How we protect your data
The plain-language version first, then the technical details for those who want to check our work.
In plain words
In short: your Premium data is encrypted with keys we don't store: they live on your iPhone and in the links or connectors you create. We have no master key and can't decrypt your stored data on our own: no employee, backup or database dump can read your stored data without your iPhone or one of your links or connectors. It's decrypted only for a moment, in memory, when your iPhone syncs or while one of your links or connectors is used. Revoke a link and its access ends immediately. Delete your account and your data becomes unreadable at once; encrypted backup copies become unreadable and are deleted within about 35 days.
What stays on your iPhone
With the free export, HealthRaw reads the Apple Health data you allow and builds the export file on your iPhone. Nothing is sent to us. The file goes only where you send it, is kept out of backups, and is deleted after sharing or after 24 hours. HealthRaw never writes to Apple Health.
What Premium sends
Only the Health data types you selected (for workouts, that includes routes, which are your location during the workout). Your iPhone sends it over an encrypted connection to our servers in the EU. It is stored encrypted with your account's key, which only your iPhone and your links or connector keys can unlock.
Who can read it, and when
- You, in the app.
- The AI services you connect, through a private link or connector key you created. The app's access log shows every read made with your links or connectors, kept for up to 90 days.
- Our server, but only for a moment, in memory, while your iPhone is uploading or while one of your links or connectors is used. Outside those moments, the stored data can't be unlocked on our side: there is no master key.
- Not us on our own. No employee, backup or database dump can read your stored data without your iPhone or one of your links or connectors.
Revoke and delete
- Revoke or replace a link or connector key at any time. Its access ends immediately.
- Pause sync to stop uploads. Data already uploaded stays until you delete it.
- Delete your cloud data in the app or without the app. We destroy your account's keys first, which makes the stored data unreadable at once, then remove the data. Encrypted backup copies become unreadable and are deleted within about 35 days.
- If your subscription ends, your data is deleted 30 days later (backup copies within about 35 days after that).
What we can't protect against
- The AI you connect. It gets a copy of what it reads and uses it under its own terms. We can't recall it. Check whether it may use your conversations for training.
- A leaked link or key. Whoever has it can read your data until you revoke it. Treat it like a password.
- A compromised running server. An attacker in control of our server while it runs could read data passing through it during uploads and link or connector requests. Stored data stays encrypted. That is why we don't call this end-to-end encryption.
- Your own devices. Anyone with your unlocked iPhone, and anywhere you send an export file.
What we never do
We don't sell your data, use it for advertising, use it to train AI, put it in iCloud, or share it with anyone except the AI you choose. This website has no cookies, analytics or third-party scripts.
Technical details
Keys
- Each account has a random 256-bit data key (DEK). Payloads are encrypted with XChaCha20-Poly1305 with a fresh nonce; the associated data binds each chunk to the account, chunk kind, object, data type, day and version. Chunk headers carry format, key and wrap versions.
- The DEK is never stored in plaintext. It exists only as wrapped copies: a device wrap whose secret is in the iPhone Keychain (this device only, available after first unlock so background sync works), and one token wrap per private link or MCP key, derived with HKDF from the token secret. The server stores a hash of each token id and the wrapped key, never the token secret.
- There is no server-held master key, so nothing on the server alone can decrypt user data. Any server-side work happens during an upload or a token-authenticated read.
- The keys used for keyed hashes (data type and day names, and the deduplication index) are derived from the DEK with HKDF under separate labels.
- When key material reaches the server, it arrives in the body of an authenticated TLS request, is held in memory for that request only, and is never logged or written to disk. It is never placed in headers of background uploads, because iOS stores those on disk.
Transport
- TLS 1.3 only, with HSTS.
- The app pins the server's public key (SPKI) and ships a backup pin, so a mis-issued certificate is not enough to intercept traffic.
- Uploads are idempotent batches, so a retry never duplicates data.
Storage
- Every payload byte in the database and object storage is ciphertext. Plaintext metadata is limited to the account id, keyed hashes of data type and day, byte sizes, counts and upload times.
- Servers are in the EU, with full-disk encryption (LUKS).
- Link and MCP tokens are separate, read-only, scoped, revocable and can expire.
- The access log (time, token name, tool or endpoint) is encrypted under the DEK and kept for at most 90 days.
Logs and backups
- Logs never contain payloads, values or data type names. Token paths and the Authorization header are redacted. Web server (Caddy) logs include IP addresses. Logs are kept for at most 30 days.
- Database backups (daily dumps, including the data chunks) are encrypted and stored in a second EU location for about 35 days at most. The wrapped keys are part of the database backups, so a deleted account's backup copies become unreadable and are deleted within about 35 days. Server secrets are never included in backups.
Deletion (crypto-shredding)
Deleting an account destroys every wrapped copy of its DEK, then purges the encrypted chunks and revokes all tokens. Your iPhone and Apple Health remain the source of truth, so the app can always upload again if you return.
Reporting a vulnerability
Please write to [email protected]. We will reply and fix what we can.