Health Index

Legal

Privacy policy

The short version: what you log stays on your device. The long version is below, and it's also fairly short, because there genuinely isn't much to describe.

Last updated: 27 August 2026

1. Who's responsible

Health Index is run by an independent solo developer. There's no company, no team, and no third party with access to any of this. To reach us about anything in this policy — including a request to access or delete your data — use the free-text box on the invite form. We deliberately don't publish an email address on this site, because an unattended public address is a spam magnet.

2. The important part: your entries never reach us

The app requires no account and has no user database. Everything you log — entries, labels, scores, tags, tracked items, targets, badges, your history — is stored in your own browser's local storage on your own device. It is read from there and written to there. As the app stands today, there is no server for it to sync to.

This is structural rather than a policy choice: the app ships as a static export with no backend for user data, which is also why it works offline.

3. What we do hold, in full

Three things. This is the complete list.

a. Your email address, if you request an invite

  • What: the email you type, plus any free text you add.
  • Why: to send you an invite and, if you asked something, to reply. Lawful basis: your explicit request (steps taken at your request prior to entering an agreement).
  • How long: until the beta closes or you ask us to remove it, whichever is first.

b. Feedback you send from inside the app

  • What: the text you wrote, its category, and — if you're signed in to the beta — the anonymous account identifier it came from.
  • Why: to fix what you reported. Lawful basis: consent.
  • Note: this is the only free-form text you write that is stored on a server, and the app says so at the point you submit it. It's readable only with an administrative credential. Please don't put anything sensitive in it — a bug report doesn't need your medical history.

c. Anonymous usage statistics

  • Your choice, and reversible. The app asks you about this when you first open it, and Settings keeps the same switch — so you can turn it off at any point, and nothing further is sent once you do.
  • What: bucketed counts and coarse distributions — how many entries fall in a range, which badge tiers have been reached, roughly what score bands look like. Plus the app version.
  • What it cannot contain: your labels, tags, notes or individual entries. The app never assembles them into the payload in the first place, so this isn't a filter that could be misconfigured — there's nothing to filter.
  • Identifier: a random value generated on your device, unrelated to your email or account, and deliberately not linkable to them.
  • Why: to tune the scoring and badge thresholds against reality rather than guesswork. Lawful basis: consent.

4. This website

This site uses Vercel Web Analytics, which is cookieless and records aggregate page views without building a profile of you. There are no advertising cookies, no cross-site tracking, no social embeds and no third-party fonts — everything is served from this domain. That's why you weren't asked to accept anything: there is nothing to consent to.

The invite form is protected by Cloudflare Turnstile, which performs a bot check in your browser. Cloudflare receives the technical signals needed for that check.

5. Who processes data on our behalf

  • Vercel — website and server hosting, plus cookieless analytics.
  • Neon — the Postgres database holding items (a) and (b) above. Hosted in the United States.
  • Resend — sending invite and acknowledgement emails.
  • Cloudflare — Turnstile bot verification on the invite form.

Some of these process data in the United States, so where you're in the UK or EEA your information may be transferred there under the providers' standard contractual safeguards. We don't sell data, share it for advertising, or pass it to anyone outside this list.

6. Your rights

You can ask what we hold about you, ask for it to be corrected or deleted, and withdraw consent at any time. Contact us through the invite form and we'll action it.

One honest caveat about deletion. We can delete your invite request and your feedback, because those are tied to identifiers we can look up. We cannot pick your anonymous usage statistics out of the pile — the identifier attached to them is deliberately not linkable to you, which is precisely what makes them anonymous. That's a design decision that protects you, and the trade-off is that it can't be reversed on request. If that bothers you, the answer is to leave the setting off, or to turn it off, which stops any further data being sent.

If you're in the UK or EEA and you think we've handled your data badly, you can complain to your national data protection authority.

7. Minimum age

You must be at least 13 to use Health Index — or at least 16 if you're in the European Economic Area, where the age of consent for this kind of processing is higher.

8. Security

Invite tokens are stored hashed, never in plain text. Administrative access is credential-guarded and separate from anything the app can reach. The honest framing: the reason a breach here would be limited isn't the strength of our defences, it's that we deliberately don't hold much — your entries aren't on our server to lose.

9. Changes

If this policy changes in a way that affects what we collect or why, we'll update the date at the top and — for anything material — tell beta users directly rather than quietly editing the page.