Guides for using Ojava. Start reading
Ojava Docs
Read your own datawithout losing the thread

Guides for bringing records in, reading a lab panel marker by marker, following a wearable trend, working with Ojava Coach, exporting everything again, and knowing exactly where the wellness boundary sits.

35 guides, kept in step with what the product actually does.

Privacy & your data

Your records are yours. Consent is explicit and reversible, your health data is never used for advertising or model training by default, and you can export or delete everything.

Your data is private to your account and access-controlled. Consent is recorded per purpose, authorizing an import, keeping results in review, any optional sharing, rather than as one blanket agreement, and you can withdraw any consent at any time from Settings. Ojava works only from records you choose to bring in; it never pulls from a provider network or patient portal on its own.

When you download a full health data package, Ojava can include a consent receipt ledger. It shows which purpose-specific consent receipts are active, denied, revoked, missing, or ready for review, while redacting direct file names, paths, URLs, contact details, tokens, and raw scope values. The receipt ledger is provenance only; it does not create sharing access or authorize a new import.

Nothing enters your record without your review

Imported results land in a review queue and stay there until you accept them. Only accepted results become part of your record and are visible to Ojava Coach, so a stray or misread upload never quietly becomes “your data.” Rejected and pending rows are kept out of the assistant’s context.

No ad tracking, no selling, no training by default

Your health data is not used for advertising, is not sold, and is not used to train models by default. Ojava’s job is to help you understand your data, not to monetize it.

Food photos are the one exception. When you submit a photo to scan a meal or a nutrition label, that photo may be used to improve Ojava’s food-recognition feature. Every other record category, labs, imaging, medications, wearables, notes, and every other health record, is never used to train any model, under any circumstance.

What Ojava collects

The table below is the product-level disclosure Ojava uses to keep app-store, account, and privacy copy aligned. It separates data needed for your account from data Ojava does not collect or does not link to you.

In the signed native app, Apple Health and Health Connect access is optional and read-only. If you grant permission, Ojava accesses only the health and wearable categories you approve, such as steps, heart rate, sleep, HRV, workout sessions, body metrics, blood oxygen, blood pressure, glucose, and related wellness readings. Those rows are stored in your private Ojava account to show trends and context. Ojava does not write back to Apple Health or Health Connect, does not use health data for advertising, and does not use these readings for real-time monitoring or alerts.

Google Health

Google Health is an optional, read-only connection. If you choose to connect it, Ojava requests only the activity and fitness, health measurement, and sleep categories shown in the consent screen. Ojava stores the readings you authorize in your private account so it can show your timeline, trends, reports, and record-grounded Coach answers. It does not write data back to Google Health, monitor you in real time, or use the connection for advertising, credit, surveillance, or model training.

A Coach request may send the minimum relevant Google Health-derived context to Ojava’s model provider solely to generate the answer you asked for. Provider response storage is disabled for those requests. Ojava does not let people read Google Health data unless you affirmatively ask for support involving specific data, access is necessary for security or legal compliance, or the data is aggregated for lawful internal operations. Ojava does not sell the data or transfer it to data brokers, advertising platforms, or information resellers. Ojava’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Disconnecting stops future Google access and removes Ojava’s stored authorization. Previously imported readings remain until you choose Delete Google Health data. That control permanently removes Google Health readings, the connection record, and Coach replies created from those readings while preserving unrelated conversation content and other provider data. Ojava attempts Google revocation first, but a Google outage cannot prevent deletion from Ojava. You can also remove Ojava from your Google Account’s connected-apps page. Google Health connection metadata and normalized readings are included in your Ojava export while they remain in your account.

CategoryStatusPurposeBoundary
Health and fitness dataLinked to your accountPowers records, reports, Ojava Coach context, and user-controlled exports.Private to the account, held for your review before use, and never used for advertising.
PurchasesLinked to your accountSupports paid membership checkout, subscription status, receipts, and account access.Stripe manages payment details. Ojava stores membership state, not card numbers, and makes no HSA/FSA claim.
Contact infoLinked to your accountUsed for account access, support, newsletter signup when requested, and optional sharing workflows.Not used to personalize health marketing and not sent with records unless you choose to share.
User contentLinked to your accountIncludes uploaded files, messages, feedback, notes, and manually entered trackers.Record content is excluded from analytics scraping and model training by default.
IdentifiersLinked to your accountOpaque account ids connect records, audit events, consent, exports, and billing state.Analytics use opaque ids rather than names, emails, or record content.
Usage dataLinked to your accountPrivacy-hardened product analytics help identify broken flows and improve the experience.Not used for advertising, not sold, and configured to avoid page or text capture that could carry health details.
DiagnosticsNot linked to youCrash and performance data help debug the app without attaching raw health records.Diagnostic telemetry carries safe metadata only, never prompt text, record snapshots, or answers.
Third-party trackingNot collectedOjava does not use health data for ad tracking.Ojava does not sell health data, use health data for advertising, or train models on health data by default.

Analytics to improve the product

Ojava uses privacy-hardened product analytics (including how the app is used) to understand what is working and improve the experience. This is never used for advertising, never sold, and never used to train models. It is hardened for a health app: your IP address is anonymized, you are identified only by an opaque account id (never your name, email, or any record content), and the analytics are configured not to scrape on-screen text or page addresses that could carry your information. Session replay is limited to an explicit set of signed-out public reading pages. It never runs in an authenticated account, on a shared-record link, during sign-in, or on a public tool that accepts personal or health inputs. Authenticated product analytics is limited to coarse, content-free named events and sanitized pageviews.

When you send feedback, use a thumbs up or thumbs down on an Ojava Coach response, or the floating feedback button, Ojava stores that note so the product team, and an automated build agent that can look into real bugs and ideas, can review it and improve the app. The feedback button never asks for health details, only the product issue or idea, and the optional name field is stored only if you choose to add it, so the team can credit you when a fix or idea ships. Response ratings can include an internal request id that links back to privacy-safe model metadata like mode, latency, token counts, and finish reason, but not the prompt, your record snapshot, or the answer text itself.

Newsletter emails

If you join the Ojava newsletter from the public site, homepage popup, free resource offer, guide, calculator, challenge, or workshop signup, Ojava stores your email address only for product updates and practical health-data resources. Newsletter and resource signup does not include your records, lab values, messages, or health history, and Ojava does not use health data to personalize marketing emails. If the main signup table is temporarily unavailable, the request can be routed through Ojava’s internal operations queue so the signup is not lost.

Sensitive categories are protected

Ojava recognizes five categories of records as sensitive and protects them by default: mental and behavioral health, substance-use treatment, reproductive and sexual health, genetic, and HIV-related. Records in these categories are withheld from exports, shareable links, and what Ojava Coach sees, and are included only on an explicit, per-action opt-in. The protection fails safe: when in doubt it withholds, because hiding a benign record is better than leaking a sensitive one. See Exports & sharing for how the opt-in works.

Your audit trail

Every action on your data, imports, reviews, exports, and changes, is recorded in a plain-language audit trail you can read in Settings. It proves traceability without exposing raw database internals: no table names, no internal row IDs, just a clear description of what happened and when. Health data package exports use a separate machine-readable audit ledger with package-local event references, object classes, chronology, source-window status, and digest-reference presence instead of raw audit ids, raw object ids, table names, arbitrary metadata values, or record contents.

Export and deletion

You can take your data with you any time, as a standards-compliant FHIR file or CSV spreadsheets, and you can request a full copy or request deletion of your account and records from Settings. These are real controls, not a buried policy. See Exports & sharing and Account & data controls.

Settings also separates selected-data requests from account deletion. If you want to remove only a category such as imported files, tracker logs, third-party platform data, or AI request context, Ojava can stage that scope for review, remind you to export first, and keep required audit or consent evidence distinct from the data selected for deletion.

Washington consumer health data (My Health My Data Act)

Washington’s My Health My Data Act covers a broad set of health-adjacent information beyond traditional medical records. The consumer health data categories Ojava collects from Washington residents include lab and biomarker results, wearable and fitness metrics (such as steps, heart rate, sleep, and HRV), food and nutrition logs, symptom, mood, and stress entries, menstrual cycle data, medications and supplements, body metrics, and any other health record you choose to import or log.

Ojava uses this data only to power your own records, reports, Ojava Coach context, and the exports described above. It is never sold, never used for advertising, and never used to train a model, except the disclosed food-photo carve-out described under “No ad tracking, no selling, no training by default”. Ojava does not use precise location data to identify or track anyone seeking health care services, and does not geofence health care facilities.

Consistent with the explicit, reversible consent model described above, Ojava collects consumer health data only for the purpose you authorize (an import, a logged entry, an optional share), not as a blanket authorization to use it for anything else. Washington residents have the right to confirm whether Ojava processes their consumer health data, to access it, to withdraw consent for its collection or sharing, and to request deletion of it, including from Ojava’s service providers. Use the export and deletion controls in Account & data controls to exercise these rights, or contact hello@ojava.health with a Washington consumer health data request.

Note

This section is a disclosure addendum describing how Ojava’s existing consent, export, and deletion controls apply to Washington’s My Health My Data Act. The exact legal language is pending final legal review and may be refined as that review completes.

Ojava participates in the Amazon Associates program and may earn a commission from qualifying purchases made through affiliate links on our site. These commissions help support the product and cost you nothing extra. Links to Amazon are marked with a "sponsored nofollow" attribute for transparency, and a product suggestion is never a medical recommendation.

Ojava referral links are first-party. They record aggregate link visits, signups, and paid memberships so your Profile card can show progress and account credit. They do not show you who joined, what that person uploaded, or any health data. Fraud fingerprints are HMAC-only when a server secret is configured; without that secret, Ojava stores no IP or user-agent fingerprint.

Note

Ojava is not a HIPAA covered entity. It is a private, consent-based General Wellness workspace for your own records. Ojava does not provide clinical services or bill insurance, and it does not present its privacy controls as a substitute for an independent provider’s legal duties.
Was this page helpful?
Keep reading

Read the guide,then bring your own record

Every page here describes something you can do with data you already have: a lab PDF sitting in an email, an export from a watch, a photograph of dinner. Nothing joins your record until you have seen it and accepted it.

  • Plain language first

    A guide says what a marker or a trend generally means in the words a person actually uses, before it suggests anything at all.

  • The boundary is written down

    Ojava organizes, explains, trends, and prepares you for a visit. It never diagnoses, prescribes, doses, orders labs, or supplies a clinician.

  • Every way in has a way out

    Wherever a guide describes bringing data in, it also describes taking it back out: export, share with someone you choose, or delete.

Ojava is a General Wellness product. It is not a medical device, it does not give medical advice, and it does not replace care from your own clinician. If something feels urgent, contact a clinician or your local emergency number.