Skip to content

Akros privacy policy

Your health record should show where the data goes.

Effective 31 July 2026 · Akros, Sydney, Australia

1. Scope and contact

This policy applies to the Akros iPhone app and akros.life. Akros controls the personal data described here. For access, correction, deletion, or privacy questions, use the Akros support form. Do not include a lab report or other health data in the initial request.

2. Data Akros handles

Account data

If you sign in, Akros receives an Apple account identifier and the name or relay email Apple makes available. Akros also stores the sex and goals you choose for your profile so it can show relevant progress and provide context for the plan and bodyweight direction. A guest can use limited local features without creating an Akros account; guest profile data remains on the device.

Apple Health data

With your permission, Akros reads sleep analysis, resting heart rate, heart-rate variability, sleeping wrist temperature, body mass, body-mass index, body-fat percentage, active energy, and steps. Those reads support the on-device dashboard and on-device Week Rescue evidence. If you separately agree to weekly aggregate processing, Akros sends daily counts, averages, minimums, maximums, and latest values for the current seven days and preceding 28 days. Raw HealthKit samples are not stored on Akros servers.

On-device Health mirror

To keep the bodyweight chart usable and prevent duplicate imports, Akros mirrors each readable HealthKit body-mass value and its HealthKit timestamp into its on-device bodyweight ledger. Other raw HealthKit values remain in HealthKit. Separately, Akros can save records only after you explicitly log them: completed strength workouts, bodyweight entries, and positive calories, protein, carbohydrate, and fat values from saved food entries. The iPhone app does not estimate workout calories. A workout you start and save on Apple Watch can include active energy measured by HealthKit during that session.

Lab report data

If you choose a PDF and consent, Akros handles the PDF bytes, file size, a cryptographic document fingerprint, normalized biomarkers, units, reference ranges, source document provenance, and processing status. PDFs are limited to 10 MB.

Subscription data

Akros receives product, transaction, renewal, expiration, and revocation information from Apple so paid access can be granted and restored. Akros does not receive your payment card details.

Technical data

Akros may receive app version, device and operating-system class, request timing, crash diagnostics, and security events. Diagnostic systems are configured to remove health content where practicable and are not used for advertising.

Support requests

If you contact Akros, the support service receives the reply email, topic, message, and any app version or device details you choose to provide. Initial requests must not contain lab reports or other health data. The request is used only to respond, protect the service, and meet legal obligations.

3. How Akros uses data

  • Display source-labeled health trends and use permitted evidence in the on-device Week Rescue decision flow.
  • Normalize a lab report you intentionally select.
  • Produce a bounded weekly briefing and show when the data is incomplete.
  • Use profile sex and goals to provide relevant plan, progress, and bodyweight context.
  • Verify, restore, expire, or revoke subscription access.
  • Provide export, account recovery, deletion, support, fraud prevention, and service security.

Akros does not sell personal data, serve behavioral advertising, use health data to determine credit or insurance eligibility, or make your data public. Akros does not use your data to train a public foundation model. OpenAI does not use API inputs or outputs to train its models unless its customer explicitly opts in, as described below.

4. Lab PDFs and OpenAI processing

A lab PDF is not sent off your device until Akros shows the processing disclosure and you choose to continue.

The complete selected PDF passes through Akros's API on Amazon Web Services (AWS), is held temporarily in a private encrypted Amazon S3 bucket, and is sent from an AWS Lambda function to OpenAI's Responses API to extract marker names, values, units, and reference ranges. Akros sets store: false. OpenAI states that this creates no application-state retention for the response, but its default abuse-monitoring logs may still include customer content and be retained for up to 30 days. OpenAI does not use API inputs or outputs to train its models unless the customer explicitly opts in. Akros does not claim that this account has OpenAI zero-data-retention controls.

Akros deletes the raw PDF after a successful or failed extraction when immediate cleanup succeeds. If an upload is abandoned before processing or immediate cleanup fails, an automatic storage-lifecycle rule provides a one-day expiration backstop. Akros keeps normalized values, provenance, a document fingerprint, and an audit record so you can understand the source and avoid duplicate processing. Apple Health data is not sent to the document processor as part of this flow.

Automated extraction can be wrong. Compare normalized values and units with the original report. Akros does not diagnose or recommend treatment from a lab result.

5. Service providers and international processing

Apple

Provides App Store distribution, StoreKit purchases, and Sign in with Apple. Apple sends Akros the account details you authorize and verified transaction information; Akros does not receive your payment card details.

Amazon Web Services

Provides API Gateway and Lambda processing; account, profile, subscription, consented weekly-aggregate, and normalized lab-record storage in DynamoDB; and private temporary lab-PDF storage in Amazon S3. AWS processes the request metadata and content needed to provide those services.

OpenAI

Receives the complete PDF you select for one Responses API extraction request with store: false. There is no response application-state retention, but default abuse-monitoring logs may include customer content for up to 30 days. API inputs and outputs are not used for model training unless Akros explicitly opts in.

Vercel

Hosts the akros.life website and its support form. Vercel processes website request metadata and the support-form fields you submit before the message is delivered.

Resend

Delivers support email from the website. It receives the reply email address, message, and delivery metadata needed for that function; do not put health data in an initial support request.

Sentry

Receives scrubbed website diagnostics where web error monitoring is enabled. Akros configures default personally identifying information off and removes health content where practicable.

These providers process data for the function listed above. Akros remains responsible for the instructions it gives them and for honoring this policy. Provider terms or applicable law may permit the limited security, abuse-prevention, or legal retention described here.

Akros operates from Australia and uses cloud infrastructure in Australia and other countries. Data may therefore be processed outside your country, where privacy laws and regulatory regimes may differ. The provider and legal terms that govern a transfer depend on the active service, account plan, processing location, and applicable law.

6. Retention and deletion

Raw lab PDF

Deleted after a successful or failed extraction when immediate cleanup succeeds. Abandoned uploads and cleanup failures use the automatic one-day expiration backstop.

OpenAI API request

The Responses API call uses store: false, so OpenAI does not retain response application state. Default abuse-monitoring logs may still include customer content for up to 30 days. Akros has not verified zero-data-retention controls for this account.

Weekly aggregates

Each consented weekly aggregate record is kept for up to 104 weeks. It contains daily aggregates, not raw HealthKit samples.

Normalized records

Normalized lab values, provenance, fingerprint, and audit records are scheduled to expire after up to 104 weeks and may be removed sooner through account deletion.

Profile and account

Profile and account records are kept while your account is active. Account deletion starts a 30-day recovery period; signing in during that period restores the account, and after the period Akros purges the account partition and deletion-queue record.

Security and transaction records

Some minimal records may be retained when required for fraud prevention, accounting, legal obligations, or resolving a charge or dispute.

Support requests

Kept only as long as reasonably needed to answer the request, protect the service, and meet legal obligations.

7. Your choices and rights

In Akros, open Settings, then Data processing & consent, choose a processing scope, and select Withdraw consent to block future weekly aggregate uploads or PDF uploads for that scope. Withdrawal does not delete data already stored; use Delete my account to start deletion. You can separately deny or revoke each Apple Health category in the Health app. Revoking Health access prevents future reads but does not delete an on-device bodyweight mirror or server aggregate that was already created.

You can also decline PDF processing, restore or manage a subscription through Apple, request an export in Akros Settings, correct profile details, or start account deletion. Depending on where you live, you may have rights to access, correct, erase, restrict, object, or receive a portable copy of personal data.

Use the Akros support form if the in-app controls do not resolve your request. Akros may need to verify that you control the account before disclosing or deleting data.

8. Security

Akros uses encrypted transport, private encrypted object storage, scoped cloud permissions, signed authentication tokens, verified Apple transaction data, and deletion backstops. No system can guarantee absolute security. Report a suspected security issue through the Akros support form without including health data in the first message.

9. Children

Akros is not directed to children under 13. If local law requires parental consent for a minor to use a health service, do not use Akros without that consent. Use the Akros support form if you believe a child provided personal data without appropriate permission.

10. Changes

Akros may update this policy as the product or law changes. The effective date will change when a revision is published. A material change will be described in the app or by another reasonable notice before it takes effect where required.

Akros is a personal wellness and record-keeping app. It is not a medical device, does not provide medical advice, and is not a substitute for a qualified clinician.