Phroneme

Connection status without theater.

Phroneme shows a provider as connected only after a real authorization flow succeeds. This release does not store durable health data or pretend that a mock is an integration.

Manual plan inputs

Available in session

The plan builder uses temporary page memory only. Refreshing or leaving clears the inputs.

Apple Health

Not connected

A web page cannot truthfully claim a direct Apple Watch connection. A future native companion must use HealthKit permission controls, or the web product can support a clearly labeled export/import flow after the data foundation ships.

Fitbit OAuth

Not connected

No live OAuth client, token store, or verified test account exists in this release.

WHOOP OAuth

Not connected

No live OAuth client, encrypted server-side token store, or verified test account exists in this release.

Blood-work upload

Deferred

Upload remains disabled until malware scanning, encrypted storage, user-confirmed extraction, authorization, retention, deletion, and audit logging are implemented and tested.

Required before durable data

Consumer health apps may face FTC and state obligations even when HIPAA does not apply. These are release gates, not roadmap decoration.

HHS and FTC health-data guidance ↗
  1. 01Verified identity and authorization on every server read and write
  2. 02Versioned, purpose-specific consent with revocation
  3. 03Separate identity and health-data records
  4. 04Encryption in transit and at rest, including wearable tokens
  5. 05Retention limits, export, deletion, and immutable audit events
  6. 06Malware scanning and size limits for PDFs and images
  7. 07Tests for empty, invalid, malicious, oversized, revoked, and deleted inputs
  8. 08Coarse analytics only, with no health values or cognitive scores