Summary. Syntropy Health is software you run yourself. Your health records are downloaded to and stored on your own device. Syntropy Labs does not operate a service that receives, stores or analyzes your health information, and never sells or shares it.
1. Who this covers
This policy covers the Syntropy Health software ("the App"), this website (health.syntropylabs.io) and the authorization relay described below.
2. Information the App accesses
Only when you connect an account and approve access, the App retrieves, read-only, the information you authorize:
- From healthcare organizations (via SMART on FHIR): demographics; conditions; medications; allergies; laboratory results and vital signs; immunizations; visits; procedures; clinical notes and diagnostic reports; care team, care plans and goals; implanted devices; insurance coverage.
- From wearables you connect (Oura, WHOOP, Google Health for Fitbit and Pixel Watch): sleep, readiness/recovery, heart rate and heart-rate variability, activity, workouts and related metrics, and for Google Health also body measurements such as weight.
- From files you import: Apple Health exports, and lab reports (PDFs or photos of paper reports), which the App reads on your device.
- From the optional iPhone app: Apple Health data you choose to share.
The iPhone app reads only the Apple Health types you allow. It sends that data only where you direct it: your own instance, and any export or automation destination you set up yourself (for example a webhook, Home Assistant, an MQTT broker or a cloud-storage folder). Syntropy Labs receives none of it.
All of it is stored in a database on the device where you run the App. Syntropy Labs has no access to that device or database.
3. What passes through Syntropy infrastructure
- Callback page (health.syntropylabs.io/callback): a static page that runs in your browser and forwards a one-time authorization code to your own instance. It makes no network requests and stores nothing. The code cannot be used without a secret that exists only on your device.
- Wearable token broker (syntropy-auth-relay.syntropylabs.workers.dev): because Oura, WHOOP and Google require a confidential client secret, this worker exchanges the authorization code for tokens and immediately returns them to your browser in the URL fragment, which is not sent to any server. It also renews tokens on your instance's request. It does not store tokens or health data and does not access your health data APIs. Its request logging is turned off, though our hosting provider (Cloudflare) may keep standard operational records (such as IP address and time). You can skip it entirely by registering your own Oura, WHOOP or Google developer app in your instance's settings.
- This website uses no cookies, analytics, advertising or third-party resources.
4. How information is used
Information stays on your device and is used only to show you your records, trends and summaries, and to let you export them. Syntropy Labs does not use your information for advertising, profiling, research or training AI models.
5. Sharing and sale
We do not sell, rent, license or share personal or health information with anyone, including insurers, employers, data brokers or advertisers. Data leaves your device only when you export it or when you configure the App to send it somewhere.
AI. The Ask assistant is optional, and the App asks you to confirm before it first uses an AI outside your network. With a model on your own hardware, nothing leaves your network. With your own provider key (for Ask, or to read a lab report with AI), or an agent on your computer (Claude Code, Codex CLI or Gemini CLI, on your own plan), your questions and the health information the assistant looks up to answer them go to that provider, under your account and its terms and privacy settings. Apps you connect over MCP receive what they look up, with read-only access you can revoke. Syntropy Labs is not a party to any of these and receives none of it.
6. Security
Connections use TLS and OAuth 2.0 with PKCE. The App encrypts access tokens at rest, requires a password for the dashboard, keeps its data files readable only by your account, and keeps an activity log of sign-ins, syncs, exports and AI lookups. You are responsible for securing the device that runs the App and its backups; Syntropy Labs cannot access or recover your data.
7. Your choices
- Disconnect any source in the App; you can keep or delete the data already downloaded.
- Export your data (FHIR R4 bundle, CSV, full database backup) or delete it at any time.
- Revoke the App's access in your patient portal or wearable account settings.
8. Children
Caregivers may use the App to manage records of minors they are authorized to access through their healthcare organization's proxy-access features.
9. Changes
We will post changes to this policy on this page with a new effective date.
10. Contact
Syntropy Labs · privacy@syntropylabs.io