1. Overview
Health Genie is a wellness application for iOS. This policy describes the data flows implemented by the app, including Apple Health access, sign-in, AI features, encrypted journal storage, analytics and purchases.
2. Health Data
- Health Genie reads only the Apple Health data types for which you grant permission, including steps, resting heart rate and sleep duration
- The deterministic Vitality Score is calculated on your device
- When an AI feature is requested, selected metrics needed for that request may be sent to Health Genie’s Convex backend and then to OpenAI to generate the response
- AI requests can include values such as the Vitality Score, steps, resting heart rate, recent score history, sleep values and optional profile or journal-derived context used by that feature
- A limited internal Health Lab test lets designated accounts choose a lab-report PDF. The PDF, including any identifiers it contains, is sent through Convex to OpenAI for marker extraction. Health Genie does not persist the PDF or extracted result in its Convex database, and requests deletion of the OpenAI file after processing; provider retention rules may still apply
- Operational AI usage records store metadata such as feature, model, token counts, success status and time; the application schema does not store the AI prompt or health metrics in those usage records
3. Authentication & Account Data
- The iOS app supports Sign in with Apple through Convex Auth
- The app stores the provider account identifier and may store the name or email returned by the sign-in provider
- Account records also include subscription status and service timestamps needed to operate the app
4. Analytics
- Health Genie uses PostHog for product analytics such as app opens, screen views and feature events
- Some analytics events include app-state values such as a Vitality Score, streak count or step-goal status
- When a journal check-in is completed, the selected mood and selected context tags are included in the analytics event. Available tags cover workout, sleep, social activity, time outdoors, rest, stress, alcohol, illness, medication and travel. Journal note text and protein amounts are not included in that event
- After sign-in, PostHog is identified with the application user ID and receives the account email, name, internal-account flag and subscription-status flag when those values are present
- Development and designated internal-account events are marked so they can be excluded from product analysis
- The Health Genie website uses Google Analytics 4 for page-traffic and acquisition measurement, including outbound App Store or Google Play clicks with the current page, destination store and campaign token. Google can receive standard website event and request data such as page URL, referrer, browser or device details, and network information used to derive approximate location. Values entered into the website calculators are not included by their calculation code
5. Subscriptions & Payments
- Subscriptions and in-app purchases are managed through Apple’s App Store and RevenueCat
- We do not store or process payment information
- RevenueCat begins with an app-generated identifier and is linked to the Health Genie application user ID after sign-in so purchases and entitlements can be restored
- For subscription-related billing, refer to Apple's privacy policy
6. Third-Party Services
We use the following third-party services:
- Apple Health (HealthKit) — to read health metrics from your device
- Convex — for authentication, backend functions, AI requests, subscription state and encrypted app-data storage
- OpenAI — to generate requested AI features from the metrics and context supplied for that request
- RevenueCat — for subscription management
- PostHog — for product usage analytics
- Google Analytics — for website traffic and acquisition measurement
7. Journal and Health Plan Storage
- Sensitive Health Journal fields are encrypted on the device before they are stored in Convex
- The journal date and service timestamps are stored unencrypted so entries can be indexed and retrieved
- Body weight and protein-target settings are encrypted on the device before Convex storage; the selected unit and service timestamp are stored unencrypted
- The active Health Plan is mirrored to Convex so it can survive a reinstall or sync across devices; the plan can contain derived scores and plan progress
- AI-generated briefs and nudges can be stored inside encrypted journal fields
8. Retention and Deletion
- Data is retained for as long as needed to provide the applicable feature or account
- You can request account deletion in the app settings
- The in-app deletion flow removes journal entries, correlations, encrypted user settings, user-linked AI usage records, the active Health Plan mirror, the application user record, authentication accounts and linked session, refresh-token and verification records
- The flow also attempts to reset the local RevenueCat account identity, resets the PostHog identity, deletes the device-held journal encryption key, clears locally cached Today actions and history, cancels scheduled Health Genie notifications, and resets app data stored in Redux Persist and AsyncStorage. A RevenueCat network or SDK failure does not block deletion of the Health Genie account. Operational records held by service providers may be subject to their own retention rules. Contact support with a deletion question
9. Children's Privacy
Health Genie is not directed at children under 13. We do not knowingly collect data from children under 13.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes through the app or on our website.
11. Contact
If you have questions about this privacy policy, contact us at: prashanthvaidya@therunninggenie.com