Privacy Policy
My AFib Companion
Effective date: 4 August 2026
Version 1.0
This policy applies to the iPhone app My AFib Companion (shown inside the app as “AFib Companion”) and to this website, afibcompanion.com. It replaces any earlier privacy policy published at a different web address.
Read this first: what this app is, and what it is not
My AFib Companion is a wellness and record-keeping tool. It helps you write down what happened and see it in one place.
It does not diagnose, detect, monitor for, screen for, treat, cure or prevent any condition. It is not a medical device, and nothing in it is medical advice. Always talk to your doctor or another qualified healthcare professional about your heart, your symptoms and your medicines.
In an emergency, call 911 (or your local emergency number) immediately.
If you have chest pain, difficulty breathing, sudden numbness or weakness, confusion, trouble speaking or severe dizziness, call for help. Do not open this app first.
The short version
We have tried to write this in a way you can actually read. Here is the honest summary; the detail follows below.
- Your data does leave your iPhone. It is uploaded to a private database in the United States so that it is backed up and available if you change or lose your phone. It is locked to your account.
- Nobody else can read your rows. Every table uses database row-level security, so a query can only ever return rows belonging to the signed-in account.
- The analysis happens on your phone. Weekly summaries, trigger correlations and adherence analysis are calculated on the device itself. Your health data is not sent anywhere to be analysed, and it is never sent to any outside AI service. Your doctor report PDF is also built on the phone.
- We do not sell your data. Ever. To anyone. There is no advertising in this app, no analytics SDK, no tracking SDK and no data broker.
- You can take it all with you, and you can delete it, from inside the app, at any time — including if your subscription has lapsed.
- This website tracks nothing. No cookies, no analytics, no fonts or scripts loaded from anyone else’s server.
1. Who is responsible for your data
My AFib Companion is made and run by one person — a solo developer trading as BGW in Nature. There is no company behind it, no marketing department and no data science team.
For the purposes of the UK and EU General Data Protection Regulation, BGW in Nature is the data controller for the information described in this policy. Under California law, we are the business that collects it.
How to reach us about anything in this policy:
Email bgwinnature@gmail.com
Please put “Privacy” in the subject line so it is not missed. This is a real inbox read by the developer, not a ticketing system.
2. What we collect, and why
Everything below is either typed in by you or read from Apple Health with your permission. We do not buy data about you, and we do not receive data about you from data brokers, advertisers or social networks.
2.1 Account and sign-in
| What | Why |
|---|---|
| Email address | To create your account, sign you in, and reset your password |
| Password (stored only as a salted hash, never in readable form) | To sign you in, if you chose email sign-in |
| The identifier issued by Sign in with Apple, and the email address Apple passes on (which may be a private relay address if you chose to hide yours) | To sign you in, if you chose Apple sign-in |
| An account ID (a random UUID) | To attach your records to you and to nobody else |
| Session tokens | To keep you signed in between launches |
Authentication is handled by Supabase Auth. We never see your password.
2.2 Your profile
Display name, AFib type, diagnosis date, date of birth, biological sex, and whether you have finished onboarding.
Why: to label your records, to show your age and AFib type on the emergency card and doctor report, and to fill in the CHA2DS2-VASc educational calculator.
Every one of these is optional except the account itself. If you would rather not give your date of birth, leave it blank; the app still works.
2.3 Emergency contact — someone else’s information
If you fill it in, we store an emergency contact name and phone number.
We are calling this out separately because this is usually a third party who has never used the app and has never agreed to anything with us. Please see section 6 for how we handle it and what we ask of you.
2.4 AFib episodes
Start time, end time, severity, notes, and whether it was created from an Apple Health event. Each episode can also carry:
- Symptoms — type and severity
- Suspected triggers — type, intensity and notes
Why: this is the core record the app exists to keep, and the basis of your doctor report.
2.5 Medications
Medication name, generic name, dosage, frequency, category, scheduled times, pill count, refill reminder threshold, whether it is active, whether it is a “pill-in-the-pocket” medicine, and your notes.
And for every dose: the medication log — scheduled time, time actually taken, status (taken, skipped, missed, pending) and notes.
Why: to show your schedule, send your reminders, and calculate the adherence figures in your report.
2.6 Daily check-ins
Mood, alcohol, caffeine, sleep quality, hours slept, stress, exercise minutes, hydration and notes — one entry per day.
Why: these are the inputs the trigger-correlation analysis compares against your episodes.
2.7 Health readings from Apple Health
Covered in full in section 4. In short: the app reads a range of heart and activity data from Apple Health to show you on screen, and uploads a subset of it — heart rate, resting heart rate, heart rate variability and step count — to your account.
2.8 Insights
The weekly summaries, correlation notes and adherence observations that the app writes. These are generated on your iPhone and then stored in your account like any other record, so they survive a phone change.
Why: so your history of insights is not lost, and so you can read them on another device.
2.9 Subscription information
My AFib Companion is subscription-only: a 30-day free trial, then $9.99/month or $59.99/year. There is no free tier.
Payment is taken by Apple. We never see your card number, billing address or Apple ID password.
To know whether your subscription is active, we use RevenueCat. RevenueCat receives your account ID (the random UUID above) and your purchase and renewal history from Apple, plus the ordinary device and app information their SDK collects to attribute a purchase — such as app version, device model, operating system version and store country.
RevenueCat does not receive any of your health data. No episode, medication, check-in, profile or Apple Health record is ever sent to them.
2.10 Things on your device that never reach us
- Face ID / Touch ID app lock. iOS does the check and tells the app yes or no. Your fingerprint and face data never leave Apple’s secure hardware and are never available to us.
- Reminders. Medication, check-in and weekly-summary reminders are scheduled and delivered by iOS on your phone. There is no push server, and the content of a reminder is not sent anywhere.
- Widget data. A small summary — your latest heart rate, your next doses — is stored in a shared container on the device so the home screen widgets can draw. It stays on the device.
- Your doctor report PDF and emergency card. Built on the phone. They go wherever you send them and nowhere else.
- Your CSV export. Written to a temporary file on your phone, protected by iOS file encryption, and shared only by you.
2.11 What we never collect
No precise location. No contacts. No photos. No microphone or camera access. No advertising identifier. No browsing or app-usage tracking. No fingerprinting. There is no advertising SDK, no analytics SDK and no crash-reporting SDK in this app — we checked, and there is nothing to disclose.
If you have switched on Share iPhone Analytics → Share with App Developers in your iOS Settings, Apple may give us aggregated, de-identified crash and energy reports through App Store Connect. That is Apple’s mechanism, controlled by you in iOS Settings, and it does not include your health records. You can turn it off at Settings → Privacy & Security → Analytics & Improvements.
3. What we do with it
We use your information only to:
- run the features you asked for — logging, reminders, check-ins, insights, reports, widgets, emergency card;
- keep your records in sync and backed up across your devices;
- generate your doctor-ready PDF and CSV export when you ask for one;
- check whether your subscription or trial is active, and unlock the app accordingly;
- answer you when you email for support;
- keep the service secure, and investigate abuse or technical faults;
- comply with the law where we are required to.
We do not use your information to advertise to you, to profile you for anyone else, to train any AI model, or to build any product other than the one you are using.
Automated decisions. The app makes no automated decision that has a legal effect on you or anything similar. The insights are informational observations calculated on your phone. They are not diagnoses, not predictions, and not a reason to change anything you do without speaking to your doctor.
4. Apple Health (HealthKit)
If you grant permission, the app reads these types from Apple Health:
Heart rate · Resting heart rate · Heart rate variability (SDNN) · Electrocardiogram (ECG) results · Atrial fibrillation history / AFib burden (iOS 16 and later) · Irregular heart rhythm notifications · High heart rate notifications · Low heart rate notifications · VO2 max · Blood oxygen · Sleep analysis · Step count · Active energy burned · Apple exercise time
You can grant or refuse each type individually, and change your mind at any time in the Health app under Sharing → Apps. Refusing does not lock you out; the app simply shows less.
What we upload, and what we do not
Uploaded to your account: heart rate, resting heart rate, heart rate variability (SDNN) and step count. For each reading we store the type, the value, the unit, the start and end time, and the name of the device that recorded it (for example, “Apple Watch”). Readings are sent in batches of up to 100.
Not uploaded — these stay on your iPhone: ECG results and their details, irregular rhythm notifications, high and low heart rate notifications, AFib burden, VO2 max, blood oxygen, sleep analysis, active energy and exercise time. The app reads them to show you on screen and to include in your on-device report. They are not sent to our database.
Apple’s rules, which we follow
- HealthKit data is used only to provide the health tracking, insight and reporting features inside the app.
- HealthKit data is never used for advertising or marketing, or for any similar service.
- HealthKit data is never sold, rented or otherwise disclosed to data brokers, information resellers, advertising networks or anyone conducting data mining.
- HealthKit data is never disclosed to a third party without your explicit consent, except where it is strictly necessary to provide a function you have asked for — which, in practice, means storing it in your own account with our hosting provider.
- HealthKit data is encrypted in transit and at rest.
The app only ever reads from Apple Health. It never writes anything into it. Nothing the app does can change, add to or delete your Apple Health records.
And the other direction: deleting your app account does not delete anything in Apple Health. Apple Health is yours and is managed separately, in the Health app.
5. Where the thinking happens
This matters enough to state plainly, and to state accurately.
Your data does leave your device. It is uploaded to a private, access-controlled database so you have a backup and can move to a new phone. We will not tell you otherwise. An earlier version of our App Store description said your data never left your device. That was wrong, it has been withdrawn, and we are not going to repeat it.
The analysis genuinely does not leave your device. Weekly summaries, trigger correlations and medication adherence analysis are computed on the iPhone itself, by analysis code that ships inside the app and runs locally. It makes no network call. No health data is sent to OpenAI, Google, Anthropic, or any other AI or analytics provider, because no such service is used at all.
Your doctor report PDF is likewise assembled on the phone.
6. Your emergency contact
If you enter an emergency contact, you are giving us the name and phone number of another person, and that person has probably never heard of us.
Here is exactly what happens to it:
- It is stored with your profile, in your account, protected the same way as everything else.
- It is shown on your emergency card, on your device.
- We never call, text, email or otherwise contact that person. The app has no ability to do so. The number is there so that you, or someone helping you, can read it off the screen.
- It is not shared with anyone, not used for any other purpose, and not used to build any kind of contact list.
We rely on legitimate interests as the legal basis for holding it (UK/EU GDPR Article 6(1)(f)) — specifically, your interest and theirs in having that number available if you are unwell, which is difficult to achieve any other way and carries very little risk to them.
What we ask of you: please tell the person you have listed them, so it is not a surprise. And if they ask you to remove them, you can clear both fields in Profile → Edit Profile and the record is overwritten. If that person contacts us directly at bgwinnature@gmail.com and asks to be erased, we will remove their name and number from the account it appears in.
7. Legal bases for processing (UK / EU GDPR)
If you are in the UK, the European Economic Area or Switzerland, we must tell you the legal basis for each use.
| What we process | Legal basis |
|---|---|
| Account, sign-in, sync, subscription status, support | Article 6(1)(b) — necessary to perform our contract with you |
| Health data: episodes, symptoms, triggers, medications and logs, check-ins, Apple Health readings, insights, AFib type, diagnosis date | Article 9(2)(a) — your explicit consent, given when you grant Health permissions and when you choose to record this information; together with Article 6(1)(b) |
| Emergency contact name and number | Article 6(1)(f) — legitimate interests (see section 6) |
| Security, fault diagnosis, preventing abuse | Article 6(1)(f) — legitimate interests in keeping the service safe and working |
| Meeting legal or regulatory obligations | Article 6(1)(c) |
You can withdraw consent at any time. Turn off Health permissions in the Health app, stop entering data, delete individual records, or delete your account outright. Withdrawing consent does not make our earlier processing unlawful, but it stops it going forward.
Do you have to provide any of this? Only an email address (or Sign in with Apple) and a subscription. Everything else is voluntary — but an app for logging AFib episodes is not much use if you do not log any.
8. Who else touches your data
These are our processors and sub-processors. Each one is bound by a contract that limits them to acting on our instructions. None of them is permitted to use your data for their own purposes.
| Who | What they do | What they receive |
|---|---|---|
| Supabase, Inc. | Hosts the PostgreSQL database and runs authentication | All the account, profile, episode, medication, check-in, insight and health-reading data described above |
| Amazon Web Services (sub-processor to Supabase) | Provides the physical servers and storage, in the US West (Oregon) region | The same data, encrypted at rest on their infrastructure |
| Apple Inc. | App Store distribution, subscription billing and receipts, the HealthKit framework on your device, local notifications | Your purchase and subscription record, per Apple’s own privacy policy. Apple does not receive your health records from us |
| RevenueCat, Inc. | Tells the app whether your subscription is active | Your account ID and purchase history, plus standard device and app information. No health data |
| Cloudflare, Inc. | Hosts this website only | The requests your browser makes to afibcompanion.com. We send no account, profile or health data to Cloudflare, and nothing you enter in the app is stored there |
That is the complete list. No advertising network, no analytics provider, no AI vendor, no data broker, no CRM, no email marketing platform.
We do not sell your personal information, and we never have. We do not share it for cross-context behavioural advertising. We do not disclose it to anyone except the processors above, and except where we are legally compelled to — for example, by a valid court order. If that ever happens and we are permitted to tell you, we will.
If the app is ever transferred to someone else, your data may transfer with it. If that happens we will tell you first, through the app and by email, and this policy will continue to apply until you are given the chance to review a new one or delete your account.
9. Where your data is stored, and international transfers
Your data is stored on servers in the United States, in the AWS US West (Oregon) region.
If you are in the UK, the EEA or Switzerland, this means your personal data — including health data, which is special category data — is transferred to the United States, a country that has not received a full adequacy decision covering all recipients.
We rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum, where the UK GDPR applies) as incorporated into our data processing agreements with Supabase and RevenueCat, together with the technical protections described in section 10 — encryption in transit and at rest, and row-level access control.
You can ask us for more information about these safeguards at bgwinnature@gmail.com.
10. How your data is protected
- Encrypted in transit. All traffic between the app and the database uses TLS.
- Encrypted at rest. The database is stored on AES-256 encrypted disks.
- Row-level security. Every table carries a policy that ties each row to one account ID. A request signed in as you can only ever return, change or delete your own rows. It is enforced by the database itself, not by the app, so a bug in the app cannot bypass it.
- Authentication. Handled by Supabase Auth. Passwords are stored hashed and salted. Sign in with Apple uses a single-use, hashed nonce for each attempt.
- On your device. Local records are held in Apple’s SwiftData store, protected by iOS device encryption. Your CSV export is written with complete file protection, so it cannot be read while the phone is locked. You can add a Face ID or Touch ID lock to the app itself from the More tab.
- Minimum access. One person — the developer — has administrative access, and uses it for maintenance and support only.
No system is perfectly secure, and we will not pretend otherwise. We cannot guarantee that a transmission or storage system will never be compromised. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and we will tell you directly and without undue delay where the law requires it or where it is the right thing to do.
Things you can do that genuinely help: use a password you use nowhere else, turn on the app’s Face ID lock, and keep iOS up to date.
11. How long we keep it
| Data | How long |
|---|---|
| Account, profile and all health records | For as long as your account exists. We do not delete your history because a subscription lapsed |
| After you delete your account | Removed from the live database straight away (see section 12) |
| Encrypted database backups | Daily encrypted backups on a rolling 7-day window; deleted records age out of backups within 7 days |
| Subscription and purchase records | Kept by Apple and RevenueCat under their own policies and retention rules, which we do not control. These are also financial records they may be required to retain |
| Support emails | Kept for up to 24 months, so we can follow up on a problem, then deleted |
If your subscription lapses, the app locks — but your data is not deleted. It is still yours, and you can still export it and still delete your account. Locking you out of your own health history would be indefensible.
12. Getting your data out, and deleting it
Both of these work from inside the app, at any time, including while unsubscribed.
Export
More → Export Data. Choose 30 Days, 90 Days, 1 Year or All Time. You get a CSV file you can open in Numbers, Excel or Google Sheets, or send to your doctor. It contains:
- Episodes — ID, start time, end time, severity, whether auto-created, notes
- Medications — ID, name, dosage, frequency, category, active status, notes
- Medication logs — ID, medication, scheduled time, time taken, status, notes
- Daily check-ins — ID, date, mood, alcohol, caffeine, sleep quality, hours slept, stress, exercise minutes, hydration, notes
- Health readings — ID, type, value, unit, date, source
A few things are not in the CSV: your profile fields, individual symptom and trigger rows, and the text of generated insights. If you want those too — or you want everything in a different format — email bgwinnature@gmail.com and we will put a complete copy together for you at no charge.
You can also generate a doctor report PDF at any time from the Insights tab.
Delete
More → Delete Account. You will be asked to type DELETE and confirm once more, because it cannot be undone.
What is deleted immediately: your profile row — and because every table is linked to it with a cascading delete rule, that removes your episodes, symptoms, triggers, medications, medication logs, daily check-ins, health readings and insights from the database at the same time. Everything stored locally on the phone is also purged: the local database, app settings, widget data and cached files.
What is not deleted, and what you need to know:
- Your sign-in record. Your email address, and either your hashed password or the identifier issued by Sign in with Apple, is held separately by Supabase Auth. The in-app deletion does not currently erase that record — it can only be removed server-side. Email bgwinnature@gmail.com and we will delete it within 30 days. We are working on making this automatic, and we would rather tell you about the gap than let you assume it is not there. Until it is removed, signing in again simply creates a new, empty account; none of your old records come back.
- Encrypted backups. Deleted records may persist in automated daily backups until they age out, which takes at most 7 days.
- Your Apple Health data. Untouched, and still yours, in the Health app.
- Your subscription. Deleting your account does not cancel it. Cancel separately in Settings → [your name] → Subscriptions on your iPhone, or you will keep being billed.
- Apple’s and RevenueCat’s purchase records. Retained under their own policies.
Please export before you delete. There is no way to recover it afterwards. Step-by-step deletion instructions.
13. Your rights
If you are in the UK, EEA or Switzerland
You have the right to:
- Access a copy of the personal data we hold about you
- Correct anything inaccurate or incomplete
- Erase your data (“right to be forgotten”)
- Restrict how we process it in certain circumstances
- Object to processing based on legitimate interests, including the emergency contact
- Portability — receive your data in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible
- Withdraw consent at any time, without affecting processing already carried out
- Not be subject to a decision based solely on automated processing with legal or similarly significant effects — as noted, we make none
Most of these you can exercise yourself, immediately, in the app: Profile to correct, Export Data for access and portability, Delete Account for erasure. For anything else, email bgwinnature@gmail.com.
We will respond within one month. If a request is genuinely complex we may extend that by a further two months, and we will tell you within the first month if that happens. There is no charge unless a request is manifestly unfounded or excessive.
Complaints. If you think we have got it wrong, please tell us first — it is usually the fastest fix. You also have the right to complain to your local supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). In the EEA it is the data protection authority for the country where you live or work.
If you are in California
Under the CCPA as amended by the CPRA, you have the right to:
- Know what personal information we collect, use, disclose and retain
- Access a copy of it, and know the categories of source and recipient
- Correct inaccurate personal information
- Delete your personal information
- Opt out of sale or sharing — there is nothing to opt out of, because we do neither
- Limit the use of sensitive personal information — see below
- Not be discriminated against for exercising any of these rights. Nothing about your price, your trial or your access changes because you made a request
Categories we collect, using the statutory labels:
| Category | Examples in this app |
|---|---|
| Identifiers | Email address, display name, account ID, Apple sign-in identifier |
| Customer records (Cal. Civ. Code §1798.80(e)) | Name, emergency contact name and telephone number |
| Protected classifications | Date of birth (age), biological sex |
| Commercial information | Subscription and purchase history |
| Sensitive personal information | Account log-in credentials; personal information collected and analysed concerning health |
| Inferences | The insights generated on your device from your own records |
We do not collect biometric information, precise geolocation, internet activity, audio or visual information, employment or education information.
Sources: you; Apple Health, with your permission; Apple and RevenueCat, for subscription status.
Purposes: the operational purposes in section 3.
Disclosure: we disclose personal information to the service providers named in section 8 for business purposes only.
Sale and sharing: we have not sold and have not shared personal information, as those terms are defined by the CCPA, in the preceding 12 months, and we do not intend to. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.
Sensitive personal information: we use it only for the purposes permitted by Cal. Code Regs. tit. 11 §7027(m) — performing the service you asked for and keeping it secure. We do not use or disclose it to infer characteristics about you. The right to limit its use therefore does not apply here. Regardless, you can delete all of it yourself from inside the app.
Retention: as set out in section 11.
How to exercise a right: email bgwinnature@gmail.com. We verify requests by matching the email address you write from to the one on the account, and may ask you to confirm details only the account holder would know. An authorised agent may act for you with your written permission, and we may still ask you to verify your identity directly. We respond within 45 days, extendable once by another 45 days where necessary.
Other US states
If you live in a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and others — you have broadly similar rights of access, correction, deletion, portability and opt-out, and a right to appeal a refusal. Email us and we will honour them. If we refuse a request, we will explain why and tell you how to appeal; if we deny an appeal, we will tell you how to contact your state Attorney General.
14. Children
My AFib Companion is rated 17+ and is intended for adults managing their own heart health. It is not directed at children.
We do not knowingly collect personal information from anyone under 17. If we learn that we have, we will delete the account and its data promptly. If you are a parent or guardian and believe your child has created an account, email bgwinnature@gmail.com and we will take care of it.
15. This website
afibcompanion.com is a set of plain static pages.
It sets no cookies. It runs no analytics. It loads no fonts, scripts, images or stylesheets from any other server — everything is served from this domain, so simply opening this page does not tell any third party that you did. We have deliberately enabled no web analytics of any kind.
Our website host, Cloudflare, processes your IP address and basic request information to deliver the page and protect the site from attack, as any web host must. We do not receive, review or retain those logs.
There is nothing here to opt out of, and no preference signal for us to honour, because there is nothing being collected.
16. Changes to this policy
We may update this policy — for example, if a feature changes what data is handled.
When we make a material change, we will update the effective date at the top, notify you inside the app, and email you where we hold an address for you, before the change takes effect. For minor changes such as clarified wording or a corrected typo, we will update the effective date only.
If a change means we need to process your health data in a genuinely new way, we will ask for your consent again rather than assume it.
Previous versions are available on request.
17. Contact us
Questions, corrections, requests, or a suspicion that something here does not match what the app actually does:
Email: bgwinnature@gmail.com
One person reads that inbox. If something in this policy is wrong or unclear, please tell us — we would rather fix it than defend it.
A final reminder. My AFib Companion is a wellness and record-keeping tool. It is not a medical device and it does not provide medical advice, diagnosis or treatment. Do not use it to decide whether you need care.
If you think you are having a medical emergency, call 911 or your local emergency number now.