Health Bridge
PRIVACY / 9 OCTOBER 2026

Your data, your choices.

Development policy. This describes the implemented service. The production operator, hosting location, backup policy, and final legal terms must be confirmed before public release.

What Health Bridge collects

When you sign in, the service stores a pseudonymous account identifier and an encrypted Apple authorization credential. When you enable cloud sync, it stores the Apple Health records you allow in Apple’s permission screen: values, units, dates, sample identifiers, workout summaries where selected, and source app identifiers and names. A random device identifier tracks sync progress. The service records your sharing choices and their date.

Why and where it is used

The data enables you to review and query your health and fitness history. Your selected records go to the managed Health Bridge service at health-bridge.arcticstudios.co. You do not configure a server. The Health Bridge operator can decrypt the records needed to answer authorized requests. Health Bridge does not include advertising, tracking SDKs, a data-sale feature, or a model-training pipeline.

Sharing with OpenAI through Codex

Cloud sync does not automatically allow Codex to read your records. Sign in with Apple from the Codex plugin to authorize that connection. When Codex queries the plugin, the requested records are sent to OpenAI and become part of that conversation's context. OpenAI handles this information under the terms and data controls of your Codex account. This integration does not inherit the separate protections of ChatGPT Health.

Disconnecting Codex in the iPhone app revokes that plugin connection. It cannot remove information already retrieved into conversations. Manage those copies with the relevant account's controls.

Storage and protection

Network connections use HTTPS in production. Record payloads and stored Apple refresh credentials are encrypted at rest with AES-256-GCM. Index metadata, including pseudonymous account and sample identifiers, categories and dates, remains queryable. This is not end-to-end encryption. API credentials are random, scoped and stored as hashes on the server. The iPhone keeps its credential in the device Keychain; Codex manages its OAuth credentials.

Retention, deletion and export

The live service retains selected records until you remove their category, delete the cloud copy, or delete your account. Deleting the cloud copy pauses uploads and invalidates old upload checkpoints. Account deletion also removes associated service credentials and revokes the stored Apple authorization. Apple Health records on your device are not changed.

Previously uploaded data is not automatically deleted when you change HealthKit permissions outside Health Bridge. Use the app's deletion controls. You can retrieve your records through paginated plugin queries; Apple Health also offers its own export. Backup retention and the treatment of deletion in backups will be published before launch.

Your choices and contact

Use Apple Health permissions to control read access, and Health Bridge Settings to pause syncing, disconnect Codex or delete your account. To ask about access, correction, portability or deletion, contact chocart.hugues@icloud.com. Avoid sending health records by email.