Your health data, on a leash you hold.
Aler is HIPAA-aware from day one. Your record is encrypted in transit and at rest, and every read and write of it is logged. Below is what we collect, what we do with it, and the lines we will not cross.
What sits behind every data flow.
You own your data
Your record is yours, not ours. We hold it so Aler can do the work you signed up for. Close your account and your record is queued for deletion with a 30-day window to change your mind, and your research contributions are removed right away.
De-identified before it trains anything
Aler does get better from the collective. Health data trains our models, and every record that reaches training is de-identified first, so what travels is the pattern and not the person. Your own baseline is still computed inside your account, from your history alone.
You hold the keys
See where every number came from, connect or disconnect a source whenever you want, and the inputs come out of your model the same day.
We only ask for what we need
We request the minimum data Aler needs to do its job, and nothing more. No quiet scope creep, no collecting things just in case.
Handled like health data, because it is.
Aler is not your covered entity; your clinician, hospital, or health plan is. On the clinical side, practices sign a Business Associate Agreement before any patient data is shared. If you use Aler only with consumer wearables and self-reported data, HIPAA may not technically apply, and we hold ourselves to the same standard anyway. Formal certifications like SOC 2 are on our pre-launch roadmap, not claims we make today. Here is what is actually in place.
Encrypted at rest
Sensitive fields are encrypted one by one in the database, on top of encrypted storage volumes. The keys are held server-side and can be rotated.
Encrypted in transit
Everything moves over TLS, with HSTS enforced. The backend refuses plain HTTP in production.
An append-only audit log
Every read and write of your record is logged. The app can only add to that log, never edit it or delete from it.
Least privilege by default
Every request is checked against your role. Support staff cannot see health data unless a specific, logged reason grants it.
Clinicians use two factors
Any clinician who signs in with a password must clear a second factor. Health data is never behind a single password.
No secrets in the logs
Identifying fields are stripped to opaque IDs before anything is logged, and model provider keys live only on the server.
Four buckets. The full list lives in the Privacy Policy.
This is the human summary. Every category we touch is enumerated in the Privacy Policy, and changes show up in the changelog before they go live.
Identity and account
- Name, email, phone (optional)
- Sign-in through Google or Apple
- Date of birth, sex, home address
- Billing identifiers (no full card numbers)
- Account preferences
Health data you connect
- Wearables through Whoop, Apple Health, and Health Connect (heart rate, HRV, SpO2, sleep, activity, weight)
- Lab results you upload or enter
- Medicines and supplements you enter
- Genetic reports you upload
- The world around you (air quality, pollen, UV, weather, altitude)
- Symptoms, journal entries, and notes
Sensitive categories
- Mental-health entries, when you share them
- Reproductive and sexual-health data, when you share them
- Genetic data, only with separate, distinct consent
- Substance-use records, with Part 2 protections honored
Operational signals
- App and sync diagnostics (identifiers stripped first)
- Crash reports (identifiers stripped first)
- The audit log of every read and write of your record
For your model, your brief, and your care team.
Aler learns your normal from your own history, scored on completed days, across every connected stream. Your baseline is computed from data inside your account and nowhere else.
Changes are measured against your own baseline, read against plain-language health knowledge, and turned into a short read on what moved and whether it needs you.
When you grant access, Aler produces a clear, sourced summary of what changed, scoped to a specific clinician for a specific visit, and nothing more.
De-identified health data trains the models that read your signals, and the collective is what makes them accurate. A pattern that shows up across thousands of de-identified records is what lets Aler recognize it in yours. Operational numbers (speed, model quality, error rates) work the same way. Data that could identify you never enters training, and it is never used for marketing.
De-identified, aggregated data can support health research. When you sign up you are included by default, and you can opt out anytime in settings. More on exactly how that works below.
Helping the science, without giving yourself away.
De-identified, aggregated data from Aler accounts trains our models and supports health research. That collective is what makes the model more accurate for everyone, including you. You are included by default when you sign up, and you can opt out at any time in settings.
Stripped of anything that points to you
What leaves your account carries no name, no exact dates, and no location, only coarse, grouped signals like a five-year age band. It is built to meet recognized de-identification standards.
You are in control
Opt out whenever you want, and it stops. Opt out or delete your account and the data you already contributed is removed, not just switched off going forward.
We want to be plain about this rather than hide behind a slogan. Aler is better because of the people using it. A signal that turns out to matter in thousands of de-identified records is a signal Aler can catch in yours. What we will not do is let anything that points back to you into that pool.
The bright lines.
Access, correct, delete. On your schedule.
We follow the individual rights under HIPAA, and the matching rights under GDPR and CCPA / CPRA, wherever you live.
Access
See exactly what we hold on you, in plain words, and export your record as a file.
Correct
Flag anything wrong and we either fix it or note it alongside the record.
Delete
Close your account and your record is scheduled for deletion, with a 30-day window to undo.
Some retention is legally required, like the audit log. Those records sit in a separate, restricted store for the minimum period the law asks for, and they are never used for analytics of any kind.
The binding agreements live here.
If you want to know exactly what we have committed to in writing, these documents are the source of truth.
Privacy Policy
The full enumeration of categories collected, lawful bases, sub-processors, retention, breach notification, and your rights.
App Terms of Service
The binding user agreement, including the de-identified data terms and the Aler Intelligence carve-outs.
Consumer Health Data Policy
The stand-alone notice required by Washington’s My Health My Data Act and similar state laws.
Sub-processors
The categories of vendors that process personal data for us, where, and our 30-day change-notice commitment.
Website Terms of Use
Governs your use of the site itself, including our vulnerability disclosure and accessibility commitments.
Questions about your record? Talk to a human.
Email our privacy team at the address below. We answer individual rights requests within 30 days, and credible security reports within 24 hours.
Last updated July 2026. This page is a plain-language summary. The legally operative text is the Privacy Policy.
Continuously monitor your health.
Aler Health pulls your whole health together and tells you what actually matters. Download it today and let's optimize your health, once and for all.
Wearables, blood work, medicines, supplements, DNA, even the air around you, read together.
Aler learns what's normal for you, then watches for the moment your numbers start to slip.
When something moves, you hear what changed and what to do next, with no charts to decode.
Not ready to download? Get an occasional email as Aler grows. No spam, leave anytime.
