ANATUMY

Legal

Privacy Policy

Last updated: May 17, 2026 · Effective at launch

This policy is still being finalized. It will be reviewed by legal counsel and published in full before Anatumy launches. Have questions in the meantime? contact@anatumy.com

Important disclosure

Anatumy is a personal wellness journal and is not a HIPAA-covered entity. We are not a healthcare provider, health plan, or healthcare clearinghouse. We do not provide medical advice, diagnosis, or treatment. Do not use Anatumy to record information about patients in a clinical setting. If you are experiencing a medical emergency, call 911 or your local emergency number.

At a glance

  • We collect what you give us: your account info, care notes, vitals, medications, and information about the person you're caring for.
  • We use it to operate Anatumy — transcribing notes with AI, generating reports, and powering the Sage assistant.
  • AI processing (Anthropic Claude, OpenAI Whisper/GPT-4o) happens through secure server-side proxies. AI providers do not use your data to train general-purpose models.
  • We do not sell your data to data brokers. Ever.
  • You can delete your account and all your data at any time.

1. Introduction

This Privacy Policy describes how Anatumy, Inc. ("Anatumy," "we," "us," or "our") collects, uses, and shares information when you use the Anatumy mobile app, the website at anatumy.com, and related services (the "Service"). By using the Service, you agree to the practices described here.

2. Information We Collect

We collect information you provide directly: your account details, care notes (voice and text), vital measurements, medication records, and information about the person you're caring for. We also collect device and usage data automatically — device type, OS version, app version, IP address, and which features you use. If you apply to be a partner or join the waitlist on our website, we collect the information you submit in those forms.

3. Voice Recordings and AI Processing

When you record a voice care note, audio is sent to OpenAI Whisper (via a secure server-side proxy) for transcription. The transcript may then be sent to Anthropic Claude for structuring. We do not send Apple Health data to AI services. AI providers are contractually prohibited from using your content to train general models. You can use Anatumy without AI features by entering notes manually.

4. Apple Health Data (iOS)

If you grant permission, Anatumy reads specific health data from Apple Health (heart rate, blood pressure, weight, sleep, and others). This data is tagged with its source and used only for display, tracking, and reporting within the Service. You can revoke Apple Health permissions at any time in Settings → Health.

5. How We Use Your Information

We use your information to provide and improve the Service, personalize your experience, send transactional communications (account confirmations, security notices), analyze usage patterns to fix bugs and develop features, and comply with legal obligations. We do not sell your personal information or use it for cross-context behavioral advertising.

6. How We Share Your Information

We share information only with service providers that help us operate the Service (Supabase for infrastructure, Anthropic and OpenAI for AI features, Resend for email, Vercel for website hosting), when required by law, or when you explicitly initiate a share (e.g., an Emergency Card share link). We do not sell data to data brokers or advertisers.

7. Data Retention

We retain your data while your account is active. Account data and all associated records are deleted within 30 days of account closure. Voice audio files are retained as long as the corresponding note exists. Waitlist data is retained until you request removal or you create a full account.

8. Security

We use TLS encryption in transit, encryption at rest, row-level database security, hashed password storage, and server-side AI API key proxying. No system is perfectly secure — use a strong password and report suspected issues to contact@anatumy.com.

9. Your Rights

You can access, correct, export, or delete your data at any time through the Service or by emailing contact@anatumy.com. California residents have additional rights under CCPA/CPRA. Washington residents have additional rights under the My Health My Data Act. Residents of Virginia, Colorado, Connecticut, and other states with consumer privacy laws may also have rights to access, delete, and correct their data.

10. Children's Privacy

The Service is not designed for children under 18. We do not knowingly collect information from anyone under 18. If you believe a child has provided us information, contact us at contact@anatumy.com.

11. Changes to This Policy

We may update this policy from time to time. For material changes that reduce your rights, we will provide prominent notice at least 30 days in advance. Continued use after changes take effect constitutes acceptance.

12. Contact

For privacy questions or to exercise your rights: contact@anatumy.com. Anatumy, Inc. · Business operations: San Francisco, CA.