Full review
Health-GPT CAIHL draft report
Evidence-linked HugoScore draft report for a health AI tool that affects patients.
HugoScore CAIHL Draft Report: Health-GPT
- Status: Draft for human review
- Last reviewed: 2026-08-15
- Review method: Public-source review of the health-gpt.org homepage, sample-record demo page, and privacy policy, plus the iTunes Store lookup record and App Store listing for the iOS app, and searches for press coverage, funding records, company registrations, and independent evaluations. The linked Terms of Use page returned a 404 to automated retrieval and could not be reviewed. The Google Play listing could not be reliably retrieved. No account creation, document-upload test, extraction-accuracy inspection, vendor interview, patient interview, security audit, accessibility audit, independent validation, or legal/regulatory determination was performed.
- Service: Health-GPT
- Vendor: Omni Timeline LLC
- URL: https://health-gpt.org/
- Category: Patient care navigation and health copilot AI
1. Executive Summary
Health-GPT is a free mobile app from Omni Timeline LLC that asks patients and caregivers to upload medical documents, screenshots, or photos, extracts the key details into a chronological health timeline, answers questions about the record in the user's preferred language, and generates questions to bring to the next doctor visit. The pitch is comprehension and preparation: "Understand your medical history. Prepare better for your next doctor visit." A downloadable fictional cardiology note lets prospective users try the workflow before trusting it with real records.
Under CAIHL, the design is squarely patient-directed. The patient chooses the app, supplies the records, controls which timeline entries are private (the app states it will not use private entries when generating answers), and can delete individual entries or the whole account, with permanent deletion within seven days. The privacy policy states plainly: "We do not train AI models on your personal data."
The caveats are about verification, not intent. The AI provider and subprocessors behind the extraction and chat are unnamed. The privacy policy grants access and deletion but documents no correction or export rights. The linked Terms of Use returned a 404 during this review. The company has essentially no public footprint: no named team, no address, no press, no funding records, and a single App Store rating. And the iOS privacy label claims "Data Not Collected," which is difficult to reconcile with the vendor's own privacy policy describing server-side storage and retention of uploaded health records until deletion.
- Agency posture: Potentially agency-expanding, with vendor-opacity and disclosure caveats
- Agency axis position: 80 of 100
- Confidence: Low draft, official sources only
2. CAIHL Question
Who does Health-GPT serve?
Health-GPT serves patients and family caregivers who choose the app to understand their own records and prepare for visits, especially people weighing treatment options, managing multiple medications, or seeing multiple specialists. It also serves Omni Timeline LLC and whatever unnamed AI and infrastructure vendors process the uploaded records. The app is currently free with no disclosed business model, so the vendor's economic interest cannot be evaluated.
CAIHL classification: Patient-directed, vendor-hosted record-comprehension and visit-preparation AI.
3. What The Service Does
The workflow has three steps. The user uploads medical documents, screenshots, or photos, including progress notes and discharge summaries. Health-GPT extracts what it judges important and assembles a timeline of symptoms, tests, treatments, medications, and visits. The user can then ask questions "in any language" and get answers in their preferred language, and the app generates questions to ask the doctor at the next visit.
Users can mark timeline entries as private, and Health-GPT states it will not use those entries when generating answers. The iOS app launched April 13, 2026, is free with no in-app purchases listed, and was last updated August 8, 2026 ("Improved the chat quality"). The App Store listing states the app is not for mental health, wellness activities, or pregnancy-related care, and that the company is unaffiliated with OpenAI despite the "GPT" name.
4. Patient-Impact Pathway
1. A patient or caregiver downloads the free app and uploads records as documents, screenshots, or photos. 2. Unnamed AI systems read the uploads and extract symptoms, tests, treatments, medications, and visits into a timeline. 3. The user reviews the timeline, marks sensitive entries private, and asks questions about their history in their preferred language. 4. The app generates questions for the next appointment, and the user walks in better prepared. 5. Agency depends on extraction accuracy the user can only check against original documents, on unnamed processors handling the records, and on the vendor's undocumented correction and export routes.
5. Evidence Table
| Source | Evidence | CAIHL relevance |
| --- | --- | --- |
| Health-GPT homepage, accessed 2026-08-15: https://health-gpt.org/ | Upload documents/screenshots/photos; timeline of symptoms, tests, treatments, medications, visits; question generation for visits; "Ask in any language"; private entries excluded from answers; "Data encrypted in transit"; "Data deletion request supported"; repeated "not a substitute for professional medical advice." | Supports product identity, patient-directed purpose, visibility, and clinical-boundary findings. |
| Sample-record demo page, accessed 2026-08-15: https://health-gpt.org/try-it-yourself | Downloadable fictional two-page cardiology progress note "for demonstration only," letting users test before uploading real records. | Supports informed trial before real data is shared. |
| Privacy policy, accessed 2026-08-15: https://health-gpt.org/privacy-policy | Entity named as Omni Timeline LLC. Collects uploaded health content, notes, generated content, and technical data. "We do not train AI models on your personal data." Encryption in transit (HTTPS), secure storage, access controls. Technical logs kept up to 30 days; user content until deletion. Entries deletable anytime; account deletion permanently removes data within 7 days. Not for children under 13. No named subprocessors, no correction or export rights, no jurisdiction, no effective date, no HIPAA mention. | Core data-governance and rights evidence, including the disclosure gaps. |
| iTunes Store lookup record, accessed 2026-08-15: https://itunes.apple.com/lookup?id=6758103804 | Seller Omni Timeline LLC; free; Health & Fitness; released 2026-04-13; version 1.3.2 on 2026-08-08 ("Improved the chat quality"); 17+ rating; English; iOS 15.1+. | Confirms vendor identity, pricing, and product recency. |
| App Store listing, accessed 2026-08-15: https://apps.apple.com/us/app/health-gpt/id6758103804 | Privacy label states "Data Not Collected." Listing states the app is not for mental health, wellness, or pregnancy-related care, that data is not shared or used for model training, and that the company is unaffiliated with OpenAI. One rating at time of review. | Supports scope boundaries and the privacy-label discrepancy finding. |
| Terms of Use link, attempted 2026-08-15: https://health-gpt.org/terms-use | Returned a 404 to automated retrieval. | The legal boundary, liability, and dispute terms could not be verified. |
| Press, funding, registry, and app-store searches, 2026-08-15 | No press coverage, funding records, team pages, or independent evaluations of Health-GPT by Omni Timeline LLC were identified. Several unrelated products also use the HealthGPT name, including a Stanford open-source project and multiple chatbot apps. | Establishes the thin public footprint and a name-confusion risk. |
6. Mixed HugoScore Profile
Who does this AI serve?
Patient-directed, vendor-controlled. Patients and caregivers choose the app, supply the records, and control privacy per entry. The vendor and its unnamed AI processors sit in the pipeline, and the free app's business model is undisclosed, so the economics behind the service cannot be evaluated.
Can patients tell AI is involved?
Yes. AI is the product's explicit identity, from the GPT-styled name to the marketed extraction and chat features. The specific models and providers behind it are not named.
Can patients meaningfully choose?
Yes, currently free. Use is voluntary, the app costs nothing with no in-app purchases listed, a fictional sample record allows a trial before real data is uploaded, and deletion is available per entry and per account. The undisclosed business model is the caveat: users cannot evaluate what sustains a free service holding their medical records.
Can patients correct or challenge what the AI produces?
Partial. Users can delete entries and mark them private, and originals stay in the user's hands for comparison. No public materials document how to correct a wrong extraction, a misdated event, or a misread medication, and the privacy policy grants access and deletion but is silent on correction and export.
Does it help patients understand or act?
Yes, for comprehension and visit preparation. Turning scattered documents into a timeline, answering questions in the user's own language, and generating questions for the next appointment are direct CAIHL-style supports for reflection and strategic action.
Who is left out or burdened?
The digitization burden stays with the patient, who must obtain and upload their own records. The app is iOS 15.1+ and English-only in the interface even though answers are multilingual. It is rated 17+, excludes children under 13, and declares itself unsuitable for mental health, wellness, and pregnancy-related care. Caregiver marketing is not matched by documented proxy or shared-access controls, and accessibility conformance is not disclosed.
What happens to patient data?
A clear no-training pledge above an opaque pipeline. The policy states no training on personal data, encryption in transit, technical logs capped at 30 days, content retained until the user deletes it, and permanent account deletion within 7 days. It names no AI provider or subprocessors, no jurisdiction, no effective date, and no export right. The iOS privacy label claims "Data Not Collected," which conflicts with the policy's own description of server-side storage, and the absence of any HIPAA claim is likely accurate for a direct-to-consumer app but leaves users outside HIPAA's protections.
Are the clinical boundaries clear?
Clear, with an unverified legal layer. The product repeats "not a substitute for professional medical advice," positions itself as informational preparation rather than diagnosis, and excludes mental health and pregnancy use. The Terms of Use, where liability and dispute terms would live, returned a 404 during this review.
Who defined what good looks like?
The vendor, with no visible external input. No patient co-design, advisory board, independent evaluation, peer-reviewed evidence, or named team was found. The company's public footprint is the website, the app listings, and a support email address.
7. Key Unknowns
- Which AI models and providers process uploaded records, under what retention and training restrictions.
- The full Terms of Use, including liability caps, dispute resolution, and content licenses.
- The business model behind a free app holding medical records, and what happens to data if the company is sold or shuts down.
- Whether a correction workflow exists for extraction errors, and whether records or the assembled timeline can be exported.
- Where data is processed and stored, and under which jurisdiction.
- Why the iOS privacy label claims "Data Not Collected" while the privacy policy describes retained server-side content.
- Encryption at rest, security attestations, penetration testing, and breach history.
- The verbatim FAQ answers, which are rendered client-side and were not retrievable.
- Founders, team, funding, and corporate history of Omni Timeline LLC.
- The Google Play listing's data-safety declarations.
- Caregiver and proxy governance, accessibility, and non-English interface support.
- Any independent evaluation of extraction accuracy or answer quality.
8. Patient Agency Interpretation
Health-GPT's core loop is close to what CAIHL asks of a patient-directed tool. It takes the documents institutions produce about a patient and turns them into something the patient can interrogate: a timeline they can read, questions they can ask in their own language, and a prepared list to bring into the exam room. The per-entry privacy switch is a small but real piece of authorship, letting the patient decide which parts of their history the AI may speak from. The fictional sample record is a thoughtful touch, letting someone evaluate the tool before entrusting it with anything real.
The gap is that agency requires verifiability, and almost nothing here can be verified. The records flow to unnamed AI systems run by a company with no named humans behind it, under a privacy policy with no date, no jurisdiction, and no export right, beneath an app-store label that contradicts it, next to a terms link that 404s. Every stated commitment is patient-friendly, and the no-training pledge is better than much of the industry. But a patient weighing this tool is being asked to trade their most sensitive documents for convenience on the strength of promises no one can currently check.
9. Publication Recommendation
Ready for human review as an AI-assisted, source-backed draft. Publish under Patient care navigation and health copilot AI with CAIHL classification "Patient-directed, vendor-hosted record-comprehension and visit-preparation AI." Do not mark reviewed or verified. Prioritize human review of the AI-provider question, the unretrievable Terms of Use, the "Data Not Collected" label discrepancy, hands-on upload and extraction-accuracy testing, export and correction routes, the business model, and company identity.
Review Provenance
- Criteria: HugoScore patient agency framework derived from CAIHL, using the same public questions and mixed answer types applied to every tool.
- Reviewer: AI-assisted public-source draft prepared in Claude (Cowork); no named human reviewer is recorded.
- AI / model: Claude Fable 5 (claude-fable-5).
- Human review: No comprehensive human review has been completed or claimed.
- Review date: 2026-08-15.
- Limitations: No account creation, document-upload test, extraction-accuracy inspection, vendor or user interview, security audit, accessibility audit, independent validation, or legal/regulatory determination. Terms of Use and Google Play listing could not be retrieved; FAQ answers render client-side and were not readable.