dataWorks
Health Export Pro

Health Export Pro · iOS · macOS

Health Export Pro — Privacy Policy

Effective date: 10 October 2026 · Last updated: 10 October 2026

English · Deutsch

1. Who We Are

Health Export Pro (iPhone app and Mac companion) is developed and operated by:

dataWorks GmbH
Seestrasse 59
8702 Zollikon
Switzerland
Email: support@data-works.ch

We are the data controller for the little processing we do ourselves (Section 3.8). We have not appointed a Data Protection Officer, as we are not required to under Swiss or EU law.

2. The Short Version

  • Health Export Pro has no user accounts and we operate no server that receives your data.
  • Your Apple Health data is read and processed on your device. It leaves your device only when you export it or send it to a destination you set up.
  • The app contains no analytics, crash-reporting, advertising or tracking SDKs.
  • Health data is never used for advertising and never sold or shared with us or anyone else.

The rest of this policy explains this in detail.

3. What Data Is Processed

3.1 Apple Health data (on your device)

With your permission, Health Export Pro reads data from Apple Health (HealthKit): for example activity, body measurements, heart rate, sleep, workouts and their routes, ECG recordings, symptoms, medications, cycle tracking, nutrition and other categories you choose to allow. The app does not write to Apple Health.

The data is used only to display it in the app and to create the exports, automations, widgets and server responses you configure. All of this happens on your device. We have no access to it.

You decide which categories the app may read, and you can change or withdraw that permission at any time in the Health app (Profile → Apps → Health Export Pro) or in your device settings.

3.2 Exports you share

When you create an export (JSON, CSV, Markdown or GPX), the file is created on your device and handed to the destination you pick in the share sheet, such as Files, Mail or another app. What happens to it there is governed by that app or service.

3.3 Automations to destinations you configure

Automations send health data on a schedule to destinations you set up:

  • REST API / webhook: the URL, headers and data you choose
  • Home Assistant: your Home Assistant instance, as sensor states
  • MQTT: the broker you enter
  • iCloud Drive: a folder in your own iCloud Drive (provided by Apple)
  • Calendar: events in a calendar on your device (requires calendar permission)
  • Email: messages sent through the SMTP server you enter

The data travels directly from your device to that destination; it does not pass through us. You decide what is sent and are responsible for the destination you choose; its operator processes the data under its own terms. Credentials you enter (tokens, passwords) are stored in the iOS Keychain on your device.

3.4 Built-in server for AI tools (MCP)

If you start the server, the app answers requests from devices on your local network (for example an AI tool such as Claude or Cursor on your computer) with the health data they ask for. The server only runs while you have turned it on and the app is in the foreground, announces itself on the local network via Bonjour, and can require an access token. It does not connect to the internet and makes no data available to us. Any device that can reach the server and, if enabled, knows the token can read the data it requests; please only run it on networks you trust. What an AI tool does with the data it receives is governed by that tool's provider.

3.5 Sync to Mac and the Mac companion

If you turn on Sync to Mac, the iPhone app writes your exported data as files to your own iCloud Drive. iCloud is provided by Apple under Apple's terms; we have no access to your iCloud account. The Mac companion reads those files and can serve them to AI tools on your Mac or local network over the same kind of server (and via stdio to apps you start on your Mac). It does not send data to us.

3.6 Data stored on your device

The following stays on your device (and, for Sync to Mac, in your iCloud Drive) and is removed when you delete the app or the files:

  • your settings, automations and their activity log,
  • recent values shown in the widgets,
  • export files until you delete them.

3.7 Notifications and background activity

Automation results can be shown as local notifications generated on the device; no push service is involved. Background refresh is used to run automations; iOS decides when it runs.

3.8 Purchases, support and crash reports

  • Purchases are handled by Apple through the App Store. We receive no payment details and no personal data from Apple beyond aggregated sales reports.
  • Support: if you email us, we receive your email address and what you write. Legal basis: our legitimate interest in answering your request (Art. 6(1)(f) GDPR; Art. 31 nDSG). Retention: until the request is settled, at most 24 months. Please don't send us health data you don't want us to see.
  • Crash reports: if you have chosen to share analytics with app developers in your device settings, Apple may provide us with anonymised crash reports. You control this in Settings → Privacy & Security → Analytics & Improvements.

4. What We Don't Do

  • We do not require or offer user accounts.
  • We do not collect, receive or store your health data.
  • We do not use analytics, crash-reporting, advertising or tracking SDKs.
  • We do not use health data for advertising, marketing or data mining, and we do not sell or share it.
  • We do not profile you or make automated decisions about you.
  • We do not operate a user database that could be breached.

5. International Data Transfers

The app itself transfers no data to us. Data goes only to destinations you choose; if those are located outside Switzerland or the EU/EEA (for example an API server or SMTP provider abroad, or Apple's iCloud), the transfer is made at your instruction and under that provider's terms.

6. Your Rights

Under the Swiss Federal Act on Data Protection (nDSG) and, where applicable, the EU GDPR, you have the right to:

  • access the personal data we hold about you,
  • have inaccurate data corrected,
  • have your data deleted,
  • receive your data in a portable format,
  • object to processing based on legitimate interest,
  • withdraw a consent you have given,
  • lodge a complaint with a supervisory authority.

Practical note: unless you have emailed us, we hold no data about you at all, so there is nothing we could look up, export or delete. Health access can be withdrawn at any time in the Health app; deleting the app removes everything it stored on your device.

To exercise your rights, contact us at the address in Section 1. We respond within 30 days.

Supervisory authorities:

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern, https://www.edoeb.admin.ch
  • EU: your national data protection authority

7. Children

Health Export Pro is a tool for people who want to work with their own health data and is not directed at children under 13. We do not knowingly collect personal data from children.

8. Security

Health data never reaches us, so there is no user database on our side that could be compromised. Credentials are stored in the iOS Keychain. Connections to your destinations use TLS where the destination supports it; you can choose unencrypted connections for local services (for example an MQTT broker or Home Assistant on your home network), in which case data on that network is not encrypted. The built-in server is unencrypted HTTP on your local network and can be protected with an access token.

9. Changes to This Policy

We may update this policy when the app's data processing changes. The current version is always available at this address; material changes will be highlighted in the app's release notes.