Privacy Policy

Effective 18 August 2026 · Health Targets app (iPhone, iPad, Apple Watch, widgets) and healthtargets.app
Data controller / publisher: LustigFarchild, Bulgaria · support@healthtargets.app

1. The architecture is the policy

Health Targets is built so that we never receive your data. The app has no accounts, no servers of ours, no analytics, no advertising, and no trackers. Your health measurements stay in Apple Health on your devices; the app reads them there, with your per-measurement permission, and draws your targets on top. Nothing is collected by us, nothing is transmitted to us, nothing is sold — not because a setting is off, but because no code path exists that could do it. Apple's App Store privacy label for this app reads "Data Not Collected."

Everything below is the precise version of that sentence, jurisdiction by jurisdiction.

2. What the app processes — on your device only

With your explicit consent, requested per measurement through Apple's HealthKit permission screen, the app reads the measurement types you choose to track. Depending on your choices these may include body measurements (weight, body fat, BMI, waist circumference), heart measurements (heart rate, resting heart rate, heart rate variability, blood pressure), activity (steps, active energy, exercise minutes), respiratory measurements (blood oxygen, respiratory rate), blood glucose, sleep, and hydration.

This processing happens entirely on your device, for the sole purpose of displaying your readings against target ranges you define. The app is read-only toward Apple Health: it never writes to the Health database, never copies health samples into its own storage, and never transmits them off the device to us or to any third party. You can revoke access per measurement at any time in iOS Settings ▸ Health ▸ Data Access & Devices; the app continues to function with whatever you allow, including nothing.

3. What syncs — your targets, through your own iCloud

The configuration you author — which measurements you track, your target ranges and their history, display preferences — can sync between your own devices through Apple's CloudKit, inside your private iCloud database attached to your Apple Account. This sync never includes health measurements. We have no access to your iCloud data; it is encrypted and governed by Apple's iCloud terms. If your device is not signed into iCloud, this data simply remains local. Deleting the app and removing its data from iCloud erases it.

4. What we can receive — one channel, initiated by you

In normal operation, no personal data reaches us at all. The single exception is correspondence you choose to send to support@healthtargets.app or security@healthtargets.app.

If you email us: we process your email address and message content on the legal basis of our legitimate interest in answering you (GDPR Art. 6(1)(f)) or, where your message concerns a contract matter, performance of a contract (Art. 6(1)(b)). We use it solely to respond, share it with no one, and delete the correspondence once your request is resolved, except where a statutory retention duty applies. Our mail provider acts as a processor for this mailbox. Please do not include health details in support email — we never need them to help you, and we will not ask for them.

5. Purchases

The optional Pro upgrade is sold by Apple through the App Store. Apple processes the payment as an independent controller under Apple's own privacy policy; we receive no payment details and no identity — only Apple's pseudonymous confirmation that an entitlement is valid, evaluated on your device.

6. No cookies, no tracking — app and website alike

The app contains no third-party SDKs of any kind. This website sets no cookies, runs no JavaScript, loads nothing from third-party domains, and uses no analytics; consequently no cookie banner is required and none is shown. Web hosting necessarily involves technical connection handling by the hosting provider; we configure hosting without visitor analytics under our control.

7. International transfers

None exist on our side, because no personal data flows to us in normal operation. Support email is stored with our mail provider under the safeguards described in section 4.

8. Retention

Health data: never held by us; its lifetime is governed by your Apple Health database. Targets and configuration: on your device and in your private iCloud until you delete them or the app. Support correspondence: deleted upon resolution of your request, absent a legal retention duty.

9. Your rights

9.1 European Union / EEA, United Kingdom, Switzerland (GDPR, UK GDPR, revFADP)

Health data is special-category data (GDPR Art. 9). Because processing occurs on your device under your sole control, we do not act as controller of your health data in normal operation — there is nothing for us to access, rectify, restrict, port, or erase. Where we are controller (support correspondence), you have the full set of rights — access, rectification, erasure, restriction, objection, portability — exercisable by email to support@healthtargets.app; we answer within one month. No automated decision-making or profiling takes place. You may lodge a complaint with your supervisory authority; our lead authority is the Bulgarian Commission for Personal Data Protection (cpdp.bg), but you may always contact the authority of your own country — in France the CNIL, in Germany your Land's authority, in the UK the ICO, in Switzerland the FDPIC.

9.2 United States

HIPAA: we are not a covered entity or business associate, and we make no "HIPAA compliant" claim. FTC Health Breach Notification Rule: as a consumer health app we are in scope; because we hold no consumer health data and integrate no third-party SDKs, our exposure is structural rather than procedural, and we re-verify at every release that no SDK receives health data.

Consumer Health Data (Washington My Health My Data Act, Nevada SB 370, and similar): this section serves as our Consumer Health Data Privacy Policy. Categories of consumer health data processed — on device only: the Apple Health measurement types you select (section 2). Purpose: displaying them against your own targets. Collection by us: none. Sharing: none. Sale: none — and we do not sell or share any personal data of any kind. Biometric identification: none. Affiliates or processors with access to consumer health data: none. To exercise access or deletion rights, email support@healthtargets.app; we confirm within the statutory timeline, and you may appeal an outcome by replying to our response, which a different reviewer will assess.

California (CCPA/CPRA): we do not collect, sell, or share personal information within the meaning of the CCPA in normal operation and have not done so in the preceding 12 months; sensitive personal information is processed only on your device. We do not discriminate for exercising rights. As no personal information is collected, no "Do Not Sell or Share" mechanism is required; Global Privacy Control signals have nothing to act upon on a cookieless site.

9.3 Other regions

Brazil (LGPD): health data is sensitive; the on-device position applies; rights requests via the address above; you may petition the ANPD. Japan (APPI) / South Korea (PIPA): same position; no third-party provision; no cross-border transfer exists because no transfer exists. Türkiye (KVKK), Thailand (PDPA), Indonesia (UU PDP), Ukraine: the strictest-overlap policy above applies uniformly. Canada (PIPEDA): same position; you may complain to the OPC.

10. Children

Health Targets is not directed at children, offers no accounts, shows no advertising, and collects no data from anyone — including children. Apple's age rating governs store availability.

11. Security

There is no server side of ours to breach. On-device protections include Apple's HealthKit consent model, iCloud encryption for your private database, and the app's optional Face ID/Touch ID lock. Vulnerability reports: security@healthtargets.app — see the security page for our coordinated-disclosure terms under the EU Cyber Resilience Act.

12. Changes to this policy

Changes appear here with a new effective date. Because the architecture collects nothing, changes can only tighten or clarify — a change that introduced data collection would be a material change requiring fresh, explicit consent in the app before anything else happened.

13. Contact

LustigFarchild, Bulgaria · support@healthtargets.app · Data protection matters: same address, subject "Privacy".

Published in English; localized versions in the app's 18 languages follow with the localization milestone. In case of divergence before then, the English version prevails to the extent local law permits.