Privacy policy.

Because we deal with your healthcare information, your privacy is incredibly important to us — it has to be. This policy explains how the HealthScout® app handles your health data and other information. By using HealthScout, you agree to the collection and use of information in accordance with this policy. HealthScout is an educational tool only and does not provide medical advice.

Our Privacy Pledge To You

We pledge the following about your privacy.

  • We cannot see any of your health data

  • We never store your health data on our servers

  • We never share your health data with advertisers

  • We never use your health data for marketing purposes

  • We never use your health data for training AI models

  • We don't combine health data with analytics data

You can read about each of these points in more detail below.

Data Collection and Use

We access health data from Apple Health only with your explicit permission. You control which types of health data we can access through iOS Settings. We use this data only to answer your health-related questions and provide insights.

HealthScout transmits the minimal necessary data to third-party AI processors under encrypted, transient ‘compute-and-delete’ rules. No raw Apple Health data is permanently stored on HealthScout-controlled servers.

You can revoke access to your health data at any time through your iOS Settings. We do not store your Apple Health data in the cloud or on any servers. Your data remains encrypted on your device protected by your device's biometric security system. Health data is only used to provide services to you within the app.

No HealthScout employee can see or read your personal health data unless you explicitly use the “Send Logs to HealthScout” feature.  

Cloud Processing and Data Transmission

To answer your questions, we process your health data using the server based AI providers. Data is transmitted securely using industry-standard HTTPS encryption, which ensures your data is protected during transfer.

The data we send includes:

  • Your health-related questions

  • Relevant health data from Apple Health needed to answer your questions

  • No personal identifying information beyond what's necessary to provide the service

HealthScout has selected AI services from Anthropic and Google which do not use queries for model training and do not permanently store your information. All data transmission occurs over encrypted connections.

Chat History and My Added Records Storage

While we never permanently store raw Apple Health data, your chat conversations with HealthScout (which may include health information you choose to discuss) and your My Added Records entries can be stored locally on your device or in iCloud (Apple's secure cloud storage service) if you enable it. This allows you to delete and reinstall HealthScout and maintain your conversation history. This storage is:

  • Secured by your device’s biometrics (Touch ID or Face ID)

  • Optionally, you can require a second biometric confirmation each time you open HealthScout, even if your device is already unlocked

  • Completely under your control

  • Can be deleted at any time

  • Is encrypted at rest on your device with Apple's strongest file protection (Data Protection "Complete"), so it can't be read while your device is locked

  • Is optionally stored in your personal iCloud with Apple's standard iCloud encryption (end-to-end encrypted if you enable Advanced Data Protection)

  • Is separate from the Apple Health data itself

  • Only includes information you explicitly shared

You can choose to:

  • Keep chat history and My Added Records only on your device

  • Sync chat history and My Added Records through iCloud

  • Delete chat history and My Added Records at any time

Family Health History

Family Health History works differently from the rest of HealthScout, and it changes some of the promises above. Please read this section before you invite family members or accept an invitation.

What it is. Family Health History lets you build a shared record of your family's medical history, so that you and the relatives you invite can see conditions, ages, and dates across your family. The feature only works if that information is shared with the people you invite, so some of the pledges above about your health data staying private to you don't apply once you share it with your family.

No account, email or phone number required. Family Health History does not require a login, an email address, or a phone number. Like the rest of HealthScout, your device is identified only by an anonymous, randomly generated ID. When you join a family, you identify yourself by selecting your own name from the family member list, there's no email or phone lookup anywhere in the feature.

Health content stays off our servers, but it is shared with the people you invite. Conditions, diagnoses, ages, and cause-of-death information you enter are stored in a shared iCloud space (Apple CloudKit), the same technology behind chat history storage, but writable by everyone you've added to your family, not just you. HealthScout cannot read this content. The relatives you invite can, once they join.

We collect birth year only, never a full date of birth, and ages at onset are recorded by decade (for example, "40s") rather than an exact age. The health details you enter, conditions, diagnoses, ages, and cause of death, are encrypted using Apple CloudKit's encrypted fields, so that only the devices of the people you've invited hold the keys, not Apple. Even Apple cannot read those details, including in response to a legal request. The structure of your family tree (who is related to whom) and your family's name are not encrypted this way.

Invitations are stored temporarily on our servers. When you invite someone to your family, we store the invited person's name, your family's name, and the private link needed to deliver the invitation, so the invite can be sent and so we can let you know when it's accepted. This record does not include any health content and is never linked to an account, email address or phone number. Every invitation record is automatically deleted from our servers within 24 hours of its 30-day expiration, whether or not it was ever accepted.

You may be entering information about people who aren't HealthScout users. Family Health History lets you add a profile for a relative, living or deceased, who has never opened the app, and sending an invitation stores that person's name before they've agreed to anything. Only add people you have a right to speak for, and consider whether they'd be comfortable with the details you include about them.

Sharing is by link, and it's broad by design. Your family's invite link can be forwarded and joined instantly, without approval from you. We built it this way so a family tree is easy to grow. To keep that safe: every new join is visible to your family, and you can see everyone who has access at any time. Any family member can remove an individual participant at any time without affecting anyone else. The Admin can also generate a new sharing link, which immediately invalidates every outstanding invitation and requires everyone, including family members who already joined, to rejoin using the new link.

Minors. A parent or guardian may add a profile for a minor child. Like anyone else's profile in your family, a minor's health information is visible to the other participants you've invited. This is different from how children's data works elsewhere in HealthScout, where it stays contained to the parent's own account (see Children's Data, below).

AI answers. If you use Family Health History, HealthScout may include a summary of your blood relatives' conditions when answering your health questions, to help surface hereditary patterns. This summary never includes names. If you'd rather HealthScout not use this context, don't use Family Health History.

Deleting your information. You can delete your own profile and its conditions at any time, or leave your family. Health content in the shared iCloud space is controlled by your family's Admin. Pending invitations are deleted from our servers automatically within 24 hours of their 30-day expiration. Your family's Admin can also generate a new sharing link at any time, which immediately invalidates every outstanding invitation.

Data Retention and Deletion

HealthScout does not store your health records on servers or in the cloud. Your questions and related health data are only temporarily processed to provide answers. Since we don't store your data on our servers, there is nothing to delete from our systems.

This describes HealthScout outside of Family Health History invitations. When you invite someone to your family, we temporarily store the invited person's name and the link needed to deliver the invitation, see Family Health History, above, for what we store and how long we keep it.

You can clear your app data at any time through your iOS Settings. The AI APIs process data transiently and do not maintain persistent storage of your health information.

Emergency Situations 

In cases where your questions indicate a potential medical emergency, our system may automatically provide emergency contact information and urgent care resources. Automated, on-device keyword detection may flag crisis terms solely to surface emergency resources; no human review occurs unless you use the “Send Logs to HealthScout” feature.

Children's Data

You must either be 18 years of age or older or be a parent/legal guardian acting on behalf of a minor to use HealthScout. We do not knowingly collect personal information directly from children under the age of 13.

We recognize that parents or legal guardians may use HealthScout to manage their children's health information. In such cases:

  • Only parents or legal guardians should input or access children's health information through their own account

  • Parents are responsible for ensuring appropriate permissions when sharing their children's health data

  • All children's health data processed through the app receives the same privacy protections as adult data

  • Parents can control all aspects of children's data access through iOS Settings

If we learn that we have collected personal information from a child under age 13 without parental consent, we will take steps to delete that information as quickly as possible. If you believe we might have any information directly from a child under 13, please contact us at privacy@healthscout.co.

Family Health History works differently: a child's profile there can be seen by the other family members you've invited. See Family Health History, above.

Responsible Privacy Officer

Joe Sipher, founder of HealthScout, serves as the designated executive responsible for HealthScout's privacy commitments and compliance with this policy.

Data Deletion Requests

Because of how HealthScout is designed, we do not maintain user accounts or email addresses anywhere in the app, including Family Health History. We do temporarily store a small amount of information on our servers when you send a Family Health History invitation, see below. Outside of that, we have no way to look up, access, or identify your data on our systems. This means:

  • Your health data from Apple Health is stored only on your device and is never sent to or stored on our servers.

  • Your chat history and added health records are stored on your device and in your personal iCloud account via Apple's CloudKit service, which only you control.

  • AI queries are processed transiently by our AI providers and are not permanently stored.

If you contact us at privacy@healthscout.co requesting data deletion, we will confirm that we do not possess any of your personal or health data outside Family Health History invitations, and provide instructions for how to delete your data yourself:

  • Chat history and added records: Use "Delete Chat History" in the HealthScout Options menu, or delete the app and its associated iCloud data through your device settings.

  • Apple Health permissions: Revoke HealthScout's access through the Apple Health app or iOS Settings.

  • App data: Deleting the HealthScout app removes all locally stored data from your device.

  • Family Health History content: Conditions, diagnoses, ages, and cause of death are never sent to or stored on HealthScout's servers, encrypted or otherwise. This content lives only in your family's shared iCloud space, with encryption keys held on your family's devices, not by Apple and not by us.

  • Family Health History invitations: We temporarily store the invited person's name, your family's name, the private share link, and a notification token, on our servers, so the invitation can be delivered and so we can alert you when it's accepted. This is never linked to an email address or phone number, and never includes health content. Every invitation is automatically deleted from our servers within 24 hours of its 30-day expiration. Your family's Admin can also generate a new sharing link at any time, which immediately invalidates every outstanding invitation.

Analytics and Performance Data

We collect basic app usage data to improve our service, including:

  • App performance metrics

  • Feature usage statistics

  • Crash reports

  • Coarse location (city-level) inferred by Firebase; no IP addresses are retained or exposed to us.

This analytics data is:

  • Completely separate from your health data

  • Never connected to your personal information

  • Used only to improve app functionality

  • Collected and processed through Firebase Analytics with appropriate privacy safeguards

  • This is separate from the invitation information described in Family Health History, above. That information is used only to deliver invitations, never for analytics.

Dormant Use

HealthScout does not require user accounts or logins. There is no concept of an active or dormant account. If you stop using HealthScout, your data remains on your device and in your personal iCloud account until you choose to delete it. We do not take any action on unused installations. Subscriptions are managed entirely through Apple and are subject to Apple's terms and renewal policies.

Transfer of Ownership

In the event that HealthScout or Doodle Buddy Labs LLC is acquired, merges with another company, or ceases operations, your personal health data would not be affected because we do not store it on our servers. Anonymous analytics data and operational logs maintained through Firebase and Google Cloud services would transfer to any successor entity, but this data contains no personal health information and cannot be linked to individual users. Family Health History invitation records (an invited person's name and the invite link) are personal information, not anonymous analytics, and would be handled the same as any other personal information described in this policy, subject to applicable law, in the event of a transfer. In the event of such a transfer, we will notify you through the app. Any successor entity will be required to honor this privacy policy unless you affirmatively consent to different terms. If you do not wish to continue under new ownership, you can delete your local data at any time: use "Delete Chat History" in the HealthScout Options menu, revoke Apple Health permissions through the Apple Health app or iOS Settings, and remove the app from your device.

Third-Party Service Commitments

HealthScout uses AI services from Google (Gemini) and Anthropic (Claude) to process your health questions. These services operate under their standard API terms of service, which prohibit the use of your queries for model training and do not permanently store your information. We select AI providers whose terms are consistent with our privacy commitments to you. We also use Google Firebase for anonymous analytics, and Apple CloudKit for optional cloud storage of your conversations and, for Family Health History, shared family health content.

If you use Family Health History, we additionally use Google Firestore (temporarily storing invitation information described in Family Health History, above), Firebase Cloud Messaging (a notification token from the inviter's device, so we can alert them when an invite is accepted), and Cloudflare (backend infrastructure that supports invitations). We do not use Sign in with Apple or any other account system for Family Health History; your device is identified only by the same anonymous ID HealthScout already uses elsewhere. None of these services receive health content.

All of these services operate under their respective terms of service with privacy protections appropriate for the data they handle.

State Specific Privacy Rights

California Residents

As a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) to:

  • Request details about personal information we collect and how we use it

  • Request deletion of your information

  • Be informed that analytics data is collected anonymously and cannot be linked to you or your health information

  • Exercise these rights without discrimination

Exercising Your Rights

To exercise your privacy rights, use the in-app settings to control data collection and delete your data, or email privacy@healthscout.co for specific requests. We will respond within 45 days at no charge for reasonable requests. Because HealthScout does not maintain user accounts or server-side personal data outside Family Health History invitations, most privacy actions -- including data deletion -- can be completed immediately by you through the app or your device settings without needing to contact us.

For Family Health History, pending invitations are automatically deleted from our servers within 24 hours of their 30-day expiration. Your family's Admin can also generate a new sharing link at any time, which immediately invalidates every outstanding invitation.

Other States

Residents of Virginia, Colorado, and other states may have similar rights under their state laws. We honor these rights regardless of your location in the US.

Your Rights

You have the rights to do the following:

  • View what health data types we access in iOS Settings

  • Revoke access to any or all health data types at any time

  • Request information about how your data is used

  • Control app permissions through iOS Settings

  • Delete all app data from your device

Security Measures

All data transmission is encrypted using industry standards. We use Apple's security frameworks and best practices. We maintain industry-standard security practices. We process only the minimum health data necessary.

By enabling Face ID or Touch ID within HealthScout, you provide express consent for us to use those biometrics to lock and unlock chat history, and, if you turn on the optional app-reopen confirmation, to confirm it's you each time you open the app. Biometric matching happens on your device through Apple's system; HealthScout receives only a yes or no result, never your actual fingerprint or face data. We never store biometric templates.

Changes to This Policy

We may update this privacy policy from time to time. For material changes -- meaning changes that affect how your data is used in ways you would not reasonably expect -- we will release an app update that presents a summary of those changes and requires you to acknowledge them before continuing to use HealthScout.

If you do not wish to accept an updated policy, you can delete your chat history and My Added Records through the HealthScout Options menu, revoke Apple Health permissions through iOS Settings, and remove the app. You can review previous versions of this policy by contacting us at privacy@healthscout.co.

Contact Information

For any questions about this privacy policy or our data practices, please contact us at:

privacy@healthscout.co

HealthScout®, a service of Doodle Buddy Labs LLC.

_______________________

Last Updated: August 9, 2026