App Privacy Policy

For the iOS app “Export Health Data” · Effective: 16 September 2026 · The website has its own privacy policy

In short

This app collects no data about you. Your health data stays on your iPhone and leaves it only to destinations you set up yourself. We operate no servers, there is no account, and there is no usage tracking.

Controller

healthspan GmbH, Gonzagagasse 11/25, 1010 Vienna, Austria. Contact: contact@healthspan.eu · healthspan.at

No data collection on our side

The app contains no libraries for analytics, advertising, or usage tracking and sends no data to the developer. Its App Store privacy label reads “Data Not Collected” accordingly.

Apple Health data

The app reads health data only after your approval in the iOS permission sheet, and only locally on your device. The sole purpose of processing is the export you trigger (file) or the delivery you configure. For privacy reasons, iOS does not reveal to apps which read permissions exist; you can change them at any time under Settings → Privacy & Security → Health → Export Health Data.

Transfers to destinations you choose

If you add a destination (e.g. a web address), the app sends health data there. Twelve values of the most recent days are transferred automatically: sleep, heart rate, resting heart rate, heart rate variability, steps, VO₂max, weight, body fat percentage, lean body mass, respiratory rate, oxygen saturation and sleeping wrist temperature — each with the technical identifier of the app that stored the value in Apple Health; for sleep additionally the display name of the source, which on Apple devices may contain a device name you chose. Recipient and purpose are yours alone; from receipt on, the destination operator’s privacy practice applies. The app accepts https:// addresses only. If your address answers with a redirect, the app sends nothing to the new address and stops. Files from the “Export” tab are never sent by the app; you share them yourself.

Access keys

Keys you store (for example, API headers) are kept in the iOS Keychain, not in the app’s database. Deleting a destination in the app also removes its key. Keychain items can outlive an uninstall and are included in an encrypted device backup.

Log & notifications

The delivery log (timestamps, status, destination name — no health values) lives locally on your device. Notifications (for example, when a destination has stopped receiving data) are generated locally; there are no push servers.

Deletion

All app data is local. Deleting the app removes the database and the log — and with them your values, destinations, and delivery history. An access key stored in the iOS Keychain can outlive the uninstall; delete the destination in the app first and its key goes with it. Data already sent to your destinations is deleted with the respective operator.

Your rights

You have the rights under Articles 15–21 GDPR (access, rectification, erasure, restriction, data portability, objection). Since we neither process nor store personal data, these rights in practice concern the local data on your device and the operators of your destinations. Complaints: Austrian Data Protection Authority (dsb.gv.at).

Changes

This policy is updated when functionality changes; the current version is available in the app.

← Back to the start page