Last updated: 6 August 2026
Health Export AI ("the app") is designed so that your health data stays under your control. This policy explains what the app does and does not do with your information.
With your explicit HealthKit authorization, the app can read health and fitness metrics available on your iPhone and Apple Watch (for example: steps, distance, energy, heart rate, heart-rate variability, respiratory rate, blood oxygen, sleep, body measurements, mobility, hearing, and workouts). You choose which categories to allow in the Apple Health permission sheet, and you can change this at any time in the Health app (Sharing → Apps → Health Export) or in iOS Settings.
The app formats the metrics you allow into JSON. By default it writes that JSON into the app's own iCloud Drive container, which Apple syncs privately under your Apple ID; the local MCP server you install reads it on your own computer. If you also configure a network endpoint in Settings, the app sends the JSON directly from your device to that endpoint, authenticated with a token you provide. In neither case does the data pass through any server operated by the developer.
You can clear the iCloud cache from the app, and deleting the app removes its local settings and logs.
The developer retains nothing server-side — there is no account and no developer server in the data path. Your exported cache lives only on your device and in the destination you configured (your iCloud container, a synced folder you picked, or your own LAN/webhook endpoint). It stays there until you clear it in the app (Settings → delete exports), delete the file at your destination, or delete the app. Revoking Apple Health access or deleting the app stops all further processing immediately. Because there is no account, there is nothing for us to delete on your behalf. The advert events described below go to Meta rather than to us; we keep no copy of them, and Meta's retention of them is Meta's, not ours.
The developer does not collect or share your health data with anyone. Health Export AI does not send your health data to any cloud AI service — there is no OpenAI/ChatGPT, Google, or Anthropic SDK or API in the app, and the on-device model that phrases Ask answers runs entirely on your iPhone. The app only writes a JSON file to the destination you choose and explicitly export to. If that destination is a network endpoint or webhook, it is a server you operate and control; the AI assistant you use then reads that file locally, on your own machine. Once data reaches the destination you configured, it has left the app's control and is governed by that destination — choose destinations you trust. We require HTTPS for any public webhook so your data is never sent in cleartext over the internet.
This section is about your health data, and it is unconditional. Data that is not health data is a separate question with a different answer: the app does send a few advert events to Meta, and that is set out in full in Advertising measurement below.
Most recent iPhones already include a system language model, and Ask uses that — nothing is downloaded.
On iPhones without one, the app offers a one-time, optional download of a model file from
models.healthexport.dev, so that Ask can still run entirely on your device. You choose whether
to download it; the app never does so on its own.
That download is an ordinary web request for a public file. No health data, device identifier or account information is sent — the request contains nothing about you or your data. As with any web request, our host necessarily sees the connecting IP address, timestamp and user agent in standard server logs. We do not use those logs to build profiles, track individuals, or link requests to any person, and we do not combine them with anything else. If you never download the model, the app makes no request to our servers at all. (It is not the app's only network activity, though: the advert events in the next section go to Meta, not to us.)
We pay for adverts, and we would rather spend that money on the ones that work than guess. The only way to know which ones work is to be told when an install or a purchase follows an advert. So the app includes Meta's SDK — Facebook's advertising kit — which reports a small number of events to Meta.
What it sends. Three things, and this is the complete list. That the app was installed and opened. That a free trial started, with the amount charged to start it (zero) and the currency. That a purchase happened, with its amount and currency. No product name or identifier goes with either — just a number and a currency code, so we cannot tell from Meta's side which thing you bought. And, only if you allow tracking, your device's advertising identifier, which is the part that lets Meta match the install to an advert you saw. As with any network request, it also carries the ordinary technical envelope: your IP address, device model, iOS version, language and region, the app's version, and an identifier the SDK generates for this installation.
What it never sends: any health data. Not a metric, not a value, not a reading, not a date, not a file you exported, not a question you asked Ask, not an answer the app gave. There is no code path from Apple Health to the SDK — the two do not exchange anything. Everything above about your health data holds exactly as written.
iOS asks first, and no is a real answer. Before any of this happens, iOS shows you the App Tracking Transparency prompt. If you decline, the app is unchanged — every feature works, we do not ask again, and there is no lesser version. Declining is not a promise we ask you to take on trust either: until you allow tracking, the app never starts Meta's SDK at all. It is not switched on and quietly held back — no Meta code runs, so there is nothing to send and nothing queued to send later. Turn tracking off afterwards and it goes back to that state.
We say it that way deliberately, because the more comfortable version would be slightly untrue. Meta's SDK declares one collection address as a tracking domain, and iOS does block that address unless you have allowed tracking — but the SDK has a second address that is not declared, which iOS therefore does not block, and an ordinary integration keeps talking to Meta through it after you decline. So the operating system is a useful backstop and not a complete one. Ours does not reach either address, because it never starts.
One thing that does not depend on your answer: the purchase itself. When someone buys a subscription, our payment processor tells our server, and our server reports that purchase to Meta so an advert can be credited with it. That happens for every purchase, including one made by someone who declined tracking — our server is not the app, and it cannot see what you answered on your phone. What it sends is the fact of a purchase, the amount, the currency, and the App Store transaction identifier for that purchase. No advertising identifier, no device identifier, no name, no email, and — as everywhere else here — no health data. It is flagged to Meta as non-tracking, so Meta may count it in aggregate and modelled reporting rather than matching it to an advertising profile of you. We would rather write this down than let the sentence above read as broader than it is.
Changing your mind. iOS Settings > Privacy & Security > Tracking, where you can switch it on or off for this app at any time, or for every app at once. Turning it off stops anything further being sent from that moment; it cannot reach back and unsend what was already sent.
Meta's side of it. What Meta receives, Meta controls. For that data Meta is an independent controller and not something we run on our behalf: it decides how it uses and keeps it, under Meta's Privacy Policy. What comes back to us is aggregate advert reporting — how many installs and purchases an advert produced — not a list of people.
If you are in the UK or the EU. Our lawful basis for advertising measurement is your consent, and the iOS prompt is where we ask for it. Decline and the app does no processing for advertising at all — no Meta code runs on your phone and nothing leaves it. The server-side purchase report described above is the single exception, and it is limited to the purchase: amount, currency, and the App Store transaction identifier, never health data and never an advertising identifier. You can withdraw consent at any time in the Settings path above, and withdrawing it stops future sending from the app; if you would also like us to stop reporting your purchases, write to us at the address below and we will. For people in the UK and the EU, Meta Platforms Ireland Limited is the controller of what it receives.
Separately from all of this, and whatever you choose here, Apple gives us aggregate App Store statistics — impressions, downloads and the like — and Apple's own attribution reporting may tell an advert network that an install happened. Those come from Apple, not from the app, and carry nothing that identifies you.
Everything above is about the app. This section is about this website, which is separate and never sees your health data. One honest caveat: if you allow tracking in the app and accept the advertising cookie below, Meta may connect the two, because both report to Meta. That is Meta's doing rather than ours, and each is asked for separately.
Our own visitor counter. We count visits with
Umami, which we run on our own server rather than paying an
analytics company. It sets no cookies and stores nothing on your device. It
records the page you opened, the site that linked you here, and your browser, operating system
and country — never your name, your email, or anything you typed. To tell one visit from
another it makes a one-way hash of your IP address and browser, salted with a secret that
rotates. We cannot turn that hash back into an IP address, and we do not link your activity
across our different sites. Your browser only ever talks to
healthexport.dev; nothing is sent to anyone else.
Because it stores nothing on your device, this one runs without asking. If you would rather not be counted, that is one click:
The Meta advertising cookie. When we run ads, we want to know whether they work, and the only way to see that here is to let Meta know you arrived. That is a third party: it sets a cookie and reports your visit to Meta, who may join it to what they already hold about you. It is not needed for anything on this site, so it does not load unless you say yes. We ask once, plainly, with the same sized button either way, and we remember what you chose.
You can change your mind whenever you like:
That is the whole line we draw, here and in the app: the thing that shares something about you with someone else has to be asked for — the cookie here, the tracking prompt there. The thing that does neither does not. If our counter ever starts storing anything, it moves behind the same question.
The app is not directed at children and does not knowingly collect data from children.
Questions about this policy: [email protected]