What this policy covers
This policy describes the Health.md consumer apps for iPhone, iPad, Mac, and Android; bundled Mac CLI and MCP helpers and portable tools where made available; healthmd.app and its documentation; and the first-party services that support those products. Health.md is operated by Cody Bontecou under the isolated.tech name, referred to here as “Health.md,” “we,” or “us.”
It does not replace the privacy terms of Apple, Google, a health provider, a file or sync provider, an API operator, an AI tool, or another destination you choose. Once you direct data to one of those services, that service's terms and your configuration govern its copy.
The simple version: Health.md does not collect or store health data on Health.md servers. Health data is processed on your devices and sent only to destinations or clients you choose.
We do automatically collect limited first-party product analytics and campaign data. Those systems are pseudonymous, contain no health records or exports, and are not used for advertising.
Health data we process on your instructions
Health.md uses platform permissions and user actions to read or receive health data. Depending on your device and the features you enable, this can include:
- Apple Health: HealthKit and WorkoutKit categories you authorize on iPhone or iPad.
- Android health data: fitness, wellness, activity, body, nutrition, reproductive-health, vital, and medical records you authorize through Health Connect.
- Connected providers: records fetched from a supported provider only after you connect that provider and approve its access.
- Direct requests: scoped queries or exports requested by an explicitly paired Mac, CLI, or MCP client while the mobile source is available.
Health.md's health access is read-only. We do not write diagnoses or treatment into HealthKit or Health Connect, and we do not use health data for advertising, profiling, credit, insurance, or employment decisions.
Exports can be highly sensitive. Lossless files and direct results may preserve exact timestamps, source UUIDs, provenance, routes and locations, medications, mental-wellbeing entries, ECG values, clinical content, documents, and binary attachments. Protect them like the source health database. Current Apple App Store builds do not request historical clinical records; Android medical-record access is described separately below.
Where health data can go
Health data leaves its source only when a feature you choose requires it. Health.md can send or write selected data to:
- Files and vaults: an on-device folder, Apple Files, Android's Storage Access Framework, an Obsidian vault, or another file provider.
- Cloud-backed folders: iCloud Drive, Dropbox, Google Drive, OneDrive, Syncthing, Working Copy, or another provider if the folder you choose syncs there.
- Paired computers: an approved Mac or standalone CLI over an authenticated encrypted direct connection.
- Local tools and agents: a CLI or MCP client that you configure. Results then follow that tool's storage, transcript, and model-provider settings.
- Your API endpoint: a user-configured API endpoint that receives the export you select. Protected endpoint mode requires HTTPS.
- Connected health providers: read-only provider requests initiated after you authorize the connection.
Health.md does not retain a health-data server copy for later queries. The iPhone remains the source for direct Apple Health queries. Direct transfer can leave durable job state and output on the paired computer, but that state is not a Health.md-hosted health corpus.
Android medical records (FHIR)
On supported Android devices, the Medical records (FHIR) feature can read only the Health Connect categories you separately authorize. Health Connect divides a portable medical record into the following categories:
Medical-record categories requested by Health.md
- Vaccines
- Allergies and intolerances
- Conditions and diagnoses
- Laboratory results
- Medications
- Personal details
- Practitioner details
- Pregnancy records
- Procedures
- Social history
- Visits and encounters
- Medical vital signs
Each category is optional and read-only. It is used only to answer a direct request or include authorized records in an export you initiate or schedule. JSON and provider-native exports can preserve FHIR resource data and source metadata; Markdown and CSV summaries may report category counts. Health.md does not keep a server copy. You can deny or revoke one category without disabling other authorized exports.
First-Party Product Analytics
Android F-Droid build: it performs no Health.md telemetry and does not create a telemetry installation identifier, event queue, worker, or persisted telemetry state. Install Referrer, onboarding analytics, Play review, Billing, direct cloud-provider OAuth, and Wear Data Layer code are not compiled into that build. Exports to an API endpoint you configure and explicit Direct CLI sessions are user-directed product actions, not Health.md telemetry.
The Apple and Google Play builds use a first-party Cloudflare Worker and D1 database to understand whether onboarding, activation, export, scheduling, paywall, and purchase flows work. Health.md collects these limited product events automatically without Firebase Analytics, Google Analytics, AppsFlyer, a third-party crash-reporting SDK, or an advertising SDK in the app.
Depending on the platform and event, an accepted payload can contain a random app-install UUID, random event UUID, event name, app version, build number, platform, experiment or variant, onboarding step or explicit skip, bounded free-export counts, export-target category, format count, coarse metric-count and date-span buckets, paywall context, product identifier, purchase or restore outcome, and broad authorization or error category.
The installation UUID persists for that app installation, so the data is pseudonymous rather than anonymous. It is randomly generated and is not derived from your name, account, health identifier, device hardware identifier, Android ID, or Advertising ID.
Product analytics never include HealthKit or Health Connect values or identifiers, metric names, health dates, medications, workouts, export contents, typed query results, folder or vault names, file paths, peer or device names, account data, prices, credentials or tokens, user text, raw referrers, full User-Agent strings, or stored IP addresses. Unknown events, properties, and property values are rejected. The public client and Worker allowlists are designed so health records and exported content cannot be represented in an analytics payload.
These events are not used for advertising, fingerprinting, or cross-app tracking, and they are not sold or shared with advertisers. Validated rows are retained for no more than 13 months and removed by automatic daily cleanup. Cloudflare still processes ordinary connection information under its own terms.
First-party campaign attribution
Health.md uses first-party short links, such as healthmd.app/v/yt-csv-001, to measure aggregate campaign performance without a third-party attribution SDK.
- The redirect service can record the campaign token and slug, platform and content angle, coarse destination or client category, referring hostname when supplied, coarse country code, and time.
- The stored click row does not include an IP address, full User-Agent, cookie, Cloudflare request ID, or fingerprint.
- On Android, Google Play Install Referrer can produce one sanitized attributed-install event with random install and event UUIDs, app version/build, validated campaign fields, event time, and optional Play click/install timestamps.
- The raw Install Referrer is discarded and never persisted or transmitted by Health.md. Clicks and installs are joined only by the validated campaign token for aggregate reporting.
Campaign click and install rows are retained for no more than 13 months. Aggregate ingest-rate windows contain only a minute and count and are deleted after 24 hours. Cloudflare processes ordinary network information while delivering these requests, but Health.md does not add it to campaign records.
Scheduling, purchases, providers, and support
Some app features use non-health operational data:
- Scheduled Apple exports: the scheduling service may receive an APNs token, random install or user ID, platform, bundle ID, schedule frequency, time, weekday, and timezone. Silent pushes contain trigger and schedule-version information. The worker does not receive HealthKit samples, export files, destination paths, API URLs, or API secrets.
- Purchases: Apple StoreKit, the App Store, Google Play Billing, and limited first-party verification paths process product, transaction, entitlement, or receipt information needed to buy or restore Full Access. Health.md does not receive your full payment-card details. F-Droid includes Full Access and has no purchase or restore flow.
- Provider authorization: a provider OAuth broker may process provider/client IDs, redirect URIs, authorization-code exchange, and token refresh in transit. Provider access tokens are stored in the iOS Keychain where supported, and provider health records flow to the phone rather than being retained by the broker.
- Feedback: email or community-issue tools open only when you choose them. A prefilled, editable diagnostics block can include app version/build, operating-system version, and broad device type. Your message includes whatever you decide to send; public issue or community channels are public.
You can use manual exports instead of scheduling, leave providers disconnected, and choose not to send feedback. Store services still process purchase and app-update activity under Apple or Google's terms.
Website data and external requests
healthmd.app uses Cloudflare Web Analytics after a small analytics-gate request. It helps us understand aggregate traffic, performance, and popular pages. For this site, the client-side analytics does not set cookies and is not connected to health records, exported files, purchase state, direct pairing, or in-app settings.
Cloudflare, our website host, and security infrastructure process ordinary web request information needed to deliver and protect the site, such as IP address, requested URL, browser information, and time, under their terms and retention controls.
Some landing, documentation, or visualization pages request assets from services such as img.logo.dev, Google Fonts, jsDelivr, or map-tile providers. Those services receive the ordinary request information your browser sends. Following links to the App Store, Google Play, GitHub, Obsidian, support, or another website takes you to that service's privacy practices.
Website and campaign analytics are separate from app health-data processing. Visiting the site does not give Health.md access to Apple Health or Health Connect.
Storage and retention
- Source health data remains in HealthKit, Health Connect, or the connected provider unless you direct an export or query.
- App settings and history are stored on your device using platform storage. Provider credentials use protected platform credential storage where supported.
- Exported files and API deliveries remain with the destination you chose until deleted under that destination's controls.
- Paired Mac, CLI, and MCP data remains in the local output, job state, credential store, transcript, or other computer storage created by your workflow.
- Product analytics and campaign rows are retained for no more than 13 months; campaign ingest-rate counters are deleted after 24 hours.
- Scheduling, purchase, support, and ordinary network records are retained only as needed to provide, secure, document, or comply with requirements for those services, subject to the applicable platform and provider terms.
Uninstalling Health.md removes app-local state according to the operating system, but it does not remove files already exported to another folder or service, data stored by a paired client, a message you sent, or data held by a destination provider.
Services we use
Health.md does not use advertising SDKs or third-party in-app analytics and attribution SDKs. It does use the following platform, infrastructure, and user-chosen services when relevant:
- Apple HealthKit and WorkoutKit
- Android Health Connect
- Apple Files, Android Storage Access Framework, and file providers you choose
- StoreKit, the App Store, Google Play, and Google Play Billing
- Google Play Install Referrer for sanitized Android campaign attribution
- Apple Push Notification service for scheduled-export wakeups
- Cloudflare for first-party analytics, campaign services, D1 storage, abuse throttling, website delivery, and website analytics
- Optional provider APIs, OAuth services, API endpoints, sync services, AI/model providers, and local clients that you configure
These providers may process data in countries where they operate. Their handling is governed by their terms and applicable law. We do not sell health data or personal information, and we do not share it for cross-context behavioral advertising.
How we protect data
We apply safeguards appropriate to each path, while no storage or transfer system can be guaranteed perfectly secure:
- Health access is controlled by HealthKit and Health Connect permissions and device protections.
- Direct Mac and CLI pairing uses authenticated encrypted sessions, bounded frames, integrity checks, and explicit approval.
- Protected API Endpoint mode requires HTTPS; the endpoint operator controls what happens after delivery.
- Analytics and campaign ingest reject unknown or oversized fields and intentionally cannot represent health payloads.
- Local files inherit the access, encryption, backup, and sync controls of the device, folder, vault, or provider where you place them.
The local Mac query API uses loopback reachability as its access boundary and has no bearer token. Do not proxy or expose its port to another machine. Direct iPhone pairing should be enabled only for computers and networks you trust. Keep devices updated, use passcodes and disk encryption, and review the retention and logging settings of destinations, agent hosts, and model providers.
Your choices and privacy rights
- Permissions: grant or revoke HealthKit and Health Connect categories in platform settings.
- Destinations: choose local folders, remove file-provider access, disconnect providers, clear an API endpoint, or unpair direct clients.
- Scheduling: use manual exports if you do not want non-health schedule and APNs metadata registered.
- Files and results: access, move, or delete them using the controls of the destination or paired computer.
- Portability: use exported Markdown, Obsidian, CSV, JSON, FHIR, and other supported files outside Health.md.
- Legal rights: depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data we control, and to appeal or complain to a data-protection authority.
Contact us to exercise an applicable right. We may need information to verify and locate the relevant record. Because analytics identifiers are random and not connected to an account or email address, we may be unable to associate an email request with a particular analytics row. Those rows still expire automatically within the period above.
Children's privacy
Health.md is a general-audience health-data portability tool and is not directed to children. We do not knowingly use health data or analytics for child-directed advertising or profiling. A parent or guardian who believes a child submitted personal information to a Health.md-controlled service can contact us so we can review the request.
Changes to this policy
We will update this page and its “Last updated” date when our practices change. If a change materially affects how the apps handle data, we may also provide notice in the app, release notes, or another appropriate channel.
Contact
For privacy questions or requests, email [email protected]. Health.md is operated by Cody Bontecou under the isolated.tech name.
Please do not include health records, export files, credentials, or other sensitive content in an ordinary support email or public issue. If we need more information, we will ask for the minimum necessary to investigate.