No ads and no ad SDKs
There is no advertising SDK, no ad network and no tracking pixel anywhere in the app, the backend or the infrastructure.
Not on the free plan, and not on any paid one.
Every sentence on this page was checked against the code and against a written audit of what BeeGoodHealth talks to. Nothing here is a promise about the future, and nothing here is a figure of speech.
There is no advertising SDK, no ad network and no tracking pixel anywhere in the app, the backend or the infrastructure.
Not on the free plan, and not on any paid one.
No Google Analytics, Segment, Mixpanel, Amplitude, PostHog, Hotjar, FullStory, LogRocket or Sentry, and no telemetry library of any kind.
We do not record your screen, your taps or your session.
We do not sell your data, and there is no mechanism that could: no partner export pipeline, no data-broker integration, and no third party receiving user records.
The app's fonts are bundled with the app and served from our own origin, not from Google's font servers, so no font host sees your IP address on every page load.
The app and this site both send a Content Security Policy with no inline or eval execution, so an accidentally pasted tracker would be refused by your browser.
Every page allows scripts only from our own origin, with one exception we name: the checkout page also allows Paddle's checkout script, and nothing else.
If you gave us Dexcom Clarity credentials while that connection was offered, they are stored encrypted with AWS KMS, with automatic key rotation, and are decrypted only in memory at sync time.
Every logging call in the backend has been reviewed. Operational logs record account identifiers, operation names and error traces, and never glucose readings, medication names, food entries or email addresses.
Every number on the Insights page comes with the arithmetic that produced it, in a panel called How these numbers are computed, on every plan.
Comparisons are against your own earlier days, never a population norm, and a window without enough data says so instead of showing a number.
Nobody sees your data unless you make a share link yourself. What a link carries and how to stop one is set out under What the app talks to below, in the app's own words rather than a summary of them.
No clinic provisions accounts here, and no professional can see your data unless you handed it to them.
As a consumer health app we are covered by the FTC's Health Breach Notification Rule. If identifiable health data is ever disclosed without authorisation, we must notify affected users and the FTC within 60 days of discovering it, and the rule counts sending health data to an advertising or analytics company as a breach.
We keep a written incident-response plan for that duty.
You can delete your account and everything in it at any time from the Account page: entries, settings, connected-service tokens, share links and push registrations all go with it, and so does the sign-in identity itself.
Three things sit outside that, and we say so: a one-way fingerprint of your email address, kept for eighteen months so the free trial stays one per person; the billing record our payment provider holds under its own tax obligations; and a beta request filed under a different address from your account's. The privacy policy spells each one out.
Third-party data-flow audit · revised 5 September 2026
We audited every outbound connection in the app, the backend and the infrastructure, and wrote down what leaves our systems, to whom, and carrying what. The verdict: there is no analytics SDK, no advertising pixel, no session-replay tool and no tag manager anywhere in the frontend, backend or infrastructure, fonts are self-hosted, and the one third-party script in the whole product is Paddle's checkout, loaded only on the checkout page.
The connections that do exist are all functional rather than commercial, and none of them hands an identified user's health record to a party that could monetise it. Some of the lines below run outward rather than inward — a share link you make yourself, the feedback report you choose to send us — and they are written down for the same reason as the rest: they are paths your data can take.
The beta request form on our homepage stores what you type on our own systems and sends it to no one.
The audit was first published on 1 August 2026 and re-run in full against the current code on 5 September 2026. Everything on this page was reconciled with that revision, including Google Health and the checkout page's Paddle script.
Where a line above says What it reads, that sentence is the app’s own wording rather than a summary of it: the same words appear in the privacy policy and on the card where you connect the thing, and a test fails if any of the three drifts from the others. They were last reconciled on 7 September 2026.
The audit also flagged two gaps on our side, and both have since been closed: this site did not send the same security headers as the app, and beta requests had no expiry. It now does, and they now expire automatically.
HIPAA applies to healthcare providers and to the vendors working on their behalf. When you choose BeeGoodHealth yourself and share a report with your doctor or dietitian, that is the patient-directed model HHS describes as sitting outside HIPAA, the same way it works when you email a clinician a food diary or show them your CGM app. We are not a covered entity or a business associate, and we do not claim to be.
That does not mean unregulated. We are covered by the FTC's Health Breach Notification Rule, which requires us to notify affected users and the FTC within 60 days of discovering a breach, and which counts sending health data to an advertising or analytics company as a breach. We hold ourselves to a higher bar than most apps in this space: no advertising, no data sale, no third-party analytics and no tracking pixels, and we have audited and published what the app talks to. You control every share link yourself, and What the app talks to above sets out what one carries and how to stop it, in the app's own words.
If your practice ever needs a signed BAA because you are deploying BeeGoodHealth as part of how you deliver care, that is a different arrangement, and we would want to talk about it. Write to admin@beegoodhealth.com.
Yes, and we would rather say so than imply otherwise. Your data is encrypted in transit and at rest, and the server can read it in order to draw your charts and compute your insights. That is not the same as encryption only you can unlock, and we do not describe the app that way.