Amazon Halo Privacy Whitepaper

June 8, 2024
Amazon

Halo Privacy Whitepaper          Last Updated October 30, 2020

AMAZON HALO PRIVACY 101

Amazon Halo combines innovations in artificial intelligence and computer vision with medical science to help customers improve their health. The Body feature measures body fat percentage as accurately as methods a doctor would use, with just the customer’s smartphone camera. The Tone feature lets customers analyze Energy and Positivity in their voice to help them better understand how they sound to others. Labs help customers make small, measurable changes to their habits to help them look, sleep, and feel their best.

With Halo, customers can trust that their health data is protected and in their control. Customers can easily manage and download their health data, delete it, or limit access to it if they share an Amazon account with household members. We’ve built strict protection mechanisms for customers’ most sensitive data, like Body and Tone, by storing it locally on the customer’s phone by default, when possible, and deleting it after it’s processed. In doing so, we ensure that Tone speech samples are never accessed and body scan images are only viewed by the customer—we do not use either dataset for improving our machine learning algorithms.

We have created secure databases to store customers’ health data within Amazon. All personally identifiable data within those datasets are hashed to protect the customer’s identity and the datasets are strictly access- restricted at Amazon and never sold to any third parties. Customers can link their health data to a third-party program if they choose, and can cancel that link at any time from the Halo app settings to end data sharing. By never compromising on customer privacy, we continue to earn our customers’ trust every day. Learn more about Amazon Halo at www.Amazon.com/HaloBand.

Health data includes data like activity and sleep scores, step count, heart rate, body fat percentage, and demographic information. Health data is stored in the cloud and is encrypted in transit and at rest in the cloud. Customers can download or delete their health data directly from the Halo app. We do not use health data for marketing, product recommendations, or advertising. We do not sell customers’ health data. Customers’ health data is strictly access-restricted at Amazon.

A Tone voice profile is an acoustic model of a customer’s voice characteristics. Tone is an opt-in feature that requires that a customer set up a voice profile to use it by reading aloud and recording a series of statements provided to the customer in the Halo app. The voice profile trains Tone to analyze only the customer’s voice.

Tone speech samples are temporary recordings of speech. Once it’s set up, Tone processes speech samples. Then it analyzes how a customer may be perceived by others and displays a summary of the analysis in the Halo app.

PRIVACY CONTROLS

Amazon Halo customers place considerable trust in us just by using our services. We take this responsibility seriously and have built tools that make it easy for customers to protect and control their health data.

Profile Protection: We know that customers may share their Amazon account with household members, but that doesn’t mean that customers always want those people to be able to view or access their health data. To ensure that health data is personalized and distinguished from others in the household, we require customers to create or choose a unique profile when they first use Halo. After selecting their profile, customers are prompted to add claim credentials to their profile (a mobile phone number or email address) that are verified via a one-time passcode. This occurs by default when customers set up their profile in Halo and provides customers with a safeguard for their health data. After adding claim credentials to their profile, customers are prompted to validate a one-time passcode on any subsequent login to the Halo app. Halo automatically prompts customers who choose to bypass claim credential entry with in-app reminders to enter and validate their claim credentials and protect their profile. These reminders are pinned to both the Halo app home screen and the Halo app settings screen until the customer either adds claim credentials to protect their profile or explicitly dismisses the reminders.

Customers who are not in physical possession of their smartphone can sign out of their Halo account remotely by deregistering the Halo app from Manage Your Content and Devices on Amazon.com. This prevents anyone else who may have access to their smartphone from viewing their Halo health data.

Health Data Download and Deletion: Customers can download all the health data that Halo retains associated with their profile and review it on their own terms. After opening Halo, it takes just a few taps for customers to download their data. A link to download

Halo Privacy Whitepaper                    Last Updated October 30, 2020

the data is delivered to the claim credential that the customer previously used to verify and protect their profile. The link to their raw health data automatically expires after seven days.

Similarly to downloading data, customers can delete all health data associated with their profile from the Halo settings. Deleting health data is a permanent action and health data cannot be recovered after it’s been deleted. However, if a customer decides they want to stop using Halo and leave no health data behind or if they simply want to reset their data and start from scratch, this control allows them to make that choice. Once a customer deletes their data in Halo, they’re automatically logged out of the app and cannot log back in with their profile until all of the health data associated with the profile has been deleted.

Delete all Tone and all Body Data: Customers can also delete all of their Body data and Tone data retained. Body data deletion includes historical data on their body fat percentage, scan images, and associated scan image assets (i.e., 3D body model and texture maps generated from the scan which are used to personalize the 3D body model). Tone data deletion includes voice profile, Tone analysis results, and any speech samples currently stored on the customer’s smartphone.

Amazon Halo Privacy Whitepaper

PROTECTING BODY DATA

The Amazon Halo Body feature allows customers to obtain an accurate body fat percentage measurement from the comfort and privacy of their own home. To get their body fat percentage, customers take a body scan that generates four images—front, back, and both sides. Along with obtaining body fat percentage results and their scan images, customers receive a personalized 3D body model so they can see an abstract representation of how their body looks at the time of that scan and then use the 3D body model to track changes over time. From the Body page, customers can hide their scan images and body fat results so they don’t have to worry about a curious friend looking over their shoulder and seeing their scan photographs or body fat percentage.

Body scan images are processed in the cloud. They are encrypted in transit and processed within seconds, after which they are automatically deleted from Amazon’s systems and databases. All scan images are fully deleted within 12 hours. The scan images are not viewed by anyone at Amazon and are not used for machine learning optimizations. The scan images and all associated scan assets are stored exclusively in the Halo app’s local storage on the customer’s smartphone—the scan assets are never shared with any other app, including the smartphone’s default photo gallery, unless the customer explicitly exports the images. No one but the customer ever sees the scan images unless the customer chooses to share them.

Storing body scan images in the Halo app’s local storage means that the scan images and assets are permanently deleted when the app is uninstalled and cannot be accessed if the customer logs in on a new smartphone. Customers can choose to opt in to cloud backup for their scan images to ensure they can recover their images if they change phones. Nobody at Amazon accesses these images. Scan images and scan assets stored in the cloud are secured using Amazon data protection best practices, including encryption and the use of least-privilege access principles, which block Amazon personnel from accessing the encrypted data. Customers can always opt out of cloud backup later via the Halo app settings, even if they’ve previously opted in. As soon as they opt out, their

Halo Privacy Whitepaper                   Last Updated October 30, 2020

images are deleted from the cloud, but continue to be stored in the Halo app’s local storage on their smartphone. Scan assets stored in the cloud are protected with controls required for the most sensitive classes of stored data at Amazon.

PROTECTING TONE DATA

With Tone, customers can use the microphones built into the Amazon Halo Band or the Halo app to understand how they may be perceived by others based on their tone of voice.

Customers must opt in to Tone if they want to use it and can do so by setting up a voice profile. The voice profile is based on technology that identifies when the customer is speaking—this technology trains Tone to only analyze the speech samples of the customer who enabled it. The more the customer uses Tone, the better Tone gets at recognizing their unique voice profile. The microphones in the band are off until and unless customers have opted in to Tone by setting up a voice profile. Customers who have enabled Tone can then turn off the microphones on the band by holding down the button on the band for three seconds. When the microphones are off, they are unable to collect speech samples for analysis.

Tone speech samples are transferred from the band to the Halo app over Bluetooth. To ensure no other apps on the customer’s smartphone can see this data, it is encrypted with a key shared between the band and the Halo app. This key is exchanged at the time the band is paired with Halo, and a new key is generated and renegotiated each time the band is deregistered and then registered again with Halo (for example, when a Halo Band is resold or paired with a different smartphone). The encryption algorithm used is AES-256 with GCM. All data transferred between the band and the Halo app is encrypted using this key.

All speech collected for Tone is processed locally on the customer’s smartphone. Samples used to assess Tone are never sent to the cloud. No one—including the customer—ever hears them. By storing and processing speech samples locally, the data is always within the customer’s control. Speech samples are automatically deleted after processing and are never used to train machine learning models.

Following processing, the Tone analysis results are stored in the secure Amazon cloud so that customers can continue to access their results even if they get a new smartphone. Tone analysis is essentially a summary of the Positivity and Energy of a given phrase. It never includes raw audio data or audio transcriptions. We do not apply machine learning to the Tone analysis results of individual customers to optimize our Tone algorithm. The Tone analysis is treated as customer health data and customer identifiers associated with the tone analysis data are one-way hashed with a secret key so that it cannot be traced back to the customer associated with it (see Data Handling for more on how we protect health data).

DATA HANDLING

Storing and Usage of Customer Health Data: All customer identifiers are one-way hashed with a secret key to ensure there is no way to map stored health data back to the customer who recorded it. This means that none of the health data collected by Halo can be tied back to a customer and the health data cannot be combined with or correlated with any other data Amazon might store about that customer. This approach ensures that customers’ health data cannot be used as an input in recommending products elsewhere on Amazon including, but not limited to, Amazon.com and Prime Video. It also means that no employee of Amazon or anyone else with access to this data can identify the customer associated with it.

Data is protected using a one-way cryptographic hash function with a key stored in the AWS key management service that is only accessible by the service responsible for performing the hash. This is a one-way operation; Amazon identifiers like customer IDs can be converted to hashed IDs but it is impossible to convert a hashed ID back into a customer ID. We use distinct namespaces for each hashed data store (e.g., the same customer’s data stored for display in Halo and for use in improving machine learning algorithms will have different hashed IDs) and we ensure the hashed IDs are never propagated outside of these data stores. These measures ensure additional data that could potentially identify the user can never be associated with the hashed IDs.

Halo Privacy Whitepaper                             Last Updated October 30, 2020

Sharing Data with Third Parties: Customers can choose to link their Amazon Halo account to other third-party programs to obtain even more benefits. For example, customers who link their Halo account with their WW (formerly Weight Watchers) account can earn Fit Points based on their Halo activity score. Account linking is always opt-in. We give customers a bulleted, plain English list of the data they are consenting to share and surface the third party’s privacy policy in case the customer would like to review it again. Customers can opt out of account linking any time from the Halo app settings. We only allow third parties to request data from customers that is useful in providing a service or feature to customers and limit, through the terms of our contracts, the use of the data they do request.

Sharing Data with Lab Providers: Some of the content offered in Labs is created by third-party Lab providers. No personally identifiable data is shared with these Lab providers without your agreement. For example, Lab providers—like Headspace—only receive aggregated, anonymized data about their labs, which can help them improve the experience they provide Halo members, like data that informs them which of their labs is most popular among customers or which labs have the highest completion percentage rate.

In summary, privacy and security are foundational to the way we designed Amazon Halo. Learn more about Halo at www.Amazon.com/HaloBand

Link Details

Amazon Halo Privacy Whitepaper – Optimized PDF
Amazon Halo Privacy Whitepaper – Original PDF

Read User Manual Online (PDF format)

Read User Manual Online (PDF format)  >>

Download This Manual (PDF format)

Download this manual  >>

Amazon User Manuals

Related Manuals