Privacy Policy
Draft. Last updated: October 2026. This policy is pending legal review.
Who we are
HealthPipe is operated by the HealthPipe team. You can reach us at support@healthpipe.app.
Health data we Sync
HealthPipe reads Apple Health data only for the Categories you allow, and only after you grant permission in iOS. The Categories HealthPipe can Sync are:
- Steps: daily step counts
- Active energy: energy burned through activity
- Heart rate: heart rate measurements
- Resting heart rate: daily resting heart rate
- Heart rate variability: HRV measurements
- Weight: body weight measurements
- Oxygen saturation: blood oxygen (SpO2) measurements
- Sleep: sleep intervals, including sleep stages where your devices record them
- Workouts: workout type, duration, energy and heart rate details where available
HealthPipe is read-only. It never writes to Apple Health. We do not store HealthKit data in iCloud.
Other data we collect
- Sign in with Apple identifiers: a stable Apple user identifier and, if you share it, your email or Apple's private relay address.
- Usage Events: things you do in the app, such as opening a screen or tapping a button, linked to your Account. They never contain health values. You can opt out in the app settings.
- Telemetry: technical traces, metrics and error logs used to operate the service. They contain Categories, Sample counts and durations, never health values. Telemetry from the app follows your analytics opt-out, except Sync errors, which we need to keep the service running.
- Push notification tokens: Apple Push Notification service (APNs) tokens, used to wake the app so it can Sync in the background.
- Subscription state: whether your Account has an active Entitlement, derived from your Apple subscription. We do not see your payment details.
Why we use it
- To Sync the Categories you chose to your Account and keep them fresh.
- To answer questions from AI assistants you have approved.
- To sign you in, manage your subscription and send technical notifications.
- To operate, secure and improve the service.
We do not use your data for advertising or marketing, we do not sell it, and we do not mine it.
Who receives it
- AI assistants you approve. Only an assistant you explicitly approve in the HealthPipe app becomes a Connection, and it can read only the Categories you picked for it. You can revoke a Connection at any time. What an assistant does with data it has read is governed by that provider's own terms.
- Apple, for Sign in with Apple, push notifications and subscription payments.
We use no third-party analytics or advertising services.
Where it is stored and how it is protected
Your data is hosted on servers we operate at Hetzner in Germany. The values of your health Samples are encrypted with a key specific to your Account, so a leaked database or backup does not reveal them. Data is encrypted in transit, and backups are encrypted.
How long we keep it
We keep your data while your Entitlement is active, including during the free TestFlight beta. If your Entitlement lapses, Sync and assistant access stop, we notify you, and we delete your data 30 days after it lapses. If you delete your Account, we delete your data and revoke the Sign in with Apple tokens we hold.
Your rights
You can export your data, delete your Account and data, and revoke any Connection. If you are in the EU or UK you also have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your data protection authority. Contact support@healthpipe.app to exercise them.
Not medical advice
HealthPipe is a personal tracking tool, not a medical device.
Changes
If we change this policy in a material way, we will tell you in the app before it takes effect.