HealthRaw Privacy Policy
Version 1.0 · Prepared 2026-10-10 · Applies from publication.
The short version
- Free: the app reads your Apple Health data on your iPhone and builds an export file there. Nothing is sent to us. You decide where the file goes.
- Premium: your iPhone syncs the Health data you select to our servers in the EU. It is encrypted with keys we don't store: they live on your iPhone and in the links or connectors you create. We have no master key and can't decrypt your stored data on our own. Our server decrypts it only for a moment, in memory, while your iPhone is uploading or while one of your links or connectors is used.
- Your AI, your choice: we share your data only with the AI service you connect (for example Grok, ChatGPT, Claude or your own agent). Once it reads your data, its own terms apply.
- Never: we don't sell your data, use it for advertising, use it to train AI, or store it in iCloud.
- Your control: the app's access log shows every read made with your links or connectors, kept for up to 90 days. You can revoke access, download your data or delete everything at any time, also without the app. If your subscription ends, we delete your data after 30 days (backup copies within about 35 days after that).
1. Who we are
The controller of your personal data is DMT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (DMT sp. z o.o.), ul. Budowlanych 1A, 62-081 Baranowo, Poland; KRS 0000836521; NIP 7812007881; REGON 385877414 ("we", "us"). You can contact us about privacy at [email protected] or by post at the address above.
For data-protection questions and requests about your rights, contact [email protected].
This policy covers the HealthRaw iPhone app, the Premium cloud service (sync, private link and MCP connector) and the website at healthraw.app.
2. What HealthRaw does
HealthRaw reads data from Apple Health (HealthKit) with your permission and makes it available in a form that AI assistants can read. It never writes to Apple Health. It is not a medical device and does not give medical advice.
- Free tier: a full-history export to a zip file on your iPhone, which you save or share yourself.
- Premium (paid subscription): background sync to our servers in the EU, a private link you can revoke, and an MCP connector so the AI you choose can read your data.
3. Free tier: we receive nothing
When you use only the free export:
- The app reads the Health data types you allow, on your iPhone.
- The export file is created in temporary storage on your iPhone, excluded from backups, and deleted after you share it or after 24 hours.
- The data leaves your iPhone only when you send the file somewhere yourself (Files, AirDrop, Mail, an AI app and so on). The terms of the place you send it to apply from then on.
- There is no account, no upload, no analytics and no advertising SDK.
Apple may share crash reports and app usage statistics with us if you allowed "Share with App Developers" in your iPhone settings. Apple collects these under its own privacy policy; they contain no Health data.
4. Premium: what we process
| Category | Examples | Source |
|---|---|---|
| Health data (special category, Art. 9 GDPR) | The Apple Health types you select: activity, workouts, heart rate and other heart data, sleep, body measurements, vitals, nutrition, mindfulness and mood, hearing, ECG metadata, and, if you select them, reproductive health and sexual activity. Also characteristics such as date of birth, sex, blood type and wheelchair use, and daily summaries we compute from these. | Your iPhone |
| Location within health data | Workout routes (GPS points recorded during workouts) | Your iPhone |
| Account and device data | A random account identifier, a device identifier, hashed device and access tokens | Created by the app and our server |
| Subscription data | Product, subscription status and expiry, Apple transaction identifiers, environment (sandbox or production) | Apple, via signed App Store transactions |
| Access settings and access log | Names, type, creation, expiry and last use of your private links and connector keys; a log of each read (time, link or key name, which tool or endpoint) | Our server |
| Consent records | Which consent text (id, version, language) you accepted or withdrew, and when | The app |
| Technical logs | Time, IP address, endpoint, status code, response size (our web server's logs, Caddy) | Our server |
| Support messages | Your email address and what you write to us | You |
We do not collect your name, phone number, contacts, photos or advertising identifier, and we don't ask for an email address to use the app.
5. Why we process it and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Store and sync your Health data and make it available to you | Health data, location within health data | Your explicit consent, Art. 9(2)(a) and Art. 6(1)(a) GDPR |
| Make your data available to the AI service you connect | Health data, location within health data | Your explicit consent given when you create each link or connector key, Art. 9(2)(a) and Art. 6(1)(a) |
| Run your account, check your subscription, manage links and keys, show you the access log | Account, subscription and access data | Performance of our contract with you, Art. 6(1)(b) |
| Prove that you gave consent | Consent records | Legal obligation, Art. 6(1)(c) with Art. 7(1) GDPR |
| Keep the service secure, prevent abuse, fix faults | Technical logs | Our legitimate interest in a secure service, Art. 6(1)(f) |
| Answer support requests and requests to exercise your rights | Support messages | Art. 6(1)(b) and Art. 6(1)(c) |
| Establish, exercise or defend legal claims | The minimum needed | Art. 6(1)(f) and, for health data, Art. 9(2)(f) |
Giving consent is voluntary. Without it, you can still use the free export. We do not make decisions about you based solely on automated processing, and we do not profile you.
What we never do with your Health data: sell it, rent it, use it for advertising or marketing, use it for data mining or profiling, use it to train AI models (ours or anyone else's), give it to data brokers, or store it in iCloud. We don't use it for anything other than delivering it to you and to the AI you connect.
6. How we protect it
- Encryption with your own key. Each account has its own random data key. Your Health data is stored only in encrypted form. The key itself is stored only in wrapped (locked) copies: one that only your iPhone can unlock, and one per private link or connector key, which only that link or key can unlock. We don't store the secrets that unlock them: they live on your iPhone and in the links and connector keys you create (and so with whoever you give them to). There is no master key on our server that could unlock your data, so we can't decrypt your stored data on our own.
- When our server can read your data. Only while your iPhone is uploading, or while one of your links or connectors is used. Your data is then decrypted in memory for that request only, and neither the key nor the decrypted data is written to disk or logs.
- In transit: TLS 1.3, and the app checks our server's certificate key (pinning).
- At rest: encrypted disks in addition to the per-account encryption. The small amount of metadata stored unencrypted is limited to your account identifier, keyed hashes of data types and dates (so the type names are not readable), sizes, counts and upload times.
- Logs never contain Health data, values or type names. Link and connector tokens are removed from logs.
- Access log: every read through a link or connector is recorded and shown to you in the app, for up to 90 days.
- People and copies: without your iPhone or one of your links or connector keys, no employee of HealthRaw can read your stored Health data, and neither can anyone holding our backups or a copy of our database.
- Revocation and deletion: revoking a link or connector key deletes its locked copy of your key, so its access ends immediately. Deleting your data makes it unreadable at once; encrypted backup copies become unreadable and are deleted within about 35 days (see section 9).
What we can't protect against. We are honest about the limits:
- An AI service you connect receives a copy of the data it reads and handles it under its own terms. We cannot recall it.
- Anyone who has your private link or connector key can read your data until you revoke it.
- If an attacker took control of our running server, they could read data that passes through it during uploads and link or connector requests at that time. Stored data stays encrypted.
- Someone with access to your unlocked iPhone can see what the app can see.
More detail: healthraw.app/security.
7. Who receives your data
| Recipient | Role | What and why | Where |
|---|---|---|---|
| OVHcloud | Processor (hosting) | Servers, encrypted disks and object storage that hold your encrypted data | EU |
| EU backup infrastructure providers | Processor (backups) | Encrypted backups | EU |
| Email-routing and mailbox providers | Processor (email) | Support emails only, never Health data | According to the email providers’ locations and safeguards |
| Apple | Independent controller | App Store, payments and subscriptions are handled by Apple under its own privacy policy; Apple sends us signed transaction information | Apple's locations |
| The AI service you connect | Independent recipient you choose | Whatever it reads through your link or connector | Wherever that provider processes data |
| Public authorities | As required by law | Only when we are legally obliged, and only what we can access | — |
We have data processing agreements (Art. 28 GDPR) with our processors. We have no advertising, analytics or data broker partners.
8. Transfers outside the EEA
We store and process your Health data on our servers in the European Economic Area. Support messages use separate email providers; do not include Health data or secret links in them.
The exception is the AI service you connect. If that provider processes data outside the EEA (for example in the United States), your data goes there because you created the link or connector key and gave it to that provider. That provider is responsible for its own processing and safeguards; please check its privacy policy.
9. How long we keep it
| Data | How long |
|---|---|
| Free-tier export files | On your iPhone only; deleted after sharing or after 24 hours. We never receive them. |
| Health data and daily summaries (Premium) | While your subscription is active. When it ends, 30 more days so you can resubscribe, then deleted (backup copies within about 35 days after that). Deleted immediately when you delete your cloud data or withdraw consent. |
| Backups | Encrypted backups, including the wrapped keys stored in them, are kept for at most about 35 days. After you delete your data, backup copies become unreadable and are deleted within about 35 days. |
| Access log | At most 90 days, encrypted with your data key. |
| Technical logs | At most 30 days, including the IP addresses in our web server's logs. |
| Account, device, subscription and link or key settings | Until your account is deleted. |
| Consent records | For the life of your account and then only as long as needed to demonstrate consent and establish, exercise or defend legal claims, taking account of the applicable limitation periods. |
| Support messages | Until the case is resolved, then only for as long as necessary to meet legal obligations or establish, exercise or defend legal claims. |
How deletion works. First we destroy every wrapped copy of your account's key ("crypto-shredding"), which makes your stored Health data unreadable straight away. Then we remove the encrypted data itself and revoke all links and connector keys. Encrypted backup copies become unreadable and are deleted within about 35 days, when those backups expire. Deleting the app from your iPhone does not delete your cloud data.
10. Your rights
You have the right to:
- access your data and get a copy (Art. 15);
- rectification (Art. 16): your Health data comes from Apple Health, so correct it there and the next sync updates our copy;
- erasure (Art. 17);
- restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on our legitimate interests (Art. 21);
- withdraw consent at any time, without affecting earlier processing (Art. 7(3));
- complain to a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You can also complain in the EU country where you live or work.
How to use them:
- In the app (Premium): download your cloud data as a zip, pause sync, revoke links and connector keys, see the access log, or delete all cloud data and your account.
- Without the app: follow the steps at healthraw.app/support#delete, or email [email protected]. Because we don't know your name or email, we will ask for proof that the account is yours before acting, for example the deletion page in an active private link, or the identity-verification steps supplied by support. Do not send Health data or secret tokens by email. If you do nothing, your data is deleted 30 days after your subscription ends (backup copies within about 35 days after that).
- Withdrawing Health data consent means deleting your cloud data: we can't keep your data without it. Pausing sync stops new uploads but keeps the data already stored.
We answer within one month. For complex requests we may extend this by two more months and will tell you why.
Your subscription is billed by Apple. Deleting your data does not cancel it; cancel it in your Apple account settings (the app links there).
11. Children
HealthRaw is for people aged 16 and over. It is not directed at children under 16, and we do not knowingly process their data. If you believe a child under 16 uses Premium, contact us and we will delete the data.
12. Cookies and the website
Our website uses no cookies, trackers, analytics or third-party scripts or fonts. Our web server (Caddy) keeps technical logs, including your IP address, for at most 30 days (see section 9) to keep the site running and secure.
13. Changes to this policy
We will publish any change here with a new effective date and tell you in the app. If a change affects what you consented to (for example a new kind of data or a new recipient), we will ask for your consent again before it applies to you. Earlier versions are available on request.
14. Contact
DMT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (DMT sp. z o.o.), ul. Budowlanych 1A, 62-081 Baranowo, Poland; KRS 0000836521; NIP 7812007881; REGON 385877414 Email: [email protected]