Legal
HealthTimeline — Privacy Policy
HealthTimeline — Privacy Policy
Last updated: 30 July 2026
HealthTimeline ("the app", "we", "our") is developed by ByteNine AS. In short: your health records are stored on your device and synced only through your own private iCloud. We run no server that stores your health data, and the app contains no ads, no tracking and no analytics. Health information leaves your device only when you deliberately use an AI feature, and what is sent then is described in full in section 4.
1. Who is responsible
ByteNine AS is the data controller for the limited processing described below. Contact: support@bytenine.com or bytenine.com/contact.
2. What the app stores, and where
Everything you enter lives in a database on your device (Apple's SwiftData) and, if you have iCloud enabled, syncs through your own private iCloud account using Apple's CloudKit. It is your iCloud storage and your Apple Account — ByteNine cannot read it, list it or recover it.
Stored on your device / in your iCloud:
- Profiles for you and any family members you add — name, birth date, sex, height, weight, country, known conditions, smoking and diabetes status, blood pressure, family history and your free-text "About you" note
- Timeline events: symptoms, appointments, medications, notes, milestones, follow-ups
- Health tracks, goals and self-experiments
- Daily intake items — medications, supplements and vitamins with doses and times
- Imported lab reports, including the original PDF or photo, extracted values and reference ranges
- Vaccine records, including scanned vaccine cards
- Data imported from Apple Health, if you connect a track to it
- AI answers you choose to save, and your AI chat history
- App settings and preferences
Lab data is stored in a separate, dedicated iCloud container (iCloud.com.bytenine.health.labs) so it can be shared with our companion app Lab Results with AI Insights if you use both. That container is also in your own iCloud, not ours. All other data uses the container iCloud.com.bytenine.healthtimeline.
There is no HealthTimeline account, and no sign-in is required to use the app for tracking. You only sign in for the AI chat (section 5).
3. Apple Health
If you connect a health track to Apple Health, the app reads the data types you approve — such as resting heart rate, heart rate, heart-rate variability, sleep, weight, steps, active energy, respiratory rate and workouts. You choose which types, per track, and you can disconnect at any time.
The app only reads from Apple Health. It never writes anything back, and Apple Health data is never sent to us. It is copied into your own on-device database so it can be charted next to the rest of your history.
4. AI features — what is sent, and to whom
AI features are optional. Nothing is sent to any AI provider unless you actively start a chat, request a lab analysis, scan a document or generate a doctor summary.
Be aware that AI requests are not anonymous. To give useful answers, the app sends the relevant context from the selected profile, which can include:
- Your first name, age, sex, height, weight and country
- Known conditions, smoking and diabetes status, blood pressure and family history
- Your free-text "About you" note
- Timeline events, health tracks, experiments, medications and supplements
- Lab values with units and reference ranges
- Vaccine records
- Photos you attach yourself — for example a lab printout, a vaccine card or a supplement label
Requests are routed through our own servers to the AI provider you have selected (OpenAI or Anthropic), so that no provider API key ever ships inside the app. Two paths exist:
- AI chat goes through our Firebase Cloud Functions proxy. It logs only technical metadata — which model was used, how many messages the request contained and the payload size in bytes. Message content is not logged.
- Lab insights, document scanning and doctor summaries go through the ByteNine AI gateway at bytenine.com. It records only accounting data per call: app, provider, model, tier, token counts, computed cost, status and a hashed installation identifier and IP address. Prompt and response content is not stored.
We do not use your health data to train models, and we do not sell or share it for advertising. The AI providers process the request under their own terms:
- Anthropic: anthropic.com/privacy
- OpenAI: openai.com/privacy
You choose the provider in Settings.
5. Sign in with Apple
The AI chat requires you to sign in with Apple, which lets us prevent abuse of the service. This creates an account with Firebase Authentication (Google) holding a user identifier and whatever Apple chooses to share — your email address, or a private relay address if you hide it. Apple decides what we receive; we never see your Apple Account password.
This sign-in gives access to the chat only. It does not upload your health records anywhere.
6. Crash reports
The app includes Firebase Crashlytics (Google), which sends us a diagnostic report if the app crashes: device model, operating-system version, app version and the technical stack trace. These reports help us fix bugs. They are not used to identify you and contain none of your health records.
7. Feedback and bug reports
If you send feedback from inside the app or from the app's page on bytenine.com, we store what you submit on our servers: the type of report, title, message text, app version, device model, your email address if you are signed in, and a hashed IP address for abuse prevention. Feature requests and bug reports may be shown publicly on the app's page so others can vote on them — your email address is never shown. Ask us and we will remove a submission.
8. Purchases
Subscriptions and AI credit packs are sold through Apple's App Store using StoreKit. Apple handles the payment — card details and billing information never reach ByteNine. We only see whether an entitlement is active on the device.
9. Privacy features in the app
- Private tracks: mark any track private and it hides its own name in lists, unlocking only with Face ID, Touch ID or your device passcode
- Hidden tracks: keep a track out of lists entirely
- Per-profile separation: each family member's data is kept separate, and the AI only receives the profile you have selected
- Doctor PDFs: exports contain exactly the tracks and time range you pick, and nothing is shared until you send it
10. Children
The app lets an adult track a child's health as a family profile. That data is entered and controlled by you, the adult, and is stored under your own iCloud account. The app is not intended for children to use on their own.
11. Security
- Data on the device is protected by iOS encryption and your device passcode, Face ID or Touch ID
- iCloud sync is encrypted in transit and at rest by Apple
- All network traffic uses HTTPS
- Provider API keys are held on our servers and are never embedded in the app
No system is perfectly secure, but we deliberately hold as little of your data as possible — the strongest protection is that your health records are not on our servers at all.
12. Your rights
Because your health records stay on your device and in your own iCloud, you already have direct access to all of it, and you can change or delete any of it in the app at any time. Deleting a profile removes its tracks, events, intake items, labs, experiments and chat history. Deleting the app and its iCloud data removes everything.
For the limited data we do hold — your sign-in identity, crash reports, feedback submissions and AI accounting records — you have the right under the GDPR to request access, correction, deletion, restriction of processing, data portability, and to object to processing. Write to support@bytenine.com and we will respond within 30 days. You may also complain to the Norwegian Data Protection Authority (Datatilsynet).
13. Data retention
- Health records: kept until you delete them; we never hold them
- Sign-in identity: kept while your account exists; deleted on request
- Crash reports: retained by Firebase Crashlytics for up to 90 days
- Feedback submissions: kept until resolved and then on request
- AI accounting records: token counts and costs kept for billing and abuse prevention; they contain no health information
14. International transfers
Our servers run in the European Union (Microsoft Azure, West Europe). Firebase Authentication, Cloud Functions and Crashlytics are operated by Google, and the AI providers you select are based in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses.
15. Not medical advice
HealthTimeline organizes information and AI can help you interpret it, but the app does not diagnose, prescribe or replace professional healthcare. Always consult a qualified clinician about medical decisions.
16. Changes to this policy
We will update this page when the app's data handling changes, and revise the date at the top. Significant changes will be announced in the app.
17. Contact
ByteNine AS support@bytenine.com bytenine.com/contact