Babu Health

Privacy Policy

Last updated July 29, 2026

About this instance

This Babu Health instance is operated locally for development and evaluation. Its application services, database, and health records run on the operator's own computer. A secure public callback address may be used so that health providers can complete OAuth authorization and deliver webhooks to the local instance.

Information we access

Babu Health requests only the provider permissions shown during authorization. Depending on the source you choose, these may include read-only activity, fitness, sleep, vital-sign, workout, profile, or clinical health information. We also process the account identifiers and authorization tokens needed to maintain the connection.

How information is used

Information is used to retrieve, normalize, display, and analyze the health data that you explicitly connect. It is not sold or used for advertising. Provider access tokens are encrypted before storage in the local PostgreSQL database. Locally stored health documents are also encrypted.

Google API data

Babu Health's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google Health permissions are requested on a read-only basis for the health categories selected during consent.

Providers and retention

When you connect a source, the relevant provider receives the authorization request and processes data under its own privacy terms. Data remains in the local instance until it is deleted by the operator. You can revoke a provider connection through Babu Health or the provider's account controls, and you may request deletion of locally held connection data.

Contact

Questions, access requests, and deletion requests can be sent to mannavascb@babuhealth.com.