Privacy Policy
Last updated: 2026-09-12
health4.ai ("we", "us") provides an iOS app and MCP server that facilitate the transfer of Apple HealthKit data to a Postgres database you configure and control. We do not operate a shared health-data backend or collect, store, or have access to your health data. This policy explains what limited data we do collect and your rights.
1. What data we collect
- Health data — we do not collect it. HealthKit metrics you authorize flow directly from your device to a Supabase project you create and own. health4.ai never receives, stores, or has access to your health data. A cloud AI provider you separately connect to may process data you choose to send to it.
- Account data — email address (waitlist sign-ups only), used to notify you at App Store launch and, only if you tick the box asking for it, to send you a TestFlight beta invitation.
- Usage data — anonymous page views and feature interaction events via PostHog (US-hosted). PostHog never receives health data. We do not use advertising cookies or trackers.
2. How we use it
- To notify you at App Store launch (waitlist email only).
- TestFlight invitations — opt-in, and shared with Apple. If you tick the TestFlight box when joining the waitlist, we pass your email address to Apple's App Store Connect so Apple can send you a beta invitation. Apple sends that email, not us. Anyone with administrator access to our App Store Connect account can see the addresses of enrolled testers. If you leave the box unticked we never pass your address to Apple, and you stay on the launch-notification list. Ask us at any time to remove you as a tester.
- To improve reliability — aggregated, non-identifiable usage metrics only.
We do not sell personal data. We do not use health data for advertising. Per Apple's HealthKit guidelines, health data will never be used for advertising or sold to data brokers. Because we never receive your health data, we are structurally incapable of misusing it.
3. Where data is stored
Your health data lives in a Supabase project you create and own. You hold the credentials, and only you can query the data. health4.ai has no access to it.
4. HIPAA
health4.ai is not a covered entity under HIPAA and does not operate as a HIPAA Business Associate unless a Business Associate Agreement (BAA) is separately executed in writing.
5. Your rights
- Health data control — your health data is in your database. You can delete it directly at any time — no request to us required.
- Account deletion — contact us to delete your waitlist email address. We will confirm deletion within 14 days.
- Revoke HealthKit access — stop syncing at any time in iPhone Settings → Privacy & Security → Health → health4.ai. No data is deleted from your database automatically; you remain in full control.
- GDPR / CCPA — EU and California residents have additional rights (portability, rectification, opt-out of sale). We do not sell personal data. Contact us to exercise any right over account data we hold.
6. Breach notification
Because health4.ai does not store your health data, a breach of our systems cannot expose it. In the unlikely event of a breach involving account data (email addresses), we will notify affected users within 30 days.
7. Analytics & cookies
We use PostHog (US-hosted) for product analytics. PostHog receives page views and feature interaction events — no health data. We do not use advertising cookies or trackers.
8. Changes to this policy
We will update the "Last updated" date and notify users by email of any material changes.
9. Contact
Questions or data requests: [email protected]