Privacy Policy
Rapha HealthLast updated 27 September 2026.
Who we are
Rapha Health ("Rapha", "we") is an app that reads your lab reports (for example GI-MAP, DUTCH, OAT and blood panels), tracks your symptoms, wearable data and protocol, and explains your results with cited sources. Operator: Alexander Gouyet, sole proprietor, Austin, Texas, USA. Privacy contact: alexandergouyet@gmail.com.
Rapha is a direct-to-consumer app during its pilot. It is not your doctor, and it is not a HIPAA covered entity when you use it on your own. Your health data is still protected: we follow the FTC Health Breach Notification Rule and applicable state consumer health privacy laws. Rapha is for adults (18+).
What we collect
| Category | What it includes |
|---|---|
| Account | Your name and email from Google sign-in. A few app-review accounts sign in with an email and password instead. |
| Consent records | Which version of our consent you accepted and when, and each time you allowed an AI app to connect. |
| Lab reports | Files you upload or forward to your Rapha email address, attachments you choose to import from Gmail, and the results we read from them after you confirm them. |
| Gmail (optional) | Only if you connect it: an encrypted token that lets Rapha search your Gmail read-only, and the address of the connected account. See Gmail access. |
| Intake and profile | Your goals, health history, diet, allergies, supplements you list, time zone and reminder settings. |
| Symptoms and notes | Check-in ratings, custom symptoms you track, and notes you write (in the app, in Telegram, or through an AI app you connected). |
| Protocol | The protocol a practitioner you invited writes for you, and which items you marked as taken, skipped or snoozed. |
| Wearables | Daily summaries from WHOOP, Oura, Garmin or Apple Health (sleep, recovery, heart rate variability, activity), and from Garmin each workout's type, time, distance, pace, heart rate and power (never its GPS track), only after you connect them. |
| Chats with Rapha | Your questions in Rapha's chat and its answers. |
| Talk to Rapha (voice) | A text transcript of each voice call, saved in your chats (into the chat you had open, or a new "Voice call" chat). Audio is never stored. During a call, Rapha can read your earlier chats to pick up where you left off. The onboarding tour before sign-in keeps no words. |
| Connected AI apps | Which AI app you connected, the permissions you chose, and when it was last used. We log which tool it called and when, never what it read or wrote. |
| Reminders | Your device's push-notification token, and your mobile number with a record of your consent and of each check-in text and call, if you add one. Older accounts may still have a Telegram chat link; Telegram is no longer used for reminders. |
| Technical and security | Request and error logs with health fields removed, sign-in and security events, and an audit log of changes to protocols and connections (who did what and when, without health content). |
We do not use advertising pixels, ad networks or third-party analytics on the app.
Why we use it
- To run the service for you: show your results, trends and insights, answer your questions about them with sources, and keep your check-in and protocol log.
- Practitioner review: if you accept a practitioner's invite, that practitioner sees your data to review your protocol and insights.
- Reminders: send the check-in reminders you asked for, by push notification, and, if you added your number, by text and an AI phone call.
- Connected AI apps: answer the requests of an AI app you connected, within the permissions you chose.
- Improving answers: only if you turn it on in Settings → Chat review, our team may read your chats to improve Rapha's answers. It is off unless you choose it.
- Security and operations: keep accounts secure, prevent abuse, fix errors, and keep the records the law requires.
We do not sell your data. We do not use it for advertising. We do not use it, or let our providers use it, to train AI models.
Connecting your own AI (Claude, ChatGPT, Grok, Muse)
You can connect an AI app you already use to Rapha. When you do:
- You choose on Rapha's consent screen what it may do: Read (your protocol items without doses, flagged results, trends, insights and profile summary) and/or Log (symptom ratings, notes and protocol check-offs).
- What your AI reads from Rapha is sent to the company that runs that AI (Anthropic for Claude, OpenAI for ChatGPT, xAI for Grok, Meta for Muse) and is handled under that company's terms and privacy policy, not this one. Rapha's protections stop at the handoff.
- Rapha never sends your data to that company on its own: only the tools your AI calls, while you use it. It never sends your uploaded files, your chats with Rapha, doses, or your practitioner's notes or name.
- For individual consumers only. Accounts managed by a practitioner (practitioner accounts, and patients linked to a practice) can't connect an AI app. If you accept a practitioner's invite, any AI app you connected is disconnected at once.
- You can disconnect at any time in Settings → Connected AI agents. Access stops right away. What the AI already logged stays in Rapha; ask the AI company to delete what it keeps.
Gmail access (Find old results in your email)
This is optional. If you connect Gmail:
- Read-only. Rapha asks Google only for read-only access (the
gmail.readonlypermission). It can't send, delete, label or change any email. - Lab senders only. Rapha searches only for messages from known lab and patient-portal senders (for example Genova, Diagnostic Solutions, Mosaic/Great Plains, Precision Analytical (DUTCH), Doctor's Data, Vibrant, Quest, Labcorp, Rupa Health, Function Health, Everlywell, MyChart) that have a PDF or photo attached. It asks Google for each message's sender, subject, date and attachment names, never the message text, and any other email is ignored and never stored.
- Only what you approve. Rapha shows you the list and imports only the attachments you tick. They become lab reports in your review list, like a file you upload; nothing is saved to your results until you confirm it. The search list itself is not stored.
- Disconnect any time in Settings. Rapha revokes its access at Google and deletes its token right away. Reports you already imported stay until you delete them or your account. You can also remove access at myaccount.google.com/permissions.
- Limited Use. Rapha Health's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to find and import the lab results you choose; it is not used for advertising, not sold, not used to train AI models, and not read by people except with your permission, for security, or as the law requires. The attachments you import are read by Anthropic's API to extract your results, the same as any report you upload.
Who receives your data
Service providers process data for us, under contract, only to run Rapha:
| Provider | What for |
|---|---|
| Supabase | Database, file storage and sign-in |
| Vercel | Hosting the app |
| Anthropic | Reading lab reports, writing cited explanations and insights, and answering chat questions (API; not used for training) |
| Sign-in, and Gmail search if you connect it (read-only, lab senders only) | |
| Resend | Receiving lab reports you forward by email, if you use that |
| Apple | Check-in reminders, if you turn them on |
| Twilio, LiveKit | Check-in texts and AI phone calls, if you add your phone number (your number, the question and your reply; calls are not recorded) |
| WHOOP, Oura, Garmin, Apple Health | Your wearable data, only when you connect them (we receive, they send) |
| LiveKit, Deepgram, Inworld | Talk to Rapha, the voice guide, if you use it: LiveKit carries the audio, Deepgram turns your speech into text and Inworld speaks Rapha's answers, which can include your results. The transcript is saved in your chats; audio is never stored |
| Sentry, LangSmith | Error reports and quality monitoring, with health values removed in production |
Recipients you choose:
- The company behind an AI app you connect (Anthropic, OpenAI, xAI or Meta), as described above. They receive what your AI reads, and use it under their own terms.
- A practitioner you link to by accepting their invite. You can ask us to end the link.
Others only when required: to comply with law or a valid legal request, to protect someone's safety, or as part of a merger or sale, where this policy would continue to apply to your data.
Text messages and calls (SMS)
If you add your mobile number in Settings and confirm it, Rapha Health sends daily check-in texts and, if you haven't checked in, may place one automated AI reminder call a day, only between 8 am and 9 pm your time. We keep your number, your consent (its wording and time), and a log of the texts and calls we send, so you can see your history. Your replies are saved to your own account as check-ins.
We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except the providers that deliver the messages and calls for us (Twilio and LiveKit), who use it only for that.
Reply STOP to any text to end texts and calls, or turn them off in Settings. Reply HELP for help, or email alexandergouyet@gmail.com. See the SMS Terms and how opt-in works.
How long we keep it
- Your account and health data (reports, files, results, check-ins, notes, protocol log, wearable data, chats, profile and consents): until you delete your account.
- Forwarded email: we keep a short record of each email sent to your Rapha address (when, from whom, what happened to it) and only its PDF or image attachments, which then follow the rule above. Anything else in the email isn't kept. Resend keeps the email on its side for the period its own policy sets.
- Voice calls: the text transcript in your chats stays until you delete that chat (or your account). A separate copy used to review and improve the voice guide is deleted after 30 days.
- Wearables: disconnecting a wearable deletes the data we stored from it.
- Gmail: the access token is kept until you disconnect Gmail or delete your account; disconnecting also revokes it at Google. Search results are never stored; attachments you import follow the lab-report rule above.
- AI app connections: access tokens expire after one hour and refresh tokens after 30 days; the record of a connection (which app, when, what you allowed) is kept with your account.
- Audit and security logs (without health content) are kept after account deletion, for security and legal records: as long as the law requires.
- Backups of the database roll off on our provider's schedule: on our database provider's standard backup schedule. Request and error logs are kept for the period its own policy sets.
Your choices and controls
- See and export: Settings → Export my data downloads everything we hold about you.
- Delete: Settings → Delete my account and data removes your account, reports, files, check-ins, chats and connections. It can't be undone.
- Correct: edit your intake and profile in Settings, and review any report before it is saved.
- Consent: we ask for your consent before collecting health data, and again before any AI app can read or log anything. You can withdraw either: disconnect an AI app in Settings → Connected AI agents, or delete your account.
- Chat review: off unless you turn it on in Settings → Chat review, and you can turn it off again at any time.
- Who has seen my data: Settings → Who has seen my data lists every time someone on the Rapha team or your practitioner opened or changed your data. That record can't be edited or deleted, even by us.
- Demo data: new accounts start with a sample patient's data; switch to your own in the header or in Settings.
- Reminders and wearables: turn reminders off in Settings → Notifications, and disconnect a wearable from its card on the dashboard.
- Gmail: disconnect in Settings → Find old results in your email (on iPhone, Settings → Find results in Gmail).
- Depending on where you live (for example Washington, Nevada, Connecticut or Texas), you may have more rights over consumer health data, such as confirming what we collected and whom we shared it with. Contact alexandergouyet@gmail.com to use them. We won't treat you differently for using them.
Security and breaches
Data is encrypted in transit and at rest. Access tokens for connected AI apps are stored only as hashes, last one hour and can be revoked. If a breach of your health data happens, we will notify you and the FTC as the Health Breach Notification Rule and state law require.
Changes
If we change what we collect or whom we share it with, we will update this page and ask for your consent again in the app before the change applies to your data.
Not medical advice
Rapha explains results and shows sources; it does not diagnose or prescribe. Talk to your practitioner before changing anything. In an emergency, call 911 or your local emergency number.