Privacy Policy
Application-specific privacy policy for Mia Herms Agent.
1. Scope of this policy
This policy explains how Mia Herms Agent ("Mia", "we") handles Google user data obtained through the Google Health API. Mia is a private personal application used by a set of explicitly authorised users. Each authorised user grants consent separately and has their own credentials. It is not a public or commercial service.
Mia's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
2. What Google user data Mia accesses
Mia only accesses Google Health data after the user has granted consent through Google's OAuth consent screen, and only within the scopes listed below.
Read access (read-only scopes)
- Activity and fitness - steps, distance, floors, active minutes, active zone minutes, activity level, energy burned, calories, time in heart-rate zones, swimming lengths, exercise sessions.
- Health metrics and measurements - heart rate, resting heart rate, heart-rate variability, oxygen saturation, respiratory rate, weight, body fat, height, blood glucose, core body temperature.
- Sleep - sleep sessions, duration, stages and related sleep metrics.
- Nutrition - nutrition logs, logged foods and hydration logs.
- Profile - basic Google Health profile details.
Write access (write-only scopes)
- Nutrition - add, update and delete nutrition and hydration entries added by Mia.
- Logged symptoms - add symptom entries at the user's request, and update or delete entries added by Mia.
- Mindfulness - add mindfulness entries at the user's request, and update or delete entries added by Mia.
Mia requests no Google Health scope outside the categories above. In particular it has no write access to activity, fitness, heart rate, heart-rate variability, SpO2, other measurements, sleep, profile or body metrics, and it cannot modify records it did not create. Logged symptoms and mindfulness are write-only for Mia: it can add entries there at the user's request but cannot read them back from Google Health.
3. How the data is used
Health data is used solely to provide functionality the user asks for:
- health and activity summaries for a date or range the user requests;
- trends, comparisons and analysis of the user's own data;
- personalised answers and health/fitness context for that user;
- recording data the user explicitly asks Mia to log.
Mia does not use Google user data for advertising, does not sell it, does not use it to determine credit-worthiness or for lending purposes, and does not use it to train generalised machine-learning models.
4. Authentication data and how it is protected
- OAuth client credentials and per-user refresh tokens are stored server-side only.
- Refresh tokens are stored encrypted at rest, in a store readable only by the backend integration service. Each user's credentials are a separate record.
- Access tokens are obtained just-in-time by the backend and are never shown to, or placed in the context of, the language model.
- OAuth secrets and tokens are never written to prompts, model context, chat history, application logs or source control.
- Credentials never leave the backend service; the language model only ever receives normalised health values for the authenticated user.
5. Storage and retention of health data
Mia follows a minimal-retention design:
- Health data is fetched from Google Health on demand, at the moment a user asks a question or requests a summary.
- Retrieved health data is held in memory only, for the duration of that request (and for at most a short local cache of under two minutes to avoid duplicate API calls). It is not written to a long-term health database or data warehouse.
- Mia does not build a persistent health archive and does not keep historical copies of a user's Google Health data.
- Each user's cached data is isolated from every other user's; caches are never shared or merged across users.
- Records of write actions (a non-sensitive audit log: which user, which tool, which category, timestamp and the resulting Google resource identifier) are retained for accountability. These audit records contain no OAuth tokens and no health payload contents.
Because Mia does not persist health data long-term, deletion primarily means revoking access (below) - after which Mia can no longer retrieve anything. Any cached values expire within minutes.
6. Sharing and third parties - exact data flow
To answer a question, health values retrieved from Google Health for the authenticated user are passed to the language-model provider used by this private cluster so that a response can be generated, and the answer is displayed in the user's own interface (a private chat client). Concretely:
- Google Health API is the source of the health data.
- The language-model provider (the Neuralwatt Cloud API, the model backend configured for this cluster) receives the relevant health values in order to generate the user's answer. It processes them to produce that answer only.
- The self-hosted chat interface stores the conversation, like any other chat message the user has with the assistant.
We do not disclose Google user data to any other third party. We do not transfer it for advertising, marketing, credit-worthiness or data-broker purposes, and we do not sell it. Data is only shared as necessary to provide the user-requested functionality described above, to comply with applicable law, or with the user's explicit direction.
7. Advertising and sale
Google user data is never sold, rented or traded, and is never used for advertising or ad personalisation of any kind.
8. Your control and revoking access
Consent is entirely under the user's control. A user can revoke Mia's access to their Google Health data at any time:
- at myaccount.google.com/permissions (Google Account → Data & privacy → Third-party apps & services), or
- at myaccount.google.com/connections.
Once access is revoked, Mia's stored refresh token stops working and Mia can no longer retrieve or add any data for that user.
9. Data deletion requests
To request deletion of any data Mia holds in relation to your Google account - including the stored encrypted token record and any audit-log entries - email support@mls2704.com from the Google account concerned, with the subject "Data deletion request". We will delete the stored credentials and associated records for that account, and confirm by reply, normally within 7 days.
10. Security
Access to the integration is restricted to the backend service; the public web pages you are reading contain no personal data and require no login. Traffic is served over HTTPS. Tokens are encrypted at rest, filesystem permissions are restricted, and the health service is not exposed to the public internet. The Google Health endpoint is private to the cluster's internal network.
11. Changes to this policy
If this integration changes in a way that affects how Google user data is handled, this policy will be updated and the "last updated" date above revised.
12. Contact
Questions about this policy or about Google user data handled by Mia Herms Agent: support@mls2704.com.