Health Protocol Tracker
Effective 29 August 2026 · Last updated 29 August 2026
This policy covers the Health Protocol Tracker app for iOS ("the app"). The app is published by Davinder Sandhu ("we", "us").
It describes what the app does with information you enter. If you choose to use iCloud sync, Apple's handling of your iCloud data is governed by the Apple Privacy Policy rather than by this one — so read the two alongside each other.
Everything in the app is information you type in yourself. The app does not import from HealthKit, does not read your contacts, photos, or location, and does not ask for any of them.
| Category | Examples | Where it lives |
|---|---|---|
| Protocol entries | Compound names, dosages, concentrations, schedules, the days you've set | Your device — and your iCloud, if you choose to sync |
| Adherence history | Which doses you logged, when you logged them, and any notes you attached | Your device — and your iCloud, if you choose to sync |
| App preferences | Reminder settings, missed-dose rollover, disclaimer acknowledgement | Your device |
This is health information, and we treat it that way. It is also, in the strict sense, information we never hold.
Your protocol and history are written to your iPhone's local storage, inside the app's sandbox. Other apps cannot read it.
iCloud sync is optional. The app is fully functional without it: every feature works on a device that has never been signed in to iCloud, and nothing is withheld if you choose not to sync. Sync exists for one reason — so your protocol follows you across your own devices.
If you do use it, the app syncs through CloudKit, into the private database of your personal iCloud account. In practice that means:
You turn this on or off yourself, in the app: Settings → Sync → Sync with iCloud. Switch it off and nothing further is written to or read from iCloud — the app keeps everything on the device. Switch it back on and syncing resumes.
Anything already synced before you switched it off stays in your iCloud account until you remove it, which you can do in Settings → Apple Account → iCloud → Manage Account Storage. Signing the device out of iCloud, or turning iCloud off for Health Protocol Tracker in iOS Settings, also stops syncing.
The app makes no network connections of its own. There is no backend server, no API we operate, no third-party service receiving your information. It contains no analytics, crash-reporting, advertising, or attribution SDK.
You can lock the app behind Face ID, Touch ID, or your device passcode. Authentication is performed entirely by iOS. The app receives only a yes-or-no answer — it never sees your face data, fingerprint, or passcode, and none of that is ever stored by the app or transmitted anywhere.
If you enable reminders, they are scheduled locally on your device by iOS. No push server is involved and no reminder content leaves your phone. You can turn them off in the app or in iOS Settings at any time.
The app can export your history as a CSV file. The export is created only when you ask for it, and iOS then hands it to whatever destination you pick — Files, AirDrop, Mail, or another app.
Once you send that file somewhere, it is outside the app's control and outside the protections described here. Treat an exported CSV as you would any other document containing your health information.
Your data is kept until you delete it. You are always the one who deletes it:
We cannot delete your data for you, for the same reason we cannot read it: it was never in our possession. Deletion is entirely in your hands, which is the strongest form this guarantee can take.
Privacy laws including the GDPR and the CCPA/CPRA give you rights to access, correct, export, and delete personal information that a company holds about you, and to know whether it is sold or shared.
We hold none, so these rights resolve unusually simply:
If you believe any of this is inaccurate, please contact us using the details below.
Health Protocol Tracker is intended for adults aged 18 and over. It is not directed at, or intended for use by, anyone under 18. We do not knowingly collect information from minors — a claim made easier by the fact that we do not knowingly collect information from anyone.
If you are under 18, please do not use the app.
Your data is protected by your device's encryption and passcode, by the app's optional biometric lock, and by Apple's protections on your iCloud account. Because there is no server of ours holding your records, there is also no database of ours that could be breached.
The security of your Apple Account matters here: keep it protected with a strong password and two-factor authentication.
If this policy changes, the updated version will be posted at this address with a new "last updated" date. Material changes to how the app handles your information will be described here rather than made quietly.
Questions about this policy or about privacy in the app: