All apps

Is Heidi Health safe with your data?

D
Heidi Health icon

Heidi Health

Heidi Health Pty

40/100

Weak disclosure · high confidence

Heidi Health earns a D (40/100) because it leaves much about its data practices unstated.

#159

of 211 apps ranked

40

score · Healthcare avg 39

+1

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Heidi Health's privacy policy is detailed on data categories, recipients and localization but relies on adjectives rather than named controls for security, gives no retention numbers, and stays silent on training opt-out mechanisms, synthetic output marking, automated decisions, biometrics, children and breach notification.

What Heidi Health's privacy policy says about your data

Training use is narrow and product-scoped

The only no-train statement covers PHI in Heidi Evidence, while de-identified health information is expressly used to improve the Platform, and no opt-out mechanism is named.

Rights are stated but not operationalized

Access, correction, erasure and portability appear as things you may ask for via a contact address, without a named self-serve mechanism, so most rights indicators sit at half.

Security language is adjectival

"Robust encryption, stringent access controls, and continuous threat monitoring" names no protocol, key length or certification, and there is no breach-notification commitment anywhere in the text.

No adverse clauses

Nothing in the policy reserves a harmful behaviour: no perpetual content licence, no refusal to delete, no indefinite retention as policy, and no selling without opt-out.

What the policy is silent or vague on

  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: your ownership of generated outputs
  • Not stated: a deletion timeline after closure or request

Heidi Health privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inPartial
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsSilent
Data-subject rights1 of 5 disclosed
Grants a right to access your dataPartial
Grants a right to delete your dataPartial
Offers data portability in a usable formatPartial
Grants a right to correct your dataPartial
Grants a way to object to or opt out of processingDisclosed
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestSilent
Sets a shorter retention for AI conversation logsSilent
Commits to collecting only the data it needsPartial
Third-party sharing1 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementPartial
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersPartial
States a standard for government and law-enforcement accessPartial
Transparency2 of 5 disclosed
Discloses that you are interacting with AIDisclosed
Marks AI-generated or synthetic outputSilent
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesPartial
Is versioned and dated, with change noticePartial
Sensitive data and children0 of 4 disclosed
Discloses automated decisions and a human-review pathSilent
Limits the use of special-category dataPartial
Governs biometric data specificallySilent
States protections for children's dataSilent
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Healthcare
Modalities
text, audio
Processes biometrics
Yes
Policy last updated
2024-10
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Other healthcare apps

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Heidi Health safe with your data? Grade D | AI App Trust & Transparency Index