Pomme — Privacy Policy
Last updated: 15 July 2026
Pomme reads health and activity data from your device and syncs it to a server so that AI agents you authorise can answer questions about it. This policy explains what we collect, why, where it lives, and the control you have over it.
Your health data is encrypted in transit and at rest, hosted in the UK, and never used for anything except answering your agents' queries. No ads, no analytics on your data, no selling it. Ever.
What we collect
- Health & activity data you choose to sync. With your explicit consent, Pomme reads the following from Apple Health and sends daily-aggregated values to the server: steps, active energy, exercise minutes, resting heart rate, heart-rate variability, VO₂ max, weight, body fat, sleep, and workouts.
- Account data. The identifier for your account and your API token(s).
- We do not embed third-party analytics, advertising, or tracking SDKs. The App Store privacy label says "no tracking" because it is true.
How syncing works
Your phone is the source of truth. You start the first upload yourself. After that, Pomme syncs in the background, about once a day — Apple Health wakes it when there is new data, and it sends what has changed since the last sync. You do not need to open the app, and you can sync manually at any time.
Data such as sleep and workouts appears on the server on the next sync, not the moment it is recorded. If you force-quit Pomme, iOS stops waking it and background syncing pauses until you open it again.
How your data is used
Your data is used for exactly one thing: answering the queries your authorised agents send. It is never used to train models, never sold, and never shared for advertising.
Where it is hosted & how it is protected
- Hosted in the United Kingdom (London — Google Cloud
europe-west2). - Encrypted in transit (TLS) and at rest.
- Access is scoped per user; your agents can only read your own data via your token.
Everyone's health data lives in this one UK database, wherever they are. If you are in the United States, your data is stored in the same UK (London) database as every other user — there is no US region and no per-user routing.
We do not claim "zero-knowledge" or that "we can't read your data" — that would require encryption with a key only you hold, which this version does not use.
Your rights (GDPR)
- Consent. We only sync the data types you explicitly agree to, and you can withdraw HealthKit access at any time in the iOS Settings app.
- Deletion. Deleting your account deletes everything held on the server, immediately. Because your phone remains the source of truth, nothing is lost — you can sync again at any time.
- Access & portability. Your device remains the source of truth, so you can export your health data from the Apple Health app at any time; contact support to exercise any GDPR right.
Contact
Questions or requests: privacy@pingpomme.com