Privacy Policy
HealthApp by Clifford Corp
Last updated: August 25, 2026
Clifford Corp ("we," "us," or "our") operates the HealthApp mobile application (the "App") and the healthapp.fit website (the "Site"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use either.
By using the App, you agree to the data practices described here. We are based in Ottawa, Ontario, Canada, and the App is offered worldwide.
1. Information We Collect
Information You Provide
- Account Information (only if you create an account): email address and password (managed via Supabase, see Section 4).
- Profile Information (optional): name, age, gender, height, weight, health goals, activity level, and profile photo.
- Health Data You Enter: habits, workouts, meals, sleep logs, mood entries, journal entries, medications, and supplements.
- Recipes and Meals: custom recipes, meal plans, and grocery lists.
- Photos: images you upload for food scanning, recipes, or journal entries.
Information Collected From Apple Health (HealthKit)
If you enable HealthKit integration, the App reads the following data from Apple Health, with your explicit permission, to personalize your insights:
- Step count, walking/running distance, flights climbed
- Active and basal energy burned
- Heart rate, resting heart rate, and heart rate variability
- Sleep analysis
- Workouts, exercise minutes, and stand time
- Body weight, body fat percentage, height
- Nutrition logged in other apps (energy, protein, carbohydrates, fat, fiber, sugar)
- State of Mind (your daily mood, if you record it elsewhere)
- Vitals, where you allow them: blood oxygen, blood pressure, respiratory rate, body temperature
With your permission, the App also writes the following to Apple Health, so what you log here is available to your other health apps:
- Workouts you record in the App
- Body weight you enter
- Water you log
- Mindful minutes from breathing and meditation sessions
- Meals you log (energy, protein, carbohydrates, fat, fiber)
- State of Mind — your daily mood check-in, saved as a daily-mood sample. Correcting a check-in replaces that day's sample rather than adding a second one.
Reading and writing are separate permissions, and you control each one. HealthKit data is used solely to display and personalize your health insights within the App. We do not transmit HealthKit data to our servers, sell it, share it with advertisers, or use it for marketing. You can revoke HealthKit permissions at any time in iPhone Settings → Health → HealthApp.
Information Collected Automatically
- Device Information: device type, operating system version, app version, anonymous device identifier.
- Usage Analytics: which features you use (e.g., "habit logged", "tab viewed", "paywall viewed"). We do not log free-text content (journal entries, mood notes, custom habit names) to analytics.
- Crash and Error Data: technical data when the App crashes or encounters errors, including device specs, app state, and stack traces.
Location
When you start a GPS-tracked run, walk, or ride, the App records your route while that workout is running — including with the screen off or the App in the background, so the route is not lost. Recording begins only when you start such a workout and stops when you end it.
Route coordinates stay on your device. They are not uploaded to our servers, are not part of cloud backup, and are never sold or shared. If you choose to share a workout image, you can trim the start and end of the route and apply privacy zones first, so a shared map need not reveal where you live. You can revoke location access at any time in iPhone Settings → Privacy & Security → Location Services.
Microphone and Voice
The App uses the microphone only when you start a voice journal entry or dictate a meal description. Voice journal recordings are stored on your device. A dictated meal description is converted to text by iOS and, for Pro users, that text is sent to our AI proxy to estimate nutrition — the audio itself is never uploaded.
On-Device Processing
Some features run entirely on your iPhone and send nothing anywhere. Reading a printed nutrition label uses Apple’s on-device text recognition: the photograph is analyzed on the device, the numbers are read from the panel, and neither the image nor the text is uploaded. This feature is free for all users and requires no account.
Cycle Tracking Stays on This Device
Menstrual cycle data — your logged periods, symptoms, and the predictions drawn from them — is held in the iPhone Keychain and is deliberately excluded from cloud backup. It is not uploaded to our servers, it is not part of the data that syncs when you create an account, and it is not included if you restore HealthApp onto a new phone. This is a design decision rather than a limitation: reproductive health data carries risks that other health data does not, and the surest protection we can offer is not to hold it at all. The trade-off is real and worth stating plainly — if you move to a new device, your cycle history does not travel with you. You can export it from the App before you switch.
Widgets, Apple Watch, and Siri
Home-screen widgets, watch complications, and the Apple Watch app read a small summary of your day (such as which pillars are lit, your water count, and tonight’s sleep window) through a private storage area shared only between HealthApp and its own extensions on your devices. Siri phrases such as “Log water in HealthApp” are handled by Apple’s App Intents on the device and simply record the action in the App. None of this sends data to us or to Apple beyond what iOS requires to run the feature.
Our Website
The Site uses Cloudflare Web Analytics to count visits and see which pages people read. It is measurement, not tracking: it sets no cookies, stores nothing on your device, does not fingerprint your browser, and cannot follow you to any other website. What we see is aggregate — page views, referrers, countries, broad device types — never an identifiable individual, and never anything you have logged in the App.
Because no cookies or device storage are involved, the Site does not show a cookie banner: there is nothing to consent to. The Site does not run advertising, and we do not operate advertising or social-media tracking pixels on it.
Information We Do NOT Collect
- We do not collect your location for advertising, profiling, or tracking, and we never sell or share it. GPS is used only while you are recording an outdoor workout — see “Location” below.
- We do not access contacts, messages, or call logs.
- We do not collect browsing or search history.
- We do not track you across other apps or websites.
- We do not sell your personal data to third parties.
2. How We Use Your Information
- To provide and personalize the App experience based on your goals and preferences.
- To calculate nutrition, fitness, and health targets (calories, macros, water, steps, etc.).
- To power the optional Pro AI features. When you start one, the input — a food or label photo, a meal, recipe or workout description, a journal entry you have separately consented to send, or a short summary derived from your own logged data for a weekly reflection — is sent to our secure proxy and forwarded to Google Gemini for processing in real time. We do not retain AI inputs after the response is generated, and they are not used to train models. AI output is informational and is never medical advice.
- To manage your Pro subscription via Apple's StoreKit and RevenueCat.
- To synchronize your account data across devices (only if you create an account).
- To monitor App performance, diagnose crashes, and improve features.
- To detect abuse and protect the integrity of the service.
3. Data Storage
On Your Device
Most of your data is stored locally on your device using encrypted storage. Sensitive information including medications, vital signs, dream logs, and journal entries is encrypted using iOS Keychain via Expo SecureStore.
In the Cloud (Optional)
If you create an account, we store the following on Supabase servers (hosted in the United States with industry-standard encryption):
- Account credentials (email, hashed password)
- Profile information you choose to save
- Synced health data (habits, workouts, meals, sleep, mood, journal entries) — only if you enable cloud backup
- Friend connections, challenges, and social features data
You can use the App fully without creating an account. In that case, no data leaves your device except as described in Section 4.
4. Third-Party Services
We use the following third-party services to operate the App. Each is bound by its own privacy policy:
- Supabase — Account authentication and optional cloud backup of your data. (Supabase Privacy Policy)
- Oura — Only if you choose to connect an Oura Ring. You authorise the connection on Oura’s own site, and the App then reads your daily readiness, sleep, daily activity and workout records from Oura so they can sit beside the rest of your day. Your Oura access tokens are stored on your device. Because Oura’s token endpoint requires a secret that cannot ship inside an app, the sign-in exchange passes through a small Clifford Corp Cloudflare Worker, which stores and logs nothing. Disconnecting in the App deletes the tokens and stops all further reading. (Oura Privacy Policy)
- RevenueCat — Manages Pro subscription state. Receives anonymous user ID and subscription status. (RevenueCat Privacy Policy)
- Apple StoreKit — Processes in-app purchases. We never see your payment information. (Apple Privacy Policy)
- Google Gemini AI (via our secure Firebase Cloud Functions proxy) — Powers the optional Pro AI features. Depending on which feature you use, the input may be: a food photo or a nutrition-label photo; a meal, recipe, or workout description you typed or dictated; a journal entry (only after you accept a separate in-app consent dialog); or a short summary derived from your own logged data — for example your recent sleep, meals, or mood — used to write a weekly reflection. Every one of these is user-initiated: nothing is sent in the background, and free accounts do not use this service at all. Inputs are processed in real time and not retained by us, and are not used to train models. Reading a printed nutrition label does not use this service — it runs entirely on your device. (Google Privacy Policy)
- Open Food Facts — When you scan a barcode, that barcode number is sent to the Open Food Facts database to look up the product’s nutrition. No account, no personal details and no health data are sent — only the barcode. (Open Food Facts Privacy Policy)
- Cloudflare — Serves the website and provides Cloudflare Web Analytics, which is cookieless and does not track visitors across sites. Cloudflare also processes the network requests needed to deliver the Site. (Cloudflare Privacy Policy)
- PostHog — Product analytics. Receives anonymous device ID and engagement events (e.g., "habit logged", "tab viewed"). Does not receive journal text, mood notes, free-text entries, names, emails, or specific health values. May record session replays of UI interactions to help us debug issues. (PostHog Privacy Policy)
We do not sell, rent, or share your data with advertisers.
5. Data Sharing
We do not sell, trade, or rent your personal information. We may disclose information only when:
- Required by law, court order, or legal process.
- Necessary to protect our rights, safety, or property.
- You explicitly authorize disclosure (e.g., adding a friend to a shared circle).
6. Your Rights
You have the right to:
- Access: View all your data within the App's Profile section.
- Export: Tap Download My Data in the Me tab, under Your Data. It writes every entry you have made to a JSON file you can save or send anywhere — including your cycle history and route data, which never reach our servers but are still yours to take. Nothing is held back, and it is not a Pro feature.
- Correct: Update your profile and health data anytime.
- Delete: Use "Delete My Data" in the Profile section to permanently erase all locally stored data. To delete cloud-stored data, contact us at the email below.
- Withdraw consent: Revoke any permission (HealthKit, photos, notifications) in iPhone Settings.
Regional Rights
- European Economic Area (GDPR): You have rights to access, rectify, erase, restrict, and port your personal data, and to object to processing. Contact us to exercise these rights.
- California (CCPA): You have the right to know what we collect, the right to delete, and the right to opt out of "sales" (we do not sell data).
- Canada (PIPEDA): You have the right to access and correct your personal information, and to file a complaint with the Privacy Commissioner of Canada.
7. Data Retention
- Local data: Retained on your device until you delete it or uninstall the App.
- Cloud data (if you have an account): Retained until you delete your account or request deletion. Backups may persist for up to 30 days after deletion.
- Analytics data: Aggregated, anonymized usage data may be retained indefinitely. Individual session replays are retained for up to 30 days.
- AI inputs: Not retained after response generation.
8. Children's Privacy
The App is intended for users 13 years and older. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly. Parents who believe their child has provided us with information may contact us at the email below.
9. Security
We implement reasonable technical and organizational measures to protect your data:
- HTTPS encryption for all server communications
- Encrypted local storage (iOS Keychain) for sensitive data
- Server-side API key management (no API keys ship with the App)
- Industry-standard authentication via Supabase
- Anonymous user identifiers for analytics
No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
10. International Transfers
If you are located outside the United States, please note that your information may be transferred to and processed in the United States and other jurisdictions where our service providers operate. By using the App, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the App. The "Last updated" date at the top reflects the most recent revision. Continued use of the App after changes constitutes acceptance.
12. Contact Us
For privacy questions, data deletion requests, or to exercise any of your rights:
Clifford Corp
Email: cliffordcorporation@gmail.com
Ottawa, Ontario, Canada