Privacy Policy

Last updated: 2026-09-16. This policy explains how personal data, including health data, is handled when you use the Hale mobile app and the web pages at https://hale.aedmobil.com. In short: your health information is used only to provide the service to you, it is encrypted with a key unique to your account, it is never used for advertising and never sold, and you can export or delete it at any time.

1. Who is responsible and how to reach us

The controller of your personal data is (address: ). For any privacy or data protection request, contact [email protected]. Requests under the EU General Data Protection Regulation (GDPR), the UK GDPR and Turkish Law No. 6698 on the Protection of Personal Data (KVKK) can be sent to this address.

2. What Hale is, and is not

Hale is an AI-powered information assistant that answers your health questions, remembers what you asked and the health information you share, and helps you keep track of your medicines, understand your test results and prepare for doctor visits.

Hale is not a doctor, not a medical device and does not provide health care. It does not diagnose, and it does not recommend treatments, medicines or doses. In an emergency, call your local emergency number.

3. What we collect

Account data: your name (optional), interface language, country, time zone, a random device identifier created by the app; if you sign in with Apple or Google, the user identifier and email address that provider shares. We do not store passwords for app users.

Health information (only if you enter it or allow it): birth year, sex, pregnancy or breastfeeding status, blood type, height, weight, kidney or liver disease, smoking and alcohol; your chat messages and the photos or documents you attach; your question history; what Hale remembers (conditions, allergies, symptoms, lab findings, procedures, family history, lifestyle, preferences, goals, concerns); symptom guide answers and results; follow-up answers; your medicines, schedules and dose logs; health records you upload, lab values and their explanations; doctor visit summaries; values read from Apple Health or Health Connect; your emergency contacts and medical ID.

Voice: voice questions are transcribed to text; the audio is not stored on our servers. For read-aloud, the answer text is converted to speech.

Subscription data: plan, trial and renewal status and purchase records (via the app stores and RevenueCat). We never receive your card details.

Usage and technical data: app version, device type, operating system, content-free events such as which screens are used and for how long, and error reports. Health content is never written to these records.

Safety flags: when an emergency sign (for example chest pain) is detected in a message, only the date, category and level are recorded; the message content is not written to that record.

4. Apple Health (HealthKit) and Health Connect

If you allow it, Hale reads heart rate, resting heart rate, sleep duration, steps, blood oxygen (SpO2), weight, blood pressure, blood glucose and body temperature. You can turn these permissions off at any time in iPhone Settings → Health → Data Access & Devices, or in Health Connect settings on Android.

These values are used only to show you your measurements, charts and health score in the app, and to give context to your chats and doctor summaries.

Data obtained from Apple Health and Health Connect is never used for advertising, marketing or data mining; it is never shared with or sold to advertising platforms, data brokers or information resellers; and it is never stored in iCloud. It is only shared at your request (for example when you share a doctor summary) or with service providers as needed to provide the service to you.

The use of information received from Health Connect adheres to the Health Connect Permissions policy, including the Limited Use requirements.

5. Why we use your data and on what legal basis

To provide the service (account, chat, memory, symptom guide, medicine reminders, record reading, summaries): performance of our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).

To process health data: your explicit consent (GDPR Art. 9(2)(a); KVKK Art. 6). You give consent when you first open the app and you can withdraw it at any time: pause memory, turn off health data permissions, delete your data or delete your account. Withdrawal does not affect processing that took place before.

Security, abuse prevention and fixing errors: our legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).

Accounting and tax records: legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)).

Measuring app installs and purchases (to see whether our ad campaigns work): on iOS only if you allow tracking; on Android based on legitimate interests. No health data is ever part of this measurement.

6. How AI is used

We use AI models to answer your questions, run the symptom guide, read your documents, extract memory items and write summaries. The model receives only the text, image or audio needed for that task; your name, email or account identifier are not sent.

Our AI providers do not use this data to train their models. They may keep it for a limited time (usually no more than 30 days) to detect abuse, and then delete it.

Hale's answers can be wrong or incomplete. There is no automated decision-making with legal or similarly significant effects on you.

7. How we protect your data

All free text (messages, memory, symptom answers, medicine names and instructions, record explanations, emergency contacts), search vectors and uploaded files are encrypted in the database and on disk with a data key unique to your account (AES-256-GCM). That key is wrapped by a master key kept separately, so a database backup on its own cannot be read.

Data is protected in transit with TLS. Server access is limited to authorised staff over an encrypted private network. Health content is never written to server logs. Our admin panel shows counts only; our team cannot see your health content.

You can lock the app with Face ID, Touch ID or fingerprint. Notifications do not show sensitive information; a medicine name appears on the lock screen only if you turn that on.

If a security incident affects your personal data, we will notify the competent authority and you within the time limits required by law.

8. Who we share it with

We do not sell or rent your data, and we do not share it for advertising. There are no ads in the app.

Our service providers (processors) handle data only on our instructions and under contract:

• Anthropic (USA) — AI for chat, symptom guide, document reading, memory extraction and summaries. Processes health content.

• OpenAI (USA) — search vectors, speech-to-text and read-aloud. Processes health content.

• Hosting: servers in the EU (Hetzner, Germany/Finland) and Cloudflare for network security. Hosts encrypted data.

• Expo (USA) — push notification delivery. Notification text contains no sensitive information.

• RevenueCat (USA), Apple App Store and Google Play — subscriptions and payments. No health data.

• Sentry (USA) — error tracking. Technical error details and user id only; no health data.

• AppsFlyer (USA/Israel) — install and purchase measurement. Only install, trial start and purchase events and the device advertising identifier (if you allow it); never any health data.

• Apple and Google — sign-in (Sign in with Apple / Google) and notification infrastructure.

• Public medicine information sources such as openFDA are queried with the active ingredient name only; your identity is never sent.

Sharing you choose: if you invite a caregiver, that person sees only what you allow (for example medicine adherence and missed-dose alerts), and you can remove access at any time. If you create a share link for a doctor summary, anyone with the link can open the summary for 24 hours, so share it only with people you trust.

Legal requirements: we disclose data only when a valid, binding legal request requires it, and only to the extent necessary. Because your content is encrypted and keys are held separately, we interpret such requests narrowly.

9. International transfers

Our servers are in the EU. Some service providers are in the United States. These transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework; for KVKK, on standard contracts under Article 9 of the Law and, where required, your explicit consent. Only the minimum data needed for each task is transferred.

10. How long we keep it

We keep your data for as long as your account exists. You can delete individual items (memory, questions, records, measurements, chats) in the app at any time.

When you delete your account (Profile → Settings → Delete account), your encryption key is destroyed immediately and your health content and files are deleted. Copies in encrypted backups expire as backups rotate (usually within 30 days); because the key is destroyed, those copies cannot be read.

Purchase records are kept in anonymised form for the period required by tax and accounting law. Content-free safety and usage counts may remain as anonymous statistics.

Doctor summary share links stop working after 24 hours, and immediately when you delete the summary.

11. Your rights

Under the GDPR and KVKK you have the right to access, correct and delete your data, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent. All rights under KVKK Article 11 are reserved.

In the app: Profile → Settings → Export my data (a JSON file for all your profiles); Profile → Memory (edit, delete, pause, erase all); Profile → Settings → Delete account. For anything else, write to [email protected]; we reply within 30 days.

You can complain to your data protection authority — in Türkiye the Personal Data Protection Board (KVKK Kurulu), in the EU/UK the authority in your country.

12. U.S. users: HIPAA and consumer health data

Hale is not a health care provider, health plan or clearinghouse, and is not a HIPAA "covered entity" or "business associate". Information you enter in Hale is therefore not protected by HIPAA; we protect it with the encryption and access controls described above.

We do not sell consumer health data and do not use it for targeted advertising. You can exercise access, deletion and consent-withdrawal rights under state laws such as the Washington My Health My Data Act, Nevada SB 370 and California's CCPA/CPRA in the app or at [email protected].

13. Children and family profiles

You must be at least 16 years old to create a Hale account. Children under 16 cannot have their own account, and we do not knowingly collect data from them.

A parent, legal guardian or adult caregiver can create a family profile in their own account for a child or a relative they care for. By doing so you confirm that you are allowed to enter that person's information and, where required, have their permission. Family profile data belongs to the managing adult's account and is encrypted with that adult's key.

14. Website and cookies

Our legal and support pages use no tracking or advertising cookies. A strictly necessary session cookie is used only when signing in to the admin panel.

15. Changes

We may update this policy. We will tell you about material changes in the app before they take effect and update the date above. If we ever need to use health data for a new purpose, we will ask for your consent again.