content for targeted or cross-context behavioral advertising. If a future practice would create a right to opt out of sale, sharing, targeted advertising, or qualifying profiling, we will provide the required notice and control before or when that practice begins.
HealthOS answers, plan admission, routing, quotas, and abuse controls use automated processing. They are not intended to make decisions that produce legal or similarly significant effects about employment, credit, housing, insurance, education, eligibility, or medical care. Do not use HealthOS as the sole basis for such a decision about another person.
International processing
Information may be processed in countries other than the one where you live. Where law requires a transfer mechanism, we use an approved mechanism, contractual protections, and supplementary measures appropriate to the information and route. No transfer mechanism eliminates every jurisdictional, provider, or government-access risk.
Essential cookies and storage-free telemetry
Operational telemetry does not create analytics cookies, use localStorage, sessionStorage, or IndexedDB, or assign a persistent telemetry identity. Essential authentication and security cookies remain separate and are never repurposed for analytics. Browser events use a credential-free request to a first-party same-origin endpoint; the browser does not send telemetry directly to Grafana or PostHog.
Guest chat uses a separate essential, HttpOnly anonymous-identity cookie and a non-exportable P-256 private key stored by the browser. The server stores only a hash of the opaque cookie token, the corresponding public key and thumbprint, activity and expiry times, bounded policy metadata, and metadata-only daily message evidence. It does not store prompt or response content in this allowance ledger, and it does not use a raw IP address, raw user-agent string, reverse DNS, or an IP address alone as the allowance identity.
User-interface friction signals are limited to explicitly registered controls. Short-lived in-memory counters can identify a dead click, repeated attempt, slow action, validation-code count, empty result, or abandonment. We do not scrape the DOM, record text or field values, capture pointer coordinates, enable blanket autocapture, build heatmaps, or run session replay.
Remote routing remains fail closed until the applicable privacy review, processor terms, region, retention, and destination evidence are verified. If a legal review concludes that an optional product or user-experience signal requires consent, that signal stays disabled; we do not introduce a consent banner to enable it.
- Telemetry excludes raw URLs, query strings, referrers, DOM text, prompts, messages, filenames, profiles, memory, audio, uploads, provider payloads, tokens, email addresses, IP addresses, exact user agents, and raw exception messages.
- Allowed records use static route, surface, action, and control identifiers with bounded outcome, severity, duration, error-class, release, deployment, request, trace, span, and anonymous aggregate fields.
Retention and deletion
Retention follows the artifact’s purpose and control class, not one period for everything. Browser-local content remains until you delete it, clear the browser, or use a local wipe. Managed attachments follow their workflow expiry or deletion state. Provider requests follow the approved route and provider deletion cycle. Account, authentication, support, billing, tax, security, and audit records remain only for the period or criteria reasonably required for their stated purpose.
Anonymous daily-message evidence is retained for 48 hours after its UTC day. Anonymous identities expire after 14 inactive days. A signed claim made after sign-in transfers that day’s dispatched guest message units into the Free usage ledger for quota continuity and audit, marks the browser identity claimed for that UTC day, and does not store an account ID on the anonymous identity record.
The telemetry configuration targets seven days for development metadata, three days for preview metadata, fourteen days for production logs and traces, thirty days for grouped errors, and thirteen months for anonymous aggregate metrics. Full-fidelity development traces remain local for no more than twenty-four hours. Remote telemetry remains disabled where authenticated provider readback cannot prove these controls.
Deletion can be delayed by secure backup rotation, fraud prevention, payment and tax rules, active disputes, legal holds, safety investigations, or technical isolation. Backups are not restored for ordinary use after deletion and age out through their protected cycle. De-identified information that can no longer reasonably identify you may be retained for statistics, reliability, and security.
Your controls and privacy rights
Depending on your location, you may request access, correction, deletion, restriction, objection, consent withdrawal, or portability; opt out of covered sale, sharing, targeted advertising, or profiling; appeal an eligible denial; and complain to a competent authority. We do not unlawfully discriminate against a person for exercising a privacy right.
Signed-in users can use account privacy controls for supported access, export, correction, and deletion workflows. On a trusted browser, the account export also downloads and locally decrypts synchronized files. You may also email hello@anistratenco.com. We may verify identity, account ownership, jurisdiction, and an authorized agent’s authority. We respond within the period required by applicable law and explain any permitted refusal, extension, or appeal route. An account export cannot recover information that remains solely in another browser or raw payment credentials held by the payment processor.
Age and children
You must be at least 13, or the higher minimum age required in your country to consent to the Service. A person under 18 must have permission from a parent or legal guardian, who should review the Service terms and relevant notices and supervise use. The Service is not directed to a child who cannot lawfully consent, and it must not be used to evade parental-consent requirements.
Contact us if you believe a child submitted information without valid authorization. We may verify the report, restrict the account, delete information where required, and preserve only what law, safety, or a documented investigation permits.
Security and breach notification
We use safeguards designed for the information and Service, including minimization, encrypted boundaries, scoped authorization, authentication controls, route evidence, monitoring, retention jobs, and recovery procedures. No internet service, provider, browser, device, or encryption method is guaranteed secure.
We assess suspected unauthorized access, acquisition, use, or disclosure under applicable privacy, consumer-health, payment, contractual, and breach-notification rules. When notification is legally required, we will notify affected people, regulators, service providers, or other parties in the required manner and timeframe. Contract wording does not remove that duty.
Changes, complaints, and contact
We may update this policy as the Service, providers, law, or data practices change. A new version will show a new effective date, and material changes receive additional notice or consent where required. A revision does not waive a mandatory right or retroactively authorize a materially different use without a lawful basis.
The complete legal name, registered address, jurisdiction, and any required EEA or UK representative or data-protection contact will be displayed here before the Service is offered in a jurisdiction that requires those particulars. Anistratenco does not treat a product or trading name alone as a substitute for legally required controller identification.
Send privacy questions, rights requests, or complaints to hello@anistratenco.com. Include the account email and enough context to identify the relevant system, but do not send unnecessary health information, passwords, payment credentials, recovery codes, or API keys. You may also complain directly to a competent privacy or consumer-protection authority where that right applies.