Privacy Policy
Effective July 22, 2026. AllHealth is designed to keep health and profile data on your iPhone.
Data stored on your device
Meals, foods, favorites, workout plans and logs, metabolic profile answers, preferences, AI-scan allowance, and stress-pattern labels are stored locally using iOS file protection. They are excluded from device backups. A random installation identifier and, when enabled, an Apple App Attest key identifier are kept in the iOS Keychain to protect the proxy from abuse. You may export or delete local app data and these stored identifiers in Settings.
Apple Health
With your permission, AllHealth reads steps, heart rate, heart-rate variability, active energy, sleep, and workouts from HealthKit. AllHealth does not write HealthKit data. HealthKit data is used on-device for app displays and is never sent to advertising services, Google Gemini, USDA, or Open Food Facts.
AI meal scans
When you choose a photo or dictate/type a meal description, that input is sent through an AllHealth Cloudflare Worker to Google Gemini to produce a nutrition estimate. The proxy processes the input in memory and does not retain meal photos, descriptions, or Gemini results. Do not scan people, documents, or other sensitive content. AI results may be inaccurate and should be reviewed.
Food lookup
Food search terms may be sent to USDA FoodData Central through the AllHealth proxy and to Open Food Facts. The proxy may cache USDA public food responses, not personal profiles or HealthKit records.
Advertising and consent
Free users may choose to watch a rewarded ad for additional AI scans. Google Mobile Ads and Google’s consent platform may process device, advertising, consent, diagnostic, and approximate-location information under Google’s policies. AllHealth requests contextual/non-personalized ads, does not request App Tracking Transparency permission, and never adds HealthKit, meal, food-log, workout, or profile data to an ad request.
Speech and photos
Speech recognition and photo selection use Apple system services and permissions. AllHealth keeps a selected photo only while preparing and reviewing that scan; it is not saved to the local meal history.
Security and retention
Network traffic uses HTTPS. The proxy validates request sizes, rate limits traffic, enforces an account-wide daily AI request safety budget, and sanitizes upstream errors. The random installation or App Attest identifier is sent to the AllHealth proxy for abuse prevention and quota enforcement; it is not sent in ad requests. Local data remains until you delete it or remove the app. Operational proxy logs contain route, status, timing, and a random request identifier, not request bodies.
Children, changes, and contact
AllHealth is not directed to children under 13. This policy may change with the app; the effective date above will be updated. Questions or deletion requests can be sent to lux.doljanin@gmail.com. Do not send health records by email.