EEurekAI Lab

HealthDoor · Privacy

Privacy Policy

Local-first, separate consent, and we never sell your personal information.

Last updated · 2026-07-23

HealthDoor is a personal and family health-management product, operated by HealthDoor. We are local-first: your health data stays on your device by default. Only after you consent for a specific feature (separate consent where sensitive personal information such as health is involved) do we upload the minimum necessary data to our servers. We do not sell your personal information and do not use it for ad targeting.

Medical disclaimer

HealthDoor provides health information and lifestyle support. It is not a medical device, does not provide medical diagnosis or treatment, and is not a substitute for care from a doctor or other qualified professional. Any advice or analysis is for reference only; do not self-diagnose or medicate based on it.

Any emergency guidance shown in the app is region-localized general information, not an emergency service; in an emergency or life-threatening situation, call your local emergency number (120 in mainland China) or go to the nearest medical facility immediately.

What we collect and why

Following the “minimum necessary” principle, we collect only the personal information needed to run the features you use: health-summary features, chat health-Q&A context, AI memory, Care sharing, nutrition / skin / clinical records, account information (email), push identifiers, and de-identified crash / performance telemetry. Health-related information is sensitive personal information under China's Personal Information Protection Law (PIPL) and is processed only with your separate consent.

Health data & AI (core)

Our AI advice, health Q&A, and analysis are produced by a third-party AI processing service. Your health data is not used to train any model.

Health data stays on your device by default. Only after you give separate consent to “AI health analysis” in the app do we upload the minimum necessary health summaries for AI analysis. You can turn it off anytime under Settings → Privacy; once off, we stop analysis and delete the health summaries and AI health memory already uploaded to the server.

Care sharing is a separate, per-grant authorization, independent of AI consent; revoking a friend's grant stops only that share and affects nothing else.

Voice audio

When you use voice input in Chat, or describe a meal by voice in a nutrition record, the app collects that audio and sends it to a third-party AI processing service for transcription (speech-to-text). The sole purpose is to turn your speech into editable text input.

The voice audio is discarded immediately once transcription completes and is not retained on our servers; only the resulting transcribed text is kept, as chat or nutrition-record content. Your voice is not used to train any model.

Third-party processors

We engage several categories of third-party service providers (entrusted processors) to deliver features, disclosed by category:

We share with each category of processor only the data necessary for its service, and bind each by contract to process it under our instructions and within the agreed purpose.

  • A third-party AI processing service — powers AI advice, health Q&A, analysis, and voice transcription
  • A third-party email delivery service — sends login / verification-code emails
  • A push service — delivers push notifications
  • A third-party crash-diagnostics service — receives de-identified crash / performance telemetry (no identity information, tokens, or health values)
  • Third-party cloud and edge providers — provide hosting, CDN, and edge

Storage (within mainland China, no cross-border transfer)

Your account and health data are stored on servers located within the People's Republic of China and are processed within China. We do not transfer your personal information outside China for this product's features — there is no cross-border provision of personal information under the PIPL, so no outbound mechanism (CAC security assessment, filed Standard Contract, or protection certification) applies.

We protect your data through encryption in transit, data minimization, and de-identification; health data enters the AI processing chain only after your explicit consent.

Data retention

We keep your personal information only for the shortest period necessary to achieve the processing purpose; content you delete is removed from our servers, and copies in backups are cleared as those backups rotate (within 30 days). Retention per category:

Apart from the above, we retain your personal information only for the period necessary to achieve the processing purpose, and we comply with the minimum retention periods required by laws and regulations; beyond that period we delete or anonymize it.

  • Health summaries & AI memory: deleted when you withdraw consent or delete your account.
  • Chat conversations & attachments: kept until you delete the conversation or your account.
  • Voice audio: discarded once transcription completes, never stored on our servers; only the transcribed text is kept, as chat / nutrition-record content.
  • Account information: kept until you delete your account.
  • Push identifiers: unbound on logout; cleared when invalidated; deleted with your account.
  • Subscription & transaction records: kept as long as needed for accounting, refund disputes, and legal obligations; unlinked from your account identity after deletion.
  • Care messages & shares: kept until you delete them or your account; revoking a share stops it immediately.
  • Crash & performance telemetry: de-identified, kept at most 90 days.

Your rights

Under the PIPL and other applicable laws, you have the following rights over your personal information:

  • Access, copy & portability: you may request to access, copy, or transfer your data.
  • Correction & completion: you may correct inaccurate or complete incomplete information.
  • Deletion: deleting your account in-app permanently removes all your server-side data (health summaries, AI memory, Care shares, account).
  • Withdraw consent: turn off “AI health analysis” or revoke a Care grant anytime; we stop the corresponding processing and delete the related server data.
  • Explanation & complaints: you may ask us to explain our processing rules, and lodge a complaint with us or with the competent authorities.

Minors

HealthDoor is intended for users aged 14 and older. Children under 14 may use it only with the consent of a parent or guardian; for a child under 14, we process personal information under the PIPL and the Provisions on the Cyber Protection of Children's Personal Information, and only after obtaining the guardian's separate consent. If we collect a child-under-14's personal information without guardian consent, we will delete it as soon as possible.

Security

Encryption in transit (HTTPS/TLS); the on-device health store is excluded from cloud backup and encrypted; server access is minimized; telemetry is de-identified at a single egress.

Handler & contact

The personal-information handler under this policy is 上海壹幽睿可科技有限公司 (the China-registered entity that operates the HealthDoor product). To exercise your rights, understand our processing rules, or reach the person responsible for personal information protection, email contact@eurekailab.com.

HealthDoor provides health information and lifestyle support and does not replace professional medical advice.

Terms of Service →← Back to HealthDoor