MIDNIGHT
Privacy Policy
Effective date: September 6, 2026
Midnight is a health companion app operated by Midnight Health LLC, a New Jersey limited liability company (“Midnight,” “we,” “us”). This policy explains what we collect, how we use it, who can see it, and the choices you have. It applies to the Midnight iOS app and the Midnight web app (together, the “Service”).
The shortest honest summary: we collect the health data you choose to share so the app can work, we never sell it, we never use it for advertising, and you can ask us to delete it at any time.
What we collect
- Account information. Your name and your email address, and how you chose to sign in. You can create an account three ways: with a password (stored as a secure hash by our authentication provider — we never see or store your plaintext password); with a one-time code we email you, which uses no password at all; or with Sign in with Apple, which passes us the name and email address you approve on Apple’s screen. If you use Apple’s Hide My Emailoption, we only ever receive the private relay address Apple generates for you, never your real one. Signing in with Apple also stores one encrypted Apple token, kept for a single purpose: so that deleting your account also ends Midnight’s access to your Apple ID.
- Health data from connected sources.Metrics like weight, body fat percentage, steps, active and resting energy, sleep, resting heart rate, heart rate variability, exercise minutes, VO2 max, blood glucose, water, and alcohol consumption — from Apple Health (only the categories you explicitly authorize in iOS, revocable anytime in iOS Settings) and, if you choose to link them, third-party accounts you connect via OAuth: Strava, Fitbit, Oura, or Whoop. You can disconnect any provider at any time; disconnecting stops future syncing but doesn’t delete metrics already synced.
- Calendar, if you connect one.Connecting Google Calendar stores the connection itself: that Google account’s email address, which of its calendars you chose to include, and the tokens needed to read them. Today’s event titles and times are then read on demand to show your next event on the Home tab — we do not store your events. Apple Calendar is read on your device only and never reaches our servers. You can disconnect either one at any time.
- Profile basics. Optionally, your birthdate, sex, and height — used only to calculate metabolic estimates like BMR.
- Content you create. Your stated health goal, food and habit logs, chat messages with the Midnight companion, and progress check-ins — including any progress photos you attach, which are stored in a private bucket only you can read. Progress photos are optional, are available only to adult accounts, and are never visible to a health professional you link with.
- Professional relationship data. If you link with a health professional using an invite code: the link itself, the goals and checkpoints they set with you, and their session notes.
- Analytics. Which screens you open and which controls you tap. These go to PostHog, and they are associated with your account rather than collected anonymously. We never attach a health value to them. The apps do not send crash reports or diagnostic logs anywhere — if something crashes, nothing about the crash leaves your device. The one exception is text you type yourself and choose to send: if you submit feedback from inside the app, the message you wrote is included so we can read it.
- Approximate location, for environmental context.If you allow it, your coarse location — rounded to roughly a mile, never a street address — so we can look up your area’s temperature, air quality and daylight hours and suggest when to move an outdoor session. You can also set a city by hand instead — either by picking one of a handful of curated metros, which sends nothing extra, or by searching for any place by name, which sends the text you type (never your account information or health data) to Open-Meteo to resolve it to coordinates. Whichever way your location is set, the rounded coordinates go to our weather provider, Open-Meteo, which receives no account information and nothing about your health. We keep the day’s reading for 90 days. Turning off “Environmental context” in the iOS app under Settings › Privacy stops the lookup entirely — no coordinates are sent and no reading is stored.
- What the companion remembers about you. So it does not ask you the same thing every week, Midnight keeps a short set of plain-language notes drawn from your chats, logs, goals and nudges — things like a recurring constraint on your schedule or a preference you have stated. They are written by the model, capped at a couple per conversation, and readable only by you. Some are marked short-term and are deleted automatically after 21 days; the rest are kept until you delete your account.
- Device token. If you enable notifications, a push token so Apple can deliver them.
What we do with it
- Build your dashboard, watch-list, trends, and metabolic estimates.
- Generate AI responses: your goal text, chat messages, logs, and recent health metrics are processed by Anthropic’s Claude API and Google’s Gemini API to interpret goals, respond in chat, build training plans, and decide whether to send you a nudge. Neither provider uses API data to train its models by default.
- Hold your progress photos, if you add them — nothing more. A photo you attach to a check-in is stored in a private bucket only you can read, and shown back to you. It is not sent to any AI model, is not used to train anything, and is not shown to a health professional you link with. It is removed from our storage when you delete the check-in it belongs to. You can use check-ins without photos — weight, body fat and notes work on their own.
- Send you in-app nudges when your data drifts from your stated goal.
- Understand product usage through analytics, so we can fix bugs and improve the app.
- Operate, debug, and secure the Service.
What we never do with your health data
- We never sell it — to anyone, for any reason.
- We never use it for advertising or marketing.
- We never share it with data brokers.
- Our analytics record which screens you open and which controls you tap, never a health value — the only free text in them is a feedback message you chose to write and send. On the web app — not the iOS app — we also use PostHog session replay to understand how the Service is used and to fix bugs. Those replays mask all text and images, so the readings on your dashboard are not captured in them. PostHog never receives this data for advertising, never sells it, and we never share it with anyone outside Midnight.
- We never use Apple HealthKit or connected-provider data for any purpose other than providing the Service to you, consistent with Apple’s Health app guidelines and each provider’s developer terms.
Sharing with your health professional
Midnight supports an optional relationship with an independent health professional (for example, a nutritionist or coach). This sharing only happens if you enter an invite code they give you. Once linked, your professional can see your goals, health metrics, logs, and checkpoints, and can set goals and checkpoints for you. To end this sharing, contact us at woody@mdnt.health and we will unlink the relationship. Professionals are independent providers, not employees or agents of Midnight Health LLC.
Service providers
We use a small number of infrastructure providers to run the Service, each of which processes data only on our instructions:
| Service | What it does | Privacy policy |
|---|---|---|
| Supabase | Database, sign-in, and private file storage. Your data is stored on servers in Canada. | supabase.com |
| Vercel | Hosts the web app and the servers the iOS app talks to. | vercel.com |
| Resend | Delivers the emails we send you — your sign-in link or one-time code, and address confirmation. | resend.com |
| Anthropic | Claude API — interprets your goal, replies in chat, and writes your nudges and plans. | anthropic.com |
| Gemini API, for the same AI features. Also Google Calendar, if you connect one. | policies.google.com | |
| Open-Meteo | Weather, air quality, and daylight for the approximate location described above. | open-meteo.com |
| PostHog | Product analytics, and session replay on the web app. | posthog.com |
Open-Meteo receives the rounded coordinates and, if you search for a city by name instead of picking a curated one, the text you typed — nothing else. If you connect a third-party fitness, wearable, or calendar account — Strava, Fitbit, Oura, Whoop, or Google Calendar — that is your own account, and that provider shares the data you authorize with us under its own privacy policy. We do not use third-party advertising or marketing SDKs.
Midnight’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Security
Your data is encrypted in transit (TLS) and at rest. Database access is protected by row-level security so your records are only readable by you and, if you have linked one, your health professional. Server-side access requires authenticated sessions verified on every request.
Retention and deletion
Three things age out on their own, whether or not you ask: short-term companion notes are deleted after 21 days, the daily environmental reading after 90 days, and our own job records after 30 days. Everything else we keep until you delete your account — your health metrics, logs, chat history, check-ins and their photos, and anything you and a linked professional wrote to each other. We do not expire them on a timer, so deleting your account is what removes them.
Our service providers keep their own operational records — analytics events, server logs — under their own retention policies, linked in the table above.
We keep your data for as long as your account exists. You can delete your account and all associated data from inside the app at any time — open Profile and tap Delete account. That deletion is immediate and permanent: it removes your goals, health metrics, logs, chat history, check-ins, progress photos, any connected fitness, wearable, or calendar accounts, and any professional links, and it cannot be undone. If you signed in with Apple, it also tells Apple to end Midnight’s access to your Apple ID. If you would rather we do it for you, email woody@mdnt.health and we will complete the request within 30 days.
Your choices
Analytics are optional. In the iOS app, open Profile and turn off Share analytics & diagnostics and nothing further is sent to PostHog from your device. The rest of the app keeps working — this setting does not affect your dashboard, your data, or your AI companion. Environmental context is optional too, and turning it off stops all location lookups as described above. You control Apple Health authorization separately, in iOS Settings, and you can disconnect any linked provider at any time from Profile.
The two permissions iOS holds rather than the app:
- Apple Health— iOS Settings › Health › Data Access & Devices › Midnight. Turn off any category, or all of them; the app keeps working without it.
- Notifications — iOS Settings › Notifications › Midnight. Turning them off stops every nudge, and the push token stops being used.
Your rights
We do not sell your personal information, and we do not share it for cross-context behavioural advertising — not your health data, and not anything else. We have never done so.
Depending on where you live (including under the California Consumer Privacy Act and state consumer-health-data laws such as Washington’s My Health My Data Act), you may have the right to:
- Know what we collect about you, and why — this page is our answer, in full.
- Receive a copy of your data.
- Correct anything about you that is wrong.
- Delete your data, which you can do yourself and immediately, as described above.
- Opt out of the sale or sharing of your personal information — there is nothing to opt out of, because we do neither.
- Withdraw consent for the collection of consumer health data.
- Not be treated differently for exercising any of these.
To exercise any of them, email woody@mdnt.health. We will respond within 45 days. We will never discriminate against you for exercising a privacy right.
Children
Midnight is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
Not a medical service
Midnight is a wellness tool, not a healthcare provider, and is not covered by HIPAA. We do not provide medical advice, diagnosis, or treatment.
Changes
If we make material changes to this policy, we will update the effective date above and notify you in the app before the changes take effect.
Contact
Midnight Health LLC, New Jersey, USA — woody@mdnt.health