Privacy Policy

Last updated: April 6, 2026

1. Introduction

Euri AI ("Euri," "we," "us," or "our"), a product of Euron, is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our services, including the Euri AI Agent, Euri AI Gateway, and all associated features including our Health Data integration service.

By using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, do not use our services.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you sign in through a third-party provider (Google, Apple, etc.), we receive basic profile information from that provider.

2.2 Usage Data

We collect information about how you interact with our services, including conversations with AI models, features used, timestamps, and device information. This data helps us improve our services and provide better experiences.

2.3 Health & Biometric Data

Special Category Data

Health data receives enhanced protections under our privacy framework. This section details our health-specific data practices.

If you choose to connect wearable health devices, we collect biometric and health-related data from the following providers: Oura Ring, Fitbit, Withings, WHOOP, Polar, and Strava. The types of health data we collect include:

  • Sleep Data: Sleep duration, efficiency, stages (REM, deep, light, awake), heart rate during sleep, HRV, respiratory rate, bedtime timing
  • Activity Data: Steps, calories burned, activity minutes by intensity, distance, floors climbed
  • Heart Rate: Resting heart rate, intraday heart rate measurements, heart rate variability (HRV)
  • Blood Oxygen (SpO2): Average and lowest blood oxygen saturation levels
  • Body Composition: Weight, BMI, body fat percentage, muscle mass
  • Workouts: Exercise type, duration, calories, heart rate during exercise
  • Readiness/Recovery: Recovery scores, strain levels, body temperature deviations

Consent: Health data is only collected after you explicitly grant consent through our Health Data Privacy consent flow. You must agree to our Data Collection & Storage terms before any health data is accessed or stored. You may revoke consent at any time.

3. How We Use Your Information

3.1 General Use

  • Providing and maintaining our AI services
  • Personalizing your experience
  • Processing transactions and managing your account
  • Communicating with you about service updates
  • Improving and developing new features
  • Ensuring security and preventing fraud

3.2 Health Data Use

Your health data is used exclusively for:

  • Dashboard Display: Presenting your health metrics in an organized, visual format
  • AI-Powered Wellness Insights: With your additional consent, generating personalized wellness summaries through our AI system
  • Health Predictions: Running deterministic, science-backed prediction algorithms locally to identify wellness patterns (illness risk, recovery status, sleep debt, etc.)
  • Trend Analysis: Analyzing your data over time to show meaningful trends and changes

We do not sell your health data to any third party. We do not use your health data for advertising purposes. We do not share identifiable health data with insurance companies, employers, or any entity that could use it to make decisions affecting you.

4. Data Sharing & Third Parties

4.1 AI Processing Partners

When you consent to AI-powered insights, anonymized prediction summaries (not raw health data) may be sent to our AI processing infrastructure for natural language summary generation. No personally identifiable information is included in these requests. This processing is governed by a Business Associate Agreement (BAA) with our AI infrastructure partner.

4.2 Wearable Device Providers

We access your data from wearable providers (Oura, Fitbit, etc.) through their official APIs using OAuth 2.0 authorization. We only request the scopes necessary to provide our services. Each provider has its own privacy policy governing how they handle your data on their platform.

4.3 Service Providers

We use third-party service providers for hosting (AWS), database management, and email communications. These providers are bound by data processing agreements and are prohibited from using your data for their own purposes.

4.4 Legal Requirements

We may disclose your information if required by law, court order, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption at Rest: Health integration tokens are encrypted using AES-256-GCM with authenticated encryption
  • Encryption in Transit: All data transmissions use TLS 1.2+ (HTTPS)
  • Authentication: JWT-based authentication with bcrypt password hashing (cost factor 12)
  • Access Controls: Role-based access control (RBAC) with organization-level permissions
  • Audit Logging: Comprehensive audit trail for all health data access and modifications
  • Data Minimization: We only store the specific health metrics needed for our features, not raw API responses
  • Rate Limiting: Tier-based rate limiting to prevent abuse
  • Security Headers: Industry-standard HTTP security headers (Helmet.js)

6. Data Retention

We retain your data according to the following schedule:

Data TypeWhile ActiveAfter DisconnectAfter Deletion
Health MetricsRetained90 days, then purged30-day grace period, then purged
AI Insight Cache15 minutesCleared immediatelyCleared immediately
OAuth TokensWhile connectedDeleted immediatelyDeleted immediately
Consent RecordsRetained6 years6 years
Audit LogsRetained6 years6 years (de-identified)

7. Your Rights

You have the following rights regarding your data:

  • Right to Access: You can view all your health data through our dashboard and export a complete copy in machine-readable format (JSON)
  • Right to Deletion: You can request deletion of your account and all associated data, subject to a 30-day grace period during which you can cancel the deletion
  • Right to Portability: You can export your health data at any time through our data export feature
  • Right to Withdraw Consent: You can revoke consent for health data collection, AI processing, or third-party sharing at any time through your account settings
  • Right to Disconnect: You can disconnect any wearable device provider at any time, immediately stopping new data collection
  • Right to Correction: If you believe your data is inaccurate, contact us to request corrections

8. Health Data Notice

Important Health Information Disclaimer

Euri is a wellness technology platform, not a healthcare provider. The health insights and predictions we provide are for informational and wellness purposes only. They do not constitute medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional before making health decisions based on our insights. Do not use our predictions for emergency medical situations. If you are experiencing a medical emergency, call emergency services immediately.

9. Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly.

10. Breach Notification

In the event of a data breach involving your personal or health information, we will notify affected users within 60 days of discovery, as required by applicable law. Notification will include the nature of the breach, the types of data involved, steps we are taking to address the breach, and recommendations for protecting yourself. We will also notify relevant regulatory authorities as required.

11. International Data Transfers

Your data may be processed and stored in the United States and other countries where our service providers operate. By using our services, you consent to the transfer of your information to these countries, which may have different data protection laws than your country of residence. We ensure appropriate safeguards are in place for all international data transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For changes that affect health data processing, we will provide prominent notice and may require renewed consent. Your continued use of our services after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy, your data, or wish to exercise your rights, contact us at:

Euri AI (Euron)

Email: privacy@euron.one

Data Protection Officer: dpo@euron.one