Pomme — Privacy Policy

Last updated: 9 September 2026

Pomme reads health and activity data from your device and syncs it to a server so that AI agents you authorise can answer questions about it. This policy explains what we collect, why, where it lives, and the control you have over it.

Your health data is encrypted in transit and at rest, hosted in the UK, and never used for anything except answering your agents' queries. No ads, no analytics on your data, no selling it. Ever.

What we collect

  • Health & activity data you choose to sync. With your explicit consent, Pomme reads the following from Apple Health and sends daily-aggregated values to the server: steps, active energy, exercise minutes, resting heart rate, heart-rate variability, VO₂ max, weight, body fat, sleep, and workouts.
  • Account data. The identifier for your account and your API token(s).
  • Nothing about how you pay. The subscription is bought through the App Store, so Apple takes the money and we never see your card, your billing address or your Apple Account. What reaches us is Apple's record of the purchase — which product, when it renews, and whether it is still live — stored against your account so we know whether to answer your agents.
  • No email address. Nothing on the website or in the app asks for one, and we hold none.
  • We do not embed third-party analytics, advertising, or tracking SDKs. The App Store privacy label says "no tracking" because it is true.

How syncing works

Your phone is the source of truth. You start the first upload yourself. After that, Pomme syncs in the background, about once a day — Apple Health wakes it when there is new data, and it sends what has changed since the last sync. You do not need to open the app, and you can sync manually at any time.

Data such as sleep and workouts appears on the server on the next sync, not the moment it is recorded. If you force-quit Pomme, iOS stops waking it and background syncing pauses until you open it again.

How your data is used

Your data is used for exactly one thing: answering the queries your authorised agents send. It is never used to train models, never sold, and never shared for advertising.

Sharing your data with an AI agent

Pomme's whole purpose is letting an AI agent or other MCP-compatible tool answer questions about your health data. That is a deliberate data-sharing decision, and we want you to make it with your eyes open.

  • What is sent. A key you generate can be asked for any of the metrics listed above under "What we collect" — steps, active energy, exercise minutes, resting heart rate, heart-rate variability, VO₂ max, weight, body fat, sleep, and workouts. A key is not limited to a subset: whichever metric an agent asks about, it can read, for as long as the key is valid.
  • Who it is sent to. Whichever agent or MCP client you choose to connect the key to — Claude, Cursor, or anything else that speaks the protocol. That choice is yours to make, not Pomme's: we do not operate, vet, or see inside that agent, and we have no visibility into what it does with an answer once it has one. Only connect a key to an agent whose own privacy practices you trust, the same way you'd think about any third-party tool you hand data to.
  • Your permission, asked for explicitly. Before the app ever mints your first key, it shows you this same list of what a key exposes and asks you to confirm you understand it. Nothing is shared before that point.
  • Revoking access. Every key can be revoked from the app at any time — under "You → Your keys" — which stops that agent from reading anything further immediately.

Where it is hosted & how it is protected

  • Your health records are stored in the United Kingdom, in one London database.
  • Encrypted in transit (TLS) and at rest.
  • Access is scoped per user; your agents can only read your own data via your token.

Everyone's health data lives in this one UK database, wherever they are. If you are in the United States, your data is stored in the same UK (London) database as every other user — there is no US region and no per-user routing.

We do not claim "zero-knowledge" or that "we can't read your data" — that would require encryption with a key only you hold, which this version does not use.

Your rights (GDPR)

  • Consent. We only sync the data types you explicitly agree to, and you can withdraw HealthKit access at any time in the iOS Settings app.
  • Deletion. Deleting your account deletes everything held on the server, immediately. Because your phone remains the source of truth, nothing is lost — you can sync again at any time.
  • Access & portability. Your device remains the source of truth, so you can export your health data from the Apple Health app at any time; contact support to exercise any GDPR right.

Contact

Questions or requests: privacy@pingpomme.com