跳到主内容 · Skip to content

Privacy · 隐私政策

Privacy Policy

Last updated: August 2026

1. Local-first by design

Finuwell is built on a local-first philosophy. Everything you enter in the health report — age band, symptoms, goals — is stored exclusively in your browser's localStorage by default. None of it is automatically sent to any server.

Share links encode health parameters in the URL fragment (the part after #), which browsers handle locally and never appear in our server logs.

2. What we collect

While browsing (no account needed)

  • Anonymous analytics: We use Vercel Analytics to measure aggregate page traffic and region breakdowns. No personally identifiable information is collected.
  • Standard HTTP logs: Our hosting provider (Vercel) retains standard server logs (IP, path, timestamp). We do not store or correlate these ourselves.
  • Rate-limit counters: To prevent abuse we keep a short-lived per-IP request count in Upstash Redis. Counts and time windows only — never request content — and they expire automatically.

Once you sign in (optional)

  • Account details: your username and a bcrypt hash of your password. We never store, and cannot recover, the password itself.
  • Session records: a random session token, your browser user-agent, and a hashedIP address — used for “sign out everywhere” and for investigating abuse.
  • Reading progress: which stories and chapters you opened and how long you stayed. These are public page addresses, not anything you typed, and they let you pick up on another device.

When you use the assistant

  • Your question is sent to a third-party model provider (see section 5) to generate an answer. That is what makes the assistant work. Please do not include your name, contact details, or medical record numbers in a question.
  • We ourselves record only categorical operating metrics: question type, outcome category (answered / declined / no results), how many public content entries were retrieved, latency, and citation-check results. Neither your question nor the answer is stored.

We do not use third-party advertising trackers, behavioral analytics, or cross-site cookies.

3. Health data protections

  • Local by default: report inputs stay in your browser's localStorage. Our servers never receive them.
  • You can permanently erase all local data at any time using the “Clear all data” button on the report page.
  • Shared report links pass health parameters in the URL hash only.

The one exception: you tick “save this report”

Only after you sign in and explicitly tick the boxdoes that one report's input and result get saved to our database, so you can revisit it under “My reports”. Even then:

  • Your answers are stored encrypted (AES-256-GCM; the key lives with the server, not alongside the database). A copy of the database on its own is unreadable.
  • Leave the box unticked and nothing is uploaded — the report works the same.
  • Delete a single report from account settings, or delete your account — which also deletes every report and all reading progress.

About the assistant: it is a separate path. What you type there is sent to a third-party model provider (section 5) and is not covered by the “local by default” rule above. When asking about your own body, describe the symptom rather than yourself.

4. Cookies and local storage

  • localStorage: Stores your report inputs, theme preference, bookmarks, and your reading marks on the map (which stories and chapters you opened — public page addresses only, nothing you typed, and it never leaves this device). Cleared when you clear browser data, or with the button below.No reading marks on this device
  • sessionStorage: Temporarily stores Atlas navigation state (zoom position, etc.). Automatically cleared when the browser session ends.
  • Functional cookies: Used only for language preference (zh/en). No tracking cookies.
  • About the name: the two cookies below still begin with fitnuhealth. The site was renamed to Finuwell in August 2026 and these names were deliberately left alone — they are the keys to data in your own browser, and renaming them would make your saved bookmarks, reading marks and report draft vanish without warning. They are set by this site, not a third party.
  • fitnuhealth.session (signed-in only): an encrypted session token that keeps you signed in. Expires after 30 days; removed when you sign out.
  • fitnuhealth.trial: how many free assistant questions you have left. It holds a single number and no identifier — we cannot use it to recognise you or link two visits. Expires after a year; clearing browser data resets it.

5. Third-party services

  • Vercel: our hosting provider. See their Privacy Policy.
  • SiliconFlow: provides the language-model inference behind the assistant. Your question is sent to them to generate an answer. Your account, reports, and identity are not sent with it.
  • Neon: managed database. Used only once you create an account — it holds your account, sessions, reading progress, and any report you chose to save (with the input half encrypted).
  • Upstash: managed Redis, used for rate limiting. Per-IP counts and time windows only, never request content.

Apart from the providers above, which are required for the site to function, we do not sell, share, or trade your data with any third party, and we do not use it for advertising or profiling.

6. Minors

This site is intended for adults 18 and older. We do not knowingly collect personal information from minors. Contact us if you believe a minor's data has been inadvertently collected.

7. Policy changes

Material changes will be reflected by updating the “Last updated” date at the top of this page. We will provide prominent notice of significant changes.

8. Contact

For privacy questions, email huahaoshang2000@gmail.com. We respond within 30 business days.

← Back to Atlas