This Privacy Policy explains how Information Services handles information while operating the Arnold Health Research Gateway. It does not replace the consent materials or privacy information provided by a participating research study.

Who we are

The Arnold Health Research Gateway ("the Gateway") is a shared technical service operated by Information Services in the Office of Operations and Accreditation, Arnold School of Public Health at the University of South Carolina. Participating public health research studies use the Gateway to connect to Google Health data.

Information Services operates the Gateway but does not conduct the participating research studies.

What the Gateway does

When you participate in a study and authorize a Google connection, the Gateway stores the Google authorization credentials needed to retrieve the types of Google Health data requested by that study and permitted by you. The Gateway delivers that data to the designated system for your study.

The Gateway provides one centrally operated connection that can support multiple participating studies. Participating study applications do not receive your Google access or refresh tokens, and data for one participating study is not routed to another participating study.

Studies participating in the Gateway

  • DREAM Production
  • Google Verification
  • iReachR Prod
  • Mobile Strides prod

Each participating study has its own consent materials. This Privacy Policy covers Information Services' operation of the Gateway. The consent materials for the study you joined govern how that study uses, retains, shares, and otherwise handles data after it receives it.

What data we access

The Gateway accesses only the types of Google Health data requested for your study and covered by the Google permissions you authorize. Depending on the study, that may include daily step counts, activity minutes, resting heart rate and heart-rate zones, sleep periods and stages, weight measurements, logged food and drink, and the time-zone settings needed to date-stamp readings correctly.

Before you are sent to Google's permission screen, the Gateway shows the data types requested for your study. You may decline the authorization request.

Google Health API policies and Limited Use

The Gateway's use of information received from the Google Health API adheres to the Google API Services User Data Policy, the Google Health API Developer and User Data Policy and the Google Health API User Data and Health Research Policy, including their Limited Use requirements.

Specifically, data obtained through Google Health APIs is used only to:

  • provide the research measurements the participating study described in its consent materials;
  • provide your connection status and data-sharing state to your study so it can show them in its app;
  • meet legal, safety, or research-integrity obligations, or investigate abuse.

We do not, and will not:

  • use Google user data for advertising, marketing, or any commercial purpose;
  • sell, rent, or trade Google user data;
  • transfer Google user data to data brokers, information resellers, or advertising platforms;
  • use Google user data to build profiles for purposes outside the study you enrolled in;
  • allow humans to read your Google user data except where you have given explicit permission for a specific need, it is necessary for security purposes, it is required by applicable law, or the data is aggregated and anonymized for internal operations, and only as the applicable Google Health API policies allow.

Who your data is shared with

Data retrieved through the Gateway is delivered to the designated research system for the participating study you connected. The Gateway does not deliver that data to other participating studies.

Once the study receives the data, the study's consent materials and study-specific requirements govern how the study uses, retains, or shares it.

How long we keep it

The Gateway keeps the Google access and refresh tokens needed for your connection for as long as you remain connected. It keeps an operational record of the requests it made on your behalf, used for troubleshooting and for security review. It does not retain a copy of your measurement data beyond what is needed to deliver it to your study and to complete any historical retrieval you have requested.

Records of connection and authorization events, including when Google access was authorized, refreshed, or revoked, are retained permanently as part of the operational and security audit trail. Those records do not contain your health measurements or Google access tokens.

Stopping access

Manage your connection from the study app you enrolled through or contact your study team. When a study deactivates a connection, the Gateway attempts to revoke the Google authorization, deletes its stored access and refresh tokens, and retains the connection and authorization history described above.

You can independently stop Google from sharing new data by removing the Arnold Health Research Gateway from your Google Account connections. Google's official instructions explain how to review and remove third-party access.

Stopping access ends future collection through the Gateway. Data already delivered to your study remains with the study and is handled according to that study's consent materials and study-specific requirements. Questions about data already received by the study, including correction, withdrawal, or deletion requests, should be directed to the study team.

Information the Gateway had already collected before you disconnected — for example, a large historical download that was retrieved but not yet picked up by your study — is not automatically deleted just because you disconnected. It is held only for a limited time under the Gateway's normal retention schedule before it is deleted, the same as it would be if you had stayed connected. Disconnecting stops new collection; it does not reach back and erase information already collected while your authorization was in effect.

If your study or your institution determines that information held by the Gateway must be deleted outside of that normal schedule, that request is handled directly between your study, your institution, and the team that operates the Gateway. There is no automatic, participant-facing deletion feature separate from the process described above.

How we protect it

Google access credentials are encrypted before they are stored. Study systems authenticate to the Gateway with per-study, per-environment credentials and a signature over every request, and each study can only reach the participants linked to that study. Every request the Gateway makes to Google is recorded.

Contact

Questions about this policy or about the Gateway itself go to Information Services, Office of Operations and Accreditation:

Matt McGrievy, Ed.D., Director, Information Services
Arnold School of Public Health, University of South Carolina
Phone 803-777-0999
Email MCGRIEVM@mailbox.sc.edu

For questions about your participation in a study, the study's consent materials, your rights as a study participant, or data already delivered to the study, contact your study team using the contact information provided by that study.