PRIVACY · REVISION 1.0

Your health story stays yours.

HeartStory processes authorized Apple Health data on your devices. No HeartStory account, advertising, third-party analytics SDK, or health-data upload.

Effective
8 August 2026
Operator
NanoHits
Contact
Secure contact form

01 · Scope

What this policy covers

This policy explains how NanoHits handles information when you use the HeartStory iPhone app, its Apple Watch companion, and the HeartStory website. HeartStory is a general-wellness information product. It is not a medical device, does not diagnose or treat a condition, and is not an emergency service.

The short version

Your Apple Health information is analyzed locally. It is not sent to NanoHits, sold, used for advertising, or used to track you.

02 · Apple Health data

Data the app reads and why

With your authorization, HeartStory reads compatible heart-related information recorded by Apple Watch and stored in Apple Health. Depending on the features available on your devices, this can include heart-rate samples and summaries, resting heart rate, heart-rate variability, sleeping heart rate, respiratory rate, cardio fitness, one-minute recovery, workouts, and Apple-recorded heart events.

HeartStory uses this information to present timelines, personal trends, comparisons, provenance, data-quality indicators, and explainable observations. It requests only the HealthKit permissions required by shipped features. Apple Health remains the system of record.

  • No iPhone camera measurement.
  • No sale or sharing of health data.
  • No use of HealthKit data for advertising, profiling, or tracking.
  • No third-party analytics SDK or external event stream.
  • No health values in diagnostic logs unless you deliberately export your own data.

If you start an Active Session on Apple Watch, Apple’s workout APIs may record session-associated samples to Apple Health where the system permits. The session is deliberate and visibly active.

03 · Storage and retention

Local data on your devices

HeartStory stores the minimum local information required for performance, reproducibility, preferences, user-authored context, and purchase entitlement. Platform storage protections safeguard these local stores.

Rebuildable health-derived information—such as import anchors, sample references, aggregates, baselines, insights, and calculation receipts—is kept separately from user-authored information. Raw sample references and their minimal value cache are normally retained for 90 days. Aggregates and receipt fingerprints may be retained longer so trends remain available and calculations can be explained. A raw reference may remain longer when a bookmarked receipt requires it. Imported deletion markers are retained for 30 days while dependent results are revised, then purged.

Local, aggregate product-quality information may include import success counts, last successful import time, and similar operational diagnostics. It does not create a remote analytics profile and is not transmitted as an event stream.

04 · Backups and restore

What can be restored

Rebuildable health-derived data is excluded from iCloud Backup. On a new or restored device, HeartStory rebuilds it from the Apple Health history then readable to the app; rebuilt history may differ if Health access is limited.

User-authored information—such as journal tags or notes, source preferences, user-configured thresholds, notification preferences, and app settings—is included in your encrypted device backup in version 1.0 unless you disable device backup through Apple’s controls. Apple provides and controls that backup service under your Apple account and Apple’s terms.

05 · Exports and sharing

You decide when data leaves

CSV and Heart Report exports are generated locally. Data leaves the app only when you initiate an export or share action and choose a destination. Password-protected PDF reports use local password protection. A copy remains in HeartStory’s sandbox only when you choose to keep it there.

Once you share a file with another app, person, storage provider, or service, that recipient’s privacy practices apply. Review the destination before sharing sensitive information.

06 · Website information

Information you type into forms

The HeartStory website does not receive Apple Health data. If you join the launch list, the website sends the email address you enter, the form type, the page address, and a verification token. If you use the contact form, it sends the name, email address, topic, and message you enter, plus the page address and verification token.

Launch-list information is used to send availability and occasional launch updates. Contact-form information is used to answer your request. Do not include health records, symptoms, or other sensitive health information in either form. You can unsubscribe from launch email using the link in a message or by contacting NanoHits.

07 · Service providers

Limited website infrastructure

The static website may use hosting infrastructure, Cloudflare Turnstile to prevent automated abuse, and an email-delivery provider for form submissions. These providers process limited technical or form information only to deliver and protect the website. NanoHits does not permit them to use HeartStory form information for advertising or to receive Apple Health data.

Apple independently provides Apple Health, HealthKit, StoreKit, device backup, and related platform services under Apple’s privacy policy and your Apple settings.

08 · Your control

Access, deletion, and permissions

You control HeartStory’s Apple Health access in iOS Settings or the Health app. Revoking access stops future reading of the affected data but does not delete information Apple Health retains.

“Delete HeartStory Data” in HeartStory Settings removes HeartStory’s local stores and exports kept inside the app sandbox. It does not change or delete source data in Apple Health. You can also remove the app from your devices and manage device backups through Apple’s settings.

For a question about website form information, an unsubscribe request, or a privacy request, use the secure contact form. NanoHits cannot access or retrieve Apple Health data stored only on your devices.

09 · Children

Not directed to children

HeartStory is not directed to children under 13, and NanoHits does not knowingly collect personal information from children through the website. If you believe a child submitted information to NanoHits, contact us so it can be reviewed and deleted where appropriate.

10 · Changes and contact

Policy revisions

This policy may be updated when HeartStory’s features, legal requirements, or service providers change. The effective date and revision marker at the top of this page will change when the policy is revised. Material changes will be presented through an appropriate product or website notice.

Privacy questions can be sent through the secure contact form.

Operator: NanoHits.