Privacy at Shugo
Shugo holds your health measurements and your medical records. This page says what it collects, why, where it lives, who can see it, and how to take it out or delete it. It describes what Shugo does today, not what it plans to do.
Effective 10 August 2026.
Shugo is early, and one person runs it
Shugo is built and operated by one person. There is no company behind it yet, no security team, and no external audit. That is worth knowing before you put your medical history into it.
What follows is accurate as of the date above. As Shugo grows, this page will change, and the effective date will change with it. If something here stops being true, the page is wrong and you should tell me.
What Shugo collects
Files you import
When you import a file, Shugo reads the health data inside it. That is usually one of two things: an Apple Health export, which contains measurements your phone and watch have recorded, or a copy of your records downloaded from a patient portal, which contains what your clinicians have written down.
From records, Shugo reads your visits, your diagnoses, your medications, allergies, immunisations, procedures, lab and vital sign results, scheduled appointments, and the notes your clinicians wrote. Those notes are free text and often contain names, dates, and places. Shugo keeps them because the narrative a specialist actually reads is the useful part, and it keeps a copy of the original document so that improvements to how Shugo reads it can be applied to data you have already imported without you uploading anything again.
Wearable accounts you connect
If you connect a Whoop account, Shugo asks Whoop for two kinds of access and nothing else:
- read:recovery. Your daily recovery records. These contain your resting heart rate, your blood oxygen percentage, your heart rate variability, and a skin temperature reading. Shugo stores the first three. It does not store skin temperature, because a wrist reading is not a body temperature and putting it beside one would be misleading.
- read:sleep. Your sleep records. These contain your breathing rate while asleep and how long you spent in each stage of sleep, including light, deep, REM, awake, and time in bed, along with whether a given sleep was a nap.
Shugo does not ask for your Whoop profile, your workouts, or your body measurements. It does not store Whoop's recovery score, sleep performance score, or strain score, because those are Whoop's own calculations rather than measurements of you.
When you connect an account, Shugo keeps a key that lets it fetch new readings without asking you again. That key is encrypted.
Your account
Your first and last name, your email address, your password, your timezone, and whether you prefer metric or imperial units. Your password is stored as a hash, which means Shugo cannot read it and cannot tell you what it is.
Shugo also records when your data was read or written, and by whom. See who can see your data, below.
Why Shugo collects it
To show you your own measurements, and to trend them against your own history. That is the whole purpose. Shugo compares you to your own past rather than to a population, so your history is not a nice extra, it is the thing that makes the product work at all.
Shugo does not diagnose, predict, or recommend treatment. It describes what has changed in measurements you already have.
Where your data is stored, and who else touches it
Three companies are involved in running Shugo:
- Neon hosts the database where your measurements, records, and account live.
- Vercel hosts the application itself and serves the pages you look at.
- Whoop is a source, not a destination. If you connect a Whoop account, Shugo reads from Whoop. It never sends your data to Whoop.
Your data is encrypted in transit and at rest. This page does not go into detail about how Shugo is built, because a public description of its security would mostly be useful to somebody attacking it.
Shugo has not been certified or audited against any standard, and it does not claim to be. Formal agreements with these companies about handling health data are not yet in place. That work is planned and is not finished, which is part of why Shugo is early.
Who can see your data
You can see everything. That is a design rule, not a feature: any interpretation Shugo shows you sits on top of your raw data, and the raw data is always one tap away.
A clinician can see your data only if you grant their organisation access, and you can withdraw that at any time. Access flows from you outward, never the other way around.
Every read and every write of your data is recorded in an audit log, with who did it, what they touched, and when. That includes any access by me. The audit log exists so that casually browsing patient data is not something that can happen quietly.
What Shugo will never do with your data
- Shugo does not sell your data. Not now and not later.
- Shugo does not use your data for advertising, and shows no adverts.
- Shugo does not share your data with employers or insurers, and will not, whoever asks.
- Shugo does not use your data to train models for anybody else's benefit.
If Shugo ever wants to share your data for research, that will be a question you are asked and can decline, with a clear explanation of what is shared and with whom. It will never be assumed from your having signed up.
No tracking on signed-in pages
No analytics, advertising, or tracking scripts run on any page you see once you are signed in. This is enforced by the server, which blocks scripts from anywhere else on those pages, rather than by anybody remembering not to add one.
Shugo does not use tracking cookies. The one cookie it sets keeps you signed in, and it is removed when you sign out.
Taking your data out, and deleting it
Both of these live in Settings once you are signed in.
Export. Download your record gives you one file containing everything Shugo holds for you: every measurement with the device or document it came from, everything Shugo has calculated and the measurements behind it, your imports, and your consents. The file is the record itself, not a summary of it.
Deletion. Delete your account removes your data from the database. It does not hide it, flag it as deleted, or keep a copy for Shugo's use. There is a test in the code whose only job is to prove the rows are actually gone afterwards.
One honest limitation. Database backups exist so that a failure does not lose everybody's data, and a backup taken before you deleted your account still contains it until that backup ages out. Backups are not browsable and are not used to look anything up. If you need deletion confirmed in writing once the backups have rotated, write to me and I will confirm it.
How long Shugo keeps things
Your data stays until you delete it. Shugo does not expire your history, because the history is what a baseline is made of, and a measurement from four years ago is often the most useful one you have.
Disconnecting a device. If you disconnect Whoop, Shugo stops fetching new readings and withdraws its access at Whoop. The readings already imported stay. They are your measurements, and part of your history, so deleting years of it because you unplugged a watch would lose exactly what Shugo exists to keep. If you want those readings gone as well, deleting your account removes them.
Questions
Write to privacy@shugo.health with anything about privacy, including a request to see what Shugo holds, to correct something, or to have your data deleted. A person reads that address, and that person is me.