Privacy Policy
Last updated: 2026-06-18
health4.ai ("we", "us") provides an iOS app and MCP server that facilitate the transfer of Apple HealthKit data to a Postgres database you configure and control. We do not collect, store, or have access to your health data. This policy explains what limited data we do collect and your rights.
1. What data we collect
- Health data — we do not collect it. HealthKit metrics you authorize flow directly from your device to the Postgres database you configure (Supabase, Neon, or self-hosted). health4.ai never receives, stores, or has access to your health data.
- Account data — email address (waitlist sign-ups only), used solely to notify you at App Store launch.
- Usage data — anonymous page views and feature interaction events via PostHog (US-hosted). PostHog never receives health data. We do not use advertising cookies or trackers.
2. How we use it
- To notify you at App Store launch (waitlist email only).
- To improve reliability — aggregated, non-identifiable usage metrics only.
We do not sell personal data. We do not use health data for advertising. Per Apple's HealthKit guidelines, health data will never be used for advertising or sold to data brokers. Because we never receive your health data, we are structurally incapable of misusing it.
3. Where data is stored
Your health data lives in the Postgres database you configure — Supabase, Neon, or self-hosted. You choose the provider, you hold the credentials, and only you can query the data. health4.ai has no access to it.
4. HIPAA
health4.ai is not a covered entity under HIPAA and does not operate as a HIPAA Business Associate unless a Business Associate Agreement (BAA) is separately executed in writing.
5. Your rights
- Health data control — your health data is in your database. You can delete it directly at any time — no request to us required.
- Account deletion — contact us to delete your waitlist email address. We will confirm deletion within 14 days.
- Revoke HealthKit access — stop syncing at any time in iPhone Settings → Privacy & Security → Health → health4.ai. No data is deleted from your database automatically; you remain in full control.
- GDPR / CCPA — EU and California residents have additional rights (portability, rectification, opt-out of sale). We do not sell personal data. Contact us to exercise any right over account data we hold.
6. Breach notification
Because health4.ai does not store your health data, a breach of our systems cannot expose it. In the unlikely event of a breach involving account data (email addresses), we will notify affected users within 30 days.
7. Analytics & cookies
We use PostHog (US-hosted) for product analytics. PostHog receives page views and feature interaction events — no health data. We do not use advertising cookies or trackers.
8. Changes to this policy
We will update the "Last updated" date and notify users by email of any material changes.
9. Contact
Questions or data requests: [email protected]