H Health MCP
Privacy Terms

Legal · Effective 24 August 2026

Privacy Policy

Health MCP is a private, personal-use application. This policy explains the limited information it processes and the controls available to its user.

In brief

  • Read-only Google Health access
  • No advertising or sale of data
  • No public user profiles
  • Access can be revoked at any time

1. Scope

This Privacy Policy applies to Health MCP and its use of information obtained through Google OAuth and the Google Health API. The application is operated for private personal use and is not offered as a public health service.

2. Information processed

Health MCP may process the following information after explicit authorization:

  • OAuth credentials required to maintain the authorized connection;
  • sleep records;
  • activity, exercise, movement and fitness records;
  • health metrics and measurements available within the authorized scopes; and
  • derived summaries and technical synchronization logs.

Health MCP requests read-only permissions and does not modify Google Health data.

3. Purpose and legal basis

Information is processed solely to synchronize, organize and privately analyze the authorized user's personal health record. Processing relies on the user's explicit OAuth consent and can be stopped by revoking that consent.

4. Storage and security

Data and authorization credentials are transmitted over encrypted connections and stored in access-controlled infrastructure used to operate Health MCP. Access is limited to the private application operator. Reasonable technical safeguards are used to prevent unauthorized access, alteration or disclosure.

5. Sharing and transfers

Health data is not sold, rented, used for advertising or shared for independent third-party purposes. Infrastructure providers may process limited data only as necessary to host and secure the application. Google user data is handled in accordance with the Google API Services User Data Policy, including its Limited Use requirements.

6. Retention and deletion

Information is retained only while needed for the private record and operation of the application. The authorized user may revoke access from the Google Account permissions page at any time. Revocation prevents future collection but does not automatically erase previously synchronized records.

To request deletion of stored records, use the support contact displayed on the Google OAuth consent screen. A deletion request will be completed within 30 days, except where limited retention is required for security or legal compliance.

7. Cookies and tracking

This informational website does not use analytics, advertising trackers, user accounts or non-essential cookies.

8. Changes and contact

This policy may be updated to reflect changes to Health MCP. The effective date at the top of this page will be revised when material changes are made. Privacy and data deletion questions can be sent to the support contact shown on the Google OAuth consent screen.

← Health MCP Last updated 24 August 2026
Terms of Service