PryvaRecord
Privacy policy
Effective 8 October 2026
What the app does
PryvaRecord is a private health dashboard, food diary and report tool. It has no account system, advertising, analytics or developer-operated backend. It is not a medical device and does not diagnose conditions or recommend treatment.
Health information
With your separate permission for each type, the app reads weight, resting heart rate, heart rate variability, steps, active calories, exercise sessions, sleep and nutrition from Apple Health (HealthKit) on iOS, or Health Connect on Android. Imports are read-only. From build 70, with separate workout permission and an explicit Send action, you can export a manually logged workout to Apple Health or Health Connect. Imported records are never written back, and there is no automatic or background workout export. Exported workouts are outside the encrypted app vault and may be available to other apps authorised by your health service. Deleting the local vault does not delete them; manage those copies in Apple Health or Health Connect. You can revoke workout write permission in your device settings. Imported information is encrypted and stored in the app's private storage on this device.
Daily goal feedback and reminders
Daily goal feedback compares locally stored values with your own targets. It does not send those values to the developer or a server. The optional evening reminder is scheduled on your device, is off by default, and uses generic text without health values. You can turn it off in the app or device notification settings.
Optional network features
The core app works without an account or cloud service. If you turn on AI features and add your own Anthropic API key, the meal words or coach question you submit—and for coaching only a bounded summary of averages, streaks and targets—are sent directly to Anthropic. Raw records, dates, notes, meal history and health-source identifiers are not sent. If you enable online barcode lookup, only the product barcode is sent to Open Food Facts.
Optional encrypted phone sync
Phone sync is off by default. Build 68 nearby QR transfers encrypt imported health records, watch-change times, saved meals, manual entries, custom foods and day notes with a fresh key for each session. Both phones must use build 68 or later. Keys, API credentials, privacy permissions and audit history are not transferred. The QR contains the session key: show it only to your own phone. The session expires after 5 minutes, when stopped, or when the app locks or this screen closes. Saved entries remain in each encrypted vault. Edits and deletion markers transfer at the next successful sync; disconnecting or deleting the whole local vault does not erase the other phone. Phone sync only updates PryvaRecord's encrypted app vault. It never writes, edits or deletes records in Apple Health, HealthKit, Health Connect, Google Fit or Samsung Health. Legacy private HTTPS relay pairing transfers imported records and watch changes only, not personal entries. Relay copies expire after 30 days without an upload; the relay sees ciphertext, request times, IP addresses and sizes. No relay is deployed by this update.
Camera, microphone and device authentication
The camera is used to scan barcodes on the device; images are not stored or uploaded. Voice entry asks your device for on-device speech recognition; the operating system's speech service controls availability and processing. This app itself does not store or upload audio. Face ID, Touch ID, fingerprint or device-passcode checks are performed by the operating system, and the app receives only whether the check succeeded.
Backups and reports
Nothing leaves the device unless you choose an action that does so. A vault backup is encrypted with the passphrase shown to you. A GP report is a readable PDF after you authenticate, accept the warning and choose where to share it. Files you save or share are then controlled by the destination you selected.
Retention and deletion
Information remains in the encrypted local vault until you remove imported records or choose Delete local data. Complete deletion destroys the device-held encryption key before removing the encrypted file. It does not delete originals held by Apple Health or Health Connect, or copies you previously exported.
Security and control
The vault uses AES-256-GCM encryption. The key is protected by the iOS Keychain — passcode-gated, held on this device and never synced to iCloud — or by the Android Keystore. The encrypted vault file is excluded from operating-system cloud backups, cleartext network traffic is disabled, and an opaque privacy veil hides the app's content in the app switcher and Control Centre so system snapshots hold no detail; on Android, sensitive screens also block ordinary screenshots and recordings. You can grant or revoke each health permission at any time.
Children and contact
PryvaRecord is intended for adults and is not directed to children. For privacy questions or support, email pryvarecordsupport@gmail.com.