Privacy Policy

My AFib Companion

Effective date: 4 August 2026
Version 1.0

This policy applies to the iPhone app My AFib Companion (shown inside the app as “AFib Companion”) and to this website, afibcompanion.com. It replaces any earlier privacy policy published at a different web address.

Read this first: what this app is, and what it is not

My AFib Companion is a wellness and record-keeping tool. It helps you write down what happened and see it in one place.

It does not diagnose, detect, monitor for, screen for, treat, cure or prevent any condition. It is not a medical device, and nothing in it is medical advice. Always talk to your doctor or another qualified healthcare professional about your heart, your symptoms and your medicines.

In an emergency, call 911 (or your local emergency number) immediately.

If you have chest pain, difficulty breathing, sudden numbness or weakness, confusion, trouble speaking or severe dizziness, call for help. Do not open this app first.

The short version

We have tried to write this in a way you can actually read. Here is the honest summary; the detail follows below.

  • Your data does leave your iPhone. It is uploaded to a private database in the United States so that it is backed up and available if you change or lose your phone. It is locked to your account.
  • Nobody else can read your rows. Every table uses database row-level security, so a query can only ever return rows belonging to the signed-in account.
  • The analysis happens on your phone. Weekly summaries, trigger correlations and adherence analysis are calculated on the device itself. Your health data is not sent anywhere to be analysed, and it is never sent to any outside AI service. Your doctor report PDF is also built on the phone.
  • We do not sell your data. Ever. To anyone. There is no advertising in this app, no analytics SDK, no tracking SDK and no data broker.
  • You can take it all with you, and you can delete it, from inside the app, at any time — including if your subscription has lapsed.
  • This website tracks nothing. No cookies, no analytics, no fonts or scripts loaded from anyone else’s server.

1. Who is responsible for your data

My AFib Companion is made and run by one person — a solo developer trading as BGW in Nature. There is no company behind it, no marketing department and no data science team.

For the purposes of the UK and EU General Data Protection Regulation, BGW in Nature is the data controller for the information described in this policy. Under California law, we are the business that collects it.

How to reach us about anything in this policy:
Email [email protected]

Please put “Privacy” in the subject line so it is not missed. This is a real inbox read by the developer, not a ticketing system.

2. What we collect, and why

Everything below is either typed in by you or read from Apple Health with your permission. We do not buy data about you, and we do not receive data about you from data brokers, advertisers or social networks.

2.1 Account and sign-in

Account and sign-in data
WhatWhy
Email addressTo create your account, sign you in, and reset your password
Password (stored only as a salted hash, never in readable form)To sign you in, if you chose email sign-in
The identifier issued by Sign in with Apple, and the email address Apple passes on (which may be a private relay address if you chose to hide yours)To sign you in, if you chose Apple sign-in
An account ID (a random UUID)To attach your records to you and to nobody else
Session tokensTo keep you signed in between launches

Authentication is handled by Supabase Auth. We never see your password.

2.2 Your profile

Display name, AFib type, diagnosis date, date of birth, biological sex, and whether you have finished onboarding.

Why: to label your records, to show your age and AFib type on the emergency card and doctor report, and to fill in the CHA2DS2-VASc educational calculator.

Every one of these is optional except the account itself. If you would rather not give your date of birth, leave it blank; the app still works.

2.3 Emergency contact — someone else’s information

If you fill it in, we store an emergency contact name and phone number.

We are calling this out separately because this is usually a third party who has never used the app and has never agreed to anything with us. Please see section 6 for how we handle it and what we ask of you.

2.4 AFib episodes

Start time, end time, severity, notes, and whether it was created from an Apple Health event. Each episode can also carry:

  • Symptoms — type and severity
  • Suspected triggers — type, intensity and notes

Why: this is the core record the app exists to keep, and the basis of your doctor report.

2.5 Medications

Medication name, generic name, dosage, frequency, category, scheduled times, pill count, refill reminder threshold, whether it is active, whether it is a “pill-in-the-pocket” medicine, and your notes.

And for every dose: the medication log — scheduled time, time actually taken, status (taken, skipped, missed, pending) and notes.

Why: to show your schedule, send your reminders, and calculate the adherence figures in your report.

2.6 Daily check-ins

Mood, alcohol, caffeine, sleep quality, hours slept, stress, exercise minutes, hydration and notes — one entry per day.

Why: these are the inputs the trigger-correlation analysis compares against your episodes.

2.7 Health readings from Apple Health

Covered in full in section 4. In short: the app reads a range of heart and activity data from Apple Health to show you on screen, and uploads a subset of it — heart rate, resting heart rate, heart rate variability and step count — to your account.

2.8 Insights

The weekly summaries, correlation notes and adherence observations that the app writes. These are generated on your iPhone and then stored in your account like any other record, so they survive a phone change.

Why: so your history of insights is not lost, and so you can read them on another device.

2.9 Subscription information

My AFib Companion is subscription-only: a 30-day free trial, then $9.99/month or $59.99/year. There is no free tier.

Payment is taken by Apple. We never see your card number, billing address or Apple ID password.

To know whether your subscription is active, we use RevenueCat. RevenueCat receives your account ID (the random UUID above) and your purchase and renewal history from Apple, plus the ordinary device and app information their SDK collects to attribute a purchase — such as app version, device model, operating system version and store country.

RevenueCat does not receive any of your health data. No episode, medication, check-in, profile or Apple Health record is ever sent to them.

2.10 Things on your device that never reach us

  • Face ID / Touch ID app lock. iOS does the check and tells the app yes or no. Your fingerprint and face data never leave Apple’s secure hardware and are never available to us.
  • Reminders. Medication, check-in and weekly-summary reminders are scheduled and delivered by iOS on your phone. There is no push server, and the content of a reminder is not sent anywhere.
  • Widget data. A small summary — your latest heart rate, your next doses — is stored in a shared container on the device so the home screen widgets can draw. It stays on the device.
  • Your doctor report PDF and emergency card. Built on the phone. They go wherever you send them and nowhere else.
  • Your CSV export. Written to a temporary file on your phone, protected by iOS file encryption, and shared only by you.

2.11 What we never collect

No precise location. No contacts. No photos. No microphone or camera access. No advertising identifier. No browsing or app-usage tracking. No fingerprinting. There is no advertising SDK, no analytics SDK and no crash-reporting SDK in this app — we checked, and there is nothing to disclose.

If you have switched on Share iPhone Analytics → Share with App Developers in your iOS Settings, Apple may give us aggregated, de-identified crash and energy reports through App Store Connect. That is Apple’s mechanism, controlled by you in iOS Settings, and it does not include your health records. You can turn it off at Settings → Privacy & Security → Analytics & Improvements.

3. What we do with it

We use your information only to:

  • run the features you asked for — logging, reminders, check-ins, insights, reports, widgets, emergency card;
  • keep your records in sync and backed up across your devices;
  • generate your doctor-ready PDF and CSV export when you ask for one;
  • check whether your subscription or trial is active, and unlock the app accordingly;
  • answer you when you email for support;
  • keep the service secure, and investigate abuse or technical faults;
  • comply with the law where we are required to.

We do not use your information to advertise to you, to profile you for anyone else, to train any AI model, or to build any product other than the one you are using.

Automated decisions. The app makes no automated decision that has a legal effect on you or anything similar. The insights are informational observations calculated on your phone. They are not diagnoses, not predictions, and not a reason to change anything you do without speaking to your doctor.

4. Apple Health (HealthKit)

If you grant permission, the app reads these types from Apple Health:

Heart rate · Resting heart rate · Heart rate variability (SDNN) · Electrocardiogram (ECG) results · Atrial fibrillation history / AFib burden (iOS 16 and later) · Irregular heart rhythm notifications · High heart rate notifications · Low heart rate notifications · VO2 max · Blood oxygen · Sleep analysis · Step count · Active energy burned · Apple exercise time

You can grant or refuse each type individually, and change your mind at any time in the Health app under Sharing → Apps. Refusing does not lock you out; the app simply shows less.

What we upload, and what we do not

Uploaded to your account: heart rate, resting heart rate, heart rate variability (SDNN) and step count. For each reading we store the type, the value, the unit, the start and end time, and the name of the device that recorded it (for example, “Apple Watch”). Readings are sent in batches of up to 100.

Not uploaded — these stay on your iPhone: ECG results and their details, irregular rhythm notifications, high and low heart rate notifications, AFib burden, VO2 max, blood oxygen, sleep analysis, active energy and exercise time. The app reads them to show you on screen and to include in your on-device report. They are not sent to our database.

Apple’s rules, which we follow

  • HealthKit data is used only to provide the health tracking, insight and reporting features inside the app.
  • HealthKit data is never used for advertising or marketing, or for any similar service.
  • HealthKit data is never sold, rented or otherwise disclosed to data brokers, information resellers, advertising networks or anyone conducting data mining.
  • HealthKit data is never disclosed to a third party without your explicit consent, except where it is strictly necessary to provide a function you have asked for — which, in practice, means storing it in your own account with our hosting provider.
  • HealthKit data is encrypted in transit and at rest.

The app only ever reads from Apple Health. It never writes anything into it. Nothing the app does can change, add to or delete your Apple Health records.

And the other direction: deleting your app account does not delete anything in Apple Health. Apple Health is yours and is managed separately, in the Health app.

5. Where the thinking happens

This matters enough to state plainly, and to state accurately.

Your data does leave your device. It is uploaded to a private, access-controlled database so you have a backup and can move to a new phone. We will not tell you otherwise. An earlier version of our App Store description said your data never left your device. That was wrong, it has been withdrawn, and we are not going to repeat it.

The analysis genuinely does not leave your device. Weekly summaries, trigger correlations and medication adherence analysis are computed on the iPhone itself, by analysis code that ships inside the app and runs locally. It makes no network call. No health data is sent to OpenAI, Google, Anthropic, or any other AI or analytics provider, because no such service is used at all.

Your doctor report PDF is likewise assembled on the phone.

6. Your emergency contact

If you enter an emergency contact, you are giving us the name and phone number of another person, and that person has probably never heard of us.

Here is exactly what happens to it:

  • It is stored with your profile, in your account, protected the same way as everything else.
  • It is shown on your emergency card, on your device.
  • We never call, text, email or otherwise contact that person. The app has no ability to do so. The number is there so that you, or someone helping you, can read it off the screen.
  • It is not shared with anyone, not used for any other purpose, and not used to build any kind of contact list.

We rely on legitimate interests as the legal basis for holding it (UK/EU GDPR Article 6(1)(f)) — specifically, your interest and theirs in having that number available if you are unwell, which is difficult to achieve any other way and carries very little risk to them.

What we ask of you: please tell the person you have listed them, so it is not a surprise. And if they ask you to remove them, you can clear both fields in Profile → Edit Profile and the record is overwritten. If that person contacts us directly at [email protected] and asks to be erased, we will remove their name and number from the account it appears in.

If you are in the UK, the European Economic Area or Switzerland, we must tell you the legal basis for each use.

Legal basis for each kind of processing
What we processLegal basis
Account, sign-in, sync, subscription status, supportArticle 6(1)(b) — necessary to perform our contract with you
Health data: episodes, symptoms, triggers, medications and logs, check-ins, Apple Health readings, insights, AFib type, diagnosis dateArticle 9(2)(a) — your explicit consent, given when you grant Health permissions and when you choose to record this information; together with Article 6(1)(b)
Emergency contact name and numberArticle 6(1)(f) — legitimate interests (see section 6)
Security, fault diagnosis, preventing abuseArticle 6(1)(f) — legitimate interests in keeping the service safe and working
Meeting legal or regulatory obligationsArticle 6(1)(c)

You can withdraw consent at any time. Turn off Health permissions in the Health app, stop entering data, delete individual records, or delete your account outright. Withdrawing consent does not make our earlier processing unlawful, but it stops it going forward.

Do you have to provide any of this? Only an email address (or Sign in with Apple) and a subscription. Everything else is voluntary — but an app for logging AFib episodes is not much use if you do not log any.

8. Who else touches your data

These are our processors and sub-processors. Each one is bound by a contract that limits them to acting on our instructions. None of them is permitted to use your data for their own purposes.

Processors and sub-processors
WhoWhat they doWhat they receive
Supabase, Inc.Hosts the PostgreSQL database and runs authenticationAll the account, profile, episode, medication, check-in, insight and health-reading data described above
Amazon Web Services (sub-processor to Supabase)Provides the physical servers and storage, in the US West (Oregon) regionThe same data, encrypted at rest on their infrastructure
Apple Inc.App Store distribution, subscription billing and receipts, the HealthKit framework on your device, local notificationsYour purchase and subscription record, per Apple’s own privacy policy. Apple does not receive your health records from us
RevenueCat, Inc.Tells the app whether your subscription is activeYour account ID and purchase history, plus standard device and app information. No health data
Cloudflare, Inc.Hosts this website onlyThe requests your browser makes to afibcompanion.com. We send no account, profile or health data to Cloudflare, and nothing you enter in the app is stored there

That is the complete list. No advertising network, no analytics provider, no AI vendor, no data broker, no CRM, no email marketing platform.

We do not sell your personal information, and we never have. We do not share it for cross-context behavioural advertising. We do not disclose it to anyone except the processors above, and except where we are legally compelled to — for example, by a valid court order. If that ever happens and we are permitted to tell you, we will.

If the app is ever transferred to someone else, your data may transfer with it. If that happens we will tell you first, through the app and by email, and this policy will continue to apply until you are given the chance to review a new one or delete your account.

9. Where your data is stored, and international transfers

Your data is stored on servers in the United States, in the AWS US West (Oregon) region.

If you are in the UK, the EEA or Switzerland, this means your personal data — including health data, which is special category data — is transferred to the United States, a country that has not received a full adequacy decision covering all recipients.

We rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum, where the UK GDPR applies) as incorporated into our data processing agreements with Supabase and RevenueCat, together with the technical protections described in section 10 — encryption in transit and at rest, and row-level access control.

You can ask us for more information about these safeguards at [email protected].

10. How your data is protected

  • Encrypted in transit. All traffic between the app and the database uses TLS.
  • Encrypted at rest. The database is stored on AES-256 encrypted disks.
  • Row-level security. Every table carries a policy that ties each row to one account ID. A request signed in as you can only ever return, change or delete your own rows. It is enforced by the database itself, not by the app, so a bug in the app cannot bypass it.
  • Authentication. Handled by Supabase Auth. Passwords are stored hashed and salted. Sign in with Apple uses a single-use, hashed nonce for each attempt.
  • On your device. Local records are held in Apple’s SwiftData store, protected by iOS device encryption. Your CSV export is written with complete file protection, so it cannot be read while the phone is locked. You can add a Face ID or Touch ID lock to the app itself from the More tab.
  • Minimum access. One person — the developer — has administrative access, and uses it for maintenance and support only.

No system is perfectly secure, and we will not pretend otherwise. We cannot guarantee that a transmission or storage system will never be compromised. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and we will tell you directly and without undue delay where the law requires it or where it is the right thing to do.

Things you can do that genuinely help: use a password you use nowhere else, turn on the app’s Face ID lock, and keep iOS up to date.

11. How long we keep it

Retention periods
DataHow long
Account, profile and all health recordsFor as long as your account exists. We do not delete your history because a subscription lapsed
After you delete your accountRemoved from the live database straight away (see section 12)
Encrypted database backupsDaily encrypted backups on a rolling 7-day window; deleted records age out of backups within 7 days
Subscription and purchase recordsKept by Apple and RevenueCat under their own policies and retention rules, which we do not control. These are also financial records they may be required to retain
Support emailsKept for up to 24 months, so we can follow up on a problem, then deleted

If your subscription lapses, the app locks — but your data is not deleted. It is still yours, and you can still export it and still delete your account. Locking you out of your own health history would be indefensible.

12. Getting your data out, and deleting it

Both of these work from inside the app, at any time, including while unsubscribed.

Export

More → Export Data. Choose 30 Days, 90 Days, 1 Year or All Time. You get a CSV file you can open in Numbers, Excel or Google Sheets, or send to your doctor. It contains:

  • Episodes — ID, start time, end time, severity, whether auto-created, notes
  • Medications — ID, name, dosage, frequency, category, active status, notes
  • Medication logs — ID, medication, scheduled time, time taken, status, notes
  • Daily check-ins — ID, date, mood, alcohol, caffeine, sleep quality, hours slept, stress, exercise minutes, hydration, notes
  • Health readings — ID, type, value, unit, date, source

A few things are not in the CSV: your profile fields, individual symptom and trigger rows, and the text of generated insights. If you want those too — or you want everything in a different format — email [email protected] and we will put a complete copy together for you at no charge.

You can also generate a doctor report PDF at any time from the Insights tab.

Delete

More → Delete Account. You will be asked to type DELETE and confirm once more, because it cannot be undone.

What is deleted immediately: your profile row — and because every table is linked to it with a cascading delete rule, that removes your episodes, symptoms, triggers, medications, medication logs, daily check-ins, health readings and insights from the database at the same time. Everything stored locally on the phone is also purged: the local database, app settings, widget data and cached files.

What is not deleted, and what you need to know:

  • Your sign-in record. Your email address, and either your hashed password or the identifier issued by Sign in with Apple, is held separately by Supabase Auth. The in-app deletion does not currently erase that record — it can only be removed server-side. Email [email protected] and we will delete it within 30 days. We are working on making this automatic, and we would rather tell you about the gap than let you assume it is not there. Until it is removed, signing in again simply creates a new, empty account; none of your old records come back.
  • Encrypted backups. Deleted records may persist in automated daily backups until they age out, which takes at most 7 days.
  • Your Apple Health data. Untouched, and still yours, in the Health app.
  • Your subscription. Deleting your account does not cancel it. Cancel separately in Settings → [your name] → Subscriptions on your iPhone, or you will keep being billed.
  • Apple’s and RevenueCat’s purchase records. Retained under their own policies.

Please export before you delete. There is no way to recover it afterwards. Step-by-step deletion instructions.

13. Your rights

If you are in the UK, EEA or Switzerland

You have the right to:

  • Access a copy of the personal data we hold about you
  • Correct anything inaccurate or incomplete
  • Erase your data (“right to be forgotten”)
  • Restrict how we process it in certain circumstances
  • Object to processing based on legitimate interests, including the emergency contact
  • Portability — receive your data in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible
  • Withdraw consent at any time, without affecting processing already carried out
  • Not be subject to a decision based solely on automated processing with legal or similarly significant effects — as noted, we make none

Most of these you can exercise yourself, immediately, in the app: Profile to correct, Export Data for access and portability, Delete Account for erasure. For anything else, email [email protected].

We will respond within one month. If a request is genuinely complex we may extend that by a further two months, and we will tell you within the first month if that happens. There is no charge unless a request is manifestly unfounded or excessive.

Complaints. If you think we have got it wrong, please tell us first — it is usually the fastest fix. You also have the right to complain to your local supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). In the EEA it is the data protection authority for the country where you live or work.

If you are in California

Under the CCPA as amended by the CPRA, you have the right to:

  • Know what personal information we collect, use, disclose and retain
  • Access a copy of it, and know the categories of source and recipient
  • Correct inaccurate personal information
  • Delete your personal information
  • Opt out of sale or sharing — there is nothing to opt out of, because we do neither
  • Limit the use of sensitive personal information — see below
  • Not be discriminated against for exercising any of these rights. Nothing about your price, your trial or your access changes because you made a request

Categories we collect, using the statutory labels:

CCPA categories of personal information collected
CategoryExamples in this app
IdentifiersEmail address, display name, account ID, Apple sign-in identifier
Customer records (Cal. Civ. Code §1798.80(e))Name, emergency contact name and telephone number
Protected classificationsDate of birth (age), biological sex
Commercial informationSubscription and purchase history
Sensitive personal informationAccount log-in credentials; personal information collected and analysed concerning health
InferencesThe insights generated on your device from your own records

We do not collect biometric information, precise geolocation, internet activity, audio or visual information, employment or education information.

Sources: you; Apple Health, with your permission; Apple and RevenueCat, for subscription status.

Purposes: the operational purposes in section 3.

Disclosure: we disclose personal information to the service providers named in section 8 for business purposes only.

Sale and sharing: we have not sold and have not shared personal information, as those terms are defined by the CCPA, in the preceding 12 months, and we do not intend to. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.

Sensitive personal information: we use it only for the purposes permitted by Cal. Code Regs. tit. 11 §7027(m) — performing the service you asked for and keeping it secure. We do not use or disclose it to infer characteristics about you. The right to limit its use therefore does not apply here. Regardless, you can delete all of it yourself from inside the app.

Retention: as set out in section 11.

How to exercise a right: email [email protected]. We verify requests by matching the email address you write from to the one on the account, and may ask you to confirm details only the account holder would know. An authorised agent may act for you with your written permission, and we may still ask you to verify your identity directly. We respond within 45 days, extendable once by another 45 days where necessary.

Other US states

If you live in a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and others — you have broadly similar rights of access, correction, deletion, portability and opt-out, and a right to appeal a refusal. Email us and we will honour them. If we refuse a request, we will explain why and tell you how to appeal; if we deny an appeal, we will tell you how to contact your state Attorney General.

14. Children

My AFib Companion is rated 17+ and is intended for adults managing their own heart health. It is not directed at children.

We do not knowingly collect personal information from anyone under 17. If we learn that we have, we will delete the account and its data promptly. If you are a parent or guardian and believe your child has created an account, email [email protected] and we will take care of it.

15. This website

afibcompanion.com is a set of plain static pages.

It sets no cookies. It runs no analytics. It loads no fonts, scripts, images or stylesheets from any other server — everything is served from this domain, so simply opening this page does not tell any third party that you did. We have deliberately enabled no web analytics of any kind.

Our website host, Cloudflare, processes your IP address and basic request information to deliver the page and protect the site from attack, as any web host must. We do not receive, review or retain those logs.

There is nothing here to opt out of, and no preference signal for us to honour, because there is nothing being collected.

16. Changes to this policy

We may update this policy — for example, if a feature changes what data is handled.

When we make a material change, we will update the effective date at the top, notify you inside the app, and email you where we hold an address for you, before the change takes effect. For minor changes such as clarified wording or a corrected typo, we will update the effective date only.

If a change means we need to process your health data in a genuinely new way, we will ask for your consent again rather than assume it.

Previous versions are available on request.

17. Contact us

Questions, corrections, requests, or a suspicion that something here does not match what the app actually does:

Email: [email protected]

One person reads that inbox. If something in this policy is wrong or unclear, please tell us — we would rather fix it than defend it.

A final reminder. My AFib Companion is a wellness and record-keeping tool. It is not a medical device and it does not provide medical advice, diagnosis or treatment. Do not use it to decide whether you need care.

If you think you are having a medical emergency, call 911 or your local emergency number now.