← HealthNat
H

Privacy Policy

HealthNat for iOS

Last updated: 30th August 2026

1. About this Privacy Policy

This Privacy Policy explains how Natan Gluszko trading as HealthNat (“we”, “us”, or “our”) collects, uses, stores, and shares personal data when you use the HealthNat iOS application (the “App”).

We process personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), where applicable.

2. Data Controller

The data controller is:

HealthNat
Email: natandeveloper@icloud.com

We have not appointed a Data Protection Officer, as the processing operations do not require one under Article 37 UK GDPR. For any questions regarding your data privacy, contact us directly at natandeveloper@icloud.com.

3. Personal Data We Collect

Depending on how you use the App, we collect and process the following categories of personal data:

Category Data Elements Collected Source Where Stored
Account Data Apple user identifier, email address (or Apple-generated private relay email if using Hide My Email) Sign in with Apple Backend Database
Health Data (Special Category) Daily water intake logs, daily body weight logs, user-defined step and hydration goals User manual entry Backend Database
Activity Data (On-Device) Daily step counts read via Apple HealthKit Apple HealthKit Processed strictly on-device; never transmitted to our backend
Technical & App Data User preferences, app configuration settings Device / App Device and Supabase Backend

We do not knowingly collect personal data from individuals under the age of 18 or any other special category data outside the specific health metrics described above.

4. Health Data and Apple HealthKit Processing

Our App tracks personal wellness metrics to help you monitor your health and fitness goals.

What We Process

With your explicit consent, the App processes:

  • Water intake entries: logged manually and synchronised across your authenticated devices.
  • Weight entries: logged manually and synchronised across your authenticated devices.
  • Fitness targets: custom daily goals (e.g., target step goals, daily water targets) synchronised across your authenticated devices.
  • Step count readings: read from Apple HealthKit solely to display your real-time progress against your daily step goal.

Critical Commitments Regarding Apple HealthKit Data

  • On-Device Restriction for Step Counts: Actual step count history read from Apple Health is processed entirely on your local iOS device. We do not transmit, sync, or store your HealthKit step count history on our backend servers. Only your custom numerical step target (goal) is synchronised.
  • No Advertising or Commercial Sale: We never sell your health data, nor do we use HealthKit data or health metrics for marketing, advertising, profiling, or data mining purposes.
  • Third-Party Disclosures: Health metrics synchronised to our backend are stored securely with our infrastructure provider (Supabase) exclusively to provide the synchronisation feature, and are never shared with advertisers or data brokers.

You may grant or revoke HealthKit permissions at any time through your iOS device settings via Settings > Health > Data Access & Devices > HealthNat.

5. Purposes of Processing and Lawful Bases

Under Articles 6 and 9 UK GDPR, we process your personal data on the following grounds:

Purpose Personal Data Involved Lawful Basis (UK GDPR Art. 6) Special Category Condition (UK GDPR Art. 9)
User Authentication & Account Management Apple ID / Relay Email, user identifier Performance of a contract (Art. 6(1)(b)) N/A
Cross-Device Synchronisation of Health Logs & Goals Water intake, weight, health/step goals Consent (Art. 6(1)(a)) Explicit Consent (Art. 9(2)(a))
Displaying Step Goal Progress (On-Device) Step count data read via HealthKit Consent (Art. 6(1)(a)) Explicit Consent (Art. 9(2)(a))
Subscription & In-App Purchase Management Transaction identifiers, receipt data Performance of a contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) N/A
App Security, Error Mitigation, & Maintenance Error logs, backend transaction logs Legitimate interests (Art. 6(1)(f)) N/A
Statutory and Regulatory Compliance Legal dispute records, compliance records Legal obligation (Art. 6(1)(c)) N/A

Where we rely on legitimate interests, our interests consist of maintaining the operational integrity, uptime, and security of the App.

Where processing is based on consent (including explicit consent for health data), you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

6. iOS System Permissions

The App requests the following device permissions:

  • Notifications: To deliver local notifications and hydration reminders scheduled locally on your device. No push-notification server tokens are sent to external servers.
  • Apple Health (HealthKit): To read daily step counts from the Apple Health repository on your device to display progress towards your daily step target.

7. Analytics, Tracking, and SDK Disclosures

  • The App does not use third-party analytics SDKs, advertising networks, or user tracking frameworks.
  • The App does not track your activity across apps and websites owned by other companies; therefore, Apple’s App Tracking Transparency (ATT) prompt is not required.
  • We do not use cookies or tracking technologies subject to Regulation 6 of PECR.

8. Sharing Personal Data

We do not sell, rent, or trade your personal data. We disclose personal data only to the following trusted recipients:

  • Cloud Infrastructure & Hosting Providers: We use Supabase (PostgreSQL database and authentication services) to securely host account records, synchronised water and weight logs, and goal preferences.
  • Platform Provider: Apple Inc., which processes authentication (Sign in with Apple) and manages in-app billing transactions through the App Store.
  • Legal and Regulatory Authorities: Law enforcement or regulatory authorities only where required by law, court order, or binding statutory obligation.

All cloud service providers acting on our behalf process data solely under binding data processing agreements that satisfy Article 28 UK GDPR.

9. International Data Transfers

Your personal data may be stored on servers managed by our cloud infrastructure provider, which operates in data centres located in the European Economic Area (EEA).

Where personal data is transferred outside the United Kingdom:

  • Transfers to the EEA are carried out pursuant to the UK Government's adequacy regulations under Schedule 21 of the Data Protection Act 2018.
  • Transfers to the United States or other third countries are secured via the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (SCCs) or the UK Extension to the EU-US Data Privacy Framework.

10. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes set out in this policy:

  • Account Data & Synchronised Health Metrics: Retained for the duration of your active account lifecycle. All data is deleted immediately upon receiving a valid account deletion request.
  • Local HealthKit Data: Cached step counts residing in the local app cache are refreshed continuously and removed upon app uninstallation.

11. Security Architecture

We have implemented technical and organisational safeguards to secure your personal data against accidental loss, unauthorised access, alteration, or disclosure:

  • Encryption in Transit: All communications between the App and the backend are encrypted using Transport Layer Security (TLS 1.3 / HTTPS).
  • Access Controls & Database Isolation: Per-user Row-Level Security (RLS) policies ensure that users can only access their own database records.
  • Client Security: Authentication tokens generated via Sign in with Apple are stored securely in the local iOS Keychain.
  • Hard Deletion Protocols: In-app account deletion executes an automated cascade hard-delete across all database tables associated with your user identifier.

12. Your Data Subject Rights

Under Chapter III of the UK GDPR, you have the following statutory rights regarding your personal data:

  • Right of Access (Article 15): The right to obtain confirmation as to whether your data is being processed and obtain a copy of your personal data.
  • Right to Rectification (Article 16): The right to correct inaccurate or incomplete data.
  • Right to Erasure / “To Be Forgotten” (Article 17): The right to have your data erased from our systems.
  • Right to Restriction of Processing (Article 18): The right to restrict the processing of your personal data under certain circumstances.
  • Right to Data Portability (Article 20): The right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Article 21): The right to object to processing based on our legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent or explicit consent (such as health data synchronisation), you may withdraw consent at any time without penalty.

To exercise any of these rights, contact natandeveloper@icloud.com. We respond to all verified requests within one calendar month in accordance with Article 12 UK GDPR.

Right to Complain

You also have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk

13. Children’s Privacy

The App is strictly intended for individuals aged 18 and over. Do not use these Services if you are under the age of 18. Our services are not designed nor otherwise intended for children or anyone under 18. If we become aware that personal data relating to a person under 18 has been collected, we will immediately delete that account and all associated data from our servers.

14. In-App Account and Data Deletion

In compliance with Apple App Store Review Guidelines and Article 17 UK GDPR, you can initiate complete account and data deletion directly within the App:

Open the App and navigate to Settings > Account > Delete Account.

Effect of Deletion

  • Server Deletion: Your account record, authentication credentials, and all backend-stored health logs (water entries, weight entries, custom goals) are immediately and permanently deleted from our database.
  • Apple Credential Revocation: The App triggers credential revocation for Sign in with Apple.
  • Apple HealthKit Data: Deleting your HealthNat account does not delete historical records stored natively within Apple’s Health app repository. To remove step data or metrics directly from Apple Health, use the native Apple Health application controls.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory modifications. Any updates will be published within the App along with a revised “Last updated” date. Material changes affecting how we process health data will be notified to you directly in-app, and consent will be re-obtained where required by law.

16. Contact Us

For queries, privacy notices, or data rights requests:

Natan Gluszko

natandeveloper@icloud.com

17. Document History

Last updated: 30th August 2026