Privacy Policy

How getbased handles your data.

Effective 22 August 2026

In one sentence: getbased is a local-first application. Your core health data lives in your browser on your own devices by default. There is no account and no central plaintext health database. Data leaves your device only when you use a network feature — cloud AI or voice, wearables, sync, encrypted profile sharing, support/security contact, or hosted-site/app telemetry described below.

1. Who runs getbased

The hosted getbased website and application are operated by getbased s.r.o., identification number (IČO) 298 97 777, with registered office at Drahanovice 315, 783 44 Drahanovice, Czech Republic, registered in the Commercial Register maintained by the Regional Court in Ostrava, file C 104867. The source code remains available under the GNU Affero General Public License v3 (AGPL-3.0).

For the purposes of the EU General Data Protection Regulation (GDPR), getbased s.r.o. is the Data Controller for processing it determines on the hosted website and application. A cloud AI, voice, wearable, relay, or custom provider you choose may be a separate controller or processor under its own terms. When you self-host getbased, you determine the controller and processors for that deployment.

2. What we don't collect

Before listing what might transit, here's what we never do:

3. What stays on your device

Virtually everything you put into getbased is stored locally in your browser:

Health, genetic, biometric, voice, and wearable data may qualify as special-category or otherwise sensitive personal data. getbased's default design keeps core data on your device; external processing happens only when you intentionally use a feature that sends data to a third-party provider, sync relay, encrypted sharing endpoint, or support/security contact. Cloud AI and voice require the separate express approval described below.

None of these are sent to getbased's website by default. If you clear your browser storage, uninstall the app, or use the "Clear all data" action in Settings → Data, the data is gone from your device.

4. Third-party services you choose

getbased calls third-party services only when you configure or use the relevant feature. Each has its own privacy policy that governs data handling on its side. Where a provider acts as an infrastructure processor, getbased relies on that provider's data-processing terms and security measures; where you choose an external AI, wearable, relay, or custom endpoint, that provider may act as an independent controller or processor under its own terms.

4.1 AI providers (all optional)

If you use cloud AI, your prompt, attachments you choose to send, and the enabled profile context are sent to the provider you selected. Context may include health, genetic, biometric, wearable, lifestyle, medication, or other sensitive data. The free hosted app uses credentials or funding you obtain directly from the provider; getbased does not supply a managed AI key or resell the inference.

Cloud voice is also optional. Depending on the provider and feature you select, recorded audio may be sent for transcription and text may be sent to generate speech. Supported routes include the selected AI provider where compatible and separate xAI (see its API terms and Data Processing Addendum) or ElevenLabs connections. Audio and voice data may itself be personal or biometric data depending on its content and how the provider uses it.

Ordinary requests to the listed cloud AI and voice providers are sent directly from your browser to the selected provider, not through getbased's hosted compatibility service. OpenRouter may route a request to the model provider you selected; Routstr may route it to the selected node. Review the provider's retention, training, privacy, and data-policy controls before sending sensitive information.

Before the first data-bearing request to each cloud provider, getbased displays a separate, unchecked approval that names the recipient and transmission route. The approval covers cloud AI and voice requests you later initiate with that provider. Refusing sends nothing and leaves local features available. The app stores the provider, recipient, route, consent-version, and timestamp locally in your browser. You can withdraw all future cloud AI approval in one action under Settings → Privacy. Withdrawal does not affect processing already completed by a provider or delete data from the provider; use the provider's own controls for that.

Before text-based AI analysis, getbased can replace likely identifiers found by deterministic patterns and, optionally, a local model. Automated obfuscation can miss identifiers and cannot scrub image or audio content, so review what will be sent. Obfuscation is a risk-reduction aid, not anonymisation or a guarantee.

4.2 Direct requests and hosted services

AI, voice, and Custom API requests on the official hosted app run directly from your browser to the provider you selected. The Company-operated /api/proxy does not offer a generic authenticated or body-bearing forwarding service for those requests. A Custom API or other AI/voice provider that does not permit browser-based inference is unavailable on the official hosted app; you may instead use a compatible provider or a self-hosted deployment whose infrastructure you control.

The official app does provide a narrowly scoped compatibility path at integrations.getbased.health for features that cannot operate browser-direct. This service runs on Company-operated Czech VPS infrastructure. Its server-side policy fixes the permitted provider host, path, method, headers, and request shape. It covers Oura, Withings, Polar, and existing legacy Fitbit OAuth/API calls; the exact NVIDIA NRAS GPU-attestation endpoint used to verify Venice E2EE; a fixed privacy-rounded CAMS lookup; and an explicitly marked public product-page read that cannot contain authorization headers or a request body. Requests outside those shapes are rejected before an upstream connection is made.

Hosting a website cannot eliminate all hosting metadata. Vercel serves the public website and app assets and may process IP address, timestamp, requested path, TLS/connection, routing, status, security, and abuse-prevention metadata under its configured terms and retention. Current official-app compatibility payloads and new encrypted profile-share ciphertext use the separate Company-operated VPS services described above rather than Vercel storage or execution.

Browser-direct provider traffic uses HTTPS/TLS in transit, but it is not end-to-end encrypted against the selected provider: that provider must decrypt the request to perform the service. getbased is not in that route. When a feature is described as end-to-end encrypted below, the getbased-operated relay or storage service receives ciphertext and does not hold the decryption key.

4.3 Cross-device sync (optional)

Opt-in sync uses Evolu, a CRDT protocol with end-to-end encryption. Your BIP-39 mnemonic derives the encryption key; a relay server relays ciphertext between your devices but cannot read the contents. You can choose the relay (getbased's default, or one you host).

4.4 Wearable integrations (optional)

When you connect a wearable (e.g. Oura), getbased:

Disconnecting a wearable wipes its local rows immediately. The vendor retains the data they already have on their side per their own policy; getbased cannot delete it there. To revoke getbased's access, disconnect inside the app and revoke the app on the vendor's site.

4.4.1 Google Health

Google Health is a separate, explicit opt-in, self-host-only connection. It is intended for Fitbit and Pixel Watch data and can also act as an optional hub for other sources linked to your Google account. The official getbased-hosted app does not operate the confidential OAuth relay it requires. It does not silently replace or route independent integrations.

Immediately before starting Google's OAuth consent flow, getbased shows an in-product disclosure and asks you to continue. If you continue, getbased requests only these three read-only Google Health permission categories:

getbased does not request Google Health write access, profile, location/GPS, ECG, irregular-rhythm, nutrition, or settings permissions. You can grant only a subset of the requested read permissions; metrics from a category you decline will be omitted.

Google Health data is handled as follows:

Disconnecting Google Health deletes that browser's credential record, imported rows, and Google-derived source data. To stop access across every browser, also revoke getbased in your Google Account. Revoking or disconnecting getbased does not delete source data held by Google or a connected device vendor; their policies apply to their copy. See the Google Privacy Policy.

Google Health Limited Use: getbased's use of information received from the Google Health API adheres to the Google Health API Developer and User Data Policy, including its Limited Use requirements.

4.5 Encrypted profile sharing (optional)

If you create a password-protected profile share link, your browser exports the selected profile and encrypts it before upload using AES-GCM with a password-derived key. The isolated shares.getbased.health service on the Company's Czech VPS stores only the encrypted ciphertext envelope and the limited expiry, deletion, size, and abuse-prevention metadata needed to operate the link. The password is not sent to getbased, and the Company cannot decrypt the shared profile.

Share links expire automatically, with a maximum lifetime of 30 days. You can also stop sharing from the device that created the link. Temporary share copies are not backed up and can be lost after a service failure. Anyone with both the link and the password can decrypt and import the shared profile, so keep them separate.

4.6 Knowledge Base (Interpretive Lens)

Documents you add to the on-device Knowledge Base are indexed and embedded locally in your browser using the Origin Private File System (OPFS). Nothing is uploaded. If you use the external-server lens option, the server you point at is under your control and its privacy model is yours.

4.7 Fonts, analytics, and CDNs

The public website serves Inter, Outfit, and JetBrains Mono locally and does not contact Google Fonts. The public landing page may load the Umami tracker described above from umami-iota-olive.vercel.app; Terms, Privacy, blog, and other public pages do not load that tracker. The app bundles its core fonts locally, while some optional libraries or models such as transformers.js may load from jsdelivr.net only when you invoke the relevant feature and are then cached by your browser.

Checking this browser's website analytics preference…

4.8 Voluntary donations and external links

The public website contains user-activated links to third-party sites. When you follow one, the destination receives ordinary request metadata under its own policy. If you choose a HydraNode/BTCPay or Ko-fi donation option, that provider and any payment processor it uses handle the payment. The Company may receive the amount, transaction identifier and status, and any name, contact detail, or message you choose to provide. The getbased site and app do not collect full payment-card credentials or cryptocurrency private keys.

5. Legal basis for processing

6. Recipients and processors

Depending on what you use, the following providers may receive limited data:

6.1 Retention

6.2 Automated processing

getbased uses deterministic calculations and optional AI to produce educational summaries and suggestions. The Company does not use them to make decisions about you that produce legal or similarly significant effects. You decide whether and how to act on any output.

7. Your rights

Under GDPR and most privacy frameworks, you have the rights to access, correct, delete, export, restrict processing, object, withdraw consent, and complain to a supervisory authority. Because getbased stores most data on your own device, you can exercise many of these rights directly, without contacting us:

For personal data the Company controls (for example, if you email a support request, submit a vulnerability report, or contact through GitHub), you can write to privacy@getbased.health.

8. Children

getbased is not designed for children under 15. This matches the minimum age for consent to information-society services under Czech law (the governing law of the Terms). If you live in an EU Member State with a higher minimum age (16 in several countries under GDPR Article 8), that higher age applies to you. Please do not enter a child's medical data without appropriate guardianship and consent.

9. Security

Measures we apply:

No system is unbreakable. If you discover a vulnerability, please report it via a private GitHub security advisory at github.com/elkimek/get-based/security.

10. International data transfers

If you use the hosted getbased website or app, Vercel may process website/app access and security metadata in regions outside your country. The compatibility, CAMS, and encrypted profile-share services described above run on Czech VPS infrastructure; their destination wearable vendors and other upstream services may still process data elsewhere. Google Health on a self-hosted deployment, jsDelivr, Umami infrastructure, AI/model-routing/voice providers, wearable vendors, Evolu relays, Copernicus CAMS, Open-Meteo, custom endpoints, and optional donation providers may also process request metadata or user-selected payloads outside the EU/EEA depending on their infrastructure and policies.

Do not enable a provider, relay, custom endpoint, or share link unless you are comfortable with that provider's jurisdiction, transfer safeguards, and privacy terms. Self-hosting lets you replace getbased's hosted infrastructure with your own.

11. Changes to this policy

If we update this policy, we'll change the Effective date above and mention it in the app's changelog. Material changes, or changes to the app's built-in privacy version, will also be shown on the app's first launch after the update and the app will ask you to accept the current Terms and Privacy Policy before continuing.

12. Contact

getbased s.r.o.
Drahanovice 315
783 44 Drahanovice
Czech Republic
IČO: 298 97 777
Commercial Register: Regional Court in Ostrava, file C 104867

Privacy questions and data-subject requests: privacy@getbased.health

Source code, issues, general discussion: github.com/elkimek/get-based