In short
HP works without an account. Optional Sign in with Apple lets you save records to HP’s dedicated storage and restore them on another device. Signing in alone does not upload health records.
Photo reading, separately consented text reading in build 5 and later, permitted weather requests, and purchase verification use external services. A meal photo is sent only with HP Pro and your explicit consent. Health data is never sent for photo analysis. Account record transfers are described in section 4 below.
What is normally processed on your device
- Health data (sleep, heart rate, resting heart rate, heart-rate variability, activity, body measurements, medications, cycle) — raw query caches and anchors stay on this device. Measurements and estimates contained in HP, ability history and body measurements are included when you choose to save account records
- Meals you type — version 1.0 builds 1–4 use Apple's on-device model. In version 1.0 build 5 and later, typed meal descriptions are sent through HP's relay to OpenAI only after separate consent to cloud text reading. Photo consent does not grant text consent. Saved meals are included in optional account transfers
- Water, how you feel, settings, your HP history — kept in a file on the device
What can leave your device
For version 1.0 build 5 and later text reading, the same OpenAI processing and retention terms apply. Withdraw this separate permission in Settings → Cloud text reading. Declining keeps manual food selection available.
1. A meal photo (only with Pro, and only after you agree)
- No photo is sent until you press the button on the consent screen
- It goes through HP's own relay (Cloudflare Workers) to OpenAI
- The relay stores nothing. It has no storage attached to it at all — no KV, no R2, no database, no queue
- Version 1.0 builds 1–4 receive food names and rough amounts. Version 1.0 build 5 and later receive names, descriptions, quantities, nutrients, kcal, uncertainty and sources. OpenAI web search may use food/product names to check commercial products. HP does not attach health records or account details to meal analysis requests
- HP’s relay does not retain the photo. Saving the meal keeps a thumbnail, no more than 200 pixels on its longest edge, in your local meal record and history. The original and source metadata such as GPS are not saved
- OpenAI API data is not used for training unless the API customer explicitly opts in to data sharing. HP does not send photos for training
- OpenAI may retain inputs for abuse monitoring, normally for up to 30 days, with exceptions for legal or safety needs and image safety review. The relay’s lack of storage does not mean OpenAI has zero retention. See OpenAI’s data controls
- You can withdraw this at any time: Settings → Cloud photo reading
2. Approximate location (only if you allow it)
- Used only to read the weather. Approximate, not precise
- It reaches exactly two things: the weather shown at the top of Home, and that day's water goal
- If you decline, the weather quietly disappears and nothing is said about it
3. Purchases
- Purchases are handled by the App Store. HP never sees a card
- RevenueCat is used to check whether a subscription is active. It receives purchase records, an anonymous app-generated identifier (or your HP account ID after sign-in), and technical information such as OS, device and app versions — no name, no email address, and no health data
4. Sign in with Apple and saved records (optional)
- Apple authenticates you. HP links Apple’s subject identifier to an HP account ID, which also identifies your plan in RevenueCat. HP does not request your name or email.
- Only after you confirm Save in Account & records, HP sends your profile (including your in-app name, birth year, body measurements and pregnancy setting), HP/debt/calculation timestamp, abilities and daily history, meals and nutrients, drinks, water, and body/sleep reports to dedicated Cloudflare Workers/D1 storage. These records contain health measurements and estimates.
- HTTPS protects transport; AES-GCM encrypts stored records and Apple refresh tokens. HP’s server holds the keys used to encrypt and decrypt these records; this is not end-to-end encryption. Raw HealthKit query caches/anchors, photos/thumbnails and device permissions are excluded.
- Save and Restore are explicit; records are not automatically merged. Conflicting saves are rejected. A pre-restore copy stays inside this account’s local storage.
- Signing out retains saved records. Delete HP account deletes active cloud records and this account’s local files and revokes Apple authorization. Other devices’ offline copies cannot be remotely erased. Operational backups may remain for Cloudflare’s retention period. App Store subscriptions must be cancelled separately.
What HP does not do
- No advertising
- No app-behavior analytics or advertising-tracking SDKs. RevenueCat uses purchase information for subscription verification and aggregated purchase/subscription reporting
- No sale of data or sharing for advertising or tracking. Processing by the services above occurs only for the described features
What you can do
- Export: Settings → Export my data — includes saved thumbnails; you choose where to keep or share the exported file
- Delete: The data deletion control removes the current local records. Use Account & records → Delete HP account to also delete its cloud records and local recovery copies
- Revoke Health access: iOS Settings → Privacy & Security → Health
- Stop cloud photo reading: Settings → Cloud photo reading
Children
HP is not directed at children under 13, and does not knowingly collect their information.
Changes
When this policy changes, the date at the top changes with it. Anything significant will be said in the app's release notes.