Skip to content

Privacy

Your record should remain yours.

This page describes Claritide as it actually works today. Your health record lives on your iPhone; when you sign in, part of it is encrypted here and synced to your account, and an account also carries your subscription and, if you want one, a pact. Everything below says which is which.

Last updated Sep 26, 2026

What stays on your device

Your protocol details, compounds, dose amounts, vial records, injection sites, notes, outcome readings, labs and progress photos are stored in the app database on your device. Progress photos, anything imported from Apple Health, lab records and device settings remain on this device unless you export or share them.

If you sign in, Claritide keeps a synced copy of part of that record so it can restore on a new iPhone: your protocols, your dose history, your vial records, measurements you typed in yourself, their attached notes, and the state of your daily check-in. That copy is encrypted on your iPhone before it is sent, with a key that belongs to your account. Claritide operates the service that holds the wrapped form of that key, so this is ordinary account recovery, not zero-knowledge storage: it exists only to put your record back on a phone you have signed into, it is deleted with your account, and it is not read for any other purpose.

The iPhone app keeps a second, encrypted copy of that record in protected storage on this iPhone. Personal health records and progress photos are excluded from iCloud and computer device backups. The encryption key is bound to this device and does not sync through iCloud Keychain. This protected copy can recover from WebKit storage loss or an app offload on the same iPhone, but it does not move to a replacement phone.

Deleting the app or losing the iPhone without an export can erase the record. You → Your data holds export, import and delete controls, so you can move a record deliberately, keep your own copy or remove local data at any time. Exports come as a JSON archive you can re-import, or as CSV spreadsheets you can open in any spreadsheet app.

Information you choose to enter

You may enter your age, height, weight, protocol schedule, dose history, outcomes, photos, labs and free-form notes. Claritide uses those entries to provide the tracking features you ask for. It does not use them for advertising or sell them. The records and attached notes listed above sync encrypted for account recovery; the other records stay on your device unless you export or share them.

Your Claritide account

An account exists to carry your subscription and to connect a pact. Signing in with Apple or Google gives Claritide four things and nothing else: an opaque account id, a one-way hashed version of the provider’s subject identifier, your email address if the provider released one, and which provider it was. Apple and Google identities are never matched to each other by email address.

The account record also holds your entitlement, which is the state of your subscription: whether it is trialling, active, in a billing grace period, expired or cancelled, which plan it is, which rail billed it, and the renewal date. Sessions are stored as hashes of the sign-in token, never the token itself.

The account service itself holds nothing clinical. Your compounds, doses, vials, schedules, injection sites, notes, outcomes, measurements, labs and photos are never sent to it, and that is enforced in the app’s own code: outgoing payloads are checked against a list of forbidden fields before they are allowed to leave the device. The synced copy described above is a separate, encrypted store keyed to your account; the account service only tells it that you are signed in.

Pacts with a partner

If you deliberately create or accept a pact, the relay receives an invite code, an optional first name you chose to share, the agreed dates and length, a weekly target, your friendly stake in your own words, the day-level marks (done, missed, rest or open) and any nudges you send. It never receives what you are taking. Compounds, protocol names, dose amounts, vials, outcomes, notes, labs, photos and your email address are all excluded, and the free text you write for a stake or a nudge is scanned on your device for compound names before it is sent. Your partner sees the marks and the stake. They do not see your protocol.

The feature-request board

Feature requests appear immediately after automated text checks and are visible to other signed-in users without your name or email. Requests, votes, reports and your block list are associated with your account to prevent abuse and make your controls work across devices. Your account id and moderation records are not displayed on the board. Do not include private or health information in a public request. Deleting your account removes your requests, votes, block list and reports you submitted.

Community safety and reports

You can report content and block contributors on the feature-request board or partners in Together. Reports include your selected reason, optional explanation and a copy of the relevant shared content. A Together report can include the shared name, stake and latest delivered nudge; your private tracking record is not attached. Only authorized moderators can access reports. Drawings are delivered directly to your partner. Moderators can review shared content and remove community-rule violations. Reports are deleted by a daily cleanup after 90 days, or earlier when the reporting account is deleted. Blocking a Together partner ends shared pacts and prevents future connections between those accounts until unblocked. Limited account restriction records may be retained to prevent repeated abuse. Contact support@claritide.app to ask about a restriction.

Crash reports

When the app crashes, it sends a short technical report so the crash can be fixed: the app version and build, the iOS version, the device model, and the signature and first line of the failure. That is all. There is no account id, no sign-in token, no email address, and nothing from your health record, and the text of a report is scrubbed of anything that looks like a compound name or a dose before it is sent. Reports are kept for 30 days and then deleted. You can turn them off in You → About under “Send crash reports”.

This website

When you visit claritide.app, Cloudflare Web Analytics counts page views so we can see which pages people find useful. It uses no cookies and does not identify you or follow you to other sites. The app has no analytics; its only telemetry is the crash reports above.

Sharing and external links

Share cards are drawn on your device and leave it only when you pick a destination through your browser or your operating system. Claritide is not told where one went. Links to research, to a payment page or to any other website are governed by those services’ own privacy practices.

Who processes what

Claritide uses a small number of processors, each for one job:

  • Cloudflare hosts the account, pact, link and sync services and their storage (Workers, D1 and Durable Objects), and counts visits to this website. Everything described above as leaving your device is stored there, and the synced copy of your record is stored there only in its encrypted form.
  • Apple verifies Sign in with Apple, processes App Store subscriptions, and delivers push notifications through APNs. Claritide never sees your card details.
  • Google verifies Google sign-in. Claritide does not store a Google profile, name or avatar.
  • Stripe processes card subscriptions bought in a browser and holds the payment details for them. Claritide receives the subscription state, never the card.

None of these is given your health record in readable form. Apple, Google and Stripe never receive any of it; Cloudflare stores the encrypted synced copy and cannot read it without the account key that Claritide’s own sync service holds.

How long things are kept

A sign-in session lasts up to 90 days and is deleted once it expires or is revoked. Signing out revokes it immediately. A pact that has been abandoned is deleted after 30 days, and any pact record is deleted six months after its last activity. Push registrations are deleted after six months without use. Crash reports are deleted after 30 days. Your account record, its entitlement and your synced account record (the encrypted copy of your protocols, dose history and vial records that restores them on a new iPhone) are kept while the account exists.

Deleting your account and your data

You → Account holds the controls, and they take effect immediately. Sign out removes the session from this iPhone and revokes it on the server; if you are offline when you do it, Claritide finishes revoking it the next time the app can reach the network. Delete account removes your account record, your identities, your sessions, your entitlement, your synced account record and its encryption key, and every pact you were part of, and it cancels a card subscription as part of the deletion. An App Store subscription is not cancelled by deleting your account; Apple owns that, and you cancel it in Apple Settings. Signing in again afterwards starts from nothing.

Deleting your account does not touch the health record on your iPhone. That is a separate control, in You → Your data, and it is yours to erase whenever you want.

Children

Claritide is for adults. You must be at least 18 to use it, and the app will not continue past the age screen if the age you enter is under 18.

Changes and contact

If this policy changes in a way that affects what leaves your device, the date at the top of this page changes with it. Questions, corrections and data requests go to support@claritide.app, and a person reads it. The terms of use cover the rest of the agreement.