Terms & Conditions
Effective date: 28 August 2026 Service: Neem Health Connect ("the Service", "the Platform"), operated by Neem Health Inc. ("Neem Health", "we", "us", "our"). Contact: admin@neemhealth.ai
1. What the Service is
Neem Health Connect is a backend platform that ingests health and related data from third-party sources — wearables (Whoop, Oura), device health stores (Apple Health, Android Health Connect), electronic health records (via SMART on FHIR), and calendar/email metadata (Google Calendar, Outlook Calendar, Outlook Mail, iCloud Calendar, Gmail) — normalizes it into a common data model, and exposes it over an API to Developers who build consumer-facing applications ("Developer Apps") on top of it.
The Service has two kinds of parties:
- Developers — companies or individuals who register a Neem Health Connect account, receive API keys, and integrate the Service into their own application.
- End Users — the people whose health data flows through the Service, identified only by an opaque
userId chosen by the Developer. Neem Health Connect does not have a direct relationship with End Users; the Developer does.
These Terms govern Developer use of the Service. Developers are responsible for their own terms with End Users, including obtaining any consents required to connect an End User's accounts and share their data with Neem Health Connect.
2. Eligibility and accounts
- You must be at least 18 and able to form a binding contract to register.
- You are responsible for safeguarding your account credentials, API keys, and any OAuth client credentials issued to you, and for all activity under them.
- You must notify us promptly at admin@neemhealth.ai if you suspect an API key or account has been compromised. We may rotate or revoke keys on reasonable notice, or immediately if we detect abuse.
3. Acceptable use
You will not use the Service to:
- Violate any applicable law, including data protection, healthcare (e.g., HIPAA), or consumer protection law in any jurisdiction where your Developer App operates.
- Ingest, store, or request data for an End User without that End User's informed consent.
- Attempt to re-identify End Users from data you were not otherwise authorized to access, or to access another Developer's tenant data.
- Probe, scan, or test the Service's security without prior written authorization, or interfere with its availability (e.g., excessive load, denial-of-service).
- Reverse-engineer the Service beyond what is necessary for interoperability permitted by law.
- Use the Service to make automated clinical decisions without appropriate human oversight and regulatory clearance — the Service is an ingestion and normalization layer, not a medical device, and is not FDA-cleared.
4. Data you connect through the Service
- Multi-tenant isolation. Every record you ingest is scoped to your Developer account. We do not share your tenant's data with other Developers.
- Sources are adapters. Each supported source (device sync, wearables, calendar, email, EHR) is normalized into a canonical model before it reaches storage; you interact with that canonical model, not vendor-native formats.
- PHI handling. Data retrieved through the EHR (SMART on FHIR) integration is treated as Protected Health Information and stored in an isolated data store with append-only audit logging, access controls, and consent gating as described in
docs/HIPAA_CHECKLIST.md. Production use of the EHR integration requires a signed Business Associate Agreement (BAA) with Neem Health before you may connect real End User accounts to it. Contact admin@neemhealth.ai to initiate a BAA. - You represent that you have all rights, consents, and legal bases necessary to share End User data with us for the purposes of the Service, and to have us process it on your behalf.
- Deletion. End Users' data can be erased on request via the
DELETE /me/data endpoint, which removes wellness and PHI records alike (subject to the append-only audit trail, which is retained for compliance purposes even after underlying records are deleted).
5. Your responsibilities as a Developer
- Obtain and document End User consent before connecting any source on their behalf.
- Do not store, log, or transmit API keys, OAuth tokens, or webhook secrets in client-side code or public repositories.
- Comply with each upstream provider's own developer terms (Google, Microsoft, Apple, Whoop, Oura, and End Users' health systems) for any data you access through the Service.
- If you are a "Covered Entity" or "Business Associate" under HIPAA, you are solely responsible for determining whether your use of the Service requires a BAA, and for not transmitting PHI through the Service until one is in place.
6. Service availability and changes
- The Service is provided on a best-efforts basis. We do not guarantee uninterrupted availability. Scheduled maintenance will be communicated where practicable.
- We may modify, suspend, or discontinue any part of the Service (including individual source adapters) with reasonable notice, except where necessary to address security issues, in which case we may act immediately.
- We may update these Terms; continued use after an update constitutes acceptance. Material changes will be notified via a notice on the developer dashboard and an email to registered Developers.
7. Fees
The Service is currently offered free of charge. Rate limits apply per tenant and are documented in docs/API.md. If we introduce fees, we will give registered Developers at least 30 days’ notice before they take effect, and no charge will apply to usage before that date.
8. Disclaimers
- THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
- The Service is not a medical device and is not intended to diagnose, treat, cure, or prevent any disease. Data normalized by the Service may originate from consumer wearables and self-reported sources and is not validated for clinical accuracy.
- We do not warrant that any upstream integration (Whoop, Oura, Google, Microsoft, Apple, and End Users' health systems) will remain available, unchanged, or free of errors, as these depend on third parties outside our control.
9. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEEM HEALTH WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF DATA, REVENUE, OR PROFITS, ARISING FROM YOUR USE OF THE SERVICE. OUR AGGREGATE LIABILITY FOR ANY CLAIM ARISING OUT OF THESE TERMS WILL NOT EXCEED THE GREATER OF (A) THE AMOUNT YOU PAID US IN THE TWELVE MONTHS PRECEDING THE CLAIM AND (B) ONE HUNDRED US DOLLARS (USD 100).
10. Indemnification
You will indemnify and hold Neem Health harmless from any claim arising from your breach of these Terms, your violation of applicable law, or your failure to obtain required End User consents.
11. Termination
Either party may terminate at any time. On termination, your API keys are revoked; End User data ingested under your tenant may be retained per our data retention policy or deleted on your request, subject to legal hold requirements (e.g., audit-log retention).
12. Governing law and disputes
These Terms are governed by the laws of the State of Delaware, USA, without regard to conflict-of-laws principles. Disputes will be resolved in the state and federal courts located in Delaware, USA.
13. Contact
Questions about these Terms: admin@neemhealth.ai