MODEL HEALTH

Privacy Policy

This privacy statement explains how Model Health collects, uses, discloses, and otherwise processes personal information in connection with its platform.

Model Health’s platform includes:

  1. The Model Health website
  2. The Model Health web application
  3. The Model Health smartphone application
  4. Application Program Interfaces (API)

Please contact us at info@modelhealth.io if you have any questions after reading this document and viewing the corresponding links.

Data Security and Data Flow

The security, integrity, and confidentiality of your information are extremely important to us.Model Health is a spin-off from Stanford University, where the core of the technology was developed.

Our platform was therefore developed following Stanford’s privacy and security regulations.

The Stanford University Privacy and Security Offices reviews research projects conducted atStanford that handle High Risk Data (e.g., video data that is considered protected healthinformation [PHI] in some instances). The office has certified our platform to be compliant withthe Stanford University Minimum Security Standards for Infrastructure-as-a-Service Solutions.The details of these requirements can be found here. Part of these standards ensures that ourplatform is HIPAA compliant.

All video and processed data are encrypted in transit and at rest (i.e., while stored). The flow ofdata can be seen in Figure 1. More details on data and data flow are below:

Figure 1: Data flow for videos and processed movement data in Model Health’s platform.

What personal information do we collect?

When you use our software to conduct your research study, Model Health collects and processes the following information:

Information about you (the investigator):

Information related to the participant(s) of your data collection:

In addition, where participants are minors, personal information includes data about minors.

How will we use this information?

Data protection legislation requires that we meet certain conditions before we are allowed to use your data in the manner described in this statement, including having a "lawful basis" for theprocessing. The basis for processing could be one or more of the following:

We may use this information to:

  1. deliver our services to you in support of your study and to provide you with information about study participants;
  2. detect, investigate, and prevent activities that may violate our policies, pose safety issues, or be fraudulent or illegal;
  3. improve algorithms; and
  4. compile and share aggregated movement characteristics.

Data storage, retention, and destruction

Videos are collected by the smartphone application, then are uploaded to S3 through the API, where they are encrypted in storage. Backend servers download these videos from S3 and process them into de-identified movement data, which is uploaded to S3. These backend machines are encrypted. Users, who have logged into the web application can view and download their videos and processed de-identified movement data. Python scripting also enables data download, after users log in for authentication. Data is stored in S3. Data is als obacked up in S3 in a different region.

If a participant requests to have their data removed, you (the investigator) can delete their datafrom the platform dashboard. Otherwise, data will be retained for a period of 50 years. Data thatparticipants consent to share publicly will not be deleted, unless a participant requests their databe removed.

Who has access to the data?

In summary, Model Health will have access to the data. It is the responsibility of the ModelHealth account holder to obtain the participant’s consent to using the Model Health platform.

The use of AI in data processing

AI is not used for automated decision making. We use AI to compute the location of key points on the body (e.g., the center of the ankle, the foot) from the recorded smartphone videos. We have tested the accuracy of using this AI approach to gold-standard techniques conducted in a “traditional” laboratory and published the results in peer-reviewed papers. We continuously benchmark our AI system against non-AI processed data.

What are my rights?

Under certain circumstances, you have rights under the data protection laws that apply to you inrelation to your Personal Information. To exercise, please contact the Model Health account holder who collected your data, or Model Health Inc.

Changes to our privacy statement

We may modify this statement from time to time. Your further use of our Services after a change to our statement will be subject to the updated statement. If you don't agree to the changes, then you can always stop using our services, delete your account and stop giving us any more personal information.

Contacting us

If you have any questions, concerns, or complaints regarding this Policy, the information we hold about you, or if you wish to exercise your rights, we encourage you to contact us using the details below:

support@modelhealth.io

This document was last updated on March 25, 2025