Effective date: August 8, 2026
Simple Health reads your Apple Health data and explains it in plain language. This policy is written the same way. It tells you exactly what we collect, where it goes, who sees it, and how to make any of it stop.
This policy covers the Simple Health iPhone app, the Apple Watch app, the widgets, our backend service, and our website (hellosimplehealth.com). It applies together with our Terms of Service. You can always find the latest version of both inside the app and at our legal pages.
Simple Health is operated by Haider Nawaz ("we," "us"), based in Pakistan. For data protection law, we are the controller of the personal data described in this policy.
Questions, requests, or complaints: haider.builds@icloud.com
With your permission through Apple's Health permissions screen, the app can read these categories from Apple Health. You can grant or deny each one individually, and change your mind anytime in iOS Settings > Privacy & Security > Health.
How your Health data is stored: when you are signed in and have left the "Share my health timeline with the developer" setting on (it is on by default; Settings > Privacy), the app uploads a daily snapshot of your rolled-up Health metrics (such as sleep, steps, heart rate, and workouts) and your day's activity timeline to the Simple Health backend, where it is stored and tied to your account. We use it to power the experience across your devices and to improve the app. Under that same setting, the app also stores monthly and yearly summaries of your Health history: averages, totals, and trends for metrics such as sleep, steps, and workouts, never raw sensor recordings. These summaries reach back as far as your Health data goes (often several years), so the AI can answer questions about earlier months and years. You can turn this off at any time in Settings > Privacy, which stops further uploads, and deleting your account removes everything we have stored (see "Deleting your account and data" below).
These are the categories we may request, including but not limited to the examples above; you grant or deny each individually.
This data comes from your iPhone's Health app, including data that wearables (Apple Watch, or third-party devices like Oura or Whoop) sync into Apple Health. We read it; we do not write anything into Apple Health.
When the app sends health information to our server (for cloud insights, chat, or smart notifications), it sends summaries and event-level statistics: for example, daily totals and averages, a single workout's duration and average heart rate, last night's sleep-stage totals, or in some cases your most recent heart-rate reading. We never send continuous raw sensor recordings.
No advertising identifiers. No precise or GPS location. No contacts. No advertising SDKs, and nothing that tracks you across other apps or websites. Diagnostic logs created by the app (Apple's OSLog) stay on your device.
We use Mixpanel to understand how the app is used so we can improve it: which screens are opened, which features are used, your sign-in, onboarding, and subscription steps, and your app and OS version, subscription tier, and chosen AI engine. These product-interaction events are linked to your account identifier. We never send your Apple Health values or any health readings to Mixpanel; a built-in safeguard strips health values before any event leaves your device, and we never use this data for advertising or cross-app tracking. Mixpanel also derives an approximate location (country, region, and city) from your IP address to understand where the app is used; we never collect precise or GPS location. Analytics is on by default in the released app and is always off in our development builds. You can turn it off anytime in Settings > Privacy, and doing so never changes how the app works.
When the app crashes or hits an unexpected error, we send a diagnostic report to Sentry, a crash-reporting service, so we can find and fix the problem. These reports contain technical information such as the error and its stack trace, sampled performance timings, your device model, operating system, and app version, and a short trail of recent non-health app events (for example, that a screen opened or a network request failed), tagged with your account identifier. We never send your Apple Health values or any health readings to Sentry; the same safeguard that protects analytics also strips health values here, and no advertising or cross-app tracking is involved. Crash and error reporting is part of keeping the app reliable, so it is always on in the released app and always off in our development builds.
If you enter your email on our website (hellosimplehealth.com) to join the early-access list, we store that email in our database (Neon) for the sole purpose of telling you when the beta opens. We do not use it for anything else and do not share it. Ask us to remove it anytime at haider.builds@icloud.com.
New accounts pick an AI engine during setup, and you can change it anytime in Settings. If no choice has been made, the app uses Auto.
Your health data is processed entirely on your iPhone using Apple's on-device models. Nothing is sent to our servers or to any AI provider to generate your insights.
Health summaries and event-level statistics are sent from your iPhone to our server (a Cloudflare Worker), which forwards them to OpenAI. When the cloud engine is active, questions you type into the in-app chat are also sent, together with the related health context. We use Cloud AI for insights when you have chosen Cloud AI or Auto (Auto prefers the cloud when it is available).
What OpenAI does with this data:
Settings also offers an Auto option, and Auto is what the app uses until you pick an engine. Auto prefers Cloud AI whenever it is available on your plan, then On-Device AI, then a simple non-AI template. Picking Auto, or leaving it as the default, can send your health summaries to our server and to OpenAI exactly like choosing Cloud AI. If you never want that, pick On-Device AI.
This is the one exception to the on-device promise, and we want it to be impossible to miss.
When smart notifications are enabled, the app generates notification text with the cloud AI, regardless of which engine you selected. When a notable event happens (a workout, a sleep session, a mindfulness session, your activity rings, a heart event such as a high, low, or irregular-rhythm notification, a body-measurement entry such as weight or body composition, or a cycle-tracking entry), a short summary of that single event (for example, one workout's duration and effort, or that a high or irregular heart rate event occurred), bucketed to the hour of day, is sent to our server and forwarded to OpenAI so the notification copy can be written. We never send raw sensor streams or precise timestamps. This now applies to all accounts with notifications enabled, including the free plan, not only the free trial or a Cloud AI plan. To control cost, free accounts are limited to a set number of AI-written notifications per day. When cloud generation is unavailable at that moment (you are offline, or a free account is over its daily limit), the notification is not written from an on-device template; instead it waits and is generated by the cloud once it is reachable again or the limit resets. Over the daily limit, the summary still reaches our server but is not forwarded to OpenAI until the limit resets. Disabling notifications for Simple Health in iOS Settings stops all of this entirely. Everything else then runs fully on-device if that is your chosen engine.
We do not use your data for any other purpose without telling you and, where required, asking first.
Your watch app and widgets read health data locally on your devices (from data your iPhone shares with them and, on the watch, from the watch's own Health database). They never communicate with our servers.
We share data only with the service providers below, only so they can run parts of the service for us. Each is bound by a data processing agreement requiring protection at least as strong as this policy, and none of them may use your data for their own purposes. We have no affiliates and share consumer health data with no one else. We would disclose data beyond this list only if validly required by law, and we would tell you unless legally prevented.
| Provider | What they do | What they receive |
|---|---|---|
| Apple | Sign in with Apple, push notifications, App Store payments | Apple receives your device's push notification token (to deliver notifications) and purchase verification requests containing transaction identifiers. In the other direction, Apple sends us your Apple identifier, email, optional name, and purchase records (transaction identifiers, never payment details). We never receive card details or billing addresses. |
| RevenueCat | Runs our in-app purchase infrastructure and revenue analytics | Purchase records from the App Store: transaction and product identifiers, prices and currency, and subscription status, together with a pseudonymous customer identifier (your account ID) and basic app and device metadata. RevenueCat never receives your name, email, payment details, or any health data. |
| Cloudflare | Hosts our API (Workers) and, where configured, routes cloud AI requests (AI Gateway) | All traffic between the app and our backend, including health summaries when cloud features are used. Requests are processed on Cloudflare's global network at the data center nearest you. Cloudflare does not use this content to train AI models. |
| Neon | Our database (serverless Postgres) | Your profile, your stored daily health snapshots, monthly and yearly summaries of your Health history, weekly story insights, your chat conversations, push notification tokens, subscription and trial records, AI memory (patterns and facts from chat, including supporting sentences), and any feedback. Stored in the United States, encrypted at rest and in transit. |
| OpenAI | Cloud AI engine | Health summaries and event-level statistics sent for cloud insights, questions you type into the in-app chat with the related health context (when the cloud engine is active), and single-event summaries for smart notification text (for all accounts with notifications enabled, including free accounts up to a daily limit). Not used to train OpenAI's models under its API terms; retained only briefly for abuse monitoring, longer only if required by law. |
| Mixpanel | Product analytics | App usage events such as screen and feature interactions and your sign-in, onboarding, and subscription steps, plus app and OS version, subscription tier, and chosen AI engine, and an approximate location (country/region/city) derived from your IP, linked to your account identifier. Never any Apple Health values. Not used for advertising and not shared for cross-app tracking. |
| Sentry | Crash & error diagnostics | Crash and error reports (error type and stack trace), sampled app performance timings, a short trail of recent non-health app events, and your device model, OS version, and app version, tagged with your account identifier. Never any Apple Health values. Not used for advertising or cross-app tracking. |
Our database is hosted by Neon in the United States. API requests are processed on Cloudflare's global network. OpenAI processes cloud AI requests in the United States. RevenueCat processes purchase records in the United States. Our team administers the service from Pakistan.
If you are in the EEA, the UK, or Switzerland, this means your data is transferred outside your region. Where a provider is certified under the EU-US Data Privacy Framework, we rely on that certification; otherwise we rely on Standard Contractual Clauses and equivalent safeguards. You can ask us for a copy of the relevant safeguards at haider.builds@icloud.com.
You can withdraw any consent at any time, as easily as you gave it: switch to on-device AI, turn off notifications, turn off analytics in Settings, revoke Health permissions in iOS Settings, or delete your account. Withdrawing consent does not affect the lawfulness of processing that already happened. The app keeps working without cloud consent: the on-device engine and your Health data on your phone do not depend on it.
We make no automated decisions about you that have legal or similarly significant effects. AI insights are informational explanations, nothing more.
If a law ever requires us to keep specific data longer, we will keep only that data, only as long as required, and we will tell you.
Open the app, go to Settings, and tap Delete account. This immediately and permanently deletes everything we store about you in our database: your profile, your stored daily health snapshots (summaries and activity timelines), the monthly and yearly summaries of your Health history, stored insights (weekly stories), your chat conversations, your AI memory (including the sentences from chat that support it), push notification tokens, subscription records, trial record, and any feedback. We also revoke your Sign in with Apple token with Apple, so the app can no longer use it. No email or phone call required.
Three things deletion cannot do for you:
You can also request deletion, or ask what we hold about you, by emailing haider.builds@icloud.com.
You can ask us to access, correct, export, or delete your data, and you can withdraw any consent, by using the in-app controls or emailing haider.builds@icloud.com. We aim to respond within 30 days and will always meet the deadline your local law sets. We will never punish you for exercising your rights. Nothing in this policy limits mandatory consumer or privacy protections you have under the laws of your country.
You additionally have the rights of access, rectification, erasure, restriction, objection, and data portability, plus the right to lodge a complaint with your data protection authority (any EU supervisory authority, or the ICO in the UK).
The categories of information we collect, the third parties we share with, and your choices are all described above. We do not sell or share personal information for cross-context behavioral advertising. We will notify you of policy changes as described below. Global Privacy Control and Do Not Track signals request opt-outs from selling or sharing personal information; we never sell or share personal information, so there is nothing for these signals to switch off, and you are already opted out by default.
This section, with the rest of this policy, serves as our Consumer Health Data Privacy Policy.
No system is perfectly secure. If a breach affects your data, we will notify you and the relevant regulators as required by law, including the timelines of the US FTC Health Breach Notification Rule.
Simple Health is not directed at children. You must be at least 13 years old, and at least the age of digital consent where you live (16 in parts of the EEA). We do not knowingly collect data from anyone under these ages; if you believe we have, email haider.builds@icloud.com and we will delete it.
Simple Health is an informational and educational tool, not a medical device. Its AI explanations are not medical advice, diagnosis, or treatment. Always talk to a qualified clinician about your health, and never rely on the app in an emergency: call your local emergency services.
When we change this policy, we will update the effective date at the top and post the new version in the app and at our legal pages. For material changes, we will notify you in the app, and where the law requires fresh consent (for example, a new use of your health data), we will ask before the change applies to you.