Back to HealthMailer
HealthMailer

Privacy Policy

Last updated: July 31, 2026

In short: HealthMailer does not have user accounts, and we do not collect, receive, view, or store your health, fitness, or activity data at any point. That data is read from Apple Health or Health Connect on your own device, compiled into a report on your own device, and emailed directly from your own email account to the clinician or researcher who sent you the request link. Our servers never see it.

1. Who we are

HealthMailer is a mobile application and companion website (together, the "Service") that lets a clinician or researcher request specific, passive health and activity data from a patient or participant, and lets that person send it directly by email, without either party needing to create an account.

The Service is provided by Clinician People Ltd ("we", "us", "our"), a company registered in England and Wales under company number 15880511, with its registered office at 82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE. This Privacy Policy explains what information the Service processes, why, and the choices and rights available to you. If you have any questions, you can reach us at info@clinicianpeople.com.

2. There is no account, login, or user profile

HealthMailer does not require you to register, sign in, or create a profile, whether you are the person requesting a report or the person sending one. We do not maintain user accounts, usernames, passwords, or persistent user profiles of any kind.

3. How a request link is created

A clinician or researcher generates a request using our website. To do this, they provide:

  • the email address the report should be sent to;
  • the categories of health or activity data being requested (for example, steps, heart rate, or sleep);
  • the time period the report should cover; and
  • a reference label of their choosing, used to identify the request (for example, a patient initials or study ID that they select — we do not require or ask for real names).

These details are sent to a signing service we operate, which uses them to create a unique, cryptographically signed link. This link — and not our servers — is what carries the request. The signing service does not store the email address, requested data categories, time period, or reference label after the link has been created; that information exists only inside the signed link itself, which is held on the requester's and recipient's own devices (for example, in a text message or email they send each other).

To protect this free service from automated abuse, our signing service temporarily keeps a record of the IP address and timestamp of link-creation requests, on a short, rolling basis, purely to detect unusual request patterns. This record is not linked to any patient, participant, health data, or the content of any request.

4. How a request link is used, and why we never see your health data

When you open a request link on your phone, the HealthMailer app verifies it entirely on your own device — checking that it hasn't expired and hasn't been tampered with. This check does not involve contacting our servers.

The app then asks your device's operating system (Apple Health on iOS, or Health Connect on Android) for permission to read only the specific categories of data named in the link, for the specific time period requested. This is a read-only permission — HealthMailer cannot add, change, or delete anything in Apple Health or Health Connect.

The requested data is compiled into a report (a CSV file) entirely on your device. Nothing is uploaded to us, and nothing is transmitted anywhere, at this stage.

When you choose to send the report, HealthMailer hands it to your own email app, already addressed to the recipient named in the link. Your email app sends it from your own email account, over your own connection. At no point does this report, or the health data inside it, pass through our servers or infrastructure. We have no ability to see, intercept, retain, or recover it — and, because the sending happens entirely within your own email app, we also have no way of confirming whether an email was actually sent, or received.

5. On-device data storage

While a report is being prepared, the app may hold it briefly in your device's memory or private app storage so it can be attached to your outgoing email. This copy is automatically cleared as soon as you send the report, or if you cancel or back out before sending. HealthMailer does not retain a copy after that point, and does not back up, sync, or export this data anywhere else.

6. Special category (sensitive) health data

Depending on what a clinician or researcher requests, and what is available on your device, the categories of data covered by this Service may include particularly sensitive information, such as reproductive or menstrual health data, heart and cardiovascular measurements, sleep, or clinical vitals. This is treated as "special category data" under data protection law. Because this data is read, compiled, and sent entirely on your own device, and never reaches our servers, we do not process, store, or have access to it in any form — the protections described in this Policy for the request link (Sections 3–4) apply equally, and with the same emphasis, to sensitive categories of data.

7. Information about our website

Our website does not use cookies, does not run analytics or advertising scripts, and does not track visitors across sessions or across other websites. The only information submitted through the website is the link-creation request described in Section 3.

Like any website, ours is served through third-party hosting and cloud infrastructure providers, who may process standard technical information (such as IP address, browser type, and request timestamps) as an ordinary part of operating that infrastructure and keeping it secure. We do not use this information for analytics, profiling, or marketing purposes.

8. No advertising, analytics, or third-party trackers in the app

The HealthMailer app does not contain advertising SDKs, analytics SDKs, or crash-reporting tools that transmit data to us or to any third party. We do not sell, rent, or share personal data or health data with advertisers, data brokers, or any other third party, because we do not collect or hold it in the first place.

9. Data retention

We do not retain health data, report contents, patient or participant reference labels, or recipient email addresses, because this information is never sent to or stored by our servers — it exists only within the signed link itself and on the devices of the people using it. The only information we retain is the short-lived, IP-based security record described in Section 3, which is kept only for as long as needed to protect the signing service from abuse, on a rolling basis.

10. Your rights

Depending on where you are located, you may have rights under data protection law (such as the UK General Data Protection Regulation and the Data Protection Act 2018, or equivalent laws elsewhere) to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. Because HealthMailer is designed so that we do not collect or hold your health data or a persistent record of your requests, there is typically nothing on our systems to access or delete beyond the limited security record described in Section 3.

If you believe we hold information about you and would like to exercise any of these rights, or if you have a concern about how we handle information, please contact us at info@clinicianpeople.com. If you are in the UK and remain unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), or the equivalent supervisory authority in your jurisdiction.

11. International use

The Service may be used by people and organizations in different countries, and our infrastructure providers may operate servers in jurisdictions other than your own. Because we do not transmit or store your health data, its processing occurs on your own device and remains subject to your own device's operating system and settings, rather than being transferred internationally by us.

12. Children's privacy

The Service is intended for use by clinicians, researchers, and the adult patients or participants they work with. It is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us so we can address it.

13. Not a medical device or diagnostic service

HealthMailer is a transport tool: it helps compile and send data that already exists on your device, at the request of a clinician or researcher. It does not analyze, interpret, diagnose, or offer any medical opinion on the data it helps you send, and should not be relied upon for any medical decision-making.

14. Changes to this Policy

We may update this Privacy Policy from time to time, for example to reflect changes to the Service or to applicable law. If we make material changes, we will update the "Last updated" date above. We encourage you to review this page periodically.

15. Contact us

If you have any questions about this Privacy Policy or how the Service handles information, please contact:

Clinician People Ltd (company number 15880511)
82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
info@clinicianpeople.com