Privacy

Privacy Policy — HealthState
HealthState

Privacy Policy

Last updated 9 August 2026 · Applies to HealthState for iPhone and Apple Watch.

The short version

By default, your health data never leaves your device. HealthState has no developer accounts, no servers of ours, and no analytics. Nobody — including the developer — can see your heart rate, your stress scores, your notes, your locations, or your sleep.

Three things can leave your device, and every one of them is off until you choose it: iCloud sync, which copies your history into your own private iCloud so your devices stay in step; Stay Close, which shares your stress band with one person through your iCloud; and any file you personally export and send somewhere. Leave all three alone and the app is entirely local.

Who is responsible

HealthState is an independent app. The developer is the data controller for the limited purposes described below. Contact: support@hessamzahedi.com.

What the app accesses, and where it goes

HealthState asks permission before accessing anything below. You can decline any of it and still use the app; features that need a permission simply stay switched off.

DataWhyWhere it goes
Heart rate, heart rate variability, resting heart rate Calculating your stress score and its trends Stays on device
Sleep, respiratory rate, wrist temperature, blood oxygen Recovery scoring and the overnight Baseline Guard Stays on device
Workouts Pausing stress alerts during and after exercise Stays on device
Steps, time in daylight, environmental sound levels Showing what actually moves your stress Stays on device
Mindful sessions (from any app) Crediting relaxation you do elsewhere Stays on device
Notes you write yourself A plain notebook for what you already know about your own health — nothing in it is generated or suggested Stays on device (and in your own iCloud if you switch sync on). Never read by the coach, the companion chat, or the Chronicle, and never sent to any model. Included in your export so you can take it with you
Caffeine, alcohol and water — read only Showing how they line up with your stress, and how the nights after a drink compare with the nights after none Stays on device. HealthState never asks you to log these and never writes them. If you don’t already track them in Health or another app, nothing is read and these features simply don’t appear
Cycle tracking Optional: adjusting baselines by cycle phase, so normal physiology isn’t read as stress Stays on device
Location (visits) Optional, off by default: learning which places run high without naming them Stays on device. Never geocoded, never labelled, never transmitted
Calendar Optional: event times only, to warn you before busy stretches Stays on device. Titles, invitees and notes are never read
Camera Optional: measuring your pulse from a fingertip Frames are analysed in memory and discarded. No image is saved or sent
A photo you choose Optional: building your pixel companion Analysed on device and discarded immediately. Only a handful of settings — skin tone, hair colour, whether you wear glasses — are kept

What HealthState writes to Apple Health

With your permission the app can save mindful minutes when you finish a breathing session, and mirror your mood check-ins into State of Mind. Nothing else is written, and you can revoke this at any time in the Health app.

What HealthState does not do

  • No user accounts, sign-ins, or profiles.
  • No servers or cloud storage operated by the developer.
  • No analytics, telemetry, crash reporting SDKs, or usage tracking.
  • No advertising, ad identifiers, or ad networks.
  • No selling, renting, or sharing of your data with anybody, for any purpose.
  • No third-party SDKs receiving your health information.
  • No use of health data for marketing, or for any purpose beyond showing you your own results.

Apple HealthKit commitments

In line with Apple’s requirements, HealthState will never use HealthKit data for advertising, marketing, or similar services; will never sell it, or disclose it to data brokers, information resellers, or any third party; and does not share it with anyone without your explicit consent. HealthKit data is not used for anything other than health, fitness and wellbeing features inside the app.

Some of what HealthState can read is sensitive beyond the usual — alcohol especially. Two commitments about it: the app is read-only here, so it never asks you to log a drink and never writes one; and where it reports on drinking it stays descriptive, showing what your own numbers did and nothing more. HealthState does not advise you about your drinking, score it, or judge it. You can withhold any single data type in the Health app’s permission screen and everything else keeps working.

Artificial intelligence

HealthState’s coach, companion chat, and written monthly chapters are generated on your device using Apple’s built-in on-device models, or by simple arithmetic when those aren’t available. Your health data is never sent to an external model or API — not to the developer, not to Apple, not to anyone.

Notes are the exception, deliberately. The Notes section is not generated, not suggested, and not read by anything. No AI feature in the app can see it: the coach, the companion and the Chronicle are all built without access to it, and an automated test fails the build if that ever changes. What you write there is yours, and the app’s only job is to keep it.

Where your notes can appear

Notes stay on your device, but three features can put one somewhere you should know about:

  • Widgets and the Lock Screen. If you pin a note, its text is copied into HealthState’s private app group so the widget can display it — which means a pinned note can be read by anyone who can see your Lock Screen, without unlocking your phone. Only pinned notes are ever copied. Unpin it and the copy is removed.
  • Reminders. A pinned note can show as a daily notification containing your own words, which also appears on the Lock Screen. Off unless you switch it on per note.
  • Siri and Shortcuts. “Add a note to HealthState” writes the text into the same private app group and the app files it next time you open it. Dictation is handled by Siri under Apple’s terms; HealthState receives only the finished text.

You can require Face ID to open Notes in Settings → Notes. It falls back to your passcode so you can’t be locked out of your own writing. Note that the lock protects the Notes screen — a note you have deliberately pinned to a widget is still visible there by design.

iCloud sync (optional, off by default)

If you switch on Sync across my devices, HealthState stores your history in the private database of your own iCloud account so your iPhone, iPad and future devices show the same data. This uses the Apple Account your device is already signed into — there is no HealthState account to create, and no password we could lose.

What this means in practice:

  • Your data is held by Apple in your personal iCloud, under Apple’s privacy policy and your iCloud settings — including Advanced Data Protection, if you have it enabled.
  • The developer has no access to that database and cannot read, export or recover it. There is no admin console and no copy on any server of ours.
  • Nothing is shared with anyone else, and nothing is used for advertising or analytics.
  • Turning sync off stops future changes from being uploaded. To remove what is already there, delete the app’s data from iCloud in the Settings app, or delete the app.

If you would rather keep everything strictly on one device, simply leave this switch off — that remains the default and the app works fully without it.

Stay Close (optional sharing)

If you invite someone through Stay Close, HealthState creates a private share inside your own iCloud account. Only two things are shared: your current stress band (for example “calm” or “strained”) and the display name you choose. Your scores, heart rate, notes, sleep, and locations are never shared. Apple operates iCloud under Apple’s privacy policy; the developer has no access to the shared zone. You can stop sharing at any time.

Exports you create

You can export a CSV of your readings, a JSON backup, a PDF report, a story image or an animated GIF. These are generated on your device and go wherever you send them. Once you share a file, this policy no longer governs it — treat health exports with care.

Purchases

HealthState Pro is a one-time purchase, and tips are optional. All payments are handled by Apple; the developer never sees your name, card, or address. The app stores only a local flag recording that a purchase exists. There is no subscription.

Notifications

Stress alerts, check-in reminders, and the smart wake-up are local notifications scheduled on your device. No push server is involved and no notification content is transmitted.

Keeping and deleting your data

Your history stays on your device for as long as you keep the app. Deleting HealthState removes everything it stored, including chapters, notes, places and nights. If iCloud sync is on, also remove the app’s data in Settings → your name → iCloud to clear the copy held in your own account. Health data written to Apple Health is managed by you in the Health app, and revoking permission there stops the app reading anything further. Because nothing is stored on a developer server, there is no copy for us to delete on your behalf — and none we could hand to anyone else.

Children

HealthState is not directed at children under 13, and the developer does not knowingly collect information from them. In any case, no personal information is collected by the developer at all.

Your rights

Privacy laws such as the GDPR and CCPA give you rights to access, correct, export and delete your personal data. HealthState satisfies these by design: your data is already in your hands, exportable in open formats, and deletable by removing the app. There is no developer-held copy to request, and nothing is ever sold or shared for advertising.

Not a medical device

HealthState provides wellness estimates derived from heart-rate variability, heart rate and movement. It is not a medical device, does not diagnose, treat, cure or prevent any condition, and should never replace professional advice. If something about your health worries you, please speak to a clinician.

Changes to this policy

If this policy changes in any meaningful way, the updated version will be posted here with a new date, and the change will be described in the app’s release notes.

Contact

Questions about privacy: support@hessamzahedi.com.