Privacy Policy
How Northstar collects, uses, and protects your personal and health information, and your rights to export or delete everything.
Last updated July 1, 2026
Overview
This Privacy Policy explains how Northstar Health Inc. ("Northstar", "we", "us") handles personal information and health data that you share with us when you use Northstar. We have written it to be readable, not just legally complete.
Northstar is a consumer health product, not a healthcare provider and not a covered entity under HIPAA. The labs, vitals, and notes you add are your personal health information, and we treat that data with care. We do not sell it. We do not use it to profile you for advertising. We hold it only to provide the service.
What we collect
We collect only what we need to make Northstar useful to you:
- Account information: your name, email address, and a secure hash of your password.
- Health data: lab results, vitals, sleep data, and notes you enter or upload, including the values, dates, and any context you add.
- Usage data: basic information about how you use the app, such as which features you use, to help us improve the product. This is not linked to your health data.
- Communications: messages you send us through support forms or email.
We do not collect or store your payment card details. Card information is handled directly by our payment processor, Stripe.
How we use your information
We use the information you provide to:
- Operate your account and keep it secure.
- Generate plain-language explanations, trend summaries, and visit summaries from the data you have entered.
- Send you notifications you have chosen to enable.
- Respond to support requests and questions.
- Improve Northstar's features and reliability, using aggregate and anonymised patterns, never your identifiable health data.
We do not use your health data to train AI models. When Northstar uses an AI model to generate an explanation or summary, your data is sent to the provider under a data processing agreement that prohibits use for model training.
AI model processing
Northstar uses large language models to turn your lab values and vitals into plain-language explanations and visit summaries. When it does, a portion of the data you have entered may be sent to an AI model provider to generate the output.
We apply a minimum-necessary principle: we send only the context needed for the specific task, not your full history. The provider processes this data under an agreement that:
- Prohibits use of your data to train or improve any public AI model.
- Requires confidentiality and security protections equivalent to our own.
- Limits use to fulfilling your specific request.
We keep a current list of AI model providers that may process your data and will notify you of material changes.
Security
We protect your data with encryption in transit (TLS) and at rest (AES-256), strict access controls, and isolated data storage. No system is perfectly secure, but security is a first-class part of how we build Northstar.
To report a security concern, write to security@northstars.health.
Data retention
We keep your account information and health data for as long as your account is active. When you delete your account, we remove your health data from our systems within 30 days. Some records, such as billing history, may be retained longer where the law requires it.
Your rights
You have the following rights regarding your personal information:
- Access: you can download a complete copy of your data from Settings at any time.
- Correction: you can update your account information and any entry directly in the app.
- Deletion: you can permanently delete your account and all your health data from Settings.
- Objection: you can contact us to object to any processing we have described in this policy.
To exercise any right or to ask a question about this policy, write to us at privacy@northstars.health.
Subprocessors
We work with a small number of subprocessors to provide the service:
- Hosting provider: the infrastructure that runs Northstar and stores your data.
- Database provider: Neon (Postgres-compatible serverless database), for storing your account and health data.
- AI model provider: OpenAI or a compatible provider, for generating plain-language explanations and visit summaries. Data is processed under a data processing agreement that prohibits training use.
- Payment processor: Stripe, for billing. Stripe never sees your health data.
We update this list when our subprocessors change and will notify you of material changes.
Children
Northstar is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us and we will delete it promptly.
Changes to this policy
We will update this policy when our practices change in a meaningful way. We will notify you by email and by posting the updated policy with a new effective date. Continued use of Northstar after the update means you accept the revised policy.
Contact us
For questions about privacy, write to privacy@northstars.health. For security matters, write to security@northstars.health. For anything else, write to hello@northstars.health.
Northstar Health Inc., 98 San Jacinto Boulevard, Suite 400, Austin, TX 78701, United States.