Jasmar Health Privacy Policy
Effective date: September 23, 2026.
Jasmar Health is an independently operated personal health-data integration for its authorized account holder. The operator can be contacted at wyqqrince@gmail.com. This policy covers the Jasmar Health integration and this public website.
1. Information accessed
With Google authorization, the integration requests read-only access to Google Health profile and settings, activity and fitness, health metrics and measurements, sleep, and nutrition. Available records may include steps, workouts and their dates, distance, calories, heart rate, sleep, weight, oxygen saturation, and related wellness measurements. Availability depends on the account, connected devices, granted permissions, and Google Health.
The integration also handles OAuth access and refresh tokens so it can retrieve authorized data without requiring a new sign-in for every request. Google credentials are entered on Google's authorization pages, not on this public website.
2. How information is used
Health records are used to provide user-requested or scheduled personal summaries, activity and sleep reviews, and routine-planning assistance. The current Google Health authorization is read-only; it does not authorize changes to the user's Google Health records.
Assistant conversations may also contain information the account holder supplies, such as health goals, routines, and subjective wellbeing. Assistant summaries are informational, not medical diagnosis or treatment.
3. Services involved and data disclosure
- Google Health / Fitbit: supplies the records the account holder authorizes the integration to read.
- Cloudflare Workers and KV: run the health connector, store authorization tokens, and cache health responses.
- The operator's NanoClaw assistant and configured AI services: receive relevant health data to generate summaries and responses. Requests may pass through a configured credential gateway or model-routing service before reaching the selected AI model provider. AI processing is not necessarily local to this VM.
- WeChat, when enabled: receives the health summaries sent to the account holder's configured conversation. Other explicitly configured assistant clients may also receive requested health information.
- Website and infrastructure providers: process connection information needed to deliver and secure the service, such as IP addresses and request metadata.
External services process information under their applicable terms, privacy policies, and account settings. Processing or storage may occur outside the account holder's country. This website does not publish the account holder's health records.
4. Storage and retention
- OAuth tokens are stored in the connector's Cloudflare KV namespace. They remain stored until replaced or removed; expiration or revocation can make a stored token unusable without erasing it.
- Health-read responses are normally cached with a one-hour expiration. This cache duration does not apply to assistant history or delivered messages.
- Assistant conversations, saved memories, task records, and generated summaries can persist on the operator's systems until deleted. There is currently no uniform automatic deletion period for these records.
- Diagnostic logs may include request metadata and limited response or error excerpts. Copies in logs or backups can have a different retention period from the live response cache.
- AI service records and messages delivered to WeChat or another configured client are subject to that service's retention and deletion controls.
5. Revocation and deletion requests
You can revoke future Google access through Google Account connections by removing this application's access. Revocation does not automatically delete tokens, cached data, assistant history, or previously delivered messages.
To request disconnection, deletion of app-held information, or clarification of the services used for your data, contact wyqqrince@gmail.com. The operator will review the request, verify the requester's authority where needed, and identify the records and systems involved. Do not email passwords, access tokens, or unnecessary health details.
Deleting records from the integration does not delete the original Google Health / Fitbit records. Copies held by messaging or AI services may require separate deletion using those services' controls; the operator cannot promise immediate removal of copies outside their control.
6. Security and this website
The public website uses HTTPS. The connector uses authenticated access controls, and service credentials are kept in server-side storage rather than public pages. No security measure can guarantee absolute protection.
These static public pages do not include analytics scripts, advertising trackers, sign-in forms, or health-data collection forms, and do not themselves set cookies. Infrastructure providers may still process technical connection information.
7. Policy updates and contact
Updates will be published on this page with a revised effective date. For privacy questions, data requests, or support, contact wyqqrince@gmail.com.