Private by Design

Privacy in Plain English

Health Check-In is private by design. The app is built so your health journal stays on your device by default. No account required. No ads. No tracking. No data selling.

What stays on your device

Your check-ins, scores, notes, symptoms, medications, supplements, experiments, routines, Key Results, and imported health data are all stored locally on your device.

Health data from Apple Health, Google Health / Health Connect, or Oura is used to help you see patterns inside the app. It is not uploaded to a Health Check-In account because there is no Health Check-In account.

What we can't see

We cannot open a dashboard and read your health journal.

  • We cannot see your notes.
  • We cannot see your symptoms.
  • We cannot see your medications or supplements.
  • We cannot see your experiments or Key Results.
  • We cannot see your connected sleep, HRV, RHR, or step data.

The only exception: if you explicitly use AI analysis, selected data needed for that analysis is sent securely for processing. AI is never run unless you choose to use it.

What may leave your device

Some features require limited data to leave your device. Each one is either anonymous, optional, or user-directed:

Anonymous app analytics

We use Aptabase, a privacy-focused analytics service, to understand basic app usage — things like app opens, onboarding completion, and which features are used. These events do not include your health scores, notes, symptoms, medications, supplements, or health data. Aptabase does not use cookies, does not track users across apps, and is fully GDPR-compliant.

Subscription status

Purchases are handled through the App Store or Google Play. Health Check-In uses a subscription service (RevenueCat) to verify whether Pro or Pro+AI is active using a random, anonymous ID. We never see your credit card information.

Location, weather, air quality & pollen

If you enable environmental tracking, your approximate location may be sent to a weather, air quality, or pollen provider to retrieve data for your check-ins. This helps identify possible environmental triggers. Location access is optional and is not used for advertising or cross-app tracking.

AI analysis (optional)

AI analysis is entirely optional. When you ask Health Check-In to generate an analysis, it sends only the information needed to answer your request — such as recent check-ins, notes, tags, experiments, Key Results, routines, medications, supplements, sleep data, steps, HRV, resting heart rate, and environmental context. Health Check-In does not store your AI request data on our servers after processing. Google Gemini processes requests according to Google's applicable API terms. The app is fully functional without AI.

Backups and exports

If you export a report or create a backup, that is your choice. Backups are saved to the location you choose, such as your own Google Drive or a local file. Health Check-In does not maintain a cloud account containing your data.

What our analytics actually look like

Here is the kind of data Health Check-In receives from Aptabase:

  • Daily active users (a number, not names)
  • Total sessions
  • App version distribution
  • Country and OS (e.g. “42% iOS, US”)
  • Event names like app_opened, checkin_submitted, onboarding_completed

What is not included: your check-in scores, notes, symptoms, medications, supplements, experiments, AI questions, or health data.

Why the App Store and Google Play show privacy labels

The app stores require developers to disclose broad data categories when an app may access or transmit certain types of information. These labels are important, but they can make local, optional, or anonymous features sound less private than they are.

For example, Health Check-In may show categories such as Health & Fitness, Usage Data, Purchases, or Identifiers because the app supports health integrations, subscription verification, anonymous analytics, backup/export, and optional AI analysis.

The important distinction:

Your personal health journal is not stored on our servers, not sold, not used for ads, and not visible to us.

Both stores define “collection” broadly: any data transmitted off the device. Data that is only processed locally is not considered “collected.” Most of what Health Check-In does with your health data is local.

How to delete your data

  • In-app: Delete all data via Settings → Clear All Data, or delete individual check-ins from your history.
  • Uninstalling: Removing the app deletes all local data from your device.
  • Health permissions: Revoke access through your device settings or disconnect integrations inside the app.
  • Backups & exports: Files you created are controlled by you and should be deleted from wherever you saved them.

This page is a plain-English summary. For the full legal privacy policy, see Privacy Policy.

Questions about your data? privacy@healthcheckin.app