Health Gateway Privacy Policy
Effective date: September 5, 2026
Health Gateway lets you sync selected Apple Health data from your iPhone to your private Health Gateway backend, then query that data through your authenticated MCP connection.
Data We Collect
- Health and fitness data you authorize through HealthKit, such as step count, heart rate, resting heart rate, heart rate variability, active energy, weight, blood oxygen, workouts, sleep samples, and curated v1 metadata such as workout activity type.
- HealthKit consent records, including the policy version, requested HealthKit data types, purpose, and timestamp.
- Account identifiers from Sign in with Apple, used to create and secure your account.
- Subscription entitlement status from StoreKit, used to confirm access to paid functionality.
- Service security logs, including authenticated health-data access events.
- Account lifecycle milestones, such as first sign-in, subscription activation, Health permission, successful sync, AI connection, successful health question, and feedback submission. Each milestone stores only the account identifier, milestone name, and first-occurrence time.
We do not collect payment card numbers. StoreKit purchases are processed by Apple.
How We Use Data
We use your data only to provide app functionality:
- Syncing your approved HealthKit data.
- Storing that data for your authenticated account.
- Enforcing your StoreKit subscription entitlement.
- Returning your own data through MCP tools you authorize.
- Exporting a copy of your synced account data when you request it.
- Investigating security, access, or reliability issues.
- Measuring aggregate onboarding, activation, retention, sync reliability, and support friction so we can improve the service.
Product measurement uses lifecycle and operational events, not HealthKit values, prompts, AI responses, email addresses, IP addresses, or device identifiers. We do not use HealthKit data for ads, marketing segmentation, data brokerage, or unrelated analytics.
HealthKit Data
HealthKit permission is controlled by iOS. You can change Health permissions at any time in Apple Health or Settings.
Before Health Gateway opens the iOS HealthKit permission prompt, the app shows the data-use summary. After the HealthKit permission request returns, the app records consent with the backend account, including the exact HealthKit data types requested.
Health Gateway does not write data back to HealthKit in v1. Health Gateway does not store HealthKit data in iCloud or CloudKit.
Sharing
We do not sell your data. We do not share HealthKit data with advertising networks, analytics SDKs, or data brokers.
Syncing HealthKit data to Health Gateway does not, by itself, send that data to an AI service. Your data is exposed through MCP only after you explicitly authorize a specific OAuth client for your own account. The authorization page names the recipient before any health data is sent. MCP tools do not allow callers to choose another user id.
The recipient may be OpenAI (for ChatGPT or Codex), Anthropic (for Claude), Google (for Gemini), or another compatible MCP client that you explicitly choose. Depending on the question you ask, Health Gateway may send that named recipient summaries or individual records from the HealthKit categories you approved: step count, heart rate, resting heart rate, heart-rate variability, active energy, weight, blood oxygen, workouts, and sleep. The purpose is solely to answer the health questions you choose to ask through that recipient.
Health Gateway uses encrypted transport, read-only OAuth scopes, account isolation, access logging, and revocable per-client authorization. We require supported and recommended recipients to provide the same or equal protection for personal data under their applicable privacy and security terms. A recipient's processing is also governed by its own privacy policy and your settings with that service. Do not authorize a custom MCP client unless you trust its operator and data practices.
Security
Health sample payloads are encrypted at rest with per-user data encryption keys. The iOS app also encrypts temporary pending upload batches on device with a per-user keychain data key before backend ingest, then removes that pending state after upload, account deletion, credential revocation, or user change. Backend access is scoped by authenticated user identity. Access to health data, including account export, is audit logged with request metadata, such as request id, route, token type, OAuth client id where available, scope, result count where applicable, and MCP tool name. Audit logs and lifecycle milestones do not store raw HealthKit samples, prompts, or AI responses. Internal product reports exclude the marketplace reviewer account and contain aggregate counts only.
Retention And Deletion
We retain synced health data while your account exists and your subscription entitlement is active or within a short inactive retention window. We prune accounts 30 days after the StoreKit entitlement becomes inactive.
You can delete your account in the app at any time. Account deletion removes synced health samples, HealthKit consent records, account lifecycle milestones, account-linked OAuth tokens, related entitlement records, and the backend user record, invalidates app and MCP access tokens issued before deletion, then clears local app session state, HealthKit sync anchors, pending upload state, last-sync state, and the current temporary export file reference. If this device later learns that the backend account was already deleted, it performs the same local cleanup before further sync. Deleting your account does not cancel your Apple subscription; manage subscriptions through Apple. The backend may retain a master-keyed pseudonymous deletion marker with aggregate deletion counts, an aggregate audit summary by action, and a bounded sanitized audit timeline for security, abuse prevention, disclosure investigation, and operational integrity. The retained deletion marker may include OAuth client ids needed to reconstruct MCP disclosures, but should not include raw HealthKit samples, sample filters, request bodies, signed StoreKit transaction payloads, token ids, or scopes.
You can export a bounded page of your synced account data from the app through the authenticated backend export endpoint while your StoreKit entitlement is active. The app saves approved exports as temporary protected JSON files so you can share or save them using iOS, and clears temporary export files when entitlement is no longer active or account state is removed. To request additional export or deletion help, contact hello@getgoodfeels.com.
Your AI Assistant And MCP Access
Your synced health data is exposed to AI assistants only through the Model Context Protocol (MCP) endpoint, and only after you complete an explicit OAuth authorization for the named recipient. Each authorized client receives tokens scoped to read-only health access for your account alone; no client can read another user's data. Health Gateway does not send data for advertising, marketing, or model-training purposes. You can see every authorized client in the app and revoke its access at any time.
Your Choices
- Revoke HealthKit permissions in iOS.
- Cancel or manage subscriptions through Apple.
- Revoke individual remote MCP clients in the app, or delete your account to remove all account-linked OAuth tokens.
- Export synced account data, delete your account in the app, or request export/deletion help at hello@getgoodfeels.com.
Contact
Good Feels Inc. · hello@getgoodfeels.com · Massachusetts, United States