Consumer Health Data Privacy Policy
Human Memory for iPhone. This page took effect on 10 September 2026; its claims were last verified against the app's own source on 6 September 2026, for version 1.0.
Published by Allison Bowman, an individual developer in the United States — the same name the App Store carries as this app's seller. Questions, or a request under this page: support@human-memory.ai.
Washington's My Health My Data Act asks a company that handles consumer health data to say so on a page of its own, reached by its own link, carrying only what that law asks for. This is that page. Everything on it is also true on the main privacy policy, which is longer and covers the rest of the app; nothing is disclosed here that is hidden there.
Why this page exists at all, said plainly. The Act defines "collect" as "to buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process" — words that reach reading a workout onto your own phone, with no transmission anywhere. Whether Washington intended that for an app that keeps everything on the device is genuinely unsettled, and nobody has ruled on it. We would rather write the page than win the argument. Treat this as us assuming the law applies, not as us conceding a fact about what the app sends.
What we treat as health data here
Four things in this app can amount to consumer health data. The list below is derived from the code's own set of sources rather than from memory, because this page counted to three for a while and the fourth was the one it forgot.
- Workouts read from Apple Health, with your permission: the activity, its duration, its distance, when it started and ended, and its route where the workout carries one. The live Health connection reads nothing else — not heart rate, not sleep, not body measurements, not clinical records — because the app asks the system for two things only, workouts and workout routes, and asks for no permission to write anything back. An Apple Health export file you import yourself is a separate path and does carry more; it is the fourth item below.
- Recorded visits, if you turn on background location, which is off until you do. These are arrivals and departures at places you stop, and one of those places can be a doctor's office. The app does not know which is which, and does not try to work it out — but a stop is a stop, and a stop at a clinic is health data whether or not anything labelled it.
- Health information you put there yourself, in your own words: a journal entry about an appointment, a photo taken in a waiting room, a calendar event with a procedure in its title, a message about a diagnosis inside an archive you imported. The app does not classify any of this as health data. It sits in your vault as whatever you wrote, and it is covered here because the law looks at what the information is, not at what a database column calls it.
- An Apple Health export file you import yourself. This is a separate path from the live Health connection above, and it carries more: heart rate, resting heart rate, heart rate variability, steps, active energy, sleep, State of Mind logs and medication doses. It is read from a file you already hold, on this device; the app never signs in to Apple Health to fetch it. One gap is open in this build: importing such a file while Vault → iCloud Backup is already on is not refused, so those rows can enter a vault that is being backed up. The refusal is written and tested and ships in a coming build; until then, turn iCloud Backup off before importing a Health export.
Why we collect it, and what it is used for
One purpose, and it is the whole app: to place these things on your own timeline and your own map, next to the photos and events from the same day, so that your history is legible to you. A workout is there to make a bare date into "4.2 km hike". A visit is there so a day on the map has a shape.
It is not used to profile you, score you, rate you, advertise to you, or judge you, and it is not used to train a model. There is no analytics SDK in this app, no crash reporter and no telemetry of any kind, so there is also no by-product of your use that we could put to a second purpose later.
Where it comes from
- You, directly — your journal, your corrections, the names and relationships you give people.
- Apple Health on this iPhone, after you grant the Health permission, and only workouts and their routes.
- Your iPhone's own visit monitoring, if you turn background location on.
- Your Contacts and your Calendar, if you connect them, which can carry an appointment's title.
- Archives you request from other services yourself — Meta, Google, Tinder, Hinge, and an Apple Health export — and import from a file you already hold. The app never signs in to any of those services and never fetches anything from them.
- Your photo library, including the dates and locations your camera recorded.
Every one of those is a permission you grant and can take back, and none of them is required: the app runs with all of them off.
What is shared, and with whom
Two recipients we choose, both named and both narrow — and a third that is whoever you choose, on the one occasion you can choose one. None of them is a data broker, and none of them pays us anything.
Anthropic — only when you send a message, and only after you agree
The Interview sends your question, and compact results looked up from your vault, to Anthropic's Claude. A workout can be in those results. What crosses is the one line the app composed when it read the workout — "4.2 km hike", "42 min yoga", or the bare activity name where there is neither distance nor duration — plus that record's coordinate rounded to about 1.1 km, if it has one. A recorded visit can cross the same way, coordinate rounded the same way.
This happens only while an Interview session you started is open. There is no scheduled task, no prefetch and no timer in this app that reaches Anthropic. A consent screen naming Anthropic comes before the first send, and Vault → Sending queries to Anthropic takes that consent back and re-arms the screen.
Apple — for the map, and not for your health data
Health data itself is not sent to Apple. Reading Health happens on this device, and recorded visits are never reverse-geocoded, so a stop's coordinate is not sent anywhere to be turned into a name. Photos and videos are geocoded, at a coordinate rounded to roughly 110 metres, and the Atlas draws a real Apple map of whatever region you are looking at. Neither of those carries a workout.
Whoever you publish a calendar to — and this is the one that can carry a workout
Vault → Review & Publish to Calendar writes a copy of your memories into a calendar the app creates. Put that calendar in an account that syncs — iCloud, Exchange, Google, a work account — and its entries reach that account's provider, whoever it turns out to be. This page names it rather than leaving it to the main policy because an entry can carry a workout: where the app has composed the line that describes a day, the workout's one-line summary sits inside it — "Wrightsville Beach · 4.2 km hike · 27 photos" — and that line is published as the entry's title, or as the first line of its notes. So this is the one road by which something health-related can reach a company we never named, for the good reason that you are the one who names it.
It is not silent, and it is not automatic. The app works out before you tap whether that calendar will sync, names the account, and makes you acknowledge it; nothing is published until you do. The main policy's item 7 lists exactly what a published entry carries. If you would rather no workout took that road, publish into a calendar that lives on this iPhone alone, or remove the workouts first.
What is not shared
We do not sell consumer health data, and there is no arrangement under which we could: no advertising, no data broker, no affiliate, no analytics vendor, no research partner. Nothing reaches a recipient you did not either instruct or pick yourself — the three above are the whole list, and each of them waits on something you do. If a legal demand ever arrives, the answer will be the one this whole page keeps giving: the data is on your phone and is not in our hands.
Your rights, and the button that is each one
Washington gives you the right to confirm whether we collect, share or sell your consumer health data and to see it; the right to withdraw your consent; and the right to have it deleted. Because all of it is on your device, each of those is something you do rather than something you ask us for.
| The right | How to use it |
|---|---|
| Confirm and access, including the list of third parties | Vault → Export → Export My Vault writes the whole vault as Markdown and JSON you can read anywhere. The list of third parties is the section above this one, in full — there is no longer version of it. |
| Withdraw consent to collection | Health: Settings → Privacy & Security → Health → Human Memory on your iPhone, which stops any further reading. Location: Sources in the app stops visit recording immediately. |
| Withdraw consent to sharing | Vault → Sending queries to Anthropic. Nothing further is sent until you agree again. |
| Delete | Vault → Erase Everything empties every user table in one transaction and gives you a receipt with counts. Narrower: Remove Imported Workouts in Sources deletes the workouts, Delete All Recorded Visits deletes the visits, and Vault → Chat history deletes conversations. |
Two things those buttons cannot do, and we would rather you knew before you pressed one. Deleting here does not un-send anything an Interview already sent to Anthropic — what was sent is held under Anthropic's own retention terms, not ours. And where you have published a calendar into an account that syncs, deleting inside this app does not reach into that account; delete the published calendar there too.
There is no account, so there is no request process and nothing for us to verify. That is not a dodge, it is the consequence: we could not look up your health data if you asked us to, because we do not have a copy of it. If something the app's own controls do not cover, write to support@human-memory.ai and say what you need.
If we ever say no
If we decline to act on a request under this page, we will say so within 45 days of receiving it, in writing, with the reason — and you can appeal simply by replying to that message. We will answer an appeal within 45 days too and, if we still decline, we will say how to complain to the Washington State Attorney General's Office, whose consumer-complaint form is at atg.wa.gov/file-complaint. We have set no other hurdle in front of any of this: no form, no account, no verification step.
The Act lets us take one 45-day extension where it is reasonably necessary, and we would rather tell you that here than produce it as a surprise on day 44. If we ever need it, you will hear why before the first 45 days are up — and given that we hold no copy of your data to go looking through, it is hard to imagine what would require one.
How long it is kept
For as long as you keep the app installed, or until you delete it yourself. There is no retention clock in this app: nothing expires, nothing is swept, and no health record is aged out behind your back. What you send to Anthropic is held under Anthropic's terms rather than ours.
Changes to this page
If what the app does with health data changes, this page changes with it, in the same release, and the date at the top moves. We reread it against the app's own source at least once a year.