Privacy Policy
Your labs are private.
Labs Made Clear is built with HIPAA-aligned safeguards. This Privacy Policy explains what we collect, how we use it, and the controls you have. We never sell your personal or health information.
Last updated: June 30, 2026
Our core commitments
- We never sell, rent, or monetize your personal or health information.
- We do not use your health data for advertising.
- We do not train AI models on your data without your explicit consent.
- You can delete your account and your data at any time.
- Educational only β Labs Made Clear does not provide a diagnosis or treatment plan.
What we collect
Account info you provide (name, email, optional profile fields), lab reports and values you upload, symptom and medication logs you enter, and data you authorize us to import from connected health record providers.
We follow the minimum-necessary principle: we only collect what is needed for the product to work for you.
How we use it
To show you your results, generate plain-English summaries and trends, and power the assistant features you use. We do not share your health data with advertisers, data brokers, or analytics tools that profile individuals.
How we protect it
All traffic is served over HTTPS. Health-record integration tokens are encrypted with AES-256-GCM before storage. Your records are protected by row-level access rules so other users cannot read them.
Sessions automatically expire after a period of inactivity. Administrative roles are granted manually, never based on email address.
AI processing
AI summaries run on the model gateway we operate. Your data is sent only to generate the response you requested and is not used to train third-party models. All AI output is educational and is not medical advice.
Your controls
From your Profile you can update or remove information and delete your account. Deleting your account removes your profile, uploaded reports, normalized lab values, logs, chats, and connection records.
For privacy requests (access, export, correction, deletion), email privacy@onhealthos.com.
Analytics (privacy-first)
We measure aggregate traffic to understand how the product is used. We never store visitors' IP addresses. Country, region, and city are derived from the connection at our edge and the IP is discarded before anything is written to our database. We use a first-party anonymous session cookie that rotates every 24 hours and is never joined to your account in analytics.
We collect: pages viewed, landing page, referrer category, UTM parameters, browser, operating system, device type, screen size, language, time on page, session duration, scroll depth, and click targets. Visitors who set Do-Not-Track or Global Privacy Control are excluded automatically.
Admin access boundaries
By default, Labs Made Clear admins cannot view, open, download, preview, or read your lab files, lab values, OCR text, AI summaries, diagnoses, or notes. Admin tools see only operational metadata (account, plan, file type and size, processing status).
If a support engineer needs to look at a specific issue, they must request temporary access from you. Access is time-limited (max 1 hour), revocable, and every access event is recorded in an audit log.
Technical error logs
When the service hits a technical problem (upload, OCR, AI, or payment failure), we log safe metadata so support can troubleshoot: timestamp, route, browser, file type and size, processing stage, error code, and a short technical message. We attach a short public Error ID you can quote (for example, "ERR-7F3A2B"). For critical failures, this metadata is emailed to our support inbox with rate limiting.
We never include lab text, biomarker values, reference ranges, OCR output, AI interpretations, diagnoses, symptoms, notes, or any health information in error logs or alert emails.
Vendors & contact
We use service providers for hosting, authentication, payments, and AI inference. Where required, we pursue Business Associate Agreements with vendors that may touch protected health information.
Questions or concerns? Email privacy@onhealthos.com.
This page describes current product behavior and may evolve as we improve the service. Labs Made Clear is built with HIPAA-aligned safeguards; we do not claim full HIPAA compliance until all technical, legal, administrative, and vendor requirements are independently verified.
