Privacy Policy
Last updated: September 14, 2026
Panora Health AI ("Company," "we," "us," or "our") operates Panora Health AI (the "Service"). This Privacy Policy explains how we collect, use, store, protect, and share your personal information when you use the Service.
Your health data is deeply personal. We designed this policy to be transparent about exactly what happens with your information. If anything is unclear, please contact us at admin@panorahealth.ai.
Our regulatory status. Panora Health AI is a general wellness product. We are not a healthcare provider, a health plan, or a health care clearinghouse, and we do not act as a business associate of any of them. Because of this, the federal Health Insurance Portability and Accountability Act (HIPAA) does not govern the health information you provide to the Service, and we do not describe ourselves as "HIPAA-compliant" or "HIPAA-certified" — no government body certifies products as HIPAA-compliant. We nonetheless treat your health information as sensitive data, protect it with the safeguards described in this Policy, and comply with the consumer-privacy and consumer-health-data laws that do apply to us.
Where the Service is offered. Panora Health AI is offered to, and intended for, residents of the United States. We do not target or market the Service to individuals in the European Union, the United Kingdom, or other regions outside the United States, and this Policy is written to reflect United States federal and state privacy law. The Service is not intended for use outside the United States; if you access it from elsewhere, you do so on your own initiative.
1. Information We Collect
a. Health Data You Provide
- Blood work results (lab values, panel types, dates)
- Nutrition logs (meals, macronutrients, caloric intake) including voice-logged and photo-logged meals. If you use food lookup, we send only your search request to a public government food-reference database and identify returned foods as government-provided records.
- Supplement information (products, dosages, timing) and the user's current medication list
- Workout data (exercises, sets, reps, duration) including Pilates and running sessions
- Wearable data from connected wearable devices and your device's health-data repository — including HRV, recovery scores, strain, sleep architecture, body battery, training load, and similar physiological metrics depending on the device
- Menstrual cycle data and symptom logs (when applicable)
- Daily check-in responses (self-reported wellness data), including confirmed caffeine intake and subjective per-muscle soreness history, and free-form chat transcripts you provide during the daily check-in or onboarding intake. These transcripts are user-generated text content that may contain a mix of structured health data and free-form narrative; they are stored alongside your account and used to generate AI wellness insights and to improve our prompts at the aggregate level (see Sections 2 and 13).
b. Account Information
- Email address
- Name (if provided — the display name you choose during onboarding, which may be your first name or a nickname)
- Account credentials (passwords are hashed, never stored in plain text)
- Subscription plan tier (Free / Plus / Pro / Family), retained for feature gating, billing reconciliation, and customer support. Payment card details are entered directly with our payment processor outside the app and are never visible to Panora — see Section 4 for details.
- Demographic information you optionally provide during onboarding (age, biological sex, height, and weight), used to personalize your wellness analyses. We do not collect your race or ethnicity. You may update or delete these fields at any time from Settings → Profile.
- Health profile and lifestyle context you provide during onboarding or in-app forms — including medical conditions you currently have, allergies, wellness goals, activity level, alcohol use, tobacco or nicotine use (including tobacco product type), and similar health-context information you choose to share. We use this to personalize wellness analysis, surface relevant safety language, interpret trends, and provide product functionality. You can edit some of these fields from Settings → Profile; others may require re-doing the relevant onboarding flow or contacting us to delete the value. You can also delete your entire account, which removes all profile data per Section 6.
- Profile preferences and settings
c. Usage Data
- Pages visited and features used within the Service (product interaction events, including page views, taps, and which features you open). On the web app, these events are collected through a product analytics provider (see Section 4). The native mobile app does not collect first-party product-interaction analytics and does not use a third-party product analytics service; if you opt in to sharing app analytics with developers in your device's Privacy & Security settings, the mobile platform provider may give Panora its own aggregate, non-identifiable app analytics — that telemetry is collected and aggregated by the platform provider, not by Panora.
- Device type, browser type, and operating system
- Diagnostic and performance signals. Crashes and error reports are collected through an error and security monitoring provider from the mobile, web, and server tiers (see Section 4). Aggregate app-launch-time and hang-rate metrics, where available, come from standard mobile-platform diagnostic frameworks when you opt in to sharing diagnostics with developers in your device settings; third-party performance tracing is disabled on the mobile app. These signals help us find and fix bugs and improve app responsiveness.
- IP address (used for security and approximate geolocation for state-specific compliance)
- Mobile push-delivery device token and related registration metadata — if you enable notifications or use the native mobile app, Panora stores the push token, platform, and registration timestamps so we can deliver notifications, maintain notification preferences, and protect account security. These tokens are linked to your account but are not sold or used for cross-app tracking.
- ZIP / postal code, only when you choose to use the doctor referral feature (used to surface geographically nearby providers; not retained beyond the referral session unless you save a doctor to your profile)
- Photos you take or upload (meal photos, supplement labels, blood-work document scans). Panora does not store the original photo or document scan with the saved log entry; after processing, Panora stores only the derived analysis, such as foods, macros, supplement details, or parsed lab markers.
- Date and time of access
d. Information Processed but Not Persisted
- Genetic data: Where Panora offers genetic-file interpretation (for example, an export from a consumer genetic-testing service), the raw file is processed locally in your browser or on your device when you use that feature. Panora does not intentionally upload or store your raw genetic file, and does not currently persist derived genetic markers, variant flags, or wellness interpretations to our servers. If a future version of the Service stores any genetic-derived information, we will disclose that storage and obtain any consent required by applicable law before enabling it.
e. Device Permissions (Native Mobile App)
The native mobile app may ask for the following device permissions. Each is optional, is requested only when you first use the related feature, and can be changed at any time in the device settings:
- Microphone — used only for voice-driven daily check-ins. When you start a voice check-in, the app captures audio from your microphone so that it can be transcribed to text. The raw audio is processed in real time; it is not saved to a file and is not stored by Panora.
- Speech recognition — used to transcribe a voice check-in into text using the device's speech-recognition framework. On devices that support on-device recognition, the audio is transcribed entirely on your device. On other devices or for some languages, the audio may be sent to the mobile platform provider's speech-recognition service to produce the transcript. The resulting text becomes part of your check-in entry, which — like any typed check-in — is then sent to and stored by Panora to generate your wellness insights. Panora does not receive the audio itself.
- Camera and photo library — used so you can photograph or attach meal photos, supplement labels, and blood-work document scans. These photos are handled as described in Section 1c.
- Device biometric authentication — if you turn on the optional app lock, the device's biometric authentication is used to unlock the app. The biometric match is performed by the operating system; biometric data never leaves your device and is never sent to Panora (see Section 1f).
- Device health-data repository — read-only access to the health-data categories you approve, as described in Section 1a. Panora does not write data back to the repository.
f. Information We Do Not Collect
- Biometric identifiers (fingerprints, facial geometry)
- Insurance information
- Social Security numbers
- Payment information from minors (the Service is for users 13 and older)
2. How We Use Your Information
- To provide AI-generated wellness insights based on your health data
- To display trends, patterns, and educational information about your health data
- To detect patterns that may warrant a recommendation to consult your healthcare provider
- To detect potential mental health crisis language and redirect to appropriate crisis resources (988 Suicide & Crisis Lifeline)
- To support the planned doctor-sharing workflow described in Section 5, under which you could prepare and share a wellness summary with a healthcare provider with your explicit consent — this workflow is not yet enabled in production
- To improve the accuracy and quality of our AI wellness insights
- To communicate with you about your account and the Service
- To comply with legal obligations
3. How We Store and Protect Your Information
We take the security of your health data seriously and employ the following safeguards to protect it:
- Encryption at rest: All health data is encrypted using AES-256 encryption in our cloud database
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2+
- Access controls: Row-level security ensures you can only access your own data. No other user can see your information.
- Employee access: No Panora Health AI employee can view your individual health data without a formal access request logged in our audit trail
- Audit logging: Panora maintains audit logs for key account, consent, export, deletion, sharing, administrative, and security events, and uses database and infrastructure logs for additional operational monitoring. We continue to expand audit-log coverage as workflows that depend on it (such as user-directed health-data sharing) are enabled.
- Infrastructure: Our database is hosted by a managed cloud database provider with encryption and automated backups
4. Service Providers That Process Data for Us
We use service-provider categories including cloud database and authentication, hosting and server compute, AI inference, research retrieval, wearable connections, payments, email and push delivery, product analytics, error and security monitoring, and advertising measurement to operate Panora. Each has access only to the data necessary to perform its function:
Cloud Database and Authentication
A cloud database and authentication provider stores your account information and health data with row-level security. Data is stored in encrypted form at rest and in transit.
AI Inference
After you give permission for AI processing, a third-party AI processing provider receives the selected health and wellness information needed to generate AI-powered features, conversational responses, and scheduled insights on our behalf. This may include submitted text; selected lab values; nutrition, supplement, medication, workout, wearable, cycle, symptom, demographic, and lifestyle information; and photos you choose to upload for analysis. Panora applies automated identifier-removal tooling to certain text and structured inputs before transmission, but that tooling is not applied to every AI-processing path. Uploaded photos are sent as images for analysis. Because identifier removal is automated and path-dependent, Panora does not describe data sent to the AI inference provider as "de-identified" and cannot ensure that every identifier is removed. Panora does not use or sell personal data to train large language models. The AI inference provider processes this data under commercial data-processing terms and is contractually restricted from using Panora customer content to train its models; Panora is continuing to expand both the scope of identifier removal and its data-processing and retention terms with the AI processing provider.
Hosting and Server Compute
Hosts the Panora Health AI web application. The hosting provider processes standard web request data (IP addresses, request headers) as part of serving the application. Health data is not stored at the hosting layer; all sensitive health data lives in our managed cloud database. The current provider is disclosed in our compliance inventory; users can request the full vendor list at admin@panorahealth.ai.
Error and Security Monitoring
The error and security monitoring provider receives crash logs and error reports from the mobile, web, and server tiers of the Service so we can find and fix bugs. Our monitoring configuration sets sendDefaultPii = false across all tiers and disables session replay and local-variable capture. Every event additionally passes through a redaction callback (beforeSend) that replaces request bodies with a redacted sentinel, clears cookies, and removes IP addresses from the user context before the event leaves the device or server. The callbacks are a defense-in-depth measure; Panora does not intentionally pass health data into monitoring events at any tier.
Mobile app and web browser: performance tracing is disabled (tracesSampleRate = 0). The mobile app additionally disables profiling, screenshot capture, and view-hierarchy capture, and the web browser client disables session replay.
Server functions and edge middleware:performance tracing is enabled at the time of this update (tracesSampleRate = 1) so Panora can diagnose slow requests, hangs, and infrastructure issues. Server-tier performance traces include request paths, timings, and infrastructure metadata; they pass through the same redaction callback as error events.
Payment Processing
A payment processor handles paid plan upgrades. Payment card information is entered directly on the processor's hosted checkout page in your mobile or desktop browser and is never transmitted to or stored by Panora's servers. Panora receives only the resulting subscription tier string (Free / Plus / Pro / Family) and a payment customer identifier for billing reconciliation. The payment processor handles that hosted checkout under its own privacy practices.
Email Delivery
Panora uses third-party email delivery providers to send account, security, sharing-related, and notification emails (such as sign-in links, password resets, and a reminder that your weekly snapshot is ready to view in the app). Panora does not include your personal health data — your logged entries, results, wellness metrics, or summaries — in the emails it sends to you; that data stays in the app behind your sign-in. The provider receives only your email address and the message text needed to deliver these account and notification messages.
Product Analytics — Web
The web application at panorahealth.ai uses a product analytics provider for aggregate product analytics (page views, feature usage counts). The provider is configured not to receive your health data; only interaction events are transmitted. The native mobile app does not currently include a third-party product analytics SDK and does not collect first-party product-interaction analytics. If you opt in to sharing app analytics with developers in your device's Privacy & Security settings, the mobile platform provider may give Panora aggregate, non-identifiable app analytics collected and aggregated by that provider, not Panora (see Section 1c). If we later add a third-party analytics SDK to the native mobile app, we will update this Policy and our mobile app marketplace privacy disclosures before doing so.
Advertising Measurement — Public Web Pages Only
Our public marketing pages carry a pixel from an advertising measurement partner so we can measure how our advertising performs, for example how many people who click an ad go on to join the waitlist. The advertising measurement partner receives the address of the marketing page you viewed, the page you came from, your IP address, your browser and screen information, and a cookie identifier that lets the partner recognise the same browser on later visits. It runs on marketing, legal and informational pages only. It does not run on the signed-in app, on the sign-in and account-recovery pages, or on checkout, so the pages where you view or enter health information are never reported to the advertising measurement partner, and the partner does not receive your health data. The native mobile app contains no advertising SDK of any kind. If your browser sends a Global Privacy Control signal, the pixel does not run at all. See Sections 7 and 13 for how to opt out.
Wearable Connections
When you connect a wearable on the web app, a wearable-data connection provider relays the device metrics you authorize (such as recovery, HRV, strain, and sleep) from devices you own into Panora. The connection provider receives only those wearable metrics, not your other health data. On the native mobile app, metrics you route through your device's health-data repository are read on your device and sent to Panora without the connection provider; other wearables you connect in the app are relayed through the connection provider, the same as on the web. Panora has no direct first-party integration with wearable brands.
AI-Powered Research Retrieval
A third-party AI-powered research retrieval provider retrieves published research that enriches your wellness insights. Panora sends research queries derived from your health observations. Before sending a query, Panora attempts to remove obvious identifiers, but automated removal is not guaranteed and the query may still contain identifying information. The query may include markers, values, or trends, but not your full stored health record.
Rate Limiting and Request Deduplication
Provides per-user and per-request rate-limit tracking and payment-webhook idempotency. Receives operational identifiers such as your user ID or request IP address and limit/idempotency-key counters — never your health data.
Push Delivery
Route push notifications to your device. Panora stores a push token linked to your account so notifications can be delivered and your notification preferences maintained. Notification payloads are limited to non-health content; Panora does not include your health data in push notifications.
Public Government Reference APIs
To look up drug information, published research, and foods, Panora sends user-derived queries — such as a drug or food name you enter or search terms derived from your blood-work markers — to public government drug, research, and food reference APIs. User-entered searches are sent as you type them. Panora does not attach stored health records or account identifiers to these queries. Do not include personal details in a search.
5. Doctor Directory and Doctor-Sharing Scope
a. Native Mobile App (Current Version)
In the current native mobile version of Panora Health AI, the doctor feature is an informational directory only. You can search the directory by ZIP code, specialty, or telehealth availability; you can view a provider's profile. Panora does not match, recommend, rank, or score providers for your specific health situation; Panora does not book appointments; and Panora does not transmit any health summary to a provider from the mobile app. Browsing or contacting a provider through the directory does not create a doctor-patient relationship with Panora or with the listed provider.
b. Web App (Current Version)
In the current web version of Panora Health AI, the doctor feature is likewise an informational directory only. Panora does not currently transmit any wellness summary from the web app to a provider, and does not currently generate provider-facing shareable links on the user's behalf.
c. Doctor-Sharing Workflow (Planned — Not Yet Enabled in Production)
Panora is designing a future doctor-sharing workflow under which a user could generate a wellness summary in the web app and share it with a healthcare provider the user selects. As designed, that workflow would have the following properties:
- Explicit consent required: A summary would be generated and made available only when the user specifically chooses to share, and each share event would require its own consent.
- User chooses what to share: The user would select which categories of data to include (such as blood work, nutrition, supplements, workouts, and wearable data).
- Raw data only: The shared summary would contain raw wellness data and trends only. AI-generated interpretations, wellness insights, and internal detection flags would not be included.
- Access by token, not by provider login: Panora would deliver the summary by generating a unique shareable link that the user forwards to a chosen provider. Providers would not have a login to Panora, would not browse Panora users, and would not request access to user data.
- Expiration and revocation: Shared summaries would be accessible only while the link is active. The user could revoke access at any time, which would permanently delete the shared summary from Panora's servers; links would also expire after a limited time.
Important — current status: This doctor-sharing workflow is not yet enabled in production on either the mobile app or the web app. No wellness summaries are currently transmitted from Panora to any provider on the user's behalf, and no provider-facing shareable links are currently generated. Before this workflow is enabled, Panora will update this Policy to describe it as live, obtain any consent required by applicable law, and complete the security review needed to support sharing health data with a third party.
d. Future Versions
Panora may, in a future version, enable provider matching, appointment booking, share-with-doctor transmission from the mobile app, or related provider workflows. We will disclose those features in this Policy and obtain any consent required by applicable law before activating them in the Service.
6. Your Rights
You have the following rights regarding your personal information:
- Right to access: You can download all your health data in a portable format at any time
- Right to delete: You can request permanent deletion of all your data. We delete your data from our active systems, and copies in our routine encrypted backups are removed as those backups age out of our backup-retention cycle. See Delete Your Account for how to do this in the app or by email.
- Right to correct: You can request corrections to any inaccurate health data
- Right to portability: You can export your data in a machine-readable format
- Right to opt-out: You can opt out of non-essential data processing
- Right to know: You can request a detailed accounting of what data we hold, how it has been used, and who it has been shared with
- Right to withdraw consent: You can withdraw consent for data collection at any time by discontinuing use of the Service
To exercise any of these rights, contact us at admin@panorahealth.ai or use the controls available in your account settings. We will respond to your request within 30 days.
7. "Do Not Sell or Share My Personal Information"
We do not sell your personal information, and we never share your health data for advertising of any kind.
We have never sold personal information, and we have no plans to do so. Your health data is used solely to provide you with the Service.
We do use a pixel from an advertising measurement partner on our marketing, legal and informational pages to measure how our advertising performs (see Section 4). The advertising measurement partner receives the address of the marketing page you viewed, the page you came from, your IP address, your browser and screen information, and a cookie identifier that lets the partner recognise the same browser on later visits. California law treats that as sharing personal information for cross-context behavioral advertising, so we disclose it plainly here. The pixel does not run on the signed-in app, the sign-in and account-recovery pages, or checkout, and it never receives your health data. If your browser sends a Global Privacy Control signal, the pixel does not run at all.
If you are a California resident and wish to exercise your right to opt out of the sale or sharing of personal information, you may submit a request at admin@panorahealth.ai. We will honor the Global Privacy Control (GPC) signal as a valid opt-out request.
8. Children's Privacy
Panora Health AI is not intended for use by individuals under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us at admin@panorahealth.ai.
9. Data Retention
We retain your data for the following periods. Rows labeled planned describe the retention schedule that will apply to the doctor-sharing workflow described in Section 5 once it is enabled in production; no shared or prepared summaries are currently stored.
| Data Type | Retention Period |
|---|---|
| Active health data | Retained while your account is active |
| Internal detection flags (no action taken) | 365 days, then auto-deleted |
| Shared summaries (active) — planned | Until you revoke access |
| Prepared but unshared summaries — planned | 90 days, then auto-deleted |
| Consent logs (sharing-event logs apply once the Section 5 workflow is enabled) | At least 6 years (legal and security recordkeeping) |
| Audit logs | At least 6 years (legal and security recordkeeping) |
| Deleted account data | 30-day grace period, then permanently purged |
10. California Residents — CCPA/CPRA Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: You may request the specific categories and pieces of personal information we have collected about you, the sources from which it was collected, the business purposes for collection, and the categories of third parties with whom it has been shared.
- Right to delete: You may request deletion of your personal information.
- Right to correct: You may request correction of inaccurate personal information.
- Right to opt out: You may opt out of the sale or sharing of your personal information. We do not sell personal information. We do share limited public-page browsing information with an advertising measurement partner, which California law treats as sharing for cross-context behavioral advertising; see Section 7 to opt out.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
- Right to limit: You may limit the use and disclosure of sensitive personal information. Your health data is classified as sensitive personal information under CPRA.
Categories of personal information collected: Identifiers (email, display name, account user ID), commercial information (subscription plan tier; payment card details are never collected by Panora — handled directly by our payment processor), health data (blood work, nutrition, supplements, workouts, connected wearable and device health-repository data, menstrual cycle, daily check-ins, medications), sensitive personal information (your health and medical information, which is treated as sensitive personal information under the CCPA/CPRA — we do not collect your race or ethnicity), photos (meal images, supplement labels, blood-work document scans, when you choose to upload them), internet activity (usage data, device type, browser type, OS version, crash and error logs), and geolocation data (approximate, from IP address; ZIP / postal code only when you use the doctor referral feature).
To submit a request, email admin@panorahealth.ai with the subject line "CCPA Request." We will verify your identity and respond within 45 days.
11. Washington Residents — My Health My Data Act Rights
If you are a Washington State resident, you have additional rights under the My Health My Data Act (MHMDA):
- Consent before collection: We will obtain your consent before collecting consumer health data, separately from our general terms of service.
- Right to delete: You may request deletion of your consumer health data. We will comply within 30 days.
- Right to withdraw consent: You may withdraw consent for the collection and use of your health data at any time.
- Separate health data privacy policy: This Privacy Policy serves as our consumer health data privacy policy as required by the MHMDA.
To submit a request, email admin@panorahealth.ai with the subject line "MHMDA Request."
12. Residents of Other U.S. States
A number of U.S. states have comprehensive consumer-privacy or consumer-health-data laws that give their residents privacy rights. These include, among others, Colorado, Connecticut, Virginia, Texas, Oregon, and Nevada, and the list of states with such laws continues to grow. Rather than apply the lowest standard each law allows, Panora applies a single, strong set of protections to every U.S. user:
- We treat your health data as sensitive data subject to your opt-in consent, and we obtain your consent before your data is sent to our third-party AI providers for analysis — we do not rely on a buried opt-out.
- We do not sell your personal information or your health data. We never process your health data for targeted advertising, and we do not carry out profiling that produces legal or similarly significant effects. We do run an advertising-measurement pixel on our public marketing pages, described in Sections 4, 7, and 13, and you may opt out of targeted advertising.
- We collect and use only the data needed to provide and improve the Service.
Depending on the law of your state, you may have the right to confirm whether we process your personal data and to access it; to correct inaccuracies; to delete it; to obtain a portable copy; and to opt out of any sale, targeted advertising, or qualifying profiling. Where the applicable law provides one, you also have the right to appeal a decision we make about a privacy request; if we deny your appeal, that law may let you contact your state Attorney General.
Illinois residents: Panora does not collect, capture, or store biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act (BIPA). Device biometric authentication, where you enable it, is handled entirely by your device and is never transmitted to Panora (see Section 1f). New York residents: we maintain reasonable administrative, technical, and physical safeguards for your information and follow applicable breach- notification requirements, consistent with the New York SHIELD Act.
To exercise any of these rights, email admin@panorahealth.ai with the subject line "State Privacy Request." We will verify your identity, respond within the timeframe your state's law requires (typically 45 days), and will not discriminate against you for exercising any of these rights.
13. Cookies and Tracking Technologies
We use essential cookies to maintain your session and authenticate your account. Our public marketing pages also carry a pixel from an advertising measurement partner, which is an advertising and cross-site tracking technology, so that we can measure how our advertising performs. It sets a cookie in your browser and reports the address of the marketing page you viewed, the page you came from, your IP address, your browser and screen information, and a cookie identifier that lets the partner recognise the same browser on later visits. The advertising measurement partner receives this report.
The advertising measurement pixel is deliberately limited. It runs on marketing, legal and informational pages only, from an explicit list. It does not run on the signed-in application, and it does not run on the sign-in, sign-up, account-recovery, or checkout pages, because those addresses can carry a one-time token. So the pages where you view or enter health information are never reported to the advertising measurement partner. It never receives your health data, and it is not present in the native mobile app. To opt out, see Section 7 or send a Global Privacy Control signal, which we honor by not running the pixel at all. One honest limitation: if you move from a marketing page into the signed-in app without reloading, the advertising measurement script and its cookie remain loaded in that browser tab. Panora does not issue further PageView calls while you are in the app.
We do not include health data in client-side product analytics events. Web-app product analytics, when collected through a product analytics provider, are limited to aggregate, non-identifiable interaction metrics about which features are used. The native mobile app does not use a third-party product analytics service. On the mobile app, Panora's only client-side telemetry is the crash and error reporting described in the next paragraph (and in Section 4); third-party performance tracing and profiling are disabled on the mobile app (tracesSampleRate = 0), and Panora does not transmit aggregate tap, screen-view, or session-replay analytics from the mobile app. Any aggregate diagnostic signals that may surface to Panora are limited to the mobile platform provider's own telemetry under the user's device Privacy & Security settings. Nothing in this paragraph contains your health data, and Panora does not use any of these signals for cross-app tracking or third-party advertising.
Separately, we may analyze aggregated health data internally to improve the accuracy and quality of our AI wellness insights — for example, looking at population- level distributions of common patterns to refine prompts or identify failure modes. This kind of analysis is performed on aggregated data only and never identifies any individual user. We do not transmit this aggregated data to third parties for advertising, marketing, or cross-app tracking.
Crash and error logs are transmitted to an error and security monitoring provider from both the mobile and web apps so we can find and fix bugs. The monitoring client is configured with sendDefaultPii = false; device identifiers, IP addresses, and user contexts are not included by default, and every event passes through a redaction callback before leaving the device. See Section 4 for full monitoring details.
14. Contact for Privacy Requests
For any privacy-related questions, requests, or concerns, contact us at:
Panora Health AI — Privacy Team
Email: admin@panorahealth.ai
Subject lines for specific requests:
- "CCPA Request" — California privacy rights
- "MHMDA Request" — Washington privacy rights
- "State Privacy Request" — other U.S. state privacy rights
- "Data Deletion Request" — delete all data
- "Data Access Request" — download your data
- "Privacy Question" — general privacy inquiries
15. App Store Privacy Nutrition Labels Summary
This section summarizes the data types Panora discloses for the current native mobile app via App Store Connect's Privacy Nutrition Labels. Each row corresponds to a category Apple displays on the App Store listing. None of the data listed below is used for cross-app tracking; the native mobile app contains no third-party advertising SDK, does not share data with data brokers, and Panora does not sell personal information (see Section 7). The advertising-measurement pixel described in Sections 4 and 13 runs on our public website only and is not part of the mobile app.
Web analytics, hosting telemetry, and any other web-only data collection described elsewhere in this Policy are additional to (and may differ from) what appears on the App Store listing. Apple's Privacy Nutrition Labels describe the mobile app only.
Data Linked to You (mobile app):
- Email Address — App Functionality (account creation, login, password recovery; support correspondence is handled via email and is bundled under this purpose by Apple's taxonomy).
- Name — App Functionality (display name used to greet you in the app).
- User ID — App Functionality, Analytics (cloud authentication identifier, used for row-level security and aggregate cohort metrics).
- Device ID — App Functionality (mobile push-delivery token and related device identifier, stored linked to your account so we can deliver notifications and maintain notification preferences; see Section 1c).
- Health — App Functionality, Product Personalization, Analytics (the core product purpose; aggregated analysis is used internally to improve AI accuracy).
- Fitness — App Functionality, Product Personalization, Analytics (workouts, wearable data routed through your device's health-data repository, and similar fitness signals; same scope as Health).
- Coarse Location — App Functionality (ZIP / postal code only, used for the doctor directory).
- Photos or Videos — App Functionality (meal photos, supplement labels, blood-work document scans, when you choose to upload them).
- Other User Content — App Functionality, Product Personalization, Analytics (free-form text from the daily check-in chat, onboarding intake, and Ask AI conversations; see Section 1a).
- Purchase History — App Functionality, Analytics (subscription tier — Free / Plus / Pro / Family — used for feature gating, billing reconciliation, and aggregate paid-vs-free analytics; payment cards are never seen by Panora and are handled by our payment processor — see Section 4).
Data Not Linked to You (mobile app):
- Crash Data — App Functionality, Analytics (the error and security monitoring provider, configured with
sendDefaultPii = falseand a redaction callback — see Section 4).
The current mobile app does not declare Product Interaction or Performance Data as separate App Store nutrition-label categories. The native mobile app does not include a third-party product-analytics SDK, and third-party performance tracing and profiling are disabled in the mobile configuration. Web analytics and server-side performance telemetry are described in Sections 1c, 4, and 13 and apply to the web product only.
If you believe any of the disclosures on the App Store do not match this Policy, please contact us at admin@panorahealth.ai with the subject line "App Store Disclosure Question."
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and notify you through the Service or by email. Your continued use of the Service after changes are posted constitutes your acceptance of the updated Privacy Policy. We encourage you to review this page periodically.
Panora Health AI provides wellness information, not medical advice. This is not a substitute for professional medical diagnosis or treatment. Always consult a qualified healthcare provider before making health decisions. Powered by AI — not a licensed healthcare professional.