1.Why this page exists
Amaina uses a third-party artificial-intelligence service to help with two things: turning your spoken or typed attack descriptions into a structured log, and drafting a readable summary you can bring to your doctor.
Apple asks any app that shares your personal data with a third-party AI to tell you clearly and get your permission first (App Store Review Guideline 5.1.2, updated November 2025). This page is that disclosure. It's written to match what you'll see in the app's consent screen, what's in our Privacy Policy, and what we report in Apple's App Privacy labels — on purpose, so they all say the same thing.
Note for our earlier website visitors: Our pre-launch website said "we do not send your answers to any third-party AI service." That was true for that website. The Amaina app is different — the app does use an AI service, exactly as described here, and only after you consent. This page replaces that earlier statement for the app.
2.Who provides the AI
The AI service is Anthropic, the company behind Claude. Anthropic is based in the United States.
- Anthropic acts as our service provider (a "subprocessor"). It processes text on our behalf, under a contract, and only for the purposes we tell it to.
- Anthropic is not a healthcare provider, is not part of your care team, and does not make any medical or eligibility decision about you.
- We use a version of Claude that is compatible with our strict data-handling settings (described in Section 6).
Which features call the AI (confirmed for this build): there are exactly two AI call sites, both live: (a) voice/typed attack logging → structured fields, and (b) the doctor-visit summary narrative — both done via Anthropic (Claude), both gated on your AI consent. The doctor summary also has a static, no-AI fallback. Our in-app Insights cards (Frequency, Sleep, Cycle, Activity, Profile) are computed inside the app by rule-based logic — they do NOT use the AI. The tap / manual-entry path never uses AI.
3.What the AI does — and doesn't do
What it does:
- Structures your description. You speak or type something like "woke up at 6 with a throbbing headache on the left side, took a triptan around 7, aura before it started." The AI turns that into fields: time, intensity (1–10), duration, symptoms, aura, medication, triggers. You always see the result and can edit any field before it's saved.
- Drafts your doctor summary. From the entries you logged, the AI drafts a short, readable narrative you can share with your doctor — for example, how often attacks happened, how the pattern changed over a period, and questions you might want to ask. You choose when to generate it and for which time range. The summary describes what you logged, and this includes your own count of the days you used acute medication over the period — a plain descriptive record of your own data. Separately, the summary may carry a neutral general educational note — the widely-cited guidance that using acute medication on roughly 10–15 days a month or more is worth discussing with your doctor. That general note is presented on its own (as a general note or footer); it is not attached to your personal count, and your personal count is not labelled as a "medication-overuse-headache (MOH) risk." The summary never produces a personalized overuse-risk calculation, a dosing recommendation, or any diagnosis.
What it never does:
- It never gives you a diagnosis or tells you what condition you have.
- It never gives a prediction, a risk score, or a weather-based forecast of future attacks.
- It never gives medication dosing, prescribing, or avoidance advice.
- It never decides anything about you automatically.
Everything the AI produces is a description or organization of what you logged — observations from your own data, not medical conclusions. Your doctor is the right person to interpret what it means. See our Medical Disclaimer.
4.Exactly what gets sent to the AI
When you use an AI-powered feature, our server sends Anthropic only the minimum text needed to do the job:
We send:
- The text of your attack description (what you typed, or the text your device produced from your speech), or
- Your structured log entries for the time range you chose (for the doctor summary).
We do NOT send:
- Your voice audio — see Section 5 for how voice is handled.
- Your name, email address, or date of birth.
- Your raw Apple Health readings (sleep, cycle, workouts) — or any value derived from them (Google Health Connect, on a future Android release, is handled the same way). HealthKit-derived triggers (for example, sleep-under-6h and menstrual-window signals) are stripped from the AI request before it is sent; only the transcript plus non-health context such as weather goes out.
- Any account or device identifier that isn't needed for the task. We don't put health-identifying labels into the technical field names we use.
In short: we send only the text needed for the task and don't attach your name, email, or date of birth. Keep in mind that anything you personally type into a log is sent as-is — so avoid typing identifying details you don't want processed.
No health data — raw or derived — reaches the AI. We never send your raw HealthKit readings (or Health Connect readings, on a future Android release), and we also strip any HealthKit-derived triggers (for example, sleep-under-6h and menstrual-window signals) from the AI request before it is sent. Only the transcript plus non-health context — such as weather — is sent. This is a settled bright-line, not a to-be-confirmed item.
5.How voice works (your audio never reaches the AI, or us)
Amaina is voice-first, so it's worth being precise about audio:
- You speak into the app.
- Your device's own speech-to-text (Apple Speech) turns your voice into text. Depending on your device, language, and settings, Apple may do this on your device or on Apple's servers — that's Apple's system, governed by Apple's terms.
- Only the resulting text — never the audio — is passed to our server, and only that text (if you've consented) goes to the AI.
So your recorded voice is never sent to Anthropic, and is never stored by us. A tap / manual-entry path is always available and uses no AI at all.
6.Safeguards on the AI processing
We've set up the AI processing to keep your data protected:
- Contract in force. A Data Processing Agreement (DPA), including Standard Contractual Clauses, is in force with Anthropic. It binds Anthropic to process data only on our instructions, with defined security and confidentiality obligations.
- No training on your data. Anthropic does not use our data to train its models. This is the default for our commercial account and we do not opt in to training.
- Short retention with automatic deletion. Anthropic automatically deletes the text of our AI requests (inputs and outputs) within 30 days. It keeps the smallest footprint needed to run the service, and we use a standard model configured for these data-handling settings. A narrow exception can apply if content is automatically flagged for a safety/policy review; if that ever happens, that review is used only for safety and abuse-prevention and is never used to train models, to build advertising audiences, or for any purpose other than safety. That is the only situation in which text could be retained beyond the standard 30-day window, and it does not create routine human access to your migraine notes.
- Zero Data Retention (not available to us). We asked Anthropic for Zero Data Retention (ZDR), which would remove even that short 30-day window, but ZDR is currently offered only to large enterprise accounts and is not available to us. So we rely on the standard 30-day-deletion policy above, together with our data-processing agreement and our own data minimization (Section 4) — only the text needed for the task, never your name, email, date of birth, audio, or raw health-app readings.
- Backend-only calls. The AI is called only from our own secure server — never directly from your phone or browser. Traffic is encrypted in transit.
- Data minimization by design. As described in Section 4, we strip out who-you-are data and send only the health text needed for the task.
For the full list of the service providers we use, see our Privacy Policy.
7.Your consent and your choice
We ask for your explicit, opt-in consent before any text is sent to the AI. You'll see a clear consent screen (reproduced in Section 8) the first time you use an AI-powered feature.
- If you consent, Amaina can structure your spoken/typed logs using the AI, as described above.
- What this one consent covers. This single AI-processing consent also covers the doctor-visit summary — one of the two confirmed Claude call sites (see Section 2). It is generated from your own logs, via the same subprocessor (Anthropic / Claude), and stays descriptive-only. If the summary ever used a different AI provider, or sent materially more data than your own log text, we would ask for a separate consent first.
- If you decline, that's completely fine — you can still use Amaina. Just tap to log your attacks manually; the manual path uses no AI. (Note: the AI-drafted doctor summary relies on the AI, so it won't be generated if you decline — you can still view and share your structured log without AI.)
- You can change your mind anytime. Go to the app's Settings and turn AI processing off (or back on). Turning it off stops any further text from being sent to the AI going forward.
- To delete everything, including anything the AI processed: in-app account deletion is available directly in the app (not only by email) — see Account & Data Deletion. Deleting your account removes your data from our active systems and we instruct our subprocessors to do the same.
Consent to AI processing is separate from other permissions (like Apple Health access or notifications) — we ask for each one on its own, and you can grant or refuse them independently.
Non-AI path (confirmed): you can generate a doctor summary from your logs and export or share it as a PDF (amaina-migraine-report.pdf), built on your device with no AI — or share it as text. The no-AI static-fallback summary can be exported as this same PDF, so the no-AI path still yields a real doctor PDF. Separately, Export my data (Settings) now lets you choose between a Doctor report (PDF) — the same on-device, no-AI PDF the Reports screen produces — and a Raw data (JSON) copy of your profile, medications, and attacks for data portability.
8.What the in-app consent screen says
The single source of truth for the exact in-app consent-screen wording (title, body, checkbox, and button labels) is the implementation pack — In-App Consent & Permissions §4 ("Consent screen — AI processing"). That pack is what the CTO wires into the app verbatim, and the app screen must match it word-for-word. To avoid two divergent "exact" strings — which is precisely the onboarding-vs-disclosure mismatch Apple reviewers reject under Guideline 5.1.2 (revised Nov 2025) — this page does not maintain a second version. It reproduces the canonical string below for reference only; if the two ever differ, the implementation pack governs.
The AI-processing consent is shown before any text is sent to Anthropic, the first time you choose to log by voice or use an AI-assisted feature. As reproduced from In-App Consent & Permissions §4:
Title: Let Amaina turn your words into a tidy log
Want to log by talking? Here's exactly what happens, so you can decide.
On your device: you speak, and Apple turns your speech into text. Your audio never reaches Amaina or any AI company — we only ever get the text.
On our server: that text is sent to our secure backend and then to Anthropic (Claude), an AI service we use to organize your note into fields like time, intensity, duration, symptoms, medication, and triggers. You'll see the result and can edit anything before it's saved.
What Anthropic does with it: Anthropic acts as our processor under a data protection agreement. It does not train on your data and automatically deletes the text of AI requests within 30 days — keeping it longer only if content is flagged for a safety/policy review. We send only text — never your name, email, date of birth, audio, or raw health-app readings.
Prefer not to? No problem — you can log by tapping instead, with no AI involved at all, and still use the whole app. The AI-drafted narrative summary won't be available, but you can still export a raw, structured doctor PDF built from your own logs, with no AI — so you're never left without something to bring to your doctor. You can change this anytime in Settings.
☐ I agree that Amaina can send the text of my logs to Anthropic (Claude) to organize them, as described here and in the Privacy Policy.
[ Turn on AI logging ] [ Not now — I'll tap to log instead ]
_How Amaina uses AI (Privacy Policy §AI processing)_
The app screen, this page, the Privacy Policy, and the App Privacy labels must all describe the AI identically. Final wording is subject to lawyer sign-off; when it changes, it changes in the implementation pack first and this reproduction is updated to match.
9.Legal basis and consumer-health-data note (US-first)
Your migraine descriptions — symptoms, medications, and related notes — are sensitive health information. Several US laws treat this as a special, higher-protection category:
- Washington My Health My Data Act (MHMDA) and Nevada SB 370 treat this as "consumer health data." We ask for your opt-in consent to collect it (captured on the health-data consent screen). Sending your text to Anthropic (Claude) is processing by a service provider (a processor) acting on our instructions — it is not a "sale" and it is not a third-party "share" that would trigger MHMDA's separate consent-to-share. That separate share-consent would only be needed if we ever disclosed your consumer health data beyond service-provider processing — which we do not. We do not sell your consumer health data, we do not share it for advertising, and any sale would require the signed valid authorization MHMDA specifically requires (which we do not seek). These laws can apply to you wherever you live if you're a resident of those states. The AI-processing consent (Section 7) is a separate, explicit opt-in to this processing, layered on top of the collect-consent.
- California (CPRA): health data is "sensitive personal information." You have the right to limit its use, we honor the Global Privacy Control (GPC) signal, and we do not share your health data for cross-context advertising.
- FTC Health Breach Notification Rule (HBNR): if there were ever a breach affecting your health data, we would notify affected users and the FTC (and the media, if a large number of a state's residents were affected). See our Privacy Policy for details.
Sending your text to the AI to organize it happens only after you consent, and that consent is the basis for this processing. You can withdraw it anytime (Section 7). Amaina is for adults 18 and older.
HIPAA does not apply to Amaina — we're a direct-to-consumer wellness app, not a healthcare provider or insurer, so we do not (and cannot) claim HIPAA compliance. That does not lower the protections above.
10.If you're in the EU or UK (secondary)
We do not currently target the EEA or UK — Amaina launches in the United States only. If that changes, the following would apply, and we'd update this page and our consent flows first:
- Your health data is special category data under the GDPR (Article 9). The lawful basis for sending it to the AI would be your explicit consent (Article 9(2)(a)), asked for separately and freely given.
- Anthropic acts as a processor under Article 28; our DPA includes Standard Contractual Clauses to cover any transfer of EU/UK data to the United States.
- You would have the usual GDPR rights (access, correction, deletion, objection, withdrawal of consent) via legal@smart-it.io.
12.Changes to this disclosure
If we change how we use AI — for example, adding a new AI-powered feature, changing what's sent, or changing the provider — we'll update this page, change the Effective Date, and, where the change is significant, ask for your consent again before the new processing begins.
The current version is always available at amaina.health/ai.
13.Contact us
Questions about how Amaina uses AI, or want to change your choice?
Privacy / legal: legal@smart-it.io Product support: support@smart-it.io Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
For medical questions, contact your healthcare provider. In an emergency, call your local emergency number (911 in the U.S.).
Written in plain English. Amaina is operated by Smart IT US Inc. This is a wellness tracker, not a medical device.