What we collect, and what we do not
Healthsome is paid for by the people who use it. There is no advertising business behind it, so there is nothing to gain from knowing more about you than the app needs. Here is exactly how that works in practice.
Encrypted before it leaves your device
What you record in your trackers and your journal is encrypted on your device with AES-256-GCM, and only your devices hold the key. That covers:
- The values you log, and any notes attached to them
- Your journal entries
- The names you give your trackers
- Your reminders and workout templates
Your 12-word recovery phrase is what unlocks all of it on a new device. Healthsome never receives that phrase and genuinely cannot recover it for you.
The details on your account — your name, birthday, height and the rest — are a separate matter, and they are not encrypted this way. The next section says exactly what stays readable.
What the server can still see
Some structure has to stay readable, or the app could not sort, filter or remind you of anything. The server can see:
- Your account identifier, and the identifiers of your trackers and entries
- Timestamps, reminder times, and whether a reminder is switched on
- Tracker types, Apple Health metric names, and goal flags, so a weight tracker is known to be a weight tracker
- The details on your account itself: your name, email, birthday, gender, height, weight and units. These are not encrypted the way your entries are
- Which trackers and tags you have hidden. Hiding a journal tag stores its name in the clear, even though the same tag is encrypted inside the entry
So the server can tell that you logged a sleep entry this morning. It cannot tell what the entry said. Our host also keeps ordinary web server logs, which include request times and IP addresses, as any website does.
No ads, and no analytics
There is no advertising SDK and no analytics or telemetry SDK anywhere in Healthsome, on the phone or on the web. Nothing profiles you, nothing follows you between apps, and the iPhone app does not ask for tracking permission because it has no use for it. Your health data is never sold, and never shared for marketing.
Cookies
This website sets only the cookies needed to sign you in and keep you signed in. There are no advertising cookies and no analytics cookies, so there is nothing here to consent to and no banner to dismiss.
The iPhone app does not use cookies at all. It keeps your sign-in token in the device's keychain instead.
If you joined the waitlist
The signup form on the homepage stores four things: the address you gave us, the moment you gave it, a random token that takes it back off the list, and — once the launch email has gone out — the fact that we sent it, so that a retry cannot mail you twice. No IP address, no browser details, and nothing about where you came from.
It exists to send one email, when the app reaches the App Store. We keep the list ourselves rather than handing it to a mailing service, so there is no open- or click-tracking in the message — the same reason there is no analytics anywhere else here. The message itself goes out through our own mailbox, which Microsoft hosts.
Every message carries an unsubscribe link, and following it deletes the address outright rather than marking it as unsubscribed. Your waitlist address is not an account, is never matched against one, and is never sold or shared.
The services we rely on
Running the app means a few companies are involved. None of them receive anything they could read your health data from.
Auth0
Handles signing in. It sees your email address and the usual login records, such as times and IP addresses.
RevenueCat and the App Store
Handle healthsome+ subscriptions. They see your account identifier and your purchase history, along with device details Apple provides for billing. No health data goes to either.
Vercel and MongoDB
Host the service and store your data. What they hold for the things you log is encrypted, and neither can read it.
Microsoft 365
Hosts our email. It sees anything you write to us, including a request to see or delete what we hold, and every address on the waitlist when the launch email goes out.
Apple Health
Steps, weight, heart rate, sleep and nutrition are read on your device, with your permission, and encrypted like everything else before they are uploaded.
Two lookups that leave your device in the clear
We would rather tell you about these than let you find them yourself. Both are requests to outside services that carry no account identifier, but they do reveal your IP address to that service:
- Weather. If the weather module is on, your device asks Open-Meteo for the forecast at your coordinates. You can switch the whole module off in your account settings, and nothing is requested after that.
- Barcode scanning. When you scan food, the barcode goes to Open Food Facts to find out what it is. It is sent only at the moment you scan.
Questions
If anything here is unclear, or you want to see, correct or delete what we hold, write to hello@healthsome.io. You do not have to wait for us, though. The iPhone app can export a full, readable copy of everything it holds for you, from App Settings, and either app can delete your account outright whenever you like.
The formal privacy policy
Everything above is the plain-language version, and it is the one we would rather you read. The full legal policy lives here too, and nothing in it contradicts this page.
Read the full privacy policy ↗