Skip to content
Tesseta
What it tracks Screens Privacy Terms Open the app

Legal

Privacy Policy

Last updated: July 28, 2026

Plain-language summary. Tesseta is your private health record. We collect the health and account data you connect or enter, use it only to run the product for you, never sell it, and scope every record strictly to your own account. You can disconnect a data source or request deletion at any time.

This policy explains what Tesseta ("we", "us") collects, how we use and protect it, and the choices you have. Tesseta handles health information, and we treat it as the sensitive, PHI-grade data it is.

1. Information we collect

Account and identity

You sign in with Google. We receive your name, email address, and Google account identifier to create and secure your account. We do not receive or store your Google password.

Health and fitness data

The core of the product. Depending on what you connect or enter, this includes:

  • Activity and sleep, heart-rate variability (HRV), and resting heart rate
  • Body composition — weight, body fat, lean mass, and DEXA regions
  • Blood markers extracted from lab reports
  • Medications, dosage schedules, and adherence history
  • Nutrition — meals, macros, and calories
  • Training — programs, logged workouts, and exercise history

Connected sources

With your explicit consent, Tesseta reads activity and health metrics from your Fitbit through the Google Health API. We request read-only access to the specific data categories the product uses, and we store an encrypted authorization token so syncing can continue. You can revoke this at any time from your Google account or by disconnecting in the app.

Files you upload

Lab report PDFs, DEXA scans, and meal photos you provide. These are processed to extract structured data (for example, markers from a lab report or macros from a meal photo).

Technical data

To operate and secure the service, we process standard technical information such as device identifiers for push notifications and sync, and security and diagnostic logs.

2. How we use your information

  • To provide the product — resolving your signals into one record and keeping it in sync across your phone, watch, and the web.
  • To power features you invoke, including AI-assisted extraction (lab PDFs, meal photos) and AI goal and program planning grounded in your own history.
  • To send you service notifications, such as dose reminders and alerts that a connected data source needs to be reconnected.
  • To secure the service, prevent abuse, and diagnose problems.

We do not sell your personal information, and we do not use your health data for advertising.

3. AI processing

Some features send the specific content you submit — for example, a lab report you upload or a meal you describe — to a third-party AI provider (Google's Gemini API) to extract structured data or generate a plan. This content is processed to return a result to you and is not used to train third-party models. Always review AI-extracted values; you can edit them.

4. How we share information

We share information only with service providers who process it on our behalf and under contract, and only as needed to run the product:

  • Google Cloud & Firebase — hosting, database, authentication, and push delivery.
  • Google (Health API) — to read the health data you authorize.
  • Google Gemini API — to power the AI features described above.

We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the service.

5. How we protect your data

  • Access is authenticated and denied by default.
  • Data is strictly scoped per user — by construction, you can only ever reach your own records.
  • Secrets such as connection tokens are envelope-encrypted at rest with managed keys (Cloud KMS); data in transit is protected with TLS.
  • The Android app's on-device mirror is encrypted with SQLCipher.

No system is perfectly secure, but the product is designed so that the easy path and the private path are the same path.

6. Data retention

We keep your data for as long as your account is active or as needed to provide the service. When you delete data in the app, or request that your account be deleted, we remove the associated records, subject to any limited retention required by law or for security.

7. Your choices and rights

  • Access — view your data in the app at any time.
  • Correct — edit entries, including AI-extracted values.
  • Disconnect a source — revoke Google Health access from the app or your Google account; syncing stops immediately.
  • Delete — remove individual records, or request deletion of your account and associated data.

To exercise any of these, use the in-app controls or contact us at hello@tesseta.com.

8. Children

Tesseta is not intended for anyone under 18, and we do not knowingly collect data from children.

9. Changes to this policy

We may update this policy as the product evolves. When we make material changes, we will update the date above and, where appropriate, notify you in the app.

10. Contact

Questions about your privacy or this policy? Email hello@tesseta.com.

Tesseta

A personal health record. Activity, blood, body, meds, nutrition, and training — resolved into one trustworthy view.

What it tracks How it works Privacy Terms of Service Open the app
© 2026 Tesseta Built for one trustworthy view of your own health.