Health Gateway

Health Gateway Privacy Policy

Effective date: September 5, 2026

Health Gateway lets you sync selected Apple Health data from your iPhone to your private Health Gateway backend, then query that data through your authenticated MCP connection.

Data We Collect

We do not collect payment card numbers. StoreKit purchases are processed by Apple.

How We Use Data

We use your data only to provide app functionality:

Product measurement uses lifecycle and operational events, not HealthKit values, prompts, AI responses, email addresses, IP addresses, or device identifiers. We do not use HealthKit data for ads, marketing segmentation, data brokerage, or unrelated analytics.

HealthKit Data

HealthKit permission is controlled by iOS. You can change Health permissions at any time in Apple Health or Settings.

Before Health Gateway opens the iOS HealthKit permission prompt, the app shows the data-use summary. After the HealthKit permission request returns, the app records consent with the backend account, including the exact HealthKit data types requested.

Health Gateway does not write data back to HealthKit in v1. Health Gateway does not store HealthKit data in iCloud or CloudKit.

Sharing

We do not sell your data. We do not share HealthKit data with advertising networks, analytics SDKs, or data brokers.

Syncing HealthKit data to Health Gateway does not, by itself, send that data to an AI service. Your data is exposed through MCP only after you explicitly authorize a specific OAuth client for your own account. The authorization page names the recipient before any health data is sent. MCP tools do not allow callers to choose another user id.

The recipient may be OpenAI (for ChatGPT or Codex), Anthropic (for Claude), Google (for Gemini), or another compatible MCP client that you explicitly choose. Depending on the question you ask, Health Gateway may send that named recipient summaries or individual records from the HealthKit categories you approved: step count, heart rate, resting heart rate, heart-rate variability, active energy, weight, blood oxygen, workouts, and sleep. The purpose is solely to answer the health questions you choose to ask through that recipient.

Health Gateway uses encrypted transport, read-only OAuth scopes, account isolation, access logging, and revocable per-client authorization. We require supported and recommended recipients to provide the same or equal protection for personal data under their applicable privacy and security terms. A recipient's processing is also governed by its own privacy policy and your settings with that service. Do not authorize a custom MCP client unless you trust its operator and data practices.

Security

Health sample payloads are encrypted at rest with per-user data encryption keys. The iOS app also encrypts temporary pending upload batches on device with a per-user keychain data key before backend ingest, then removes that pending state after upload, account deletion, credential revocation, or user change. Backend access is scoped by authenticated user identity. Access to health data, including account export, is audit logged with request metadata, such as request id, route, token type, OAuth client id where available, scope, result count where applicable, and MCP tool name. Audit logs and lifecycle milestones do not store raw HealthKit samples, prompts, or AI responses. Internal product reports exclude the marketplace reviewer account and contain aggregate counts only.

Retention And Deletion

We retain synced health data while your account exists and your subscription entitlement is active or within a short inactive retention window. We prune accounts 30 days after the StoreKit entitlement becomes inactive.

You can delete your account in the app at any time. Account deletion removes synced health samples, HealthKit consent records, account lifecycle milestones, account-linked OAuth tokens, related entitlement records, and the backend user record, invalidates app and MCP access tokens issued before deletion, then clears local app session state, HealthKit sync anchors, pending upload state, last-sync state, and the current temporary export file reference. If this device later learns that the backend account was already deleted, it performs the same local cleanup before further sync. Deleting your account does not cancel your Apple subscription; manage subscriptions through Apple. The backend may retain a master-keyed pseudonymous deletion marker with aggregate deletion counts, an aggregate audit summary by action, and a bounded sanitized audit timeline for security, abuse prevention, disclosure investigation, and operational integrity. The retained deletion marker may include OAuth client ids needed to reconstruct MCP disclosures, but should not include raw HealthKit samples, sample filters, request bodies, signed StoreKit transaction payloads, token ids, or scopes.

You can export a bounded page of your synced account data from the app through the authenticated backend export endpoint while your StoreKit entitlement is active. The app saves approved exports as temporary protected JSON files so you can share or save them using iOS, and clears temporary export files when entitlement is no longer active or account state is removed. To request additional export or deletion help, contact hello@getgoodfeels.com.

Your AI Assistant And MCP Access

Your synced health data is exposed to AI assistants only through the Model Context Protocol (MCP) endpoint, and only after you complete an explicit OAuth authorization for the named recipient. Each authorized client receives tokens scoped to read-only health access for your account alone; no client can read another user's data. Health Gateway does not send data for advertising, marketing, or model-training purposes. You can see every authorized client in the app and revoke its access at any time.

Your Choices

Contact

Good Feels Inc. · hello@getgoodfeels.com · Massachusetts, United States