Personal health intelligence needs explicit consent.
InVivo is designed around opt-in capture, derived summaries where possible, clear permission prompts, and no silent background collection before consent.
phone, avatar, connectors, cloud mirrors
raw audio/video is not retained by default
small-cell suppression for reporting
not emergency care or diagnosis
Local-first where possible
Sensitive phone, meal, and physiology workflows prefer local processing, derived summaries, and recoverable local data stores.
Optional avatar capture
Face, voice, persona build, and chat setup are opt-in. Onboarding can be completed without creating a twin.
Opt-in connectors
Apple Health, CGMs, wearables, rings, and cloud mirrors are explicitly connected by the user.
No raw media by default
Phone sleep and Bio Scan focus on derived summaries, not retaining raw audio or video.
Clear medical boundary
The app supports insight and clinician conversations; it is not emergency care or a diagnosis engine.
Aggregate learning should not become surveillance.
The population-health layer keeps consent scope, privacy class, source receipts, retention policy, prohibited use, and small-cell reporting rules explicit.
Scoped sharing
Users decide which data can contribute to aggregate learning and which context remains personal.
Small cells withheld
Cohort reports are suppressed when groups are too small for safe aggregate display.
Auditable evidence
Every event can carry source, confidence, method, and retention metadata.
No medical shortcuts
Outputs are withheld when data is unsafe, sparse, or outside the wellness and care-conversation boundary.