Constellate Health Privacy Policy
Last updated: 2026-09-11
Constellate Health is a research participation app. This policy explains what information we collect, how we use it, and
your choices.
If you are participating in a specific study, your study team may provide additional consent and privacy
information that applies to your participation.
Information we collect
- Account information: email address and name (if provided).
-
Profile and demographics (optional): date of birth, sex, ethnicity, height/weight, and other
profile fields you choose to provide.
-
Photos you choose to capture: the app uses your device camera to let you capture and upload
photos as part of study participation.
-
Health-related inputs you provide: check-ins/trackers and other data you enter in the app.
-
Device/app information: basic technical and diagnostic information needed to operate, secure,
and improve the app (such as app version and device type).
-
Permissions-based data (only if you grant permission): for example, camera access to capture
photos from within the app. If a study enables location capture and you allow it, we may collect location data
associated with submissions for that study.
Connected health data
We access connected health data only with your permission, for the research purposes described in your
study consent. The sources and data available depend on your app version, device, study and permissions.
Historical collection is limited to the period authorized for your study participation.
-
Apple Health (HealthKit, iOS): authorized categories can include steps and flights climbed;
distance; energy burned, exercise, standing time and workouts; sleep timing and stages; heart rate and
heart rate variability (HRV); heart events and ECG; height, weight, BMI, waist size and body composition;
temperature, blood oxygen and circulation measurements; blood glucose and blood pressure; breathing
measurements; water and nutrition; mindfulness; menstrual flow; walking speed; hearing; insulin delivery;
and skin conductance. Only supported types within the categories you authorize are read.
-
Health Connect (Android): authorized categories can include steps and flights climbed;
distance; energy burned, activity intensity and workouts; sleep timing and stages; heart rate and HRV;
height, weight, BMI and body composition; body or skin temperature and blood oxygen; blood glucose and
blood pressure; respiratory rate; water and nutrition; menstrual flow; and movement speed.
Health Connect's on-device permissions are separate from a Google Health account connection.
-
Google Health API: sleep timing, duration and stages; steps, distance, active and total
calories burned, activity minutes and sedentary time; heart rate, resting heart rate, HRV, blood oxygen,
respiratory rate and weight, when available. Read-only profile access supplies your Google Health user
identifier and, if present, your legacy Fitbit identifier so records can be associated with the correct
connected account. We request read-only sleep, activity and fitness, health metrics and measurements,
and profile permissions. We do not write to Google Health or request its exercise-location permission.
-
Fitbit: sleep, steps, distance, calories, activity minutes, heart rate, HRV, blood oxygen,
respiratory rate, temperature, weight and cardio-fitness estimates, where supported. An account identifier
links the connection to your Constellate account. The legacy Fitbit connection is separate from Google Health.
-
Oura Ring: sleep, readiness and activity scores and their underlying measurements,
including heart rate, HRV, respiratory rate, temperature variation, blood oxygen, steps, calories,
workouts and sessions; and available stress, resilience and cardiovascular-fitness estimates.
-
Dexcom: glucose readings and timestamps, glucose trends, device information and
associated events available through the Dexcom API, such as carbohydrate, insulin or exercise events.
How we use information
- To provide app functionality (account access, study enrollment, data capture, and upload).
- To make your study participation data available to authorized study staff/researchers.
- To maintain safety and security, prevent abuse, and troubleshoot issues.
- To improve app performance and reliability.
Health data and Google Limited Use
We do not use data from any connected health source for advertising or marketing, or sell it to third
parties, or use it to train general-purpose artificial-intelligence or machine-learning models.
These restrictions also apply to aggregated, de-identified and derived health data. Study-specific
research, including model development, must be explicitly covered by your study consent and comply
with the applicable provider policies.
Constellate Health's use and transfer of information received from Google APIs will comply with the
Google API Services User Data Policy,
including its Limited Use requirements. We will also follow the
Google Health API Developer and User Data Policy
and the Google Health API User Data and Health Research Policy,
including their Limited Use requirements, for Google Health data used in research.
Google Health data is used for your consented study participation and the related features you use in
Constellate. Access by researchers is limited to authorized members of your study team who need the data
for that research. Service providers may process it only as needed to operate those features and under
restrictions on further use. Other access or disclosure is limited to the security and legal exceptions
permitted by Google's policies. A different study or research purpose requires separate informed consent
unless an applicable research-policy exception permits an IRB waiver.
Permissions
Camera (android.permission.CAMERA): used only to capture photos when you choose to
do so inside the app.
Sharing
-
We share your information with authorized researchers/study staff involved in the study you
joined.
-
We may share information with service providers that help us operate the app (e.g., hosting),
under appropriate safeguards.
- We may disclose information if required to comply with law or to protect safety and security.
Storage and security
Google Health records are transmitted over HTTPS and stored in the Service's research databases and
file storage. Google Health connection tokens are encrypted when stored and used to maintain the
connection you authorized. Access to research records is controlled by account and study permissions.
The app may retain local records and sync status needed to display data and resume interrupted syncing.
Retention
We retain information for as long as needed to provide the service, support research operations, and comply with
applicable legal and study requirements. Your study team may have additional retention requirements described in
study consent materials.
Your choices and controls
- You can stop providing new information at any time by discontinuing use of the app.
-
If you are participating in a study, you may be able to withdraw according to your study's consent process.
Withdrawing may not remove data already shared with the study team, depending on the study's policies and
applicable law.
-
Account deactivation: You may deactivate your account from within the app. Deactivation
disables your login but preserves all your data. You may contact us to reactivate at any time.
-
Account deletion: You may permanently delete your account from within the app. Upon deletion,
your personal information (name, email, demographics, login credentials) is removed. De-identified research
data and consent records are retained as required by applicable study protocols and institutional regulations.
-
Disconnect a health source: In the app's Settings, open the connected source and choose
Disconnect. Disconnecting stops future access from that connection but does not automatically delete
records already collected. For deletion of existing research data, contact your study team or use the
account-deletion option, subject to the retention requirements above.
-
Google Health: You can also revoke access outside Constellate from your
Google Account's connections page. Select
Constellate Health, review its access to your Google Account, and remove access. Google provides
instructions for managing app access.
Removing Google access is separate from withdrawing from a study or deleting data held by Constellate.
-
Apple Health and Health Connect: You can revoke Constellate's permissions in the
Apple Health app's data-access settings or Health Connect's app-permissions settings on Android.
Contact
For app support or privacy questions, contact us at constellatehealth@gmail.com.
Constellate Health is developed by the Applied Bioinformatics Laboratories at NYU Langone Health.