← Back to open source
21 stars5 forks0 watchingTypeScript4+ contributorsPolyForm-Noncommercial-1.0.0
ai-insightsapple-healthapple-health-importdockerfitbitglucose-trackergoogle-healthhealthhealth-trackingmedication-trackermood-trackernextjsperiod-trackerpersonal-healthprivacypwaquantified-selfself-hostedwhoopwithings

What's new in v1.37.0

2026-08-07

Two people, one record, was the whole of sharing until now. This release adds

the two things that were missing from it: choosing which parts of the record an

invitation opens, and looking after a record for somebody who has no account to

sign in with.

Share a part of it

An invitation can name the sections it opens rather than handing over

everything. Readings, medications, lab results, health background, illness,

mood and mind, cycle, documents. Anything you do not pick stays closed, and a

section you kept back is refused exactly the way a record nobody shared with

you is, so the shape of what you held back is not readable from outside.

The invitation screen says two things out loud rather than leaving you to work

them out. A section can mention the rest of your health in its notes and its

names, so sharing a section shares whatever was written in it. And the dashboard

overview, the health score and the daily digest appear only when the entire

record is shared, because a figure computed from part of a record would read as

a figure about the person.

Every grant that already exists opens the entire record and is untouched.

Nobody has to agree to anything again.

A third level

Read access looks. Write access adds. Manage access can also change and remove

what is already in the record, including entries you made yourself, and can read

the insights generated from it.

Where it stops is the account around the record: your login, your second factor,

your connected services, your API tokens, where your notifications go, which

modules and thresholds are on, and who else has access. Offering manage asks for

your second factor, so it happens in a browser. It always covers the entire

record, because a note in one section can be about any other. Everything a

manager does is recorded under their own name, with a verb that says what it was.

A record for somebody who does not sign in

@balajiv113 asked in #360 for a way to look after a family member's record, and

a grant between two accounts only ever covered half of that. The other half is

the person who has no account to begin with: a child, or somebody you care for.

A managed profile has no login and no e-mail address. You give it a name,

optionally a real date of birth, and the language and timezone its own days and

reminders are measured in. Nothing is invented from a year you did not give.

Creating one asks for your second factor, and you become its first guardian in

the same transaction, so there is no moment where the record exists and nobody

is looking after it.

You can invite a second guardian, who accepts the invitation the way any other

is accepted. The record can never be left with nobody: the last guardian cannot

hand it back and cannot be removed, and the screen says so where the refusal

happens. The way out is to add somebody else, or to delete the profile.

Its reminders reach the people looking after it. A record with no login has no

phone and no chat of its own, so medication reminders, measurement reminders,

safety-floor alerts and low-stock alerts go to its guardians, each in their own

language and over the channels they had already chosen. The message names whose

record it is about, and it carries no buttons: opening the app takes you through

the ordinary switch into that record rather than acting on it from a lock

screen. One guardian turning off their own reminders does not silence anybody

else.

A guardian can keep that record's settings too: its modules, its units, its

language and timezone, its thresholds and its notification preferences. Your own

screens stay in your own language while you do it. Connected services show a

status and nothing more for now.

Also in this release

Two tabs of one browser could disagree about which record they were in.

Switching records moves a session rather than a tab, so a tab left open on the

record you just left went on reading and writing there until somebody reloaded

it. Every request now carries the record the tab believes it is in, and one

naming a record it has left is refused with an answer the tab recovers from by

re-reading who it is. A session that has never opened somebody else's record is

unaffected, and so is the phone app.

Closing a document could leave it named in the address bar, so a reload or a

shared link re-opened the sheet you had just closed. The close now checks that

the browser consumed the history step it asked it to consume.

The document vault opens inside a shared record, and "take all due" and marking

a dose skipped are offered to somebody with write access. Somebody with write

access can no longer overturn a dose you had already recorded, on either of the

two paths that reach it.

Upgrading

Seven migrations run on start, `0296` through `0302`. Nothing to configure:

sharing and managed profiles need no environment variable and do nothing until

one account invites another.

`docs/self-hosting/account-sharing.md` is rewritten for all of the above,

including the two places where the second-factor requirement is deliberately

not the same on both features.

Key features

8 total
  • Self-hosted Docker Compose
  • Unified vital timeline
  • Withings/WHOOP/Oura/Polar/Apple Health sync
  • Per-metric source priority
  • Traceable medication ledger
  • BYOK or local AI insights
  • FHIR R4 + clinician PDF
  • AES-256-GCM encryption at rest

Who use HealthLog

1 signals

Privacy-focused self-hosters who want a Docker-deployed, FHIR-compatible health tracker with wearable sync and BYOK AI insights. *Personal health record-keeping tool — does not diagnose, treat, or prevent disease.*