Future Health AI Privacy Policy

Effective Date: April 20, 2026 · Last Updated: April 20, 2026

Version 2.0 — Health-Specific

Your health data stays on your phone. Future Health AI is built with a zero-cloud-PHI architecture. All health records, medications, and AI conversations are stored and processed entirely on your device. We do not upload, sell, share, or train AI on your health data. Not now. Not ever.

Contents

  1. Overview & Scope
  2. Core Privacy Principles
  3. Information We Collect
  4. Protected Health Information (PHI)
  5. On-Device AI Processing
  6. How Your Data Is Stored
  7. Data Security
  8. Data Sharing & Disclosure
  9. Your Rights
  10. California Rights (CCPA/CPRA)
  11. Other State Rights (CO, VA, CT, UT, TX, OR)
  12. HIPAA Notice
  13. Children's Privacy (COPPA)
  14. Minors 13-17 (CA SB 976, State Laws)
  15. Family Linking & Caregiver Access
  16. Emergency Features
  17. Consent Framework
  18. Audit Logging
  19. Data Retention & Deletion
  20. Third-Party Services
  21. International Users
  22. Changes to This Policy
  23. Contact Information

1. Overview & Scope

This Privacy Policy applies exclusively to Future Health AI ("the App"), a mobile application for Android developed and operated by Future @I LLC ("we", "us", "our"), a California limited liability company. This policy supplements, and where more specific, supersedes our general Privacy Policy for Future @I applications.

Future Health AI is a personal health information coordinator. It helps you organize, track, and manage your personal health records. It is not a medical device, not a licensed healthcare provider, and does not provide medical advice, diagnosis, or treatment.

By installing, accessing, or using the App, you acknowledge that you have read, understood, and agree to this Privacy Policy.

2. Core Privacy Principles

Future Health AI is designed around four non-negotiable privacy principles:

3. Information We Collect

3.1 Information Stored Only on Your Device

The following categories are stored exclusively on your device and never transmitted to us:

3.2 Information We Collect on Our Servers

The following minimal data is transmitted to our backend ("FM") to enable account recovery and abuse prevention:

3.3 Information We Do NOT Collect

4. Protected Health Information (PHI)

"Protected Health Information" includes any information in the App that identifies you and relates to your past, present, or future physical or mental health, the provision of healthcare, or payment for healthcare.

PHI Never Leaves Your Device. All PHI in Future Health AI is stored on your device under AES-256-GCM encryption with keys protected by the Android Keystore (hardware-backed where available). PHI is never transmitted to our servers, never shared with third parties, and never used to train AI models.

5. On-Device AI Processing

Future Health AI uses "Aria," an on-device AI assistant, to help you organize and understand your health information.

6. How Your Data Is Stored

6.1 On-Device Storage

6.2 Server Storage (FM Backend)

7. Data Security

We implement layered security controls aligned with HIPAA Security Rule, NIST SP 800-53, and industry best practices:

No security system is perfect. If we become aware of a breach that compromises your personal information, we will notify you within 60 days (or sooner if required by applicable law) via email and in-app notice.

8. Data Sharing & Disclosure

We do not sell your personal information. We do not share your data with advertisers, data brokers, marketing firms, or any third parties for their own purposes.

We may disclose limited information in the following narrow circumstances:

9. Your Rights

You have the following rights regarding your information, regardless of where you live:

10. California Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you additional rights:

To exercise these rights, use the in-app Settings menu or email privacy@futureati.app with the subject line "CCPA Request." We will verify your identity and respond within 45 days (extensions may apply for complex requests up to 90 days total, per statute).

We will not retaliate or discriminate against you for exercising your CCPA rights. If your request is denied, you have the right to appeal by emailing privacy@futureati.app with "CCPA Appeal" in the subject.

Categories of Personal Information Collected (CCPA Disclosure)

In the preceding 12 months we have collected the following categories of personal information:

We have not sold or shared any category of personal information in the preceding 12 months.

11. Other State Rights (CO, VA, CT, UT, TX, OR, and Others)

Residents of Colorado (CPA), Virginia (VCDPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA, effective July 2024), Oregon (OCPA, effective July 2024), Montana, Iowa, Tennessee, Indiana, Delaware, New Jersey, New Hampshire, and Kentucky have rights similar to those described above, including access, correction, deletion, data portability, and the right to opt out of targeted advertising and sale of personal information.

We provide all these rights to all users nationwide regardless of state of residence. To exercise them, email privacy@futureati.app.

Washington My Health My Data Act: As of March 2024, Washington residents have specific rights regarding consumer health data. Our on-device architecture means we do not collect or process "consumer health data" as defined by the Act. However, if you believe this Act applies, you may exercise your rights by emailing the address above with "MHMDA Request" in the subject line.

12. HIPAA Notice

Important HIPAA Clarification. Future @I LLC is NOT a "Covered Entity" under HIPAA. We are also not a "Business Associate" in the default consumer configuration. This means HIPAA does not directly govern our consumer services. However, we voluntarily follow HIPAA's Security Rule technical safeguards as a privacy best practice.

If you are a healthcare provider, clinic, or other HIPAA Covered Entity considering using Future Health AI with patients, please contact legal@futureati.app to discuss Business Associate Agreement ("BAA") availability for enterprise deployments. We expect BAA-eligible enterprise plans to be available in a future release.

If you share information about your care with a Covered Entity (e.g., by emailing a Future Health AI-generated export to your doctor), that entity's HIPAA obligations govern the use of that information on their end.

13. Children's Privacy (COPPA)

Future Health AI is not directed to, and we do not knowingly collect information from, children under 13 as independent account holders.

The App supports a parent/guardian-managed family account model for children under 13, in compliance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6505 and 16 CFR Part 312. Under this model:

If you believe we have collected information from a child under 13 without proper consent, contact us immediately at privacy@futureati.app. We will delete the information and the associated account within 30 days.

14. Minors 13-17 (Teen Privacy)

Users aged 13–17 may create accounts, with the following privacy protections tightened in 2024–2026 state laws (including California SB 976):

15. Family Linking & Caregiver Access

The App supports linking family members for care coordination, with strict age-based and consent-based access controls:

All family-link permissions are cryptographically consent-recorded and reversible at any time. Revoking a family link immediately removes the caregiver's access and is logged in your immutable audit trail.

16. Emergency Features

The App's emergency system NEVER activates automatically. Every emergency action requires explicit user confirmation:

Emergency packets are encrypted, expire after 24 hours, and are revocable. Location data collected during an emergency is never transmitted to Future @I LLC servers — it is transmitted only to the contacts you explicitly designate and, if you activate it, to 911 services via Android's standard emergency APIs.

Every consent event (granting, modifying, or revoking data sharing with family, caregivers, providers, or first responders) is recorded in an immutable SHA-256 hash-chained ledger on your device. This provides cryptographic proof of what you consented to and when.

18. Audit Logging

Every data access event is logged in an INSERT-only audit trail. Database triggers prevent UPDATE or DELETE operations on audit logs. You can view and export your audit history at any time through Settings → Privacy → Audit Log.

19. Data Retention & Deletion

Your data is yours. You control retention:

20. Third-Party Services

We minimize third-party dependencies. The complete list of third-party services in Future Health AI:

We do NOT use: Firebase Analytics, Google Analytics, Meta/Facebook SDK, TikTok SDK, Crashlytics (we use our own FM crash infrastructure), AppsFlyer, Adjust, Branch, Sentry, or any other tracking, attribution, or analytics SDK commonly found in consumer apps.

21. International Users

Future Health AI is currently available only in the United States. If you access the App from outside the U.S., you do so at your own initiative and are responsible for compliance with local laws.

We do not currently offer GDPR-compliant data processing agreements for EU/UK users. International expansion is planned, and this policy will be updated with GDPR-specific provisions at that time.

22. Changes to This Policy

We may update this Privacy Policy periodically to reflect new features, legal requirements, or privacy improvements. Material changes will be communicated through:

We will never reduce your rights without your explicit consent. If a change materially reduces your privacy protections, we will obtain fresh opt-in consent before applying the change to your account.

23. Contact Information

Future @I LLC
Porterville, California, USA
D-U-N-S: 144266395

Privacy inquiries: privacy@futureati.app
General support: support@futureati.app
HIPAA / BAA inquiries: legal@futureati.app
Data deletion requests: Use in-app Settings → Account → Delete Account, or email the privacy address above

Response SLA: 48 hours for general support; 45 days (extendable to 90) for formal CCPA/state rights requests, per statute.