What's new in v1.37.0
2026-08-07Two people, one record, was the whole of sharing until now. This release adds
the two things that were missing from it: choosing which parts of the record an
invitation opens, and looking after a record for somebody who has no account to
sign in with.
Share a part of it
An invitation can name the sections it opens rather than handing over
everything. Readings, medications, lab results, health background, illness,
mood and mind, cycle, documents. Anything you do not pick stays closed, and a
section you kept back is refused exactly the way a record nobody shared with
you is, so the shape of what you held back is not readable from outside.
The invitation screen says two things out loud rather than leaving you to work
them out. A section can mention the rest of your health in its notes and its
names, so sharing a section shares whatever was written in it. And the dashboard
overview, the health score and the daily digest appear only when the entire
record is shared, because a figure computed from part of a record would read as
a figure about the person.
Every grant that already exists opens the entire record and is untouched.
Nobody has to agree to anything again.
A third level
Read access looks. Write access adds. Manage access can also change and remove
what is already in the record, including entries you made yourself, and can read
the insights generated from it.
Where it stops is the account around the record: your login, your second factor,
your connected services, your API tokens, where your notifications go, which
modules and thresholds are on, and who else has access. Offering manage asks for
your second factor, so it happens in a browser. It always covers the entire
record, because a note in one section can be about any other. Everything a
manager does is recorded under their own name, with a verb that says what it was.
A record for somebody who does not sign in
@balajiv113 asked in #360 for a way to look after a family member's record, and
a grant between two accounts only ever covered half of that. The other half is
the person who has no account to begin with: a child, or somebody you care for.
A managed profile has no login and no e-mail address. You give it a name,
optionally a real date of birth, and the language and timezone its own days and
reminders are measured in. Nothing is invented from a year you did not give.
Creating one asks for your second factor, and you become its first guardian in
the same transaction, so there is no moment where the record exists and nobody
is looking after it.
You can invite a second guardian, who accepts the invitation the way any other
is accepted. The record can never be left with nobody: the last guardian cannot
hand it back and cannot be removed, and the screen says so where the refusal
happens. The way out is to add somebody else, or to delete the profile.
Its reminders reach the people looking after it. A record with no login has no
phone and no chat of its own, so medication reminders, measurement reminders,
safety-floor alerts and low-stock alerts go to its guardians, each in their own
language and over the channels they had already chosen. The message names whose
record it is about, and it carries no buttons: opening the app takes you through
the ordinary switch into that record rather than acting on it from a lock
screen. One guardian turning off their own reminders does not silence anybody
else.
A guardian can keep that record's settings too: its modules, its units, its
language and timezone, its thresholds and its notification preferences. Your own
screens stay in your own language while you do it. Connected services show a
status and nothing more for now.
Also in this release
Two tabs of one browser could disagree about which record they were in.
Switching records moves a session rather than a tab, so a tab left open on the
record you just left went on reading and writing there until somebody reloaded
it. Every request now carries the record the tab believes it is in, and one
naming a record it has left is refused with an answer the tab recovers from by
re-reading who it is. A session that has never opened somebody else's record is
unaffected, and so is the phone app.
Closing a document could leave it named in the address bar, so a reload or a
shared link re-opened the sheet you had just closed. The close now checks that
the browser consumed the history step it asked it to consume.
The document vault opens inside a shared record, and "take all due" and marking
a dose skipped are offered to somebody with write access. Somebody with write
access can no longer overturn a dose you had already recorded, on either of the
two paths that reach it.
Upgrading
Seven migrations run on start, `0296` through `0302`. Nothing to configure:
sharing and managed profiles need no environment variable and do nothing until
one account invites another.
`docs/self-hosting/account-sharing.md` is rewritten for all of the above,
including the two places where the second-factor requirement is deliberately
not the same on both features.
Key features
8 total- Self-hosted Docker Compose
- Unified vital timeline
- Withings/WHOOP/Oura/Polar/Apple Health sync
- Per-metric source priority
- Traceable medication ledger
- BYOK or local AI insights
- FHIR R4 + clinician PDF
- AES-256-GCM encryption at rest
Who use HealthLog
1 signalsPrivacy-focused self-hosters who want a Docker-deployed, FHIR-compatible health tracker with wearable sync and BYOK AI insights. *Personal health record-keeping tool — does not diagnose, treat, or prevent disease.*