Guide · Health

Asking AI about your health, privately

Health questions are the ones people most want kept off their name, and the ones where people most often assume a law is protecting them. In the situation that brings you here, it usually is not.

Written 4 September 2026 · Reading time about six minutes

Read this first

This page is about privacy, not medicine. Nothing here is medical advice, and no AI assistant, this one included, is a substitute for a clinician. If something is urgent, contact a doctor or emergency services rather than a chatbot.

Why health is the sharpest case

Most privacy arguments are abstract. This one is not, because the harm has a shape people can picture: a question about a lump, a mental health crisis, a pregnancy, a sexually transmitted infection, an addiction, sitting in a database next to a verified email address, indefinitely.

Nobody is going to read it tomorrow. The problem is the word indefinitely. A record created today outlives the company's current management, its current retention policy, its current owner and its current legal jurisdiction, and there is no mechanism by which you find out when any of those change.

There is a second cost, quieter and probably larger. People do not ask. The question about the thing they are frightened of goes unasked because it would be typed into a box with their name above it, and so they arrive at the appointment with the question they were willing to type instead of the one they needed.

The HIPAA misunderstanding

This comes up constantly and it is worth being exact, because the intuition is almost universally backwards.

HIPAA does not follow the information. It follows the organisation. It binds covered entities, meaning healthcare providers, health plans and clearinghouses, and the business associates that handle data on their behalf. Health information becomes protected health information because of who is holding it and why, not because of what it is about.

If you type a symptom into a consumer chatbot for your own use, you are not a covered entity, the chatbot is not a business associate, and HIPAA does not apply to what you typed.

Which means the protection you actually get is whatever the service's own privacy terms say, plus whatever consumer law applies where you live. That is a much weaker and much more changeable thing than people assume they are relying on, and it is why "is this AI HIPAA compliant" is usually the wrong question for an individual. The right question is what the service collects and how long it keeps it.

The picture changes if a hospital or an insurer puts an AI tool in front of you, or if a clinician uses one on your behalf. Then a covered entity is involved and the obligations attach to them. That is a different situation from the one that brought most people to this page.

And in Europe

The GDPR is broader than HIPAA in an important way: it follows the data, not the sector. Health data is a special category under Article 9 and gets stronger protection wherever it is processed, including by an AI company, and you keep rights of access, erasure and portability against that company.

Two honest caveats. Those rights are exercised after the data exists, through a request, a wait and sometimes an argument. And the strongest legal position in the world does not help against a breach that has already happened. The GDPR is a good backstop and a poor first line.

Which points at the same conclusion from both directions: the reliable move is to reduce what gets collected in the first place.

What actually reduces the exposure

  1. No account. A health question that was never joined to an email address is a fragment rather than a record. This is the single largest change available to you, and it is available for free.
  2. History on your device, not a server. There is then no server-side archive of your health questions to breach, export or subpoena.
  3. A mode that saves nothing at all. For the ones you do not want on the device either. Ask, read the answer, close it.
  4. Named providers with retention terms. Your text has to reach a model. What can be checked is which company receives it and whether it is required to drop it afterwards.
  5. Your own device and connection. Not the work laptop. Not the office wifi. See the layer-by-layer guide if that is your situation.

What an AI is genuinely good for here

  • Translating a report into words. A discharge summary or a lab result is written for a colleague, not for you. Having each term explained is a real service and a low-risk one.
  • Preparing for the appointment. Ten minutes goes fast. Arriving with a written list of what you want to ask, in order, is the difference between leaving informed and leaving with a leaflet.
  • Rehearsing the sentence you cannot say. Some things are hard to say to a person, including a doctor. Writing it once, privately, makes saying it possible.
  • Reading a label or a leaflet in another language. A medicine box in a country you have just moved to, photographed and read back to you.
  • Understanding the letter about the appointment, which is often the actual problem: which department, which preparation, what to bring.

And what it is not

It is not a diagnosis, and it should not be treated as one even when it sounds certain. That confidence is a property of how these systems write, not of how much they know about you. NOLO in particular does not use a frontier model, which is stated plainly rather than buried: it is chosen for privacy and price, not for being the smartest available.

It does not know your history, your medication, your family background or what the clinician saw. It cannot examine you. And it has no way to tell you when it is wrong.

The right shape is: use it to understand and to prepare, then take the substance to a person who is qualified and who can be held responsible for the answer. If a symptom is severe, sudden or getting worse, skip all of this and get medical help.

How NOLO handles it

There is no sign-up. The first visit generates a random identifier such as nolo_a7b3_x9k2 and that is the login: no email, no phone number, no verification. So a health question arrives without an identity attached, and there is no profile for it to become part of.

Conversations are written to your browser's local storage on your own device, not to a NOLO database. Anonymous mode is one tap and does not write them even there, which is the mode most of the questions on this page belong in.

Reading a photograph of a report or a leaflet works on the free plan, so none of this requires paying, and uploading a PDF of a few hundred pages does too. The models are named: Groq runs Fast and Plus with zero data retention enabled on NOLO's account, and OpenRouter carries Pro and the image reader with zdr and data_collection: deny set in the request, so the platform will not route to a provider that keeps it.

And the limits, in the same voice. The text does leave your device, because it has to reach a model. The local history is not encrypted at rest, so use anonymous mode if the device is shared. Your network can see that you visited. And NOLO is not a doctor and will get things wrong.

If the question is one you would rather not leave anywhere

Open it, switch on anonymous mode before you type, ask, and close it. Nothing is stored on our side and nothing is written to your browser.

Open NOLO

Questions people ask next

Can I upload a scan or an X-ray?

You can upload the image and it will describe what it sees and read any text on it. Treat that as description, not as reading the scan: interpreting medical imaging is a clinical skill and this is not that, whatever the answer sounds like.

Will it tell me what is wrong with me?

It will produce something that reads like an answer, which is exactly the danger. What it can honestly do is explain terminology, list what a clinician might want to know, and help you write down what you want to ask. Anything that resembles a diagnosis should be treated as a prompt to see someone, not as the conclusion.

Is a health question safer in a private browser window?

Marginally. A private window stops your own browser writing history to disk. It does nothing about the account the conversation is stored in, which is the part that matters here. Not creating the account is the version of that idea which actually works.

What if I already asked these things in an account I have?

Delete what you can and turn off training in the settings, then be realistic: deletion from your view and deletion from every backup are different operations. There is a practical guide to that, including what deletion does and does not reach.

No name on the question.

No sign-up, no email, and an anonymous mode that writes nothing to your browser either.