App Privacy Policy
Halor ("we", "us") is built so that your health information stays yours. This policy explains exactly what data the Halor app handles, where it lives, and what never leaves your control. It covers the Halor iOS app, including free membership and the optional Healthspan Brief. The halor.app website has its own privacy policy at halor.app/privacy.
The short version
- Your health data lives on your device and — only if you turn it on — in your own private iCloud. It is never stored on our servers. We cannot read it.
- Our servers hold your account identity (e-mail address or Apple/Google sign-in identifier) and the timestamps that come with having an account — when it was created and when you last signed in. Nothing about your health.
- If you choose the weekly Healthspan Brief, we send your account e-mail address to beehiiv to deliver it and measure newsletter delivery and engagement. This choice is separate from free membership. You can unsubscribe at any time without losing access to Halor. No health data is sent to beehiiv.
- Only if you tick the box, we collect how far you get — which lessons you finish and which sections and trackers you use, as names only, never what you put into them (§ 6).
- The app checks for updates when it opens or when you return to it. That check carries nothing about you or your health (§ 7).
- Data read from Apple Health never leaves your device at all — it is not included in iCloud backup sync and never reaches any server.
- You can delete your account and app data in-app at any time.
1. Data you create in Halor (health and journey data)
This includes biomarker values you enter or scan from lab reports, tracker check-ins (exercise, sleep, nutrition, supplements), family-history entries, cognitive baseline entries, appointment-preparation documents, learning progress, and your conversations with the on-device Co-Pilot.
- Stored: on your device.
- Optional iCloud backup (off by default): if you enable "Back up to your iCloud" (onboarding or Profile → Sync), this data syncs to your personal iCloud account so it survives device loss and stays consistent across your devices. It is protected by Apple's iCloud encryption under your Apple ID; enabling Apple's Advanced Data Protection makes it end-to-end encrypted. We have no access to your iCloud.
- Never: sent to Halor servers, sold, shared, or used for advertising.
2. Data read from Apple Health
With your permission, Halor reads activity, heart rate, sleep, and VO₂ max from Apple Health to build your baseline and fill your trackers.
- Processed on-device only, held in memory for display and scoring.
- Never written to iCloud (excluded from backup sync by design), never sent to any server, never sold or shared — in line with Apple's HealthKit rules.
3. Lab-report scanning (camera / photos)
Lab-report images are processed by on-device text recognition. The image itself is never uploaded and never stored — only the biomarker values you confirm are saved (as § 1 data).
4. Account data
If you create an account, our authentication provider (Supabase) stores: your e-mail address (or your Apple/Google sign-in identifier) and session tokens, plus the timestamps that come with any account — when it was created, when you last signed in, and when your session was last renewed. We record none of this deliberately; it is how sign-in works. It does mean we could tell roughly how recently you signed in, though not what you did in the app. Your IP address is seen by the authentication provider when you sign in.
This is used to identify your account, save your membership status, and secure account-only actions such as subscribing your own account e-mail address to the Healthspan Brief. No health data ever touches this system, and nothing you record in Halor — biomarkers, tracker entries, learning progress, streaks — is stored here or anywhere else on our servers.
5. Diagnostics
Errors are recorded in a small log on your device (error codes and technical messages only — never health values). It leaves your phone only if you tap "Share diagnostics" in Profile and choose where to send it.
6. Usage data
Two things, and nothing else, are collected to tell us what to build next, covered by the "Help improve Halor" box shown when you sign up, which you can change at any time in Profile → Preferences → Share how you use Halor. Turn it off and nothing is collected.
Course progress. Which lesson or chapter you finished, and that you opened the app. This carries a random installation identifier so we can tell one person finishing forty lessons from forty people finishing one. It is not linked to your e-mail, your name, or your account; it says "same phone as last time" and nothing else, and if you delete your account it is discarded, so what was collected before can never be tied to you or to any future account on this phone. It contains no scores and no quiz answers.
Which parts of Halor you use. That you read a card in a section, finished a section, saved an entry in a tracker, or set up your appointment plan — each as the name of the section or tool and nothing more. What you put in never leaves: not a logged value, not a note, and none of your appointment plan's answers (your age band, sex, and family history stay on your phone). Because sections are named after health topics, this does show which areas of the app you spend time in; if you would rather not share that, the box above turns it off along with everything else.
Nothing from the Co-Pilot is collected automatically. Not your questions, not their length, not the subjects they touch on. The Co-Pilot works out its answers on your phone and none of that leaves it. The single exception is the one below, which only happens if you press a button.
A question you choose to send us. When the Co-Pilot cannot answer something, it offers to pass your question on so we can write material covering it. Your question is shown back to you and you can edit it before sending. Nothing is sent unless you tap the button. This is the only circumstance in which anything you have typed leaves your phone.
What is sent is the question and nothing else. It reaches us as an e-mail, carries no account identifier and no session token, and is not stored alongside anything that could identify you — we do not record who asked, and nothing we store can connect two questions to the same person. It is not part of the usage reporting above and does not depend on it: switching that off does not switch this off, and vice versa.
Never collected, under any heading: anything you record about your health, anything read from Apple Health, your appointment-preparation notes, what you type into search, and error reports (their text can contain anything, so they stay in the on-device log described in § 5). This is enforced in the app by a default-deny list, and by tests that fail the build if anything on it is ever added.
If you are in the EEA or UK: this usage data is collected only with your consent — the box above, which starts unticked — and you can withdraw it at any time in Profile → Preferences.
7. App updates
Every time you open or return to Halor, the app asks our update provider (Expo) whether a corrected version of the app's code is available. This is how we can fix an error in health content quickly rather than waiting for an App Store review.
That request contains the device's operating system, our project identifier, and a random per-install token, generated on your device, that Expo uses to tell installations apart for update delivery and to count active installs. It is not tied to your account or to anything about you, and it carries nothing about your health. Expo acts as our data processor, is SOC 2 Type 2 attested, and publishes its own privacy policy and list of sub-processors at expo.dev/privacy.
8. Free membership and the Healthspan Brief
Halor membership is free. Creating an account gives you membership and does not subscribe you to marketing e-mail. On the join screen you can choose either "Join free + get the weekly Brief" or "Join free without the Brief". Both choices provide the same app access.
If you choose the Healthspan Brief, the app sends your authenticated account e-mail address to beehiiv, our newsletter platform. It does not accept a different address on this route. beehiiv processes the address and newsletter records needed to operate the Brief, including subscription status, delivery events, opens, clicks, signup source, and unsubscribe activity. beehiiv may use technical data generated when you interact with an e-mail in accordance with its privacy policy. We use this information to deliver the Brief, understand whether it is reaching readers, and improve it. No health information, tracker entries, app activity, or Co-Pilot content is sent to beehiiv.
Subscribing is a single opt-in: your deliberate tap requests immediate enrolment and beehiiv may send a welcome e-mail. You can unsubscribe in Profile or from the link in any issue. Unsubscribing never changes your membership or access to Halor. If you subscribe again after unsubscribing, we treat that as a new request.
We rely on your consent for this newsletter processing. You can withdraw it by unsubscribing. beehiiv processes newsletter data in the United States and may use its own service providers. See beehiiv's privacy policy and data processing addendum.
9. Deleting your data
- Delete account (Profile → Account → Delete account): permanently removes your account from our authentication provider, your synced data from your iCloud container, and your data on the device. The app also asks beehiiv to unsubscribe your account e-mail address. Newsletter suppression records or other records required for legal and operational purposes may remain. To request deletion of newsletter data, e-mail privacy@halor.app.
- Unsubscribe from the Brief (Profile → The Healthspan Brief): stops future issues without affecting your account, membership, or app data. The unsubscribe link in any issue does the same.
- Uninstalling the app removes on-device data; your iCloud copies (if backup was enabled) can be removed via in-app deletion or Apple's iCloud settings.
10. What we never do
We never sell your data, never share it with data brokers or advertisers, never use your health information for marketing, and never train models on it.
11. Age
Halor is for adults only. You must be at least 18 years old — or the age of majority in your jurisdiction, whichever is higher — to use the app. We do not knowingly collect data from anyone below this age; if we learn we have, we will delete it.
12. Who is responsible for your personal data
The Halor application and service are currently operated by Benjamin Sang-Hjon Cistecky, based in Singapore. References in this policy to "we", "us", and "Halor" are to that operator.
We handle personal data in accordance with the Singapore Personal Data Protection Act 2012 (PDPA). Where you are located outside Singapore, we also observe the data protection principles applicable in your jurisdiction to the extent they apply to us.
Change of operator. We intend to incorporate a Singapore company to operate Halor. When that happens, the service and the responsibility for personal data described in this policy will transfer to that company. We will update this policy, identify the new operator, and notify you in-app before or at the time of the transfer. If the transfer materially changes how your personal data is handled, we will seek your consent as required by the PDPA.
13. Changes
We will update this policy as the app evolves (for example if subscriptions or optional analytics launch) and note material changes in-app before they apply.
14. Contact
Questions, access and correction requests, withdrawal of consent, and complaints: privacy@halor.app. We will acknowledge within 5 business days and respond substantively within 30 days.