What to check before a health app sees your prescription

Two things most people assume about a health app are not true. The first is that medical privacy law covers it, for the great majority of apps it does not, and the FTC says so plainly. The second is that the App Store privacy label answers the question "does this app respect my privacy": it answers a narrower question, in words with specific definitions. This is what those words mean and what to check instead.

HIPAA almost certainly does not apply

This is the misconception worth clearing first, because it is load-bearing. The FTC's own guidance states that many companies collecting health information ("whether it's a fitness tracker, a diet app, a connected blood pressure cuff, or something else") are not covered by HIPAA. HIPAA follows the healthcare relationship: your clinic, your hospital, your insurer. An app you downloaded is generally none of those.

What does apply, in the United States, is the FTC's Health Breach Notification Rule, which exists precisely to fill that gap. It requires organisations not covered by HIPAA to notify their users, the FTC and in some cases the media when there has been a breach of unsecured, individually identifiable health information — "without unreasonable delay" and no later than 60 days after discovery.

Note what that is and is not. It is a rule about telling you after something has gone wrong. It is not a rule that limits what an app may collect while everything is going right.

What the App Store label actually says

The label has three sections, and the middle one is where the meaning hides.

  • Data Used to Track You. Apple's definition of tracking is specific: linking data collected in the app about a user or device with third-party data (data from apps, websites or offline sources the developer does not own) for targeted advertising or advertising measurement, or sharing it with a data broker.
  • Data Linked to You. Collected and tied to an identity. Apple's rule is that data is treated as linked unless the developer strips direct identifiers before collection and does not re-link it afterwards. The default is linked.
  • Data Not Linked to You. Collected, but with that linkage genuinely broken.

And the clause that most changes how you read a label. Apple's own list of what is not tracking begins: "When the data is linked solely on the end-user's device and is not sent off the device in a way that can identify the end-user or device."

So an app can show an almost empty tracking section and still send a great deal about you somewhere. "Not tracking" means "not combined with third-party data for advertising or handed to a broker": a narrower promise than "we do not collect this".

The five questions worth asking

  1. Does it require an account? An account is the mechanism that turns records into records-about-a-person on someone else's server. No account is not a feature list item; it is the shape of the whole thing.
  2. Does it sync to a cloud, and can that be turned off? "Backup" and "sync" are different promises. One is a file you hold; the other is a copy someone else holds.
  3. What does the privacy label list under Health? Apple's Health category covers "any other user provided health or medical data", so a medication name typed into an app belongs there. If the label is silent on Health and the app records medications, one of the two is wrong.
  4. Does the policy name what is collected, or describe it? "We may collect certain information to improve your experience" is not a list. A policy that can be checked names things.
  5. What happens when you delete the app? On a device-only app, that is the deletion. Where there is a server, deleting the app and deleting the account are separate acts, and only one of them is in your hands from the home screen.

Dozify's own answers, so this page is not asking questions it dodges. No account, no cloud sync, no in-app ads. Health records stay in the app's own storage on the device; backup writes an encrypted file you keep. Anonymous usage statistics are collected (which screens are used, whether something crashed) and they never carry a medication name, a symptom or a weight. One more thing does leave: a measurement of whether an install came from one of our own App Store or Meta campaigns, which runs behind Apple's tracking permission and contains none of your records. Delete the app and the records go with it. The detail is in the privacy policy and the KVKK notice, and the reasoning is on the privacy page.

What this page will not do

Name another app and imply something about what it does with data. We have not audited anyone else's servers, we cannot, and an accusation dressed as a comparison is marketing rather than information. The questions above work on any app, including this one: that is the point of writing them as questions.

No account to make, nothing to sync

Your doses, weight and symptoms stay on the phone. The app opens straight into your own data, and deleting it is the deletion.

Download the app How privacy works here →

Questions

Isn't my health data protected by law?

Some law applies, but probably not the one you are thinking of. The FTC states that many health apps are not covered by HIPAA; what covers them in the US is the Health Breach Notification Rule, which is about being told after a breach rather than about limiting collection beforehand.

The label says "Data Not Collected". Is that enough?

It is the strongest thing a label can say, and it is a developer's own declaration rather than an audit. Read it alongside the privacy policy: a policy that names what is collected and a label that says nothing is collected should agree, and where they do not, the policy is the more detailed document.

What is the difference between backup and sync?

Who holds the copy. A backup is a file you produce and store; sync is a copy kept on someone's server so devices can agree with each other. Both are useful; only one of them means your records exist somewhere you do not control.

Does "no ads" mean nothing ad-related happens?

Not necessarily, and it is worth being precise. An app can have no in-app ads and still measure whether an install came from an ad it ran elsewhere. Those are different things; a policy worth trusting says which one it means. Ours says both, in as many words.

How do I check any of this myself?

Open the App Store listing and read the privacy section, then open the app's privacy policy and see whether the two describe the same app. Then try the practical test: can you use it without making an account, and does deleting it take the data with it?

Educational information, not legal or medical advice. Dozify is a personal tracking app, not a medical device. Privacy law differs by country and changes; this page describes publicly published rules and definitions and does not assess any specific app other than this one.