Mia Herms Agent

Privacy Policy

Application-specific privacy policy for Mia Herms Agent.

Effective 26 September 2026 · Contact: support@mls2704.com

1. Scope of this policy

This policy explains how Mia Herms Agent ("Mia", "we") handles Google user data obtained through the Google Health API. Mia is a private personal application used by a set of explicitly authorised users. Each authorised user grants consent separately and has their own credentials. It is not a public or commercial service.

Mia's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

2. What Google user data Mia accesses

Mia only accesses Google Health data after the user has granted consent through Google's OAuth consent screen, and only within the scopes listed below.

Read access (read-only scopes)

Write access (write-only scopes)

Mia requests no Google Health scope outside the categories above. In particular it has no write access to activity, fitness, heart rate, heart-rate variability, SpO2, other measurements, sleep, profile or body metrics, and it cannot modify records it did not create. Logged symptoms and mindfulness are write-only for Mia: it can add entries there at the user's request but cannot read them back from Google Health.

3. How the data is used

Health data is used solely to provide functionality the user asks for:

Mia does not use Google user data for advertising, does not sell it, does not use it to determine credit-worthiness or for lending purposes, and does not use it to train generalised machine-learning models.

4. Authentication data and how it is protected

5. Storage and retention of health data

Mia follows a minimal-retention design:

Because Mia does not persist health data long-term, deletion primarily means revoking access (below) - after which Mia can no longer retrieve anything. Any cached values expire within minutes.

6. Sharing and third parties - exact data flow

To answer a question, health values retrieved from Google Health for the authenticated user are passed to the language-model provider used by this private cluster so that a response can be generated, and the answer is displayed in the user's own interface (a private chat client). Concretely:

We do not disclose Google user data to any other third party. We do not transfer it for advertising, marketing, credit-worthiness or data-broker purposes, and we do not sell it. Data is only shared as necessary to provide the user-requested functionality described above, to comply with applicable law, or with the user's explicit direction.

7. Advertising and sale

Google user data is never sold, rented or traded, and is never used for advertising or ad personalisation of any kind.

8. Your control and revoking access

Consent is entirely under the user's control. A user can revoke Mia's access to their Google Health data at any time:

Once access is revoked, Mia's stored refresh token stops working and Mia can no longer retrieve or add any data for that user.

9. Data deletion requests

To request deletion of any data Mia holds in relation to your Google account - including the stored encrypted token record and any audit-log entries - email support@mls2704.com from the Google account concerned, with the subject "Data deletion request". We will delete the stored credentials and associated records for that account, and confirm by reply, normally within 7 days.

10. Security

Access to the integration is restricted to the backend service; the public web pages you are reading contain no personal data and require no login. Traffic is served over HTTPS. Tokens are encrypted at rest, filesystem permissions are restricted, and the health service is not exposed to the public internet. The Google Health endpoint is private to the cluster's internal network.

11. Changes to this policy

If this integration changes in a way that affects how Google user data is handled, this policy will be updated and the "last updated" date above revised.

12. Contact

Questions about this policy or about Google user data handled by Mia Herms Agent: support@mls2704.com.

Mia's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.