Privacy Policy
Last updated 12 September 2026. Applies to the Whole Story iOS app and its API.
Operator: Indemni, Inc., 325 S Legend Tree Dr, Liberty Lake, WA 99019, USA. Contact: contact@indemni.io.
This policy is written to be read, not to be survived. Where a section could be shorter and vaguer, it is longer and specific on purpose — health data deserves that.
The short version
We collect your health data so a coach can talk to you about it. It is stored in our own database and sent to Anthropic to generate replies. It is never sold, never used for advertising, and never given to anyone else. You can export all of it or delete all of it from inside the app, at any time, without asking us.
What we collect
Health and fitness data. If you connect Apple Health, we read: steps, active energy, resting heart rate, heart rate variability, body weight, sleep (including stage durations), workouts (type, duration, energy), and period days (menstrual flow, if you track them). We read these only. We never write anything back to Apple Health. Period days are reproductive data — a special category. We read them so a weight change in that week is treated as what it is, not as a stalled cut. We do not use them to guess a next period or anything else.
What you tell the coach. Everything you type: your messages, and the things the coach records from them — meals, drinks, supplements and medications you mention, how you say you feel, your goals, things you commit to doing, and facts it stores to remember you by. Each of these keeps the sentence you said it in, so you can always see where it came from.
Your profile. The name you want to be called, your timezone, and anything you choose to enter about your health history, conditions, medications, or diet — including, if you tell us, whether you are pregnant, postpartum or breastfeeding, which the coach uses only to decide what it should and should not say to you.
Account data. Your email address and authentication details, held by our sign-in provider (Clerk). We do not store your password; we never see it.
Technical data. Request logs containing a request identifier, timing, and error information, used to find and fix faults. These do not contain health data. Crash reports carry your account identifier so we can find yours if you report a problem; they carry no health data and no email address.
What you send when you get in touch. The feedback form in the app keeps your words, the app version, device model and iOS version, and — only if you tick it — the one exchange with the coach you chose to attach, shown to you first. It stays with us; no help-desk service receives it. A person at Whole Story reads it and replies inside the app.
What we never collect
We do not collect your location, contacts, photos, calendar, microphone, camera, or advertising identifier. We do not track you across other apps or websites. There are no third-party advertising or analytics trackers on any screen that shows health data.
Why we hold it, and what we do with it
Intended purpose. Whole Story is a health and wellbeing app. It is not a medical device, it does not practise medicine, and using it does not create a doctor–patient, therapist–patient, or any other clinical relationship.
Solely to run the product for you: to let the coach answer with knowledge of your actual history, to draw your own data back to you on the Home and Health screens, and to notice changes over time.
We do not use your health data for advertising, marketing, or data mining, and we do not sell it. Not to anyone, for any price, ever. This is both our position and a requirement of App Store Guideline 5.1.3.
Who your data reaches
These processors, and no one else:
| Who | What reaches them | Why | Retention |
|---|---|---|---|
| Anthropic (Claude) | Your messages, and the health figures relevant to what you asked | To generate the coach's replies. This is the one place your health data leaves our systems, and it is unavoidable — it is what makes the coach work | 30 days. Not used to train their models |
| Neon (PostgreSQL, hosted on AWS) | Everything described above | It is our database | For as long as you have an account; deleted with the account |
| Railway | Data in transit through our API | It runs our server | In transit and in memory for the request |
| Clerk | Your email and authentication details — no health data | Sign-in | For as long as the account exists |
| RevenueCat | Your App Store subscription status — no health data | To know whether the coach is entitled | While the subscription record exists |
| Sentry | Crash and error diagnostics, tagged with your account identifier — no health data, no email | To find and fix faults | Diagnostics only |
| PostHog | Event names only (for example that a screen was opened) — never a health value | To see whether the product is used | Event names only |
| Resend | Operator mail only (a reply to you) — no health data in the product | To write back when you get in touch | Operator mail only |
About Anthropic specifically. We use the Anthropic API under its commercial terms, which provide that inputs and outputs are not used to train its models. Anthropic deletes your data within 30 days. We do not use consumer Claude, and we do not permit training on your data.
When the coach looks something up. The coach can search the web — for a race, a trail, a gym, a product, or what current guidance on something says — and when it does, the search runs on Anthropic's systems rather than ours. What leaves is the search wording the coach composed and your time zone, so results are for roughly the right part of the world. Your time zone is the only location we hold, and it is coarse by nature: it identifies a region, not a place. Your health data is not sent to any search engine, the coach is instructed not to search for anything about you, and the pages it read are listed at the end of its reply so you can see exactly what it was working from.
We will disclose data to no one else, except where the law compels us — and where we can lawfully tell you, we will.
We do not store your health information in iCloud.
Where it is held
Our database and API run in the United States. If you use Whole Story from elsewhere, your data is transferred to and processed in the US.
How long we keep it
For as long as you have an account. Health data is kept indefinitely by design — a coach whose memory resets every ninety days cannot do the one thing this product exists to do.
When you delete your account, everything is deleted immediately and permanently. Not archived, not soft-deleted, not hidden. It cannot be recovered afterwards, including by us. Backups roll off within 30 days.
Your rights and controls
Built into the app, under You, and usable without contacting anyone:
- Export everything. A complete machine-readable file of every record we hold about you.
- Delete everything. Your account and all data, permanently.
- Correct or delete what the coach remembers. Every stored fact is listed in your own words under What the coach knows, and you can fix or remove any of it.
- Correct anything logged. Anything recorded from a conversation can be edited or retracted.
- Control what the coach discusses. Under How the coach behaves, you can tell it subjects to leave alone.
- Withdraw Apple Health access at any time in iOS Settings → Privacy & Security → Health.
- Stop letting the coach read what you tell it. You → App and account → Let the coach read what you tell it. With it off the coach and the nightly notes stop; Health and Plan still read, and nothing is deleted. A subscription that lapses keeps your data the same way.
Subscriptions
Whole Story is offered as a monthly or annual subscription through the App Store, with a 7-day free trial. You cancel in iOS Settings → Apple ID → Subscriptions. If a subscription lapses, your data is kept; the coach pauses until you start again.
If you are in the UK, EU, or a US state with a privacy statute, you also have rights of access, rectification, erasure, restriction, portability, and objection — and to complain to your data protection authority. Our lawful basis for processing health data, which is a special category under UK and EU GDPR, is your explicit consent, given when you connect Apple Health or tell the coach something. You may withdraw it at any time by deleting your account.
Security
Data is encrypted in transit (TLS) and at rest by our database provider. Access to production is restricted to the operator. Authentication is handled by Clerk; we never hold your password.
We are a very small operation and will not pretend to hold a certification we do not have. No system is perfectly secure. If we discover a breach affecting your data, we will tell you and the relevant regulator without undue delay.
Children
Whole Story is for adults, 18 and over. We do not knowingly collect data from anyone younger. If we learn that we have, we will delete it.
Beta software
Whole Story is currently distributed for testing via TestFlight. It is under active development, may contain defects, and may lose data. Do not rely on it as your only record of anything that matters to you.
Changes
If we change this policy materially, we will tell you in the app before the change takes effect. The date at the top always reflects the current version.
Contact
contact@indemni.io — for any question about your data, or to exercise any right above.
This website
The pages at wholestory.health are a static site. They set no cookies, run no analytics, and load no third-party scripts. Visiting them does not create an account and does not send health data anywhere.