Health.md Privacy Policy
Last updated: 2026-07-30
This draft was written from the shipping code rather than from a template. Every factual claim below is traceable to an implementation detail, and the notes in brackets say where. Remove the bracketed notes before publishing.
The short version
Health.md has no account, no analytics, and no advertising. Your health information is stored on your iPhone and excluded from iCloud backups. Two things leave your device: your questions go to Apple's Private Cloud Compute when that setting is on, and your Oura token goes to Oura if you connect it. Nothing goes to us. We cannot see your health data, your questions, or your chats.
This website
This section covers joinhealthmd.com, the site you are reading. It is separate from the Health.md app, and the two behave very differently. The app collects nothing. This site does collect the email address you type into it, because that is the only way to tell you when the beta opens.
If you join the beta list, we store: your email address, the iPhone model you selected, and which page you signed up from. These go to Klaviyo, our email provider, who stores and sends on our behalf. We use them to email you about Health.md and nothing else. Every email carries an unsubscribe link, and unsubscribing removes you.
We never sell, rent or share that list. No advertiser, no data broker, no partner.
Advertising measurement. When we run ads, this site may send a single "Lead" event to Meta so we can tell which ad brought you here. That event carries a one-way hashed copy of your email address and nothing about your health. We never send health information to any advertising platform, and there is nothing on this site that could collect any.
This site sets no advertising cookies of its own.
To be removed entirely, unsubscribe from any email or write to preston@metapv.co and we will delete your record.
Nothing in this section applies to the Health.md app. The app has no account, sends no analytics, and is covered by everything below.
Who we are
Health.md is published by MetaPV. Contact: preston@metapv.co.
What Health.md stores, and where
All of it is on your iPhone:
- Your profile — conditions, medications, and lab values you enter.
- Your chats — every conversation, including the questions you asked.
- Memories — durable facts Health.md picked up from your chats, which you
can view, pause, and delete individually.
- Health history — the metrics Health.md reads from Apple Health (activity,
heart, sleep, respiratory, blood oxygen, temperature, weight, blood glucose, blood pressure, workouts, medications), plus Oura scores if connected.
- Check-ins — the notifications you've asked Health.md to send you, and
the wording of each, which you can read, pause, and delete individually.
- Your Oura access token, if you connect Oura, in the iOS Keychain.
[Implementation: Application Support/HealthMD/ — profile.json, chats/, memory/memories.json, check-ins/check-ins.json, health.sqlite — plus the readable mirrors in Documents/HealthMD/. Token in KeychainStore, accessible only after first unlock, on this device only.]
This data is excluded from iCloud and iTunes backups. That is deliberate: it keeps your health record off Apple's servers. It also means the data will not move to a new phone by itself — use Settings → Export my data first.
One exception, stated plainly: a check-in you have scheduled is handed to iOS, and iOS holds its text until it fires. That copy lives in the system's notification store rather than in Health.md's own files, so it is outside the backup exclusion above and it can appear on your lock screen. This is why check-in wording is kept general — it never contains a number, a condition, or a medication. Anything specific stays in the app, behind your app lock.
[Implementation: CheckInContent rejects any message containing a digit, a condition or medication name, a claim, or urgency, and the notification title is a constant. The notification carries only the check-in's identifier; the subject is looked up inside the app.]
We do not have a copy of any of it. There is no server to hold one.
What leaves your device
1. Apple Private Cloud Compute
On by default. When on, answering a question sends the following to Apple's Private Cloud Compute:
- your question and the conversation so far
- the reference passages the library retrieved for it
- your saved conditions, medications, and lab values
- your stored memories
- a summary of roughly your last 30 days of Apple Health and Oura data
Private Cloud Compute is Apple infrastructure, not ours. Apple states that it does not retain this data, that it is not accessible to Apple, and that the guarantee is cryptographically verifiable. We never receive it.
You can turn this off in Settings → AI model. Answers are then composed entirely on your iPhone.
[Implementation: FMModelProvider, default pccEnabled = true. Context assembled in ChatPipeline from AppModel.chatProfile.]
2. Oura
Only if you connect it. Health.md sends your Oura personal access token and the range of dates it is requesting to api.ouraring.com. This tells Oura that you are using a health app and when. No health data is uploaded — Health.md only reads. Oura's handling of that request is governed by Oura's own privacy policy.
Disconnecting deletes the token and every row Oura wrote.
3. Links you tap
Tapping a source citation opens that page in Safari, like any other link.
That is the complete list. Health.md makes no other network requests.
What we do not do
- No account, no sign-in, no user identifier.
- No analytics, crash reporting, or telemetry SDKs of any kind.
- No advertising, no ad identifiers, no tracking across apps or websites.
- We do not sell, share, or disclose your information to anyone, for any
purpose. There is no mechanism by which we could.
[Implementation: the only third-party dependencies are Yams, swift-transformers, and GRDB. No SDK in the project transmits anything.]
Apple Health
Health.md requests read-only access to Apple Health. It never writes to Apple Health. You choose which categories to share in the iOS permission prompt, and can change it any time in the Health app.
Health data read from Apple Health is used only to show your trends in the app and, when you have the setting on, to personalize your answers. It is never used for advertising or shared with third parties — as required by App Store Review Guideline 5.1.3.
Your rights
- Export — Settings → Export my data produces a zip containing your
profile, chats, memories, and complete health history in open formats (Markdown and CSV).
- Delete — Settings → Delete all my data permanently removes everything
from your device, including every scheduled check-in, and returns the app to its first-run state. Because your data is excluded from backups, there is nothing to restore afterward.
- Delete selectively — individual chats, memories, and check-ins can be
deleted on their own.
Because we hold no copy of your data, requests to access, correct, or delete it are things you perform in the app rather than requests you send us.
These capabilities are offered to everyone, not only to residents of jurisdictions that require them.
Children
Health.md is not directed at children and is not intended for anyone under 18.
Medical disclaimer
Health.md is an educational tool. It is not a medical device, it does not diagnose, and it does not provide treatment recommendations. Its reference library quotes published sources and has not yet been reviewed by a licensed clinician; passages are labeled "Draft" until that review happens. Never delay seeking care because of something you read here. In an emergency, call 911, or 988 for a mental-health crisis.
Changes
If this policy changes materially, the app will ask you to review the updated terms before you continue using it.
[Implementation: ConsentRecord stores the accepted terms version and date; needsReconsent is true when the current version differs.]