HealthRaw Privacy Policy

Version 1.0 · Prepared 2026-10-10 · Applies from publication.

The short version

1. Who we are

The controller of your personal data is DMT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (DMT sp. z o.o.), ul. Budowlanych 1A, 62-081 Baranowo, Poland; KRS 0000836521; NIP 7812007881; REGON 385877414 ("we", "us"). You can contact us about privacy at [email protected] or by post at the address above.

For data-protection questions and requests about your rights, contact [email protected].

This policy covers the HealthRaw iPhone app, the Premium cloud service (sync, private link and MCP connector) and the website at healthraw.app.

2. What HealthRaw does

HealthRaw reads data from Apple Health (HealthKit) with your permission and makes it available in a form that AI assistants can read. It never writes to Apple Health. It is not a medical device and does not give medical advice.

3. Free tier: we receive nothing

When you use only the free export:

Apple may share crash reports and app usage statistics with us if you allowed "Share with App Developers" in your iPhone settings. Apple collects these under its own privacy policy; they contain no Health data.

4. Premium: what we process

Category Examples Source
Health data (special category, Art. 9 GDPR)The Apple Health types you select: activity, workouts, heart rate and other heart data, sleep, body measurements, vitals, nutrition, mindfulness and mood, hearing, ECG metadata, and, if you select them, reproductive health and sexual activity. Also characteristics such as date of birth, sex, blood type and wheelchair use, and daily summaries we compute from these.Your iPhone
Location within health dataWorkout routes (GPS points recorded during workouts)Your iPhone
Account and device dataA random account identifier, a device identifier, hashed device and access tokensCreated by the app and our server
Subscription dataProduct, subscription status and expiry, Apple transaction identifiers, environment (sandbox or production)Apple, via signed App Store transactions
Access settings and access logNames, type, creation, expiry and last use of your private links and connector keys; a log of each read (time, link or key name, which tool or endpoint)Our server
Consent recordsWhich consent text (id, version, language) you accepted or withdrew, and whenThe app
Technical logsTime, IP address, endpoint, status code, response size (our web server's logs, Caddy)Our server
Support messagesYour email address and what you write to usYou

We do not collect your name, phone number, contacts, photos or advertising identifier, and we don't ask for an email address to use the app.

Purpose Data Legal basis
Store and sync your Health data and make it available to youHealth data, location within health dataYour explicit consent, Art. 9(2)(a) and Art. 6(1)(a) GDPR
Make your data available to the AI service you connectHealth data, location within health dataYour explicit consent given when you create each link or connector key, Art. 9(2)(a) and Art. 6(1)(a)
Run your account, check your subscription, manage links and keys, show you the access logAccount, subscription and access dataPerformance of our contract with you, Art. 6(1)(b)
Prove that you gave consentConsent recordsLegal obligation, Art. 6(1)(c) with Art. 7(1) GDPR
Keep the service secure, prevent abuse, fix faultsTechnical logsOur legitimate interest in a secure service, Art. 6(1)(f)
Answer support requests and requests to exercise your rightsSupport messagesArt. 6(1)(b) and Art. 6(1)(c)
Establish, exercise or defend legal claimsThe minimum neededArt. 6(1)(f) and, for health data, Art. 9(2)(f)

Giving consent is voluntary. Without it, you can still use the free export. We do not make decisions about you based solely on automated processing, and we do not profile you.

What we never do with your Health data: sell it, rent it, use it for advertising or marketing, use it for data mining or profiling, use it to train AI models (ours or anyone else's), give it to data brokers, or store it in iCloud. We don't use it for anything other than delivering it to you and to the AI you connect.

6. How we protect it

What we can't protect against. We are honest about the limits:

More detail: healthraw.app/security.

7. Who receives your data

Recipient Role What and why Where
OVHcloudProcessor (hosting)Servers, encrypted disks and object storage that hold your encrypted dataEU
EU backup infrastructure providersProcessor (backups)Encrypted backupsEU
Email-routing and mailbox providersProcessor (email)Support emails only, never Health dataAccording to the email providers’ locations and safeguards
AppleIndependent controllerApp Store, payments and subscriptions are handled by Apple under its own privacy policy; Apple sends us signed transaction informationApple's locations
The AI service you connectIndependent recipient you chooseWhatever it reads through your link or connectorWherever that provider processes data
Public authoritiesAs required by lawOnly when we are legally obliged, and only what we can access—

We have data processing agreements (Art. 28 GDPR) with our processors. We have no advertising, analytics or data broker partners.

8. Transfers outside the EEA

We store and process your Health data on our servers in the European Economic Area. Support messages use separate email providers; do not include Health data or secret links in them.

The exception is the AI service you connect. If that provider processes data outside the EEA (for example in the United States), your data goes there because you created the link or connector key and gave it to that provider. That provider is responsible for its own processing and safeguards; please check its privacy policy.

9. How long we keep it

Data How long
Free-tier export filesOn your iPhone only; deleted after sharing or after 24 hours. We never receive them.
Health data and daily summaries (Premium)While your subscription is active. When it ends, 30 more days so you can resubscribe, then deleted (backup copies within about 35 days after that). Deleted immediately when you delete your cloud data or withdraw consent.
BackupsEncrypted backups, including the wrapped keys stored in them, are kept for at most about 35 days. After you delete your data, backup copies become unreadable and are deleted within about 35 days.
Access logAt most 90 days, encrypted with your data key.
Technical logsAt most 30 days, including the IP addresses in our web server's logs.
Account, device, subscription and link or key settingsUntil your account is deleted.
Consent recordsFor the life of your account and then only as long as needed to demonstrate consent and establish, exercise or defend legal claims, taking account of the applicable limitation periods.
Support messagesUntil the case is resolved, then only for as long as necessary to meet legal obligations or establish, exercise or defend legal claims.

How deletion works. First we destroy every wrapped copy of your account's key ("crypto-shredding"), which makes your stored Health data unreadable straight away. Then we remove the encrypted data itself and revoke all links and connector keys. Encrypted backup copies become unreadable and are deleted within about 35 days, when those backups expire. Deleting the app from your iPhone does not delete your cloud data.

10. Your rights

You have the right to:

How to use them:

We answer within one month. For complex requests we may extend this by two more months and will tell you why.

Your subscription is billed by Apple. Deleting your data does not cancel it; cancel it in your Apple account settings (the app links there).

11. Children

HealthRaw is for people aged 16 and over. It is not directed at children under 16, and we do not knowingly process their data. If you believe a child under 16 uses Premium, contact us and we will delete the data.

12. Cookies and the website

Our website uses no cookies, trackers, analytics or third-party scripts or fonts. Our web server (Caddy) keeps technical logs, including your IP address, for at most 30 days (see section 9) to keep the site running and secure.

13. Changes to this policy

We will publish any change here with a new effective date and tell you in the app. If a change affects what you consented to (for example a new kind of data or a new recipient), we will ask for your consent again before it applies to you. Earlier versions are available on request.

14. Contact

DMT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (DMT sp. z o.o.), ul. Budowlanych 1A, 62-081 Baranowo, Poland; KRS 0000836521; NIP 7812007881; REGON 385877414 Email: [email protected]