HealthPrompt 🌸

Privacy Policy

Effective September 5, 2026

HealthPrompt is operated by Palmetto Ridge Holdings LLC through Palmetto Ridge Media Group. This policy covers the public website at healthprompt.pro and its embedded Streamlit application.

Information you choose to provide

You may type text prompts about general wellness, fitness, nutrition, mindfulness, or healthy habits. A prompt may also contain health-related information that you voluntarily choose to type. HealthPrompt does not need your name, medical-record number, insurance information, account credentials, precise location, or other direct identifiers. Please do not include those details or other highly sensitive information.

The current application accepts text only. It does not provide an account system, camera input, microphone recording, location collection, or file upload.

Conversation processing and session state

The application keeps the current conversation in Streamlit session state so it can display prior messages and provide conversational context. On each turn, the system instructions, prior prompts and answers from that session, and the new prompt are sent to OpenAI's Chat Completions API using the gpt-4o-mini model. In practical terms, the full current conversation is transmitted on each new turn. Generated answers are returned through Streamlit and added to the same session state.

The repository defines no HealthPrompt user-account database or persistent chat-history database. Ending or expiring a Streamlit session removes the application's ability to continue that session, but hosting and API providers may retain technical logs or request data under their own settings, legal obligations, and policies.

OpenAI processing

HealthPrompt uses a server-side OpenAI API credential; the credential is not sent to the browser. Requests explicitly set store=False, so the application does not ask the Chat Completions API to create stored application state. This does not prevent all provider processing or logging. OpenAI may retain prompts, outputs, and related metadata for safety and abuse monitoring according to the account configuration and OpenAI's current data-control policies. HealthPrompt does not represent that Zero Data Retention or a healthcare Business Associate Agreement is enabled.

Website analytics

The public healthprompt.pro pages use Google Analytics 4 property G-FRE85K7MC4 for basic website measurement. Depending on Google's services, configuration, consent controls, and your browser settings, Google Analytics may process page interactions, approximate location derived from IP address, browser and device information, timestamps, referrer information, cookie or device identifiers, and related usage data.

The site code does not configure advertising personalization or targeted advertising. Google Analytics processing is separate from the content of prompts submitted inside the embedded Streamlit application.

Hosting, cookies, and technical logs

The public wrapper is hosted through Namecheap/cPanel infrastructure. The embedded application is hosted by Streamlit Community Cloud. These providers may process IP addresses, request timestamps, browser and device details, security events, and ordinary server or proxy logs needed to operate and protect their services.

Google Analytics may use analytics cookies or similar identifiers. Streamlit may use operational session or proxy cookies; a proxy-tracking-id cookie was observed when the Streamlit application was accessed directly. Cookie behavior can vary by browser, embedded context, and provider configuration.

How information is used and shared

Information is used to provide the requested response, maintain the current session, operate and secure the services, measure public-page use, troubleshoot problems, and comply with law. Prompt content is transmitted to OpenAI and processed through Streamlit's hosting infrastructure. Technical and analytics information may be processed by the relevant hosting and analytics providers. HealthPrompt does not sell prompt content and does not use it to provide targeted advertising.

Retention and choices

HealthPrompt does not define a durable account or chat-history store. Provider logs and analytics data are retained according to provider configuration and policy. You may avoid submitting prompts, omit identifying details, block analytics through browser controls or extensions, and close the application to end your active use.

Health information and service boundaries

HealthPrompt is a general informational service, not a healthcare provider or medical-record system. No HIPAA compliance, medical-device status, or healthcare business-associate relationship is claimed. Do not use HealthPrompt to store or transmit protected health information or to obtain emergency or individualized medical care.

Security and policy changes

Reasonable measures are used to keep the provider credential on the server and out of public source and browser code. No internet service can guarantee absolute security. This policy may be updated when the product, providers, or data practices change; the effective date will be revised when material changes are published.

Contact

Privacy questions may be sent to anthony@palmettoridgeholdings.com.