Privacy policy

Last updated: 28/09/2026

About this policy

Breianna Dunks trading as Sana Health (ABN 15 988 550 553) operates SANA, a functional health practice delivering care online from New South Wales. This policy explains how we handle personal information, including health information, under the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Health Records and Information Privacy Act 2002 (NSW). Our services are for people aged 18 and over.

What we collect

Identity and contact: name, date of birth, email, mobile, address, emergency contact and your GP's details.

Health information: intake answers, consultation notes, treatment plans, supplement protocols, pathology and microbiome results, check-in answers, goals, and documents or messages you send us.

Daily tracking in the SANA app: sleep, steps, exercise, water and mind activity, and where your device records them, resting heart rate and heart rate variability. These are read on your own device from Apple Health, and only what you log or sync to your SANA app is sent to us.

Calculated indicators: your SANA score and, if applicable, biological age and speed of ageing.

Payment information: card details are entered directly with Stripe and are not stored by SANA. We keep a Stripe reference and a record of what you purchased.

Enquiries: if you book a Clarity Consultation, your name, email, phone number, reason for enquiring, and whether you agreed to marketing.

Technical information: a device token for app notifications, and standard server logs. Notifications never include health details.

How we collect it

Directly from you (forms, the app, bookings, messages, consultations), from testing providers and your GP where you have consented, and automatically through our website and app.

Why we use it

To provide and personalise your care, prepare your treatment plan, arrange testing, manage bookings and payments, communicate with you, meet our professional and legal obligations, and improve our services. We collect health information only where it is needed for your care and with your consent.

Who we share it with

We do not sell your information or use it for advertising. To run the practice we use:

Supabase: database, login and file storage (data stored in Sydney).

Stripe: payments.

Google: calendar, Google Meet and email.

Apple: app notifications and app distribution.

Heidi: AI note-taking during consultations, only where you consent. Heidi states that it removes personal identifiers before processing, does not keep audio recordings, and does not use client information to train its AI models. Transcripts and notes are kept in Heidi only as long as needed to finalise your note.

Our supplement supplier, where your membership includes personalised pods: your name, delivery details and formulation, so your pods can be prepared and sent to you.

Pathology or testing providers, and your GP, where testing is part of your care.

Regulators and complaint bodies where the law or our professional obligations require it, including reports of suspected supplement reactions to the TGA and the product's manufacturer, with identifying details removed where possible.

Information that goes overseas

Supabase, Stripe, Google, and Heidi's related companies operate outside Australia, including in the United States, and Heidi's related companies also operate in the United Kingdom and Canada. Your data is stored in Australia with Supabase, and Heidi states that it stores Australian client data in Australia, but some supporting services used by these providers may use servers overseas. We take reasonable steps to make sure they handle your information consistently with the Australian Privacy Principles.

Storage and security

Each client can see only their own records, and results and plans appear in the app only once we publish them. Practitioner notes and internal records are separated from client access at the database level. App accounts are created by invitation only. We take reasonable steps to protect information, though no electronic system is completely secure. If a data breach is likely to cause serious harm, we will notify you and the OAIC as the law requires.

How long we keep it

We keep health records for 7 years after your last consultation, then securely destroy or de-identify them. If SANA closes or moves, we will give you notice and arrange secure transfer or storage of your records.

Access, correction, transfer and deletion

Email info@sanahealth.com.au to see or correct your information, or to have your records sent to another practitioner. We will respond within a reasonable time. Because health records must be kept for the period above, we generally cannot delete them earlier, though we can restrict who sees them. We may decline access in limited circumstances, such as where it would affect another person's privacy, and will explain why.

Website and cookies

Our website may use cookies and analytics. You can turn cookies off in your browser settings, though some features may not work as well.

Marketing

We send marketing only if you have opted in, and you can opt out at any time.

Complaints

Email info@sanahealth.com.au and we will respond within 5 business days. If you are not satisfied, you can contact the Office of the Australian Information Commissioner (oaic.gov.au) or the health complaints body in your state or territory. In NSW, that is the Health Care Complaints Commission.

Changes and contact

We may update this policy, and the current version is always at sanahealth.com.au. Contact: Breianna Dunks trading as Sana Health, info@sanahealth.com.au.