Privacy Policy

Your health data should stay home.

Rhem is built so that the sensitive things — your readings, your voice, your family's health history — are processed on the device whenever possible, not shipped off to a cloud you can't see.

Last updated: June 3, 2026  ·  Operated by Rhem Labs
⬡ The short version

Rhem uses an onboard AI compute module so that voice, vision, and health-support processing can happen locally on the robot. Because of this design, we do not send your raw health readings, voice audio, or wellness images to third-party AI companies for general model training. Cloud connectivity is used only for the specific features that need it — and we tell you which ones below.

1. Who this applies to

This policy covers the Rhem robot, the Rhem companion app and mini-program, and the rhem.ai website. It applies to the account holder who sets up the device and to each family member whose profile is added to it. If you add a family member's profile, you are responsible for having their permission to do so.

2. Data we collect

Account information

  • Your name, email, and login credentials.
  • Family member profiles you create: name, age or date of birth, gender, nickname, and avatar.
  • Device records, such as your robot's serial number and which account it is bound to.

Health-support data

  • Wellness measurements you capture: blood pressure, heart rate, SpO₂, body temperature, respiratory rate, ECG indicators, and CBC indicator readings.
  • Wellness images captured by the robot's camera when you choose to take them.
  • The history, trends, and reminders built from these measurements over time.

Interaction data

  • Voice requests you make to the robot, and text you type into the app chat.
  • Reminders, intercom usage, and SOS configuration you set up.
  • Device status: battery, network, firmware version, and basic diagnostics.
▲ A note on what Rhem is

Rhem provides health-support and wellness tracking. It is not a diagnostic medical device, and the data it collects is wellness data, not a clinical medical record. Rhem does not diagnose conditions or replace professional medical judgment.

3. On-device processing comes first

Rhem is built around a dedicated onboard AI compute module. This lets a meaningful amount of work — interpreting voice, reading sensor inputs, driving expressions, and running supported AI workflows — happen on the robot itself, closer to you and away from the cloud.

The practical result is that your raw health readings, voice audio, and wellness images are processed locally for these features. We do not hand your health data to third-party AI providers to train their general-purpose models.

4. When data leaves the device

Some features need the internet to work. We want to be precise about which ones, so you can make informed choices:

  • Account sync & family sharing — profiles, reminders, and the health history shown in the app are synced so approved family members can see them.
  • Software updates & diagnostics — firmware updates and device-health signals are exchanged with our backend.
  • Optional cloud AI extensions — certain advanced or text-chat features may route a request to an external AI service. When a feature does this, it is the request you typed or asked — not a bulk export of your health archive.
  • Nearby search & weather — location-aware features query third-party services to return local results.
  • SOS alerts — when triggered, an alert is sent through our backend to your pre-set emergency contacts.

Where a feature can run either locally or in the cloud, we prefer local. Where the cloud is required, we limit what is sent to what the feature actually needs.

5. How we use your data

  • To provide the features you turn on: tracking, reminders, voice Q&A, intercom, family coordination, and SOS support.
  • To show your health history and trends back to you and the family members you approve.
  • To keep the device working: updates, troubleshooting, and customer support.
  • To improve product reliability, using aggregated or de-identified signals wherever feasible.

We do not sell your personal or health data. We do not use your health data to serve you advertising.

6. Who we share data with

We share data only in limited, necessary cases:

  • Family members you approve — the people you add and grant access to.
  • Service providers — vendors who host our backend, deliver updates, or power specific features, bound by contract to protect your data and use it only for the service they provide to us.
  • Emergency contacts — when you trigger SOS, the people you designated.
  • Legal requirements — when we are legally required to respond to a valid request.

7. Sensor & radar data

Rhem's safety sensing uses millimeter-wave radar together with positioning algorithms to support presence, motion, fall-risk, and distress detection — including breathing- and heartbeat-related signals and body-position changes. This is done without a camera, which we chose specifically to protect your privacy.

The robot's cameras are used only for wellness image capture that you initiate, and, optionally, during an active SOS event if an emergency contact you designated chooses to open the camera after answering the alert. The camera is not a continuous surveillance feed.

8. Telehealth & professional care

Connecting to licensed telehealth providers is a planned integrationwe intend to deliver as a software update after the robot ships. When telehealth is available, any information you choose to share with a provider through the app will be handled under the provider's own privacy practices in addition to ours, and we will update this policy with the specifics before the feature goes live.

9. Security & compliance

We protect data in transit and at rest using industry-standard encryption, and we restrict internal access to systems that handle personal or health data.

HIPAA Pending SOC 2 Pending GDPR Aligned

We are actively pursuing HIPAA alignment and SOC 2 certification, both of which are currently pending. Until those processes are complete, we do not claim to be HIPAA-certified or SOC 2-certified, and we will state plainly on this page when each is achieved. Because we operate an office in Germany and handle health data, we design our practices to align with GDPR.

10. Your rights & controls

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. From the app you can:

  • View, edit, and remove family member profiles.
  • Review and delete stored measurements and history.
  • Turn intercom, location features, and optional cloud AI extensions on or off.
  • Unbind the device or transfer it to a new owner.

To make a formal data request, email privacy@rhem.ai. We will verify your identity before acting and respond within the timeframe required by your local law.

11. Children & dependents

Rhem is intended to be set up and managed by an adult account holder. A profile may be created for a dependent in the household, but it is managed by the responsible adult, who is accountable for that person's data. We do not knowingly let minors create their own independent accounts.

12. International transfers

Rhem Labs operates across regions, including an office in Germany. Where data is transferred across borders, we use appropriate safeguards consistent with applicable law to protect it.

13. Changes to this policy

We will update this page as the product evolves — particularly as the telehealth integration launches and as our HIPAA and SOC 2 processes complete. Material changes will be reflected in the "last updated" date above and, where appropriate, communicated in the app.

14. Contact us

Questions about privacy or your data? Reach our team at privacy@rhem.ai or visit our contact page.