Protecting Your Health Data: Privacy and Security Best Practices
Health data privacy is the question of who can read the record you keep about your own body, and what happens if somebody reads it who should not. Health data is classified as sensitive personal information under every major privacy regulation, including GDPR, HIPAA and CCPA. A password that leaks is changed in a minute. A record does not. Health information that leaks is out for good β it can follow you into an insurance quote or a job interview, and nothing takes it back. That is the reason `/privacy` has no defined terms in capital letters and no clause numbering: it is meant to be read once, before the first entry, by the person whose record it is.
Why Health Data Privacy Matters
Health data is classified as sensitive personal information under every major privacy regulation, including GDPR, HIPAA, and CCPA. Unlike a leaked password that you can change, leaked health information cannot be taken back. It can affect insurance rates, employment, and personal relationships.
Understanding how your health apps handle data is not paranoia. It is responsible self-care.
How LifeWell Protects Your Data
Encryption
All data transmitted between your device and our servers uses TLS 1.3 encryption. Stored data sits behind row-level security, so every read and write is scoped to the account that owns the record.
Authentication
LifeWell uses Supabase Authentication with Google sign-in. Your password is never stored on our servers. Multi-factor authentication on your Google account adds an extra layer of protection.
Data Ownership
You own your data. LifeWell never sells, shares, or monetizes your health information. You can export or delete your data at any time through the Settings menu.
Minimal Data Collection
We collect only the data necessary to provide the features you use. We do not collect location data, browsing history, or device identifiers for advertising purposes.
What You Can Do
Use Strong Authentication
- Sign in with Google for managed security
- Enable two-factor authentication on your Google account
- Never share your login credentials
Back Up Your Data
Use the Google Drive backup feature to maintain a personal copy of your data. This is stored in your own Google Drive, not on LifeWell servers.
Review Permissions Regularly
Check which third-party services have access to your LifeWell data. Revoke access for any services you no longer use.
Keep Your App Updated
Updates often include security patches. Enable automatic updates or check for new versions regularly.
Use a Unique Password for Each Service
If you use email and password authentication, never reuse passwords across services. A password manager helps maintain unique credentials for every account.
The Offline Advantage
LifeWell supports offline functionality, meaning your data can stay on your device without constant server communication. This reduces your attack surface and ensures your health tracking continues even without internet access.
Questions About Privacy?
Review our complete privacy policy at lifewell.aoneahsan.com/privacy. You can also reach out through the app's contact feature with any specific privacy questions.
Elsewhere on LifeWell
- Privacy β What LifeWell stores, where it sits, and who can read it back.
- Plans β What the free plan includes, and what each paid one adds.
- Export everything β Your whole record leaves in one file, on any plan, without giving a reason.
What people use it for
Read `/privacy` end to end once
Read `/privacy` end to end once. It has no defined terms in capital letters and no clause numbering, and it names every processor and what each one does.
Generate the complete JSON copy
Generate the complete JSON copy at `/health/export`, the one file with every field in it, including things no screen shows you, and keep it somewhere you control.
Take the PDF instead when you are handing something to aβ¦
Take the PDF instead when you are handing something to a person. It is deliberately not everything, and your journal is never in it.
Connect Google Drive
Connect Google Drive at `/settings`, under Your data, so photos live in your own Drive folder, and disconnect from the same card when you want uploads to stop.
Delete the account from inside the app the day you areβ¦
Delete the account from inside the app the day you are done with it, without asking anyone for permission.
Questions
Where does my health data actually go?
Your record lives on your device first. It works with no connection at all. If you turn syncing on, a copy goes to a server so your other devices can read it. Everything between the app and the server travels over an encrypted connection, it is stored encrypted, and access to production systems is restricted. Servers sit outside your country in some cases, and the privacy page says so instead of burying it.
Does LifeWell sell my health information?
No. Not sold, not rented, not used to target advertising, and not handed to anybody else to train their model. The privacy page then says what most apps leave out: LifeWell does reserve the right to use content from free accounts to improve and train its own features, and content in a paid plan is not used that way without your explicit consent. It is a right reserved rather than something happening today, and the page will say so before it starts. How you use the app is also recorded as a screen replay, so problems can be seen rather than guessed at. Read `/privacy` and decide on the whole picture.
Can I export or delete everything?
Yes, both, yourself, from inside the app. Export offers three shapes at `/health/export`: JSON, the complete copy with every field; CSV, one file per table, zipped; and PDF, a readable summary to hand someone, with your journal deliberately left out. Deleting your account takes under a minute. You do not need to email anybody, explain yourself or wait for approval.
What happens to my photos and documents?
They go to your own Google Drive, into a folder called LifeWell that you can open, move or delete yourself. LifeWell keeps a reference, not the file. The access it asks Google for reaches only the files the app put there itself, so the rest of your Drive stays invisible to it, and you can withdraw that access from your Google account at any time.
Do I need a password for LifeWell?
No. Signing in goes through Google, so LifeWell never sees a password. Two-step verification on your Google account therefore protects this record as well, which is the practical reason the post recommends it. Check now and then which services still have access to that Google account, and remove the ones you have stopped using.
Who else touches my record?
Seven, each with its job beside it on `/privacy`: Supabase hosts the database, Google signs you in, FilesHub sends the app's email, Sentry collects crash reports, Amplitude counts which parts get used, Google Analytics counts page views, and Microsoft Clarity records a replay of how the app is used. An eighth is listed underneath them rather than left out: OneSignal, wired but switched off in this release, seeing nothing yet. Naming the switched-off one is the point. A list you can read is a list you can object to.
What does LifeWell not collect?
What you did not put in. You choose what goes in. Nothing is read off your phone and nothing is guessed about you. The offline design helps here too, since a record that lives on your device is a record that has not been sent anywhere, and this app can carry on for a whole day without a connection.
By Ahsan Mahmood Β· updated 2026-07-31
Open Protecting Your Health Data: Privacy and Security Best Practices on LifeWell