Start here
Privacy
What leaves your device, when, and where.
Nothing leaves by default#
Apple Health exports go only to destinations you add and confirm. There is no hosted relay or default destination.
- Each destination receives only its selected Health types and runs at its chosen cadence.
- Connection tests contain a fixed probe, not Health data.
- Mac discovery uses Bonjour and local-subnet probes. It stays on your network.
- No analytics, ads, update checks, feature flags or remote crash reports make requests.
Credentials stay on device#
On Apple devices, destination tokens, API keys and MQTT passwords use the Keychain setting kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly. They do not sync or enter backups.
The Mac pairing token is the exception: kSecAttrSynchronizable shares it through your iCloud Keychain, inside an access group only Hozz apps can use. Without shared iCloud Keychain, pairing happens over the local network.
Storage#
The iPhone/iPad app stores cursors, coverage, destination settings, receipts and staged batches—not a permanent Health mirror. Its database uses completeUnlessOpen file protection and is excluded from backups.
The Mac receiver keeps a durable SQLite copy and excludes it from backups. macOS has no matching per-file protection class, so enable FileVault to protect it at rest.
Logs omit data and secrets#
Apple unified logs contain status and failure descriptions, never sample values, credentials or destination secrets. The Mac may log its own local addresses during pairing. Rejected response bodies are discarded because they may echo a Health record.
Apple Health access is read-only#
On iPhone/iPad, Hozz requests read access when you first export or sync. It never requests Apple Health write access. Why not.
Android opens Hozz NDJSON/ZIP archives, not Apple Health. Archive-only mode preserves all types. Experimental Health Connect writes require explicit opt-in and Android 14+; there is no Google Play policy approval. Android limits.
Control ends at your destination#
- Public endpoints should use TLS and authentication.
- A cloud assistant may upload readings it requests through MCP.
- A synced folder follows that provider's rules.
This website#
Static files on Cloudflare Workers. No cookies, analytics, storage or third-party resources. Cloudflare keeps host logs under its policy; external links use the destination site's policy.