Privacy Policy

Brain Health · Effective 23 September 2026

Brain Health is a private, single-user personal system. It is built and run by one individual, on that individual's own computer, for their own use. That person is the only user and also the operator. There are no accounts and no other users, so throughout this policy "you" and "the operator" are the same person.

It is a personal project. It is not a product, not a service offered to anyone else, and not operated by, affiliated with, or run on behalf of any company or organisation.

This policy describes what Brain Health actually does today with Google user data. It is written from the source code, not from intent.

1. What data is accessed

Permissions requested

Brain Health asks Google for three permissions, all of them read-only:

Brain Health requests no write permission of any kind. It cannot add, change or delete anything in your Google Health data. It does not request access to your location or GPS routes, to your Google profile, to your email, or to anything outside the three permissions above.

Data it retrieves

Within those permissions, it reads a fixed list of daily-level data types:

It deliberately does not read high-frequency sensor streams: continuous heart-rate samples, intraday heart-rate variability, oxygen saturation or respiratory-rate samples, skin temperature samples, or location and GPS data from workouts. These are excluded by design, not by omission.

2. Why it is accessed

To answer your own questions about your own body, grounded in your own measurements rather than in general averages. For example: whether last night's sleep was unusual for you, how this week's activity compares with your own recent norm, or how your weight has moved over the past month.

Brain Health also computes your own 7-day and 28-day baselines from your own history, so that "unusual" means unusual for you.

There is no other purpose. The data is not used for anything you did not ask for.

3. How it is stored

Retrieved data is stored in a local database file on your own computer, in a directory used only for health data. It is kept physically separate from every other kind of data Brain stores.

What the database holds, per record:

Raw Google API responses are not stored. There is no column, in any table, that could hold a response body, a payload or a blob. A response is parsed in memory, converted into the fields above, and then discarded.

If you have turned on the notifications described in section 5, Brain also keeps a local record in the same directory of what it has already told you about, so that it does not repeat itself. That record holds measurement names, dates and how far a value sat from your own median. It holds no measurements.

The database file and its directory are created readable and writable only by your own user account on that computer. Nothing is stored in any cloud service operated by or for Brain, because there is no such service.

4. What is sent to an AI provider

This is the main case in which anything derived from your health data leaves your computer, so it is described exactly. The only other case is the optional Telegram notification described in section 5, which carries no measurements at all.

Brain answers questions by sending them to an AI provider that you have configured — Anthropic's Claude or OpenAI's Codex — through your own personal subscription, using a command-line tool that runs on your own machine.

When it happens. Only when both of the following are true:

If the check does not recognise the question as health-related, the health database is not opened at all.

What is sent. A small summary, bounded before it is built:

What is not sent:

The amount sent is bounded by the question, not by how much history exists. A database holding three years produces exactly as many entries as one holding three weeks.

What happens to it. The summary is used to compose that one answer and is not saved by Brain anywhere — not in the conversation transcript, not in long-term memory, not in any log. The AI provider's answer is saved in the conversation transcript on your own computer, and that answer may repeat figures from the summary.

What the AI provider does with the request on its own systems is governed by that provider's terms for your subscription. Brain does not use your health data to train, fine-tune or build any model.

5. Other parties

Telegram notifications — only if you turn them on

Brain can watch your own measurements for sustained changes from your own baseline and send you a notification. This runs only if you have explicitly configured it; it is off unless set up.

When it sends one, the message says that a number of changes were detected and that you should look in Brain. That number is between 1 and 12. The message contains no measurement name, no value, no direction, no magnitude and no date. It is a doorbell, not a health record.

Web search

Brain can search the web when you tick a box on an individual message. Only that message's text is sent to the search provider. Health data is never included in a search query.

Nobody else

Health data is not shared with any other third party. There are no analytics providers, no advertising networks, no data brokers, no trackers and no third-party scripts anywhere in Brain or on this website.

6. Credential handling

7. Health data is kept separate from Brain's memory

Brain keeps a long-term memory of things you have told it. Health measurements are not part of it and cannot become part of it. There is no path in the software from the health database to the memory record, automatic or manual. A measurement is never converted into a remembered fact about you.

Brain also treats what an AI infers from your data as an interpretation rather than as a fact about your body, and it does not diagnose.

8. What is never done

9. Retention and deletion

This section describes what the software actually supports today.

10. Security

11. Changes to this policy

If what the software does changes, this page is updated to match before the change is relied upon. The effective date at the top reflects the current version.

12. Contact

This system has one user, who is also its operator, personally. There is no company behind it and no support organisation. Questions about this policy reach that individual directly: m.ishida38@gmail.com