Headwater Privacy Policy
Effective date: July 10, 2026
Last updated: July 10, 2026
Headwater is an educational preventive-health app for iOS made by Matthew John Wagner, an individual developer and board-certified family medicine physician (“we,” “us,” “I”). This policy describes exactly what Headwater does with your information. It is intentionally short, because the honest answer is: your data stays on your device.
The short version
- We do not collect your data. Headwater has no servers, no accounts, no sign-in, no analytics, no advertising, and no third-party data SDKs. The app makes no network requests.
- Everything you enter — your health profile, habit logs, notes, and anything read from Apple Health — is stored only in a local database on your iPhone.
- Nothing is transmitted off your device unless you choose to share it (for example, exporting a PDF report with the iOS share sheet).
- We do not sell, share, rent, or trade any personal information, because we never receive any.
- We do not use your data for advertising, tracking, or profiling, and we do not build profiles from it — all personalization happens on your device.
When you use Headwater, the following is saved in a local database (SQLite) inside the app’s private storage on your iPhone:
- Health profile you enter: age, sex assigned at birth, gender identity (optional free text), life stage, tobacco and alcohol history, height and weight, sexual health history (optional), family health history, medications, and wellness goals.
- Activity you record in the app: habit logs and optional notes, screening completions, sleep audit answers, self-reported habits, challenge progress, and acknowledgments of educational content.
- Data from Apple Health (optional): if you grant permission, Headwater reads steps, active energy, resting heart rate, heart-rate variability, dietary energy, body weight, sleep, workouts, and mindful minutes, and stores them locally to pre-fill habit logs and show trends. Headwater only reads from Apple Health; it does not write to it. Apple Health data is never used for marketing or advertising and never leaves your device (this is also a requirement Apple places on all apps).
- App settings: on-device flags such as whether you accepted the disclaimer, notification preferences, and a sync timestamp.
None of this is transmitted to us or to anyone else.
What leaves your device, and only if you choose
- PDF reports. You can generate a PDF summary of your prevention plan (it can include your age, sex assigned at birth, plan items, and the profile-based reasons they apply to you). The PDF is created on your device and handed to the iOS share sheet — you choose where it goes (AirDrop, Mail, Files, print, etc.). We never see it.
- Links to sources. Evidence citations (for example, USPSTF or CDC pages) open in your browser. That is an ordinary web visit governed by those sites’ policies; the app itself sends nothing.
Purchases
Headwater offers one optional one-time in-app purchase (a lifetime unlock for PDF reports). The purchase is processed entirely by Apple. We do not receive your name, payment details, or Apple ID. See Apple’s privacy policy for how Apple handles purchase data.
Notifications
Reminders (screenings coming due, habit nudges) are local notifications scheduled on your device. There is no push-notification server. Reminder text is deliberately generic so specific health topics do not appear on your lock screen.
Data retention and deletion
Your data stays on your device until you delete it. You can:
- Delete everything in-app: Profile → Delete All Data permanently erases your profile, logs, health data, and progress from the device.
- Delete the app: removing Headwater removes its entire database.
- Revoke Apple Health access: Settings → Privacy & Security → Health → Headwater (data already copied into Headwater is removed by option 1 or 2).
Because we hold no copies, there is nothing for us to delete on a server, and no way for us to recover your data once you erase it. See our Data Deletion page for details.
Consumer health data (Washington, Nevada, and similar state laws)
Some states, including Washington (My Health My Data Act) and Nevada (SB 370), give consumers rights over “consumer health data.” Headwater’s design means we do not collect, share, or sell consumer health data as those laws define it — the data never reaches us. To the extent those laws apply:
- Categories of health data processed on-device: health profile, habit and lifestyle logs, family history, medications, sexual health information, and Apple Health readings, as listed above.
- Purpose: solely to provide the app’s educational features on your device.
- Sharing/selling: none. No affiliates, processors, or third parties receive it.
- Your rights: you can access everything in the app itself, and delete everything via Delete All Data. There is no server-side copy to request.
- Contact for privacy questions or rights requests: worrier.last0f@icloud.com.
California residents
We do not collect, sell, or share personal information as defined by the CCPA/CPRA, and we do not process personal information for cross-context behavioral advertising. If our practices ever change, this policy will be updated first and the App Store privacy label will be revised.
Children
Headwater is intended for adults 18 and older and enforces this in onboarding. It is not directed at children, and we do not knowingly process children’s data.
Security
Your data is protected by iOS’s built-in device encryption and app sandboxing. The app ships with no remote endpoints, which removes the most common ways health data leaks. No system is perfect — protecting the device itself (passcode, Face ID) is the most important safeguard for locally stored data.
Changes to this policy
If Headwater ever adds features that change these practices (for example, optional cloud sync), we will update this policy before the feature ships, update the App Store privacy label, and clearly note the change in the app’s release notes.
Questions or privacy requests: worrier.last0f@icloud.com