Contents
This Privacy Policy explains how Prana Force, Inc. ("Prana," "we," "us") collects, uses, and shares information when you use the Prana mobile app, the prana.health website, the Prana MCP connector, and related services (together, the "Service").
Prana is a health analytics and coaching service. We handle sensitive health information, and this policy is written to describe — specifically, not generically — what we actually collect and what we do with it.
Summary (the short version)
- We collect the health data you log or sync: blood biomarkers, body composition, medications, workouts, nutrition, sleep, heart rate, weight, and your conversations with the Prana coach.
- Parts of the Service are powered by AI (Anthropic's Claude models running on Amazon Web Services). AI outputs can be wrong and are not medical advice. Your data is not used to train AI models.
- We do not sell your personal information, and we do not use your health data for advertising.
- Deleting your account deletes your personal data. We keep a copy of your health measurements for internal research, processed so it is no longer reasonably linkable to you — without your name, email or date of birth. See Retention and deletion.
- Washington and Nevada residents: see our separate Consumer Health Data Privacy Policy.
- Questions or requests: aditya@prana.health.
1. Information we collect
1.1 Information you provide
| Category | Examples |
|---|---|
| Account | Email address, name, password (if you sign up by email), or your Google account identifier (if you sign in with Google) |
| Profile & demographics | Date of birth, sex, height, weight, health and fitness goals, timezone |
| Health records you upload | Lab result documents (PDFs), DEXA / body-composition scan reports |
| Medications | Medication names, doses, schedules, and the dose history you log |
| Training & activity | Workouts, exercises, sets, reps, loads, cardio sessions |
| Nutrition | Meals you log, barcode scans, and food photos you submit for analysis |
| Chat & coaching content | Messages, questions, and any information you share in conversations with the Prana coach, including voice input converted to text |
| Photos & media | Images you choose to upload from your camera or photo library |
| Purchase & fulfillment details | Name, email, state, and address where needed to arrange lab testing or scans; your purchase history and the balance and redemption of any Prana service credits |
| Public food database contributions (optional) | If you switch on "Submit to Public Database" when logging or editing a food, we receive that food's name, nutrition facts, serving size and units, barcode, and any photo attached to it, together with your email address. This is off unless you turn it on — see Section 1.6 |
| Support & feedback | Feature requests, support messages, survey responses |
1.2 Health data synced from your device (Apple Health / Health Connect)
With your permission, we read from and write to Apple HealthKit (iOS) and Health Connect (Android). The data types we access are:
- Steps and distance travelled
- Weight and height
- Sex and date of birth (iOS)
- Heart rate, resting heart rate, and heart rate variability (read only)
- Workouts and exercise sessions
- Active energy burned and total calories burned
- Sleep (in bed, awake, light, deep, REM, and total sleep)
- Nutrition (energy, protein, carbohydrates, fat, saturated fat, fiber, sugar)
Exact types vary by platform, since Apple Health and Health Connect support different data. We request write access for the data you log in Prana (such as weight, workouts, nutrition, sleep, steps, and distance) so it appears in your device's health app; heart rate, resting heart rate, and heart rate variability are read only.
You control these permissions in your device settings and can revoke them at any time.
Our commitments for Apple Health and Health Connect data:
- We use it only to provide the Service's features to you — tracking, analytics, insights, and coaching.
- We do not use it for advertising, marketing, or use-based data mining.
- We do not sell it or share it with third parties for their own purposes.
- We do not store HealthKit data in iCloud.
- We share it with our data processors (Section 4) only as necessary to operate the Service.
1.3 Lab results from testing we arrange
If you purchase blood testing through Prana, orders are placed through our lab-ordering partner and authorized by licensed healthcare practitioners; specimens are collected and analyzed by independent CLIA-certified laboratories. Your biomarker results are delivered to Prana and shown to you in the app and dashboard. Those results become part of your Prana health record and are handled under this policy.
1.4 Information collected automatically
- Device and app data: device model, operating system and version, app version, language, timezone, network connectivity state.
- Usage analytics: events describing how you use the app (screens viewed, features used), collected through Mixpanel.
- Cookies and similar technologies (website): essential cookies for sign-in and session management, and analytics as described above. We do not use advertising cookies.
1.5 Voice input
If you use voice input, your speech is converted to text by your device platform's speech-recognition service (Apple or Google), which processes the audio under that platform's terms. Prana receives only the resulting text, which is then handled like any other message you type. We do not record, upload, or store your raw audio.
1.6 Contributions to the shared food database
When you log or edit a food, you can optionally switch on "Submit to Public Database." It is off by default and applies only to the food entry in front of you — nothing is contributed unless you turn it on.
- What is submitted: the food's name, nutrition facts, serving size and units, barcode if present, and any photo attached to that entry. Your email address is sent with the submission.
- What we do with it: submissions arrive marked for review. We check them for accuracy and suitability before anything is added to the shared food library.
- What other people can see: if a submission is approved, the food information and photo become part of a shared library available to other Prana users. Approved photos are served from public web addresses, so anyone holding the link can view the image — treat a submitted photo as public. Your email address and name are not displayed to other users and are not part of a published entry — we retain your email internally so we can trace and correct a submission, contact you about it, and address misuse.
- Please don't submit personal images. Submit photos of food. Do not submit photos containing people, faces, documents, or anything else you would not want other users to see.
- What happens if you delete your account: we remove the internal link between you and your submissions. Approved entries stay in the shared library, because they describe a food product rather than you and other users' records depend on them. If you want a specific contribution removed, email aditya@prana.health and tell us which entry.
1.7 On-device processing
Barcode scanning and text recognition (for example, scanning a food barcode or a label) run on your device using Google ML Kit. The camera image is processed locally; we receive the extracted result (such as the barcode number), not a continuous camera feed.
2. How we use information
We use your information to:
- Provide the Service: track your health data, compute analytics and trends, generate insights, reports, and coaching.
- Power AI features (Section 3), including the Prana coach, AI-generated insights, and photo-based food logging.
- Arrange and fulfill lab testing and scan services you purchase, including verifying availability in your state.
- Process payments and manage subscriptions and credits.
- Review, correct, and publish contributions you choose to make to the shared food database, and maintain the accuracy of that library (Section 1.6).
- Send service communications, reminders (for example, medication reminders you set), and respond to support requests.
- Understand how the Service is used and improve it (analytics, debugging, quality and safety review).
- Conduct internal research to improve our health models and analytics (see Section 7 for retention; where required, research use is subject to your consent).
- Comply with law, enforce our Terms of Service, and protect the security of the Service.
We do not use your personal information for third-party advertising, and we do not engage in advertising-based profiling.
3. AI processing
Parts of the Service are powered by artificial intelligence. We use Anthropic Claude models and Amazon Nova models, all running on Amazon Web Services (AWS Bedrock) infrastructure. Our AWS account is based in the United States; for some models we use AWS cross-region inference, which allows AWS to route an individual request to another of its regions, which may be outside the United States. We do not send your data to any AI provider outside AWS Bedrock.
- What AI processes: your chat messages and, depending on the feature, relevant parts of your health record (for example, biomarkers, body composition, medications, workouts, nutrition, sleep, and activity data) are sent to our AI infrastructure to generate responses, insights, and reports. So that the AI can address you and interpret your results correctly, prompts also include profile information — your name, email address, age, sex, height, date of birth, timezone — and your subscription status. Images and documents you submit — including food photos, photos sent in chat, and lab or body-composition reports you upload — may be processed by AI to read their contents and estimate nutrition or biomarker values; where a lab report contains identifying details in its header, those are processed along with the results.
- No model training on your data: our AI infrastructure providers do not use your content to train their models. Your conversations and health data are processed to generate your outputs, not to build the underlying models.
- AI can be wrong: AI-generated content may be inaccurate, incomplete, or outdated. It is provided for informational purposes and is not medical advice, diagnosis, or treatment. Do not make medical decisions based on AI output without consulting a licensed healthcare professional.
- Quality and safety review: we may review conversations and AI outputs internally to monitor quality, safety, and abuse, and to improve the Service. Our staff can also run internal AI sessions about a specific member's health data — for example to investigate a support question or check how the coach responded — and those sessions are recorded against that member's account.
- Conversation memory: to let the coach remember context between sessions, conversation content is also stored with our memory provider (Section 4).
4. Who we share information with
We share personal information only as described here. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
| Recipient | What they receive | Why |
|---|---|---|
| Supabase | Account data and app data, including health data (our database and authentication provider) | Core infrastructure — storing and serving your data |
| Amazon Web Services (Bedrock) | Chat content and relevant health data sent to AI features | Running the AI models that power coaching and insights |
| Stripe | Your email address, the amount, and identifiers describing what you bought — for a blood panel this includes which panel and, because panels differ by sex, an identifier reflecting your sex at birth (US purchases) | Payment processing. Prana never receives your full card number |
| Apple / Google | In-app purchase and billing data (purchases outside the US); sign-in identifiers if you use Google Sign-In; speech audio if you use voice input | App-store billing, authentication, speech-to-text |
| Mixpanel | Your account identifier and email address, plus usage and app-lifecycle events (screens viewed, sign-in and sign-up, onboarding steps, subscription events) and device data. We do not send your health data — biomarker values, medications, body composition, and similar records are never included in analytics events | Product analytics |
| Mem0 | The content of your coaching conversations, associated with your email address | Giving the Prana coach memory of what you have discussed across sessions |
| Pinecone | Search queries derived from your conversations, used to look up reference material. Your health record is not stored there | Retrieving relevant health and training reference content |
| Resend | Your email address, and the contents of the messages we send you — which for an order confirmation includes the name of the blood panel you purchased, and for at-home draws your address | Sending you transactional email |
| FatSecret, Open Food Facts | Food names and barcodes you search or scan | Looking up nutrition information for foods you log |
| Web search (DuckDuckGo or Tavily) | The exercise name or description you type when creating a custom exercise | Drafting a custom exercise entry |
| Apple Health / Health Connect (on your device) | Health data you log in Prana, written back to your device's health app with your permission | Keeping your device health record in sync, at your direction |
| Lab-ordering partner (Rupa Health), authorizing practitioners, and CLIA-certified laboratories | Name, contact details, demographics, and order details needed to order testing; the labs generate your results | Fulfilling blood testing you purchase |
| Scan providers | Booking details for body-composition scans where offered | Fulfilling scan bookings |
| Cloud hosting and infrastructure providers | Data as needed to host and operate the Service | Infrastructure |
| Third-party AI clients you connect via the MCP connector | The health data you authorize (Section 5) | Only at your direction |
Where a recipient above acts as our service provider or processor — our infrastructure, AI, analytics, and payment providers — we contractually require them to protect your information to a standard at least equivalent to this policy, to use it only to provide services to us, and not to sell it or use it for their own purposes.
That does not describe every recipient in the table. Independent healthcare practitioners, laboratories, and scan providers act on their own behalf under their own privacy practices and professional obligations. Apple and Google act as independent parties for app-store billing, authentication, and device platform services. And third-party AI clients you connect through the MCP connector are chosen and controlled by you, not by us — see Section 5.
We may also disclose information: (a) to comply with law or valid legal process; (b) to protect the rights, safety, or property of Prana, our users, or others; (c) in connection with a merger, acquisition, financing, or sale of assets, in which case this policy will continue to apply to your data and we will notify you of any change in control; and (d) with your consent or at your direction.
Healthcare practitioners and laboratories involved in your testing are independent providers. Health information they hold about you is also governed by their own privacy practices and, where applicable, HIPAA.
5. The MCP connector (data export you control)
Prana lets you create personal API keys that connect your Prana data to third-party AI applications supporting the Model Context Protocol (MCP), such as AI assistants you use.
- A connected client can, at your direction, read your Prana data — including blood biomarkers, body composition, medications and dose history, workouts, cardio, steps, weight history, sleep, nutrition logs, calorie summaries, and profile information — and write entries such as logged meals, workouts, weight, sleep, and medication doses.
- You choose the third-party client. Once data reaches a third-party application, it is governed by that application's privacy practices, not this policy. Review them before connecting.
- Treat your MCP API keys like passwords. You can revoke a key at any time in the app's settings, which immediately ends that client's access.
6. Payments
US purchases are processed by Stripe; purchases elsewhere are processed through Apple App Store or Google Play billing. Prana does not receive or store full payment card numbers. We receive limited information such as card brand, last four digits, and transaction status to manage your account.
7. Retention, account deletion, and what we keep
While your account is active, we retain your data to provide the Service.
Deleting your account. You can delete your account at any time in the app's Settings, or by emailing aditya@prana.health. Deleting your account deletes your account record and your personal data — your sign-in identity, name, email address, contact and address details, and your identifiable health record, including biomarker results, body-composition history, medications, workouts, nutrition, and sleep data.
Deletion is permanent and cannot be undone. Creating a new account later with the same email address gives you a fresh, empty account — your previous history is not restored.
What we keep, and why. Three narrow categories survive deletion:
-
Records we are legally required to retain, principally payment and tax records of purchases you made. These are retained without your health data.
-
A record that the deletion happened, so we can confirm it if you or a regulator later ask. It holds the date, what was removed, and a one-way cryptographic hash of your email address — not the address itself. The hash lets us answer "was this account deleted?" without keeping your email on file, and cannot be reversed to recover it.
-
A de-identified copy of your health measurements, kept for research. When you delete your account we retain a copy of your health measurements — biomarkers, body composition, weight, sleep, activity, nutrition, training and medication records — for internal research to improve Prana's health analytics. Before it is retained we remove your name, email address, date of birth, contact details and account identifiers, and replace them with a random research identifier that is not derived from your email address. We keep only coarse demographics needed to interpret the measurements: your sex, your height rounded, and your age as a range (for example "35-39") rather than a date of birth.
We apply reasonable technical and organizational measures designed to ensure the resulting dataset is no longer reasonably linkable to you, and we assess re-identification risk before we use it. We publicly commit to maintain and use this data only in de-identified form; we do not attempt to re-identify it or re-associate it with any individual; and we contractually require any processor that handles it to do the same. It is not sold, not used for advertising, and not shared with third parties except our infrastructure processors.
This retention is part of using Prana and is not optional, because once the data is de-identified it is no longer information about you: there is no identifier linking it to you, we hold no mapping that could restore one, and we cannot tell which records were yours. For the same reason it cannot be located or removed individually afterwards, and it can never be restored to a new account.
We want to be straightforward about the limits. No de-identification technique is perfect for a detailed health history, because unusual measurements and patterns of dates can in principle make a record stand out. That is why we treat the measures above — and our commitment never to attempt re-identification — as continuing obligations rather than a one-time step. If you have concerns about this before you sign up, contact us at aditya@prana.health.
Residents of Washington, Nevada, the EEA/UK, and other jurisdictions with statutory deletion rights: we honor those requests in full over all data that identifies you or is reasonably linkable to you, as described in Section 8 and our Consumer Health Data Privacy Policy.
Deleting your Prana account does not delete data held by independent laboratories or practitioners who performed testing for you, or data you previously exported to a third-party application through the MCP connector — contact those providers directly. It also does not remove data Prana wrote to your device's Apple Health or Health Connect record, which you control in your device settings. Approved contributions to the shared food database also remain, with your link to them removed, as described in Section 1.6.
We may retain aggregated statistics that can no longer reasonably be linked to you.
8. Your rights
8.1 All users
Regardless of where you live, you can: access and update much of your data in the app; export your data by request; delete your account in the app; and contact us with any privacy question at aditya@prana.health. We will not discriminate against you for exercising privacy rights. Deletion does not reach the de-identified research copy described in Section 7, which is not information about you.
8.2 United States
Depending on your state (including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others), you may have rights to access, correct, delete, and port your personal information, and to opt out of sale, sharing, targeted advertising, and certain profiling. Prana does not sell or share personal information for cross-context behavioral advertising and does not use it for targeted advertising, so there is nothing to opt out of — but access, correction, deletion, and portability requests are honored for all US users. We treat browser Global Privacy Control signals as an opt-out preference where applicable. California residents: we collect the categories described in Section 1 for the purposes in Section 2, disclose them to the service providers in Section 4, and do not sell or share personal information as defined by the CCPA; sensitive personal information (including health data) is used only for the purposes permitted by CCPA §7027(m). You may appeal a refusal of a rights request by replying to our decision; we will respond to requests within 45 days (extendable once by 45 days where permitted).
Washington and Nevada residents: your consumer health data rights are described in our separate Consumer Health Data Privacy Policy.
8.3 European Economic Area, United Kingdom, and Switzerland
Prana Force, Inc. is the data controller. Where GDPR or UK GDPR applies:
- Legal bases. We process account, billing, and service data as necessary to perform our contract with you (Art. 6(1)(b)); usage analytics and service improvement under our legitimate interests (Art. 6(1)(f)); and health data on the basis of your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)), which we collect when you enable health features. You may withdraw consent at any time in the app or by contacting us; withdrawal stops future processing but health features will stop working.
- Your rights: access, rectification, erasure, restriction, portability, objection (including to legitimate-interest processing and research), and withdrawal of consent — exercisable by emailing aditya@prana.health. You may also lodge a complaint with your supervisory authority.
- Research data. Your erasure, objection, and restriction rights apply in full to all data that identifies you or is reasonably linkable to you. They do not extend to the de-identified research copy described in Section 7: anonymous information falls outside the GDPR's scope under Recital 26, we hold no mapping that could restore the link, and we have no means of locating the records that were yours.
8.4 International data transfers
Prana operates from the United States, and your account and health record are stored in the United States. Some processing happens elsewhere: our AI provider (AWS) may route an individual request to another of its regions, which can be outside the US, and other providers we use may process data in the regions where they operate. Our major processors participate in the EU-US Data Privacy Framework and/or offer Standard Contractual Clauses, and we rely on those safeguards for these transfers. By using the Service from outside the US, you understand that your data will be processed in the US and potentially other countries, where privacy laws may differ from those in your country.
9. Security
Your data is transmitted over encrypted connections. Access to your health record requires an authenticated session, and our services check on every request that you are the owner of the data being read or written. Credentials on your device are held in the platform's secure storage (iOS Keychain, Android encrypted storage), and data stored with our infrastructure providers is encrypted at rest by those providers.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify you and regulators as required by law, including, where applicable, the FTC Health Breach Notification Rule.
10. Children
The Service is for adults. You must be at least 18 to use Prana. We do not knowingly collect data from anyone under 18; if we learn we have, we will delete it.
11. Changes to this policy
We will post changes here and update the date above. For material changes — especially changes affecting health data — we will notify you in the app or by email before they take effect.
12. Contact
Prana Force, Inc. 2261 Market St. STE 10271, San Francisco, CA 94114 aditya@prana.health
We respond to privacy requests within 45 days or sooner where law requires.
Questions about this document? Email aditya@prana.health.