← Back

Privacy Policy

Last updated: July 29, 2026  ·  Questions? info@immunally.com

Short version You own your health data. We store it on secure servers, never sell it, and you can delete everything permanently at any time. AI features are optional and off until you turn them on: nothing is sent to our AI provider (Anthropic) unless you explicitly enable AI insights. When you do, the relevant entries for that request are sent to Anthropic to generate the analysis. We are working toward HIPAA-compatible security practices but are not yet fully HIPAA compliant — do not rely on this app as a certified medical records system.

This app is a tool, not a doctor

Immunally helps you track your health over time — symptoms, labs, diet, sleep, medications, and more. It is not a medical device and does not provide medical advice. AI-generated summaries and patterns are meant to help you notice things and have better conversations with your healthcare team. They are not diagnoses, treatment recommendations, or clinical assessments. Always consult your doctor before making decisions about your health.


Who we are

Immunally is operated by Immunally LLC, a limited liability company registered in Washington State, United States. When this policy says "we," "us," or "our," it means Immunally LLC.


What we collect

Your account

When you sign in with Google, Apple, or email, we store your email address and name so we can identify your account and send you notifications you've opted into.

What you log

Every entry you create in the app — symptoms, medications, lab results, meals, sleep, exercise, mood, notes, experiments — is stored in your account. You chose to log it; we keep it so you can look back at it.

Voice and photos

If you log by voice, your speech is transcribed to text using your device's speech recognition (Apple's Speech framework on iOS), which — depending on your device and language — may process the audio on your device or on Apple's servers. We do not store the audio recording — only the resulting text entry is saved (and encrypted).

If you log by photo (for example a lab report or a meal), and you have enabled AI features, the image is sent to our AI provider (Anthropic) to extract the relevant text, which becomes your entry. We do not store the photo — only the extracted text is saved (and encrypted). If AI features are off, photo extraction is unavailable and no image is sent.

Your health profile

Height, weight, diagnosis, allergies, and other optional profile fields. None of this is required to use the app.

Apple Health (only if you enable it)

If you connect Apple Health, we pull sleep data, steps, resting heart rate, and workout summaries to fill in your health picture automatically. You can turn this off at any time in iPhone Settings → Privacy & Security → Health → Immunally. Data obtained from Apple Health is used only to provide and improve your experience in the app — we never use it for advertising, marketing, or use-based data mining, and we never sell it or share it with data brokers or advertising networks.

Push notifications

If you enable push notifications, we store a device push token to deliver notifications such as your daily brief, medication reminders, and pattern alerts. This token is stored in your account and deleted when you disable notifications or delete your account. We do not use it to track you.

App usage and error logs

Basic technical logs — error messages, crash reports, and API call timestamps — to help us diagnose problems. We use Sentry to capture error traces from the app and our backend. These logs never contain your health data. Sentry data is retained for 30 days.

Cookies and local storage

The Immunally web app uses browser local storage and session tokens to keep you signed in and remember your preferences. We do not use advertising cookies, tracking pixels, or third-party analytics. There are no third-party cookies on this site.

Terms acceptance

When you complete onboarding and agree to our Terms & Conditions, we record the date and time of your acceptance and which version of the terms you accepted. This is required to demonstrate consent under GDPR and similar regulations. It is not health data and is not encrypted.


How we store and protect your data

Your data is stored in Supabase, a managed database service running on AWS infrastructure in the United States, under a signed Data Processing Agreement (DPA) that governs how they process your data on our behalf. Here is an honest account of how your data is protected right now:

What is encrypted

Everything you log in the app — symptoms, medications, labs, meals, mood, notes, and experiments, including the structured values within them (severity scores, durations, ratings, and similar) — and the health metrics synced from Apple Health (steps, heart rate, sleep, and other device vitals) is encrypted using AES-256-GCM before being saved. Your encryption key is held server-side within the same Supabase infrastructure that stores the encrypted data, which means Supabase, as a service, holds both the encrypted data and the key; a raw database backup cannot be read without administrative access to the platform. (Splitting key custody into separate infrastructure is on our roadmap.)

What is not yet encrypted

A small amount of derived analytical data is stored as plaintext — specifically the short symptom and trigger labels our pattern-detection engine uses to find correlations (for example "fatigue" or "high stress"), because the engine matches on these values directly in the database and encrypting them would break that analysis. These are brief derived labels, not your personal writing, and we keep what is stored this way to a minimum.

In transit

All communication between your device and our servers uses TLS encryption (the same technology used by banks and healthcare systems). Your data is never sent over an unencrypted connection.

Access controls

Row-level security is enforced at the database layer across all of our tables — your account can only ever read, write, or delete your own records. No other user can access your data, even with a valid session token. Every API endpoint that handles health data independently verifies your identity before processing any request. Administrative database credentials are never present in the app's code or bundled assets.

HIPAA status We are building toward HIPAA-compatible security practices — encryption of all fields, audit logging, breach detection, and data processing agreements with our infrastructure providers. We are not yet fully HIPAA compliant and have not undergone a formal HIPAA audit. Do not use Immunally as a covered entity's certified medical records solution.

AI and Anthropic

Immunally uses AI to help you make sense of your health data — daily summaries, pattern detection, and on-demand analysis of symptoms, labs, and diet entries.

AI features are optional and require your explicit consent. They are off by default. Before any health data is sent to our AI provider, we ask you to turn AI insights on — during onboarding and again on any AI feature, with a clear explanation of what is shared and with whom. Until you enable AI insights, no health data is sent to Anthropic. You can turn AI features off at any time in Settings → AI insights, and once off, no further data is sent for AI analysis.

We use Anthropic's Claude API to generate these insights. When an analysis runs, the relevant portion of your health data for that request is sent to Anthropic's servers — for example, if you ask for a symptom analysis, your recent symptom entries are sent. We send only the data needed for the specific request you make. Your name and email address are never included in what we send.

We access Claude through Anthropic's HIPAA-ready API under a signed Business Associate Agreement (BAA) with Anthropic. Under this arrangement, the health data we send for analysis is safeguarded throughout its lifecycle with encryption, access controls, and audit logging, and is never used to train AI models. Anthropic uses it only to generate the response you asked for, and does not sell it or use it for advertising or profiling.

Having a BAA in place for our AI provider does not by itself make Immunally a HIPAA-covered service — see the HIPAA note above. It means the specific data sent for AI analysis carries an added layer of contractual and technical protection. You can read Anthropic's privacy policy at anthropic.com/privacy and their privacy center.


Who sees your data

Who Why Do we sell to them?
Supabase Database and storage provider (AWS US East). Bound by a signed Data Processing Agreement. No
Anthropic Powers AI analysis when you request it. HIPAA-ready API under a signed Business Associate Agreement; does not train on your data. No
Google / Apple Authentication providers if you sign in with their account. No
Sentry Error monitoring. Receives error traces and stack logs — never health data. No
Resend Transactional email delivery (e.g. account confirmation emails). Receives your email address only. No

That is the complete list. We do not share your health data with advertisers, data brokers, insurers, employers, or anyone else. We do not use your data to train AI models. We do not run analytics on your health entries for any purpose beyond operating the app.


International data transfers

Immunally is operated from the United States and your data is stored on US-based servers. If you are accessing the app from outside the United States — including from the European Union, United Kingdom, or other jurisdictions — your data will be transferred to and processed in the United States. By using the app, you consent to this transfer. We apply the same security protections described in this policy regardless of where you are located.


Your rights and controls

  • See your data — everything you've logged is visible in the app.
  • Edit or delete entries — edit or delete any individual entry directly in the app.
  • Delete your account — Settings → Account → Delete Account permanently erases all your health data, entries, AI insights, and profile information. This is irreversible. We do not retain backups of deleted accounts beyond 30 days.
  • Export your data — data export is in development and will be available before broader public launch.
  • Disconnect Apple Health — iPhone Settings → Privacy & Security → Health → Immunally.
  • Disable push notifications — turn off in iOS Settings or within the app. Your push token is deleted from our servers when you disable notifications.
  • Questions or requests — email info@immunally.com. We'll respond within a few business days.

If you're in the EU or UK, you have rights under GDPR including the right to access, correct, port, restrict processing of, or erase your data. The deletion right above covers your right to erasure. For access, correction, or portability requests, contact us directly and we will respond within 30 days.

If you're in California, you have rights under the CCPA/CPRA including the right to know what personal information we collect, the right to delete it, the right to correct it, the right to opt out of sale (we do not sell your data), and the right not to be discriminated against for exercising these rights. Your health data is treated as sensitive personal information, and you may request that we limit its use and disclosure to what's necessary to provide the app. To exercise any CCPA/CPRA right, contact us at info@immunally.com.

If you're a resident of Washington, Nevada, or Connecticut, additional rights over your "consumer health data" — including the right to withdraw consent and to a list of everyone we've shared it with — are described in our separate Consumer Health Data Privacy Notice.


Data retention

Your data stays in your account until you delete it. When you delete your account, all associated health data is permanently removed from our active database immediately and from backups within 30 days. Error logs (Sentry) are purged after 30 days. Email delivery logs (Resend) are retained for 30 days. Terms acceptance records are retained for 7 years as required for legal compliance purposes.

Account inactivity

We do not automatically delete inactive accounts. Your data remains in your account indefinitely until you choose to delete it. If we ever introduce an inactivity policy, we will notify you by email at least 60 days in advance before any data is removed.

Third-party links

The app may contain links to third-party websites or services (for example, links to Anthropic's privacy policy or Apple Health documentation). We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies before providing any information to them.

Breach notification

If we discover a breach of your unsecured health information, we will notify affected users by email without unreasonable delay and within 60 days, and will notify the U.S. Federal Trade Commission (and the media where required) consistent with the FTC Health Breach Notification Rule. If you are in the EU or UK, we will also notify you consistent with GDPR Article 34. In every case we will describe what was affected, what we are doing about it, and what steps you can take.

Children

Immunally is for adults aged 16 and over. We do not knowingly collect data from anyone under 16. If you believe someone under 16 has created an account, contact us and we will delete it immediately.

Changes to this policy

If we make material changes to how we handle your health data, we will notify you by email or by a prominent in-app notice at least 14 days before the change takes effect. The date at the top of this page always reflects the current version. Continued use of the app after the effective date constitutes acceptance of the updated policy.


Governing law

This Privacy Policy is governed by the laws of the State of Washington, United States, without regard to its conflict of law provisions.


Contact

Privacy questions, data requests, or anything else — email info@immunally.com. We are a small team and will get back to you within a few business days.