AI Policy
What the AI in Homeostasis does, exactly what each feature sends and to whom, what is never sent, and the things the AI is not permitted to do. Written to be checked, not to reassure.
1. Four commitments
- Your data does not train anyone's model. Not ours, not our providers'. This is contractual, not a preference.
- Nothing is sent until you say yes. AI is off by default. Consent is checked on our servers, so a request without it fails even if the app is modified.
- Your name is removed before anything is sent. Along with your email, account ID and tokens.
- The AI never makes a clinical decision. It does not diagnose, prescribe, change a dose, or write to your medical record.
2. Who processes it
Every AI request goes through our own server first. The app never calls a model provider directly, which is how we can strip identifiers, enforce consent and keep provider credentials out of the app.
| Provider | Models | Used for | Terms |
|---|---|---|---|
| OpenAI | GPT-4o GPT-4o-mini | Assistant replies, meal photo analysis, food parsing, insights, weekly summaries | BAA signed, zero data retention |
| OpenAI | Whisper | Transcribing voice notes | BAA signed, zero data retention |
| OpenAI | GPT-4o-mini-TTS | Reading replies aloud | BAA signed, zero data retention |
| FatSecret | — | Food and nutrition database lookups | No health data sent |
Scroll the table sideways to see every column →
OpenAI is currently our only AI model provider. If that changes we will update this page and ask you to accept the new version before the change takes effect.
"Zero data retention" means OpenAI does not store your prompts or the model's responses after the request is answered — they are not kept for the 30-day abuse-monitoring window that applies to their standard API tier.
3. Feature by feature
Each feature sends the minimum it needs. Here is the whole list.
Ask the assistant
Sent to OpenAI: your question, plus a snapshot of your own treatment context — medication type and dose phase, where you are in your schedule, your current targets and today's progress against them, recent side effects, and recent scores.
The assistant answers from your plan and your logs, and cites what it drew on so you can check it. It is not a general medical search engine.
Meal photograph
Sent to OpenAI: the photograph of the meal. Nothing else — no profile, no medication, no identifiers.
Describe a meal in text
Sent to OpenAI: the text you typed.
Voice logging
Sent to OpenAI: the audio clip, and the kind of entry you are logging (food, weight, dose, side effect, activity) so the transcript can be structured correctly. Audio is transcribed and not retained.
Spoken replies
Sent to OpenAI: the reply text the assistant already generated, so it can be turned into speech. No additional personal data.
Insights and weekly summaries
Sent to OpenAI: an aggregated summary of the period — trends and totals, not individual messages, not photographs.
Food search, barcodes and autocomplete
Sent to FatSecret: the food name, the partial text as you type, or the barcode number. No health data, no medication data, and nothing that identifies you is ever sent to FatSecret.
4. What is never sent
Under no circumstance, to any AI provider:
- Your name
- Your date of birth
- Your email address
- Your account identifier or authentication tokens
- Your clinic code
- Your clinic's own medical record, or anything your clinic pushed into the app
- Your progress photographs
- Your messages with your clinic
Your name was previously included in assistant prompts. It was removed — it added nothing to the quality of an answer and was the one field that made a request unambiguously identifiable.
5. Consent, and how it is enforced
AI features are off until you turn them on. The first time you open one, you see a plain description of what will be sent and choose. Nothing is sent if you decline, and the rest of the app keeps working — logging, scoring, charts and your clinic connection do not depend on AI.
Consent is enforced on the server. Your choice is stored against your account, and our AI proxy checks it on every single request. Turning it off in Settings stops data being sent immediately, from that moment, regardless of what the app does.
Withdrawing consent does not unsend what was already processed. Because our providers operate under zero data retention, there is no stored copy on their side to recall.
6. Training and retention
Our agreements prohibit our AI providers from using anything we send — your questions, your photographs, your voice, your health context — to train or improve their models. We do not use it to train models of our own, and we do not sell or license it to anyone who would.
On our side: your assistant conversations are stored in your account so you can read them back, and are deleted with your account. Nutrition lookups are cached briefly to avoid repeating identical requests, and those caches are pruned on a schedule.
On the provider's side: nothing is retained after the request is answered.
We log AI errors for debugging. Those logs record that a request failed and why — never the content of the prompt.
7. What the AI cannot do
- It does not diagnose a condition.
- It does not prescribe, and it does not tell you to change, skip, split or double a dose. If you ask, it tells you to contact your clinic.
- It does not write to your medical record, and it cannot alter your care plan.
- It does not decide anything about your care, and no clinical action is taken automatically because of something the AI produced.
- It does not see your clinic's chart or another patient's data.
It also has real limitations you should keep in mind. It does not know your full medical history, your allergies, or every medication you take outside this app. It cannot assess drug interactions for your situation. It cannot see you, and it cannot examine you. It is not monitored in real time by a clinician and is not a route to urgent help — in an emergency call 911, or 988 for a mental-health crisis in the US.
8. Clinicians stay in charge
AI in Homeostasis is a reading aid. Your prescriber sets your medication, dose and every target in your plan; the app displays what they set. Nothing the AI produces changes your treatment, and nothing reaches your chart without a clinician deciding it should.
Where the dashboard flags something for a clinician's attention, that flag is a prompt to look — not a triage decision, not a diagnosis, and not a guarantee that anything important will be caught. Clinical judgement stays with the clinic.
9. AI on the dashboard
Clinic staff have AI tools of their own for summarising a patient's period between visits and answering questions about that patient's record.
Two things follow that patients should know:
- Your conversations with the patient assistant are not shown to your clinic. Staff cannot read what you asked it or what it told you.
- Clinic-side AI use is audited — we record that an answer was produced and for which patient, so there is an access trail. We deliberately do not store the question, the answer or the underlying payload.
10. When it is wrong
It will sometimes be wrong, and we would rather say so here than have you discover it at a bad moment.
- Photographs get misread. Portion size is the usual culprit; a model cannot weigh your plate. Treat the numbers as a starting estimate and correct them.
- Voice gets mistranscribed. Drug names and numbers are the risky ones. Check a transcribed dose before saving it.
- Language models state wrong things confidently. Fluency is not accuracy. That is why the assistant cites what it used — follow the citation when it matters.
- Nutrition databases disagree with each other, and with the packet in your hand.
You can correct any AI-produced entry before or after saving it, and an entry you corrected stays corrected. If you see the assistant say something clinically wrong, please tell us at support@titrahealth.io — we read those and act on them.
11. Your controls
- Turn AI on or off in Settings → Privacy & Data, at any time, in either direction.
- Turn the food database on or off independently of the AI features.
- Use the app without any of it. Logging, targets, charts, scoring and your clinic connection all work with AI switched off.
- Read and delete your assistant history. It is part of your account data and goes when your account goes.
- Export your data at any time.
12. Changes
If we add an AI provider, change what a feature sends, or change the retention terms we have with a provider, we will update this page and ask you to accept the new version in the app before the change applies to you. The version and date at the top tell you what you are reading.
This policy sits alongside our Privacy Policy and Terms of Service.
Want the technical detail?
Clinics and compliance officers can request our AI data-flow documentation, our provider agreements and our security package.
Email support@titrahealth.io