InVivo
Privacy

Personal health intelligence needs explicit consent.

InVivo is designed around opt-in capture, derived summaries where possible, clear permission prompts, and no silent background collection before consent.

Capture
opt-in

phone, avatar, connectors, cloud mirrors

Media
derived

raw audio/video is not retained by default

Population
>=3

small-cell suppression for reporting

Boundary
clear

not emergency care or diagnosis

Local-first where possible

Sensitive phone, meal, and physiology workflows prefer local processing, derived summaries, and recoverable local data stores.

Optional avatar capture

Face, voice, persona build, and chat setup are opt-in. Onboarding can be completed without creating a twin.

Opt-in connectors

Apple Health, CGMs, wearables, rings, and cloud mirrors are explicitly connected by the user.

No raw media by default

Phone sleep and Bio Scan focus on derived summaries, not retaining raw audio or video.

Clear medical boundary

The app supports insight and clinician conversations; it is not emergency care or a diagnosis engine.

Population privacy

Aggregate learning should not become surveillance.

The population-health layer keeps consent scope, privacy class, source receipts, retention policy, prohibited use, and small-cell reporting rules explicit.

Consent

Scoped sharing

Users decide which data can contribute to aggregate learning and which context remains personal.

Suppression

Small cells withheld

Cohort reports are suppressed when groups are too small for safe aggregate display.

Source receipts

Auditable evidence

Every event can carry source, confidence, method, and retention metadata.

Boundaries

No medical shortcuts

Outputs are withheld when data is unsafe, sparse, or outside the wellness and care-conversation boundary.