Health data is as personal as it gets. Here is exactly how Human Metrics treats yours — in plain language.
Effective 2 August 2026 · humanmetrics.health
Human Metrics stores what you give it, and nothing more: your account details (name, email, and a salted hash of your password — never the password itself), your food diary, custom foods you create, health readings you log (weight, blood pressure, stress, symptoms, and any metrics you define), your daily targets, and your region preference.
We use no advertising trackers, no third-party analytics, and no fingerprinting. The only cookie is a single session cookie that keeps you signed in; it is HTTP-only and never readable by scripts.
When you use an AI feature — a photo to estimate a dish's macros, “Ask AI” in food search, an ingredient list for a custom food, or a photo of a product's packaging — that photo or text is sent to Anthropic's Claude API for analysis and the estimate is returned. Photos are not stored by Human Metrics — only the resulting estimate you choose to save or log is kept, along with a count of your AI requests for your plan's monthly allowance. Anthropic does not use API inputs to train its models; see Anthropic's privacy documentation for their retention practices. If you never use an AI feature, nothing is ever sent to Anthropic.
When you scan a barcode we don't recognise and capture the product — its name, brand and the nutrition panel — that product record is added to a shared food database so every other user's scan of the same barcode finds it too. Only the product information goes in; nothing about you, what you ate, or when is attached to it, and your name is never shown against it. Photos of the pack and panel are used to read those details and are not stored. Edits to a shared product keep the previous version in an internal history, recorded against the account that made the change, so mistakes and vandalism can be undone. If you would rather keep a food to yourself, create it as a custom food instead — custom foods stay private.
If you connect a wearable such as Whoop, we store the access tokens needed to sync and the health data the sync retrieves (recovery, HRV, sleep, strain). You can disconnect at any time from Settings, which removes the tokens immediately; already-synced readings remain yours and stay in your account until you delete them. We only request read-only scopes.
Your data is stored in a private database operated by Human Metrics — not on third-party analytics platforms. Access to it in transit is encrypted. Health data is only ever visible to your own signed-in account: custom foods, diary entries and readings are scoped to you and are not visible to other users. The single exception is a product you contribute by scanning, which is shared as described above.
We do not sell your data, share it with advertisers, or use it for any purpose other than showing it back to you and computing the insights you ask for. The only third parties that ever receive anything are the ones you explicitly invoke: Anthropic when you use an AI feature (a photo, a food description or an ingredient list), and your wearable's provider when you connect it.
You can delete individual entries and readings anywhere in the app. To delete your account and all associated data, or to request an export, contact privacy@humanmetrics.health and it will be actioned promptly.
The food database is built from public sources: Food Standards Australia New Zealand (AFCD and AUSNUT, used with attribution), the USDA FoodData Central (public domain), and Open Food Facts (© Open Food Facts contributors, licensed under the Open Database License). These sources describe foods, not you — none of your personal data is ever contributed back to them.