dashboardfitness
Privacy

dashboard.fitness

Health data stays in service of your dashboard.

Effective August 26, 2026

The iPhone companion is a read-only transport for Apple Health. It sends only the categories you authorize to the dashboard.fitness account you deliberately connect.

What we process

  • Apple Health samples and workouts from the read categories you approve.
  • Source, device, and sample identifiers needed for attribution and deduplication.
  • Your account identifier and an app-scoped random installation identifier.
  • App version, sync state, receipt counts, timestamps, and safe error codes.

Why we process it

We use this information to move your authorized health evidence reliably, show its source on your private dashboard, resume interrupted transfers, and help you diagnose delivery without exposing health values in logs or support diagnostics.

What the app does not do

The companion does not write to Apple Health, sell health data, use it for advertising, or add third-party advertising or behavioral analytics SDKs. Disconnecting stops future delivery; it does not silently erase evidence already accepted by your account.

Service providers

Apple Health remains the on-device source. The companion sends authorized records directly to dashboard.fitness's private Open Wearables ingestion deployment. Railway hosts the application, ingestion workers, databases, queues, and operational logs. Clerk processes account identity and sign-in data; we do not intentionally send Apple Health samples to Clerk. Resend processes an email address and the message content only when you enable an email delivery or sharing feature. These providers act for the service; we do not sell health data or disclose it for advertising.

How long we keep it

Accepted health evidence and its source lineage remain in your active account until you delete that evidence or the account. On-device pending batches remain only until an exact terminal receipt, recovery, disconnect cleanup, or deletion. A terminally accepted server inbox payload is removed after processing; failed or quarantined delivery material remains available only for recovery. Its configured expiry is never more than 30 days after receipt, and a daily cleanup removes expired payload bytes within the following 24 hours when the service is operating. A verified deletion can remove it earlier.

A deletion is not reported complete until active dashboard.fitness and Open Wearables records, credentials, jobs, and caches covered by the deletion are verified absent. Backup copies, provider logs, and already-sent messages cannot always be removed at that instant. For a governed imported-health deletion, the confirmation plan shows the exact expiration date supplied for each retained copy; the final receipt repeats those dates and fails closed when they are unavailable. Retained copies are not used for product features and any disaster-recovery restore must reapply completed deletions.

Your control

You can revoke an iPhone from website connection settings, withdraw Apple Health access in iOS Settings, delete imported health evidence while preserving your login/profile, or request full account deletion. Revoking access stops future collection but does not delete Apple Health on your device. The authenticated deletion flow identifies what is removed, what remains outside our control, and the exact retained-copy expiration dates before you confirm it.

Questions

Email privacy@dashboard.fitness or use the support page for privacy questions, access requests, or deletion help. This policy will be updated when the app's data practices materially change.