Is Your Health Data Private? What Every Apple Watch Owner Should Know
You wear your Apple Watch to bed. It knows when your heart races at 2 AM. It knows your resting heart rate trend, which can reveal whether you're stressed, fighting an illness, or drinking more than usual. It tracks your menstrual cycle, your blood oxygen levels, and exactly how many steps you take each day.
This is some of the most intimate data that exists about you. And every time you install a health app that requests access to Apple Health, you're making a decision about who gets to see it.
Most people don't think twice about tapping "Allow." But where does that data actually go?
What Your Apple Watch Collects (It's More Than You Think)
Apple Watch continuously tracks over 100 types of health data. The ones most people are aware of — steps, heart rate, workouts — are just the beginning. Here's a broader picture of what's being recorded:
- Heart data: Heart rate (continuous), resting heart rate, walking heart rate, heart rate variability (HRV), heart rate recovery, ECG recordings, irregular rhythm notifications
- Activity data: Steps, distance walked, flights climbed, exercise minutes, stand hours, calories burned (active and resting)
- Sleep data: Time asleep, sleep stages (REM, deep, core), respiratory rate during sleep, wrist temperature during sleep
- Other biometrics: Blood oxygen levels, noise exposure, walking asymmetry, walking steadiness, cardio fitness (VO₂ max estimate)
- Reproductive health: Menstrual cycle tracking, cycle length predictions, ovulation estimates
Combined, this data creates a remarkably detailed portrait of your physical health, daily routines, stress patterns, and lifestyle habits. It's the kind of information that, in a medical context, would be protected by strict patient confidentiality laws.
How Most Health Apps Handle Your Data
Scope: This page explains questions to ask and documents Health Genie’s current data flows. It does not claim that every health app handles data the same way. For binding details, read each product’s current privacy policy.
When you grant a health app access to Apple Health data, what happens next varies by product. Check the app’s permissions and privacy policy for the following:
Cloud processing: Does the app send selected values to a server to provide a feature, and does it store those values or use them only for the request?
Account data: Does sign-in provide an identifier, email address, name or profile details, and how are those fields linked to feature data?
Service providers: Which backend, AI, analytics and purchase providers receive data, and what is sent to each one?
Retention and deletion: Uninstalling an app and deleting an account are different actions. Check what the in-app deletion flow removes from remote services.
The Real Risks
The practical privacy risks depend on what an app collects, whether it links those values to an account, which service providers receive them, how long records are retained and whether deletion controls work as described. Those facts vary by product and jurisdiction, so broad claims about every health app are not useful substitutes for reading the product’s current policy.
Treat health-related information as sensitive. Before granting access, check the exact permissions requested and whether optional network features send or store selected values outside Apple Health.
What to Look for in a Privacy-Respecting Health App
The Privacy Checklist
- On-device processing: Which operations happen locally, and which features send data to a service? A local calculation does not prove that every feature is offline.
- No account required: Can you use the app without creating an account? Account-free apps can't link your biometric data to your personal identity.
- No cloud sync: Is your data stored only on your device? Cloud sync means copies of your data exist on remote servers.
- Transparent privacy policy: Does the privacy policy clearly state what data is collected, where it goes, and who can access it? Vague language is a red flag.
- No advertising or analytics SDKs: Does the app include third-party tracking? Tools like Firebase Analytics, Facebook SDK, or advertising frameworks can transmit data to third parties.
- Apple HealthKit compliance: Does the app use Apple's HealthKit framework? HealthKit has strict rules — apps using it cannot sell health data to advertising platforms or data brokers.
How Health Genie Approaches Privacy
Health Genie separates local calculation from features that require a network service. The following is based on the current app implementation:
Here's what that means in practice:
On-device score calculation. The app reads permitted steps, resting heart rate and sleep data from Apple Health. The Vitality Score formula runs on the device.
Account sign-in. The iOS app supports Sign in with Apple through Convex Auth. The backend can store the provider account identifier and any name or email returned by Apple.
AI requests. When you request an AI feature, selected metrics and context needed for that feature are sent through Health Genie’s Convex backend to OpenAI. AI is not used to calculate the numeric Vitality Score.
Encrypted journal storage. Sensitive Health Journal fields are encrypted on the device before they are stored in Convex. Dates and service timestamps used for indexing are stored unencrypted.
Encrypted health settings. Body weight and protein-target settings are encrypted on the device before Convex storage. The selected unit and service timestamp are stored unencrypted.
Product analytics. Health Genie uses PostHog for events such as app opens, screens and feature usage. Some events include app-state values such as a Vitality Score, streak count or step-goal status. A completed journal check-in event includes the selected mood and selected context tags. Available tags cover workout, sleep, social activity, time outdoors, rest, stress, alcohol, illness, medication and travel; the event does not include journal note text or protein amounts. After sign-in, PostHog is identified with the application user ID and can receive the account email, name, internal-account flag and subscription-status flag when those values are present.
HealthKit compliance. The app operates within Apple's HealthKit framework, which imposes strict rules on how health data can be accessed and used. Apps that violate HealthKit's data policies risk removal from the App Store.
Account deletion. The in-app deletion flow removes journal entries, correlations, encrypted user settings, user-linked AI usage records, the active Health Plan mirror, the application user record and linked authentication sessions. It also deletes local app data and the device-held journal encryption key. Records independently retained by service providers may follow their own retention rules. Uninstalling the app by itself is not the same as running account deletion.
The bottom line: “On-device” should describe a specific operation, not an entire app. In Health Genie, the score calculation is on-device; AI, account, purchase, analytics and encrypted-storage features involve the service providers described in the Privacy Policy.
Apple's HealthKit: The Privacy Foundation
It's worth understanding what Apple's HealthKit framework does, because it provides a significant privacy baseline for any app that uses it properly.
HealthKit is Apple's health data layer. It stores all your health information from Apple Watch, iPhone sensors, and third-party apps in an encrypted database on your device. Apps must request specific, granular permissions to access specific data types — an app can request access to your step count without getting access to your heart rate, for example.
Key HealthKit rules that protect your data: apps cannot use HealthKit data for advertising or marketing purposes, apps cannot sell HealthKit data to data brokers or third parties, and health data in HealthKit is encrypted at rest using your device's passcode. Apple reviews HealthKit usage during the App Store review process, and apps that violate these rules face rejection or removal.
This doesn't mean every HealthKit app is equally private — some still upload your data to their own servers for processing. But HealthKit creates a minimum standard that's significantly stronger than what exists in most other data categories.
Practical Steps to Protect Your Health Data
Audit your HealthKit permissions. Review app access in the Health app or the Health section of iPhone privacy settings; Apple can change the exact menu path between iOS versions. Remove access for apps you no longer want to use with Health data.
Read the privacy policy before installing. Specifically look for: where data is stored (device vs. cloud), whether an account is required, whether data is shared with third parties, and what happens to your data if you delete the app.
Check each feature, not just the headline. Local processing can reduce the amount of data sent to a server, but it does not eliminate every privacy or security risk. Confirm which operations are local and which use external services.
Understand the business model. Check whether an app is funded by purchases, subscriptions, advertising or another source, and compare that with what its privacy policy says about data use.
Keep your iPhone and Apple Watch updated. Security patches protect the encrypted health data stored on your devices. Outdated software is one of the most common vectors for data compromise.
Read the Data Flows Before You Decide
Review Health Genie’s current privacy details, then choose whether its on-device and service-assisted features fit your preferences.
Read the Privacy Policy