Account & data controls
Everything about your account and your data in one place: your plan, what you have consented to, your activity trail, and the buttons to export or delete your data.
Settings, in plain terms
The Settings screen is where you control your account and your data. It is built around a simple idea: your data is yours, your consent is explicit and reversible, and you can always see what has happened and take your data with you. This page explains each control. For the principles behind them (no ad tracking, no training by default, sensitive-category protection), see Privacy & your data.
Account settings modal
The account menu opens a focused settings modal with sections for general preferences, notifications, personalization, connected apps, schedules, billing, data controls, storage, security, trusted contacts, account details, and keyboard shortcuts. The modal keeps the current app screen visible behind it while making the account controls easier to scan.
Your plan and billing
See which plan you are on and what it includes, and manage your membership. Ojava’s free tier gives you unlimited educational AI chat, a starter record import, and your readings dashboard; paid tiers add record depth, wearable integration, and biomarker context. Paid memberships use Stripe checkout, and Settings can open Stripe billing for connected paid memberships so payment methods, invoices, plan changes, and cancellation stay hosted by Stripe. The free experience remains fully usable without a card. Pricing and what each tier includes are on the Pricing & plans page.
The Family Plan is built but activation-gated and is not available to buy while its launch flags are off. Once activated, one plan has up to 5 seats: one for the plan owner and up to 4 other people. The owner can manage seats and invitations, but cannot see another member’s records, logs, conversations, or health data. Each member keeps their own sign-in and data controls.
Sign-in methods and sessions
You can sign in with email and password or with Google when Google sign-in is enabled for the project. If Google returns an error, Ojava sends you back to the sign-in page with a plain message and keeps the original destination ready, instead of silently dropping you on the public site. The browser session is designed to stay signed in so routine refreshes, reloads, and app navigation do not become a login chore. New email-password accounts require 12 or more characters with lowercase, uppercase, number, and symbol characters. Existing accounts can still sign in with their current password.
The iOS and Android shells use the same account through a PKCE-protected app callback. Ojava accepts only its exact callback address, handles both a closed-app return and an already-open app return, and ignores duplicate or malformed callback deliveries. The app checks the project’s current provider settings before it shows Google, then opens Google in the operating system browser rather than an embedded sign-in view. Closing that browser leaves sign-in retryable. If the session exchange cannot finish, the app returns to sign-in with a retry message instead of leaving setup stuck.
If your account started with email and password, connect Google from Settings > Security and login while you are already signed in. That links Google to the same Ojava account, instead of creating a second empty account or losing your existing records. Completing this action requires identity linking to be enabled for the active project.
Consent management
You choose what Ojava is allowed to do with your records, and you can change your mind at any time. Consent is purpose-specific: authorizing a record import, keeping results in review until you accept them, and any optional sharing are separate, explicit choices, not one blanket agreement. Turning a consent off withdraws it going forward, and Ojava treats a withdrawn consent as a hard stop, the same way it withholds anything you have not actively allowed.
The five confirmations shown when you finish first-run setup are different. They create an immutable, versioned receipt of the exact wellness boundaries you acknowledged at activation. That receipt does not authorize a future import, AI use, or sharing action, and it cannot replace any purpose-specific consent. Those operational permissions remain separate and revocable.
Access controls and your audit trail
Your audit trail shows what has happened to your data: imports, reviews, exports, and changes, each in plain language with a timestamp. It is written to prove traceability without reading like a database log: it never exposes raw table names, internal row IDs, or file internals, just a clear human description of each action. It is your own ledger of how your record has been handled.
Export your data (FHIR and CSV)
You can take your data with you at any time. Export a standards-compliant FHIR file (the format clinicians and other health apps understand) or plain CSV spreadsheets of your results, medications, and wearable metrics. The full health data package also gives scalar food, workout, wearable, symptom, and mood tracker events a generic package-local FHIR Observation form for portability, without exposing raw tracker ids or private notes. Exports run locally and download to your device. Records Ojava recognizes as sensitive are withheld by default and included only if you explicitly opt in, with a visible count of what was withheld. Full detail is on the Exports & sharing page.
Export-all and deletion requests
Beyond the everyday exports, you can request a full copy of your data or delete your account and every record in it. These are your data rights, surfaced as real controls rather than buried in a policy. Account deletion asks you to type a confirmation phrase, then runs immediately and cannot be undone.
You can also stage a narrower request without closing your account, for example deleting selected third-party platform data, imported records, tracker logs, or AI request context. Ojava keeps the requested category, source, date range, export-first reminder, and audit-retention boundary separate from account deletion, because those requests need different review steps.
Sensitive-data authorization
Certain categories (mental and behavioral health, substance-use treatment, reproductive and sexual health, genetic, and HIV-related information) get extra protection: they are withheld from exports and from what Ojava Coach sees unless you explicitly authorize their inclusion. This control is where you make that choice, deliberately and per use, never by default.
Notification preferences
Choose what Ojava can notify you about. Notifications stay in the wellness lane: reminders and encouragement, never a clinical alert about a health metric. Ojava does not monitor you for a condition or push threshold-triggered medical warnings, by design.
Settings also shows a workspace notice digest from your own record state: recent account or record activity, review-queue items, source-file coverage, and consent readiness. Those notices stay inside the signed-in app and point you back to Ojava. You can also enable push reminders from Settings, a generic, PHI-free nudge (never a health value) if you have not logged anything in a while. These reminders stay inside Ojava and do not connect to provider inboxes, lab status feeds, prescription status feeds, or medical alerting systems.
Share Ojava
Your Profile page shows a personal Ojava invite link. Friends get 10% off their first paid month when referral checkout is active, and your card shows aggregate link visits, friends joined, paid memberships, and account-credit totals. It never shows who joined, what they uploaded, or anything about their health. Full details are on the Referrals page.
Note