AriHum

Privacy Policy

Last updated: June 28, 2026

Overview

AriHum ("AriHum", "we", "our", or "us") refers to Forcapedia, AriHum provides an AI-powered health companion that can answer health questions, remember health context over time, analyze uploaded health documents, send reminders, and generate health summaries. This Privacy Policy explains how we collect, use, disclose, store, and protect information when you use AriHum websites, mobile apps, and related services (the "Services").

AriHum is designed for a global audience. Privacy rights and legal requirements vary by country, state, and region. Where local law gives you additional rights, we will honor those rights.

Who we are and scope

This Policy applies to AriHum websites, mobile applications, account systems, subscription flows, waitlist forms, support channels, notifications, exports, AI chat features, document analysis features, and any page or service that links to this Policy. It does not apply to third-party websites, app stores, payment platforms, identity providers, or services that we do not control.

For privacy requests, AriHum acts as the organization responsible for your AriHum account data. Some third-party providers process information for us as service providers or processors. Others, such as app stores or identity providers, may act independently for their own services under their own terms.

Health and AI notice

AriHum processes health information that may be sensitive under laws such as the EU and UK GDPR, India DPDP Act, United States state privacy laws, Brazil LGPD, Canada PIPEDA, and similar privacy frameworks. We use health information only as described in this Policy, with your consent where required, and to provide the Services you request.

AriHum is not a healthcare provider, health plan, claims clearinghouse, or emergency service. Unless we separately agree in writing, AriHum is not intended to create a HIPAA-covered provider-patient relationship or a business associate relationship.

Sensitive information

Health information can be highly sensitive. The information you enter into AriHum may reveal medical conditions, symptoms, medications, allergies, lab results, treatment history, lifestyle information, mental health concerns, family health details, and other information that privacy laws may classify as sensitive, special-category, protected, or health-related data.

We ask you to submit only information that is relevant to your use of AriHum. Do not upload another person's health information unless you have the legal authority and consent required to do so.

Information we collect

Depending on how you use AriHum, we may collect:

  • Account information, such as email address, authentication identifiers, login method, and account status.
  • Profile information you provide, such as name, age, sex, height, weight, language, timezone, health goals, and notification preferences.
  • Health information, such as medical conditions, medications, allergies, symptoms, lab values, reports, prescriptions, notes, and other information you enter or upload.
  • Conversation content, including messages, questions, uploaded attachments, AI responses, conversation summaries, and long-term health memory used to personalize future responses.
  • Document information, including medical report files, extracted text, structured values, report dates, lab or doctor names if present in the document, file names, file type, and file size.
  • Subscription and entitlement information, such as plan, trial status, renewal status, platform, purchase metadata, and app store or subscription-provider identifiers. We do not store full payment card details.
  • Device, app, and usage information, such as device type, operating system, app version, language, country or approximate region, diagnostics, crash logs, feature usage, and security logs.
  • Notification information, such as push notification tokens and reminder settings if you choose to enable notifications.
  • Support, feedback, and waitlist information, such as email address, messages you send us, survey responses, bug reports, and communications with AriHum.

Detailed data categories

The exact data we process depends on the features you use. Examples include:

  • Identity and account data: email address, user ID, authentication provider, sign-in timestamps, account status, accepted legal versions, and support identifiers.
  • Onboarding and profile data: name or preferred name, age, sex, height, weight, health goals, diet preference, activity level, timezone, language, and app preferences.
  • Health profile data: conditions, medications, dosages you voluntarily record, allergies, health challenges, symptoms, vitals, lab values, health habits, and other self-reported details.
  • Conversation data: user messages, AI responses, clarification questions, attachments referenced in chat, session summaries, and persistent health memory generated from conversations.
  • Medical document data: original uploaded files, file metadata, extracted text, structured values, report type, report date, lab name, doctor name if present, patient name if present, notes, and AI summaries.
  • Generated health data: weekly or monthly AI reports, trend explanations, suggested doctor questions, health-history exports, and summaries that AriHum creates from your inputs.
  • Subscription data: plan, entitlement, platform, renewal and expiration dates, trial status, cancellation status, app-store transaction metadata, and subscription-provider identifiers.
  • Technical data: device model, operating system, app version, IP address, approximate region, language, crash diagnostics, security events, rate-limit events, logs, and feature usage.
  • Communications data: emails, waitlist entries, support requests, feedback, survey responses, and operational messages between you and AriHum.

Information from other services

If you sign in through an identity provider, purchase through an app store, or otherwise connect a third-party service, we may receive the information needed to authenticate you, confirm your subscription, provide support, prevent fraud, and operate the Services. The third-party service may also process your information under its own privacy policy.

Data you choose not to provide

You can choose not to provide certain information. However, AriHum may need particular information to provide personalized responses, analyze reports, maintain memory, send reminders, verify subscriptions, or secure your account. If you do not provide required information, some features may be unavailable, less personalized, or less accurate.

How we use information

We use information to:

  • Provide, personalize, maintain, and improve AriHum.
  • Generate AI responses, ask clarifying health questions, analyze uploaded health documents, and maintain health context across sessions.
  • Create health summaries, trend reports, export files, reminders, and notifications you request or enable.
  • Authenticate users, manage accounts, process subscriptions, enforce plan limits, and provide customer support.
  • Detect, prevent, investigate, and respond to fraud, abuse, security incidents, policy violations, and technical issues.
  • Send service messages, security notices, account updates, support replies, and optional communications where permitted.
  • Measure product performance and reliability using analytics, crash reports, logs, and aggregated or de-identified statistics.
  • Comply with applicable laws, enforce our Terms, preserve legal records, and protect the rights, safety, and security of users, AriHum, and others.

Product personalization

AriHum is built around continuity. To make future conversations more relevant, AriHum may use previous messages, profile details, uploaded reports, extracted lab values, medications, allergies, goals, and generated summaries as context. This memory is intended to help AriHum avoid asking you to repeat the same health background and to reference your prior information when you ask related questions.

Legal bases

For users in the European Economic Area, United Kingdom, Switzerland, and other regions with similar legal-basis requirements, we rely on one or more of the following bases:

  • Contract: to provide the Services you request and manage your account or subscription.
  • Consent: for sensitive health information, optional notifications, optional communications, and other processing where consent is required.
  • Legitimate interests: to secure, improve, debug, and understand the Services in a privacy-respecting way.
  • Legal obligations: to comply with law, tax, accounting, consumer protection, safety, and regulatory obligations.
  • Vital interests or public interest where applicable: to respond to serious safety risks, emergencies, or legally required safety actions.

You may withdraw consent where our processing depends on consent, but doing so may limit or prevent AriHum from providing personalized health features.

Special-category data bases

Where laws such as the EU or UK GDPR apply and health data is treated as special-category data, we rely on explicit consent where required, and where applicable we may also rely on legal claims, vital interests, substantial public interest, preventive or occupational medicine exceptions only if those bases are legally available for the specific processing.

In ordinary consumer use, AriHum's processing of health information is based primarily on your decision to provide the information so AriHum can deliver the features you request. You may withdraw consent, but withdrawal may require deleting certain data or closing your account because health context is central to the service.

Consent and withdrawal

When we ask for consent, you may decline. You can also withdraw consent later by changing settings, disabling a permission, deleting specific data where available, deleting your account, or contacting us. Withdrawal does not affect processing that happened before the withdrawal or processing that we must continue for legal, safety, billing, fraud-prevention, or dispute-resolution reasons.

Device permissions, such as notifications, photos, camera, files, or microphone where available, can usually be changed through your device settings. If you disable a device permission, related features may stop working.

AI providers and health content

AriHum uses third-party AI model and document-processing providers to generate responses and analyze uploaded documents. This means health questions, conversation context, files, extracted text, and related prompts may be sent to those providers when needed to provide the feature you request. We do not disclose this information to AI providers for targeted advertising.

Our AI providers operate under their own data-processing terms. We select providers whose published API commitments do not use your inputs to train their models for general purposes without your opt-in. Provider data practices may include retaining inputs and outputs for a limited period for abuse monitoring, safety, and service operation. We work to configure providers and features in a way that minimizes unnecessary retention and access. The specific AI providers we use may change over time as we update our infrastructure.

How AI processing works

When you ask AriHum a question or upload a document, AriHum may send selected information to AI or document-processing providers. This may include:

  • Your message or request.
  • Relevant health profile details needed to answer your question.
  • Relevant conversation history or generated memory summaries.
  • Uploaded images, PDFs, text files, or extracted document text when you ask for document analysis.
  • System and safety instructions that tell the AI how to respond responsibly.
  • Metadata needed for security, rate limiting, debugging, and provider operation.

We try to send only what is reasonably needed for the feature. However, because the purpose of AriHum is personalized health context, AI requests may include sensitive health information when that context is necessary to respond.

AI training and improvement

AriHum does not sell your conversations or health records for AI training. We do not use your identifiable health information for targeted advertising. We may use aggregated, de-identified, or privacy-protected statistics to understand reliability, improve product design, reduce errors, and measure feature performance.

If we ever introduce a feature that uses identifiable health content to train or fine-tune AriHum-specific models beyond what is necessary to provide the service you requested, we will provide notice and obtain consent where required by law.

When we share information

We may share information with:

  • Service providers that help us operate AriHum, including hosting, database, file storage, authentication, AI processing, OCR, subscription management, app stores, analytics, crash reporting, email, push notifications, security, and customer support.
  • App stores and subscription providers to confirm purchases, trials, renewals, cancellations, refunds, and entitlement status.
  • Professional advisors, auditors, insurers, legal counsel, regulators, courts, law enforcement, or government authorities when required or reasonably necessary.
  • Successors or affiliates in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, subject to appropriate protections.
  • Other parties with your direction or consent, such as when you export your data or choose to share information outside AriHum.

We do not sell your health information. We do not share your health information with employers, advertisers, or data brokers for their independent marketing.

Service provider categories

We use service providers only as needed to run AriHum. Categories may include:

  • Cloud hosting, backend infrastructure, databases, and private file storage.
  • Authentication and account-management providers.
  • AI model, OCR, transcription, and document-processing providers.
  • Subscription management providers, payment processors, and app stores.
  • Email delivery and customer-support providers.
  • Push-notification delivery providers.
  • Analytics, product-measurement, crash-reporting, and diagnostics providers.
  • Security, fraud-prevention, abuse monitoring, rate-limiting, and logging providers.
  • Professional advisors, such as lawyers, accountants, auditors, and insurers.

What we do not do

  • We do not sell your health information.
  • We do not share your health information with employers.
  • We do not share your health information with advertisers or data brokers for their independent marketing.
  • We do not use your health information to make insurance, credit, employment, housing, or lending decisions.
  • We do not allow human review of identifiable health content except where needed for support, safety, security, legal compliance, service operation, or with your permission.

International transfers

AriHum and its service providers may process information in countries other than where you live. Those countries may have privacy laws that differ from your local laws. Where required, we use appropriate safeguards for cross-border transfers, such as contractual protections, standard contractual clauses, adequacy mechanisms, vendor due diligence, and other lawful transfer tools.

Transfer safeguards

Where required, we rely on mechanisms such as adequacy decisions, standard contractual clauses, data-processing agreements, vendor security reviews, encryption, access controls, minimization, and contractual restrictions on provider use. No transfer mechanism removes every risk, but we use safeguards designed to protect information when it moves across borders.

Retention

We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.

  • Account, profile, conversation, health memory, summaries, and report data are generally retained while your account is active so AriHum can provide personalized continuity.
  • Uploaded medical reports are retained until you delete the report, use a private processing mode that does not save the file, or delete your account.
  • Private or incognito document processing, where available, is designed to process the file without saving the file to your report library, although temporary processing, abuse-prevention, and provider logs may still exist for limited periods.
  • Subscription, billing, tax, fraud-prevention, safety, and legal-consent records may be retained as needed to comply with law, resolve disputes, enforce agreements, or establish legal rights.
  • Backups, diagnostics, and security logs may take a limited time to expire after deletion from active systems.
  • Aggregated or de-identified information that no longer identifies you may be retained for analytics, safety, and service improvement.

For account deletion details, see our Delete Account Policy.

Retention details

Retention periods depend on the type of information and why we keep it:

  • Active account data is usually kept while your account remains active.
  • Health memory and chat context are kept while needed to provide personalized continuity, unless you delete the data or close your account.
  • Uploaded report files are kept until you delete the report, delete your account, or use a mode that does not save the report file.
  • Legal consent records, subscription events, invoices, tax records, fraud-prevention records, and dispute records may be retained longer where necessary.
  • Security logs, rate-limit records, abuse-prevention logs, and crash diagnostics are kept for limited periods unless needed to investigate an incident.
  • Provider logs and backups may follow provider-specific retention schedules, subject to our agreements and applicable law.

Deletion and legal holds

When you delete your account, we delete or de-identify personal information from active systems unless retention is required or permitted for legal, tax, billing, fraud-prevention, security, safety, dispute-resolution, enforcement, or backup reasons. If there is an active legal request, security investigation, unresolved billing dispute, or abuse investigation, we may preserve relevant information until the issue is resolved.

Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, access controls, private storage controls, signed access links where appropriate, least-privilege operational access, monitoring, and deletion procedures. No online service can be guaranteed to be completely secure. You are responsible for keeping your account credentials and device secure.

Operational access

AriHum limits operational access to personal information to individuals and providers who need it to operate, secure, support, debug, or legally maintain the Services. Access may be logged, restricted, or reviewed depending on the system and sensitivity. Any contractors or service providers who handle user information are required to protect its confidentiality under appropriate agreements.

Security incidents

If we discover a security incident that affects your personal information, we will investigate and respond. Where required by law, we will notify affected users, regulators, app stores, or other parties. Because no system is perfectly secure, you should use a strong password, protect your email account, keep your device updated, and contact us if you believe your account has been compromised.

Your choices

You can control information in several ways:

  • Update profile, health, medication, allergy, goal, and notification information in the app.
  • Delete reports or attachments where the app provides deletion controls.
  • Disable push notifications through AriHum settings or your device settings.
  • Cancel subscriptions through the relevant app store or subscription platform.
  • Request access, correction, deletion, portability, restriction, objection, consent withdrawal, or other privacy actions by contacting us.

Regional privacy rights

Depending on your location, you may have rights to know what personal information we collect, access a copy, correct inaccuracies, delete information, restrict or object to processing, withdraw consent, receive data portability, appeal a decision, complain to a privacy authority, or opt out of certain uses.

California and similar U.S. state privacy laws may provide rights to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive non-discriminatory treatment. AriHum does not sell personal information or share it for cross-context behavioral advertising. We use sensitive personal information only to provide the Services, secure the Services, comply with law, and for other permitted purposes.

We may need to verify your request before acting on it. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and identity.

EEA, UK, and Switzerland rights

If you are in the EEA, UK, or Switzerland, you may have rights to access, rectify, erase, restrict, object to processing, receive portability, withdraw consent, and lodge a complaint with a supervisory authority. Some rights are limited by exceptions, such as legal obligations, safety, security, fraud prevention, or establishing and defending legal claims.

United States state rights

Depending on your state, you may have rights to know, access, correct, delete, obtain a portable copy, opt out of sale or sharing, opt out of targeted advertising, limit use of sensitive information, appeal a denial, and avoid discrimination for exercising rights. AriHum does not sell personal information or share it for cross-context behavioral advertising. If legally required, we will honor applicable opt-out or limitation requests.

India rights and grievance

If the India Digital Personal Data Protection Act 2023 (DPDP Act) or related rules apply to you, you may have rights to access information about processing, correct or update personal data, erase personal data, withdraw consent, nominate another person where applicable, and use grievance redressal mechanisms. We will handle such requests according to applicable law.

For grievances under the DPDP Act or Indian consumer law, contact our grievance officer at hello@arihum.com. Grievances will be acknowledged within 48 hours and we will endeavour to resolve them within 30 days. If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India once operational, or the appropriate consumer forum under the Consumer Protection Act 2019.

Brazil, Canada, Australia, and other regions

If privacy laws such as Brazil's LGPD, Canada's PIPEDA or provincial laws, Australia's Privacy Act, or similar laws apply, you may have rights to access, correction, deletion, withdrawal of consent, portability, information about sharing, complaint, or objection, depending on the law. We will honor applicable local rights and limitations.

How to exercise rights

To exercise privacy rights, contact us using the email at the end of this Policy. We may ask you to verify your identity before we act. To help us process your request, include:

  • The email address linked to your AriHum account.
  • Your country, state, or region.
  • The specific right or request you want to exercise.
  • Any details needed to identify the data or feature involved.

We will respond within the time required by applicable law. If we deny a request, we will explain the reason where required and tell you how to appeal if an appeal right applies.

Automated outputs

AriHum uses AI to generate health information and summaries, but AriHum does not make binding medical, legal, insurance, employment, credit, or similarly significant decisions about you. You should not rely on AriHum as the sole basis for healthcare decisions.

No solely automated legal decisions

AriHum's AI outputs can influence what information you choose to discuss with a healthcare professional, but AriHum does not make solely automated decisions that produce legal or similarly significant effects such as insurance eligibility, credit decisions, employment decisions, or access to medical treatment. Healthcare decisions remain with you and your licensed professionals.

Children

AriHum is not intended for children under 18. Do not create an account or submit personal information if you are under 18. If you believe a child has provided personal information without appropriate authorization, contact us so we can take appropriate action. If a parent or legal guardian uses AriHum to organize information for a dependent, the parent or guardian is responsible for ensuring they have the legal right to do so.

Family and caregiver use

AriHum may be used by an adult to organize information for a family member or dependent only when the adult has the legal authority and consent required. If you enter another person's information, you are responsible for making sure that submission is lawful and that the person understands how AriHum will process the information where required.

Cookies and website data

Our website may use cookies, local storage, analytics, logs, and similar technologies to operate the site, remember preferences, measure performance, prevent abuse, and understand traffic. You can control cookies through your browser settings, but disabling some technologies may affect site functionality.

Marketing communications

We may send service messages that are necessary for your account, subscription, security, legal notices, or product operation. We may send promotional or educational messages where permitted by law or with consent where required. You can opt out of promotional messages, but you may still receive essential service communications.

Do not track signals

Some browsers send "Do Not Track" signals. There is no consistent industry standard for responding to those signals. We respond to legally required opt-out signals where applicable and technically feasible.

Changes

We may update this Policy as AriHum, our providers, or applicable laws change. If changes are material, we will provide notice as required by law, such as in the app, on the website, or by email. The "Last updated" date shows when this Policy was last revised.

Contact

For privacy questions, data requests, or rights requests, contact us at hello@arihum.com. Please include the email address associated with your AriHum account and the country or state where you live so we can handle your request appropriately.