Skip to content
Perigee
How it worksSignalsScienceLearnAboutSupport Get the app
Perigee
How it worksSignalsScienceLearnAboutSupport Get the app
Legal

Privacy Policy

Effective July 17, 2026 · Last updated July 17, 2026

Perigee reads supported Apple Watch signals and summarizes the available data each morning. Because that means handling sensitive health information, this policy sets out — in plain language — exactly what we collect, why, who else touches it, and the control you keep.

The short version. Your Apple Health data is read and compared with your baseline on your iPhone. If you choose cloud AI, Perigee sends a pseudonymous derived summary and quota or tier identifiers — not your raw Apple Health records, name, email or free-text notes. The Perigee Worker does not persist the request body in its application storage, but the upstream API gateway and AI provider process it and their retention terms apply. Separately, if you choose Send feedback, the text and optional contact you enter are stored for the team as described in §7. We never sell your health data, use it for advertising, or write anything back to Apple Health.

1. Who this policy covers

Perigee (“we”, “us”, “our”) operates the Perigee iOS app and this website, and this policy applies to both. It describes how we handle information about you. If you only browse this website, we do not place advertising cookies or ask for health information. Our hosting and security provider still processes standard request and connection metadata needed to deliver and protect the site, such as IP address, request time, requested URL and browser or device information. We also measure how this website is used with a cookieless analytics setup — no cookies, no on-device storage, no advertising identifiers — described in §7.

2. Apple Health (HealthKit) data — the heart of the app

With your explicit permission, Perigee reads the following data from Apple Health. iOS asks you to approve each category separately, and you can change or revoke any of them at any time in Settings → Privacy & Security → Health → Perigee or in the Apple Health app. Perigee requests read-only access — it never writes to, or changes, your Apple Health data.

What we readWhy
Heart rate variability (HRV)To compare overnight HRV readings with your own recent baseline.
Resting heart rate & heart rateTo compare available heart-rate samples with your usual range.
Wrist temperature (Series 8+)To compare a non-specific, baseline-relative overnight temperature trend.
Sleep analysisTo describe your night — duration, stages and awakenings — against your baseline.
Respiratory rateAdditional overnight context for your morning read.
Menstrual flow & cycle notificationsTo frame signals in the context of your cycle, where available.

How your Apple Health data is used

  • Computed on your iPhone. The math that turns your readings into a baseline, a deviation and a status word runs locally on your device.
  • Only to serve you. It is used solely to generate your morning briefing, your signal panel, your trends, weekly reports and the doctor-ready summary you can export.
  • Never for advertising. We do not use Apple Health data — or any health information — for advertising, marketing, or data-mining, and we never sell it. (This is also required by Apple.)
  • Not used by Perigee to train AI. Perigee does not train a model on your health data. Anthropic says commercial API inputs and outputs are not used for model training by default unless the customer explicitly opts in; that training policy is separate from provider retention described in §4 and §10.
  • Not in iCloud. Health summaries Perigee creates are stored locally and are explicitly kept out of iCloud sync.

3. Information you enter yourself

Symptoms and hormone-therapy (HRT) notes you log are yours. They are stored on your device alongside your signals so Perigee can line them up over time. HRT logging is a context field only — Perigee never recommends starting, stopping, or changing any medication.

The in-app Send feedback form is a separate, optional channel. If you submit it, we receive the message you wrote verbatim and any contact address you chose to add. Please do not include health details or other sensitive information that are not needed to explain the bug or idea. The feedback fields and storage are described in §7.

4. Optional cloud AI (briefings, first-week reveal & weekly reports)

Perigee can write everything entirely on your device. If you opt in to cloud AI for richer language, three features use it: your daily morning briefing, the first-week “reveal” during onboarding, and your weekly report. Here is exactly what each sends:

  • The daily briefing sends the available values, baselines, deviation bands and confidence for HRV, resting heart rate, sleep, wrist temperature and sleeping respiratory rate; sleep duration, stages, awakenings and wear coverage; the overall confidence, status and red-flag indicator; cycle phase; your age band, self-reported stage, HRT status and goals; your selected tone and device locale; symptoms logged in the last seven days as type, intensity and days ago; and, when available, one reduced first-week trend.
  • The first-week reveal sends one reduced historical finding: the signal, confidence tier, window length and change; the types of symptoms logged in that window; your age band and self-reported stage; and your device locale. It does not send daily raw readings.
  • The weekly report sends up to seven computed daily feature summaries, the symptom–signal patterns Perigee found, this week’s and the prior week’s symptom type/count comparison, your HRT status and days logged where applicable, and your device locale.

Which identifiers accompany a request depends on the feature: an install identifier (to count usage against your plan) accompanies all three; the account/tier identifier (to check free / trial / Plus, a random string — not your name, email, or Apple ID, though it equals the identifier your subscription is keyed to if you have saved your account) accompanies the daily briefing and weekly report but not the first-week reveal. The specific fields each feature sends are listed above. In every case, regardless of feature:

  • Perigee never sends your name or email, your raw Apple Health records, or free-text notes — only computed statistics and the context you chose (age band, stage, HRT status, logged symptoms), and only the subset each feature needs.
  • The payload is sent encrypted through the Perigee Worker and an upstream API gateway to Anthropic to generate the requested text. The Perigee Worker does not persist the request body in application storage; it keeps only the separate counters needed for quota and tier enforcement.
  • The gateway may apply its own processing and retention terms. Anthropic’s standard API policy says inputs and outputs are automatically deleted from its backend within 30 days, subject to stated exceptions such as usage-policy enforcement or legal requirements, unless a different agreement applies. Zero data retention is a separate, approved arrangement and is not assumed here. See Anthropic’s standard retention policy and zero-data-retention scope.
  • Anthropic says it does not use commercial API inputs or outputs for model training by default unless the customer explicitly reports the material or otherwise opts in. See Anthropic’s commercial training policy.
  • You can turn this off and stay fully on-device at any time in You → AI & privacy.

5. Account & sign-in

You can start using Perigee without creating a named account. Behind the scenes, Firebase Authentication provides a pseudonymous account identity; RevenueCat keys subscription status to it where applicable. If you choose to save your account with Sign in with Apple or Google — so it survives a reinstall or new device — we store the opaque account identifier those services return. We do not receive your Apple/Google password. Daily and weekly cloud-AI requests may carry the stable pseudonymous account/tier identifier described in §4, so those requests can be associated with the same app account and subscription inside our systems even though the payload does not include your name or email.

6. Subscriptions & payments

Perigee Plus is sold through the Apple App Store. Apple processes your payment — we never see your card details. We use RevenueCat to manage subscription status, keyed to your pseudonymous app-account identifier, so the app knows whether Plus is active. No health data is shared for billing.

7. Diagnostics, product analytics & feedback

  • Crash reports (Firebase Crashlytics): if the app crashes, we collect a stack trace and basic device state to fix the bug. These reports contain no health data and none of your text.
  • Pseudonymous product analytics (PostHog): we record non-health usage events (e.g. which screens are viewed, whether onboarding completed, and bounded purchase or restore steps) under a random per-install identifier to improve the app and its subscription flow. Purchase events may say annual or monthly, trial or standard, and success, cancellation or a broad error category; they do not include a price, transaction ID, account UID or payment details. The same install identifier can select an A/B-test variant, such as when to show an optional rating prompt. These events do not include health data, free-text notes, your name or your email, and you can opt out in the app.
  • Website analytics (PostHog): this website sends a small, cookieless usage beacon — the page viewed, the referring site, any campaign tags on the link you followed, and taps on the App Store buttons — under a random identifier that changes with every page view and exists only in memory. It sets no cookies, uses no local storage, and honors the Global Privacy Control and “Do Not Track” browser signals by not sending anything at all. Connection metadata such as IP address is processed to derive an approximate, country-level location, as part of the delivery and security handling described in §1. No health information is involved — this website never asks for any.
  • Feedback you choose to send: the feedback message, optional contact address, app version, device locale, submission time and random per-install quota identifier travel through the Perigee Worker and are stored in our Notion feedback database. The message is free text, so it contains whatever you choose to write; it is not sent to Anthropic and is not a PostHog analytics property.
  • Install attribution (Apple Search Ads): if you installed Perigee after tapping one of our own ads on the App Store, iOS provides an Apple-signed attribution token on first launch. We pass it to RevenueCat, which asks Apple which of our campaigns the tap belonged to (campaign, ad group and keyword identifiers). This uses Apple’s AdServices framework: it contains no health data, no cross-app tracking and no advertising identifier, does not require App Tracking Transparency, and only ever describes our own App Store ads.

8. Third parties who process data for us

We share the minimum necessary with the service providers below, each acting on our instructions. None of them receive your raw Apple Health records. If you opt in to cloud AI, the pseudonymous, health-derived payload described in §4 leaves your device and may include a stable account/tier identifier for daily and weekly requests. If you send feedback, Cloudflare and Notion process the fields described in §7. None are permitted to use your data for advertising.

ProviderPurposeWhat they receive
AppleApp distribution, subscriptions, Sign in with ApplePurchase & account data (per Apple’s policy)
Google FirebasePseudonymous authentication & crash reportingPseudonymous account identifier, crash diagnostics
RevenueCatSubscription management & Apple Search Ads install attributionPseudonymous app-account identifier, subscription status; on ad-attributed installs, the Apple-signed Search Ads attribution token (campaign-level identifiers only, no health data)
PostHogPseudonymous product and subscription-funnel analytics; cookieless website usage analyticsFrom the app: random per-install identifier and bounded non-health usage, purchase and restore events; no price, transaction ID or account UID. From this website: page-view and App Store-button-click events under a random per-page-view identifier, with no cookies or on-device storage
CloudflareHosting and protecting this site, and running the app Worker (cloud AI, feedback, rate-limiting and tier caching)For website visits, standard request and connection metadata. For optional cloud AI, the §4 payload in transit and separate pseudonymous quota/tier counters. For feedback, the §7 fields in transit and a short-lived per-install rate-limit counter. The Perigee Worker does not persist cloud-AI request bodies in application storage.
Upstream API gateway (production provider to be confirmed)Forwarding cloud-AI requestsThe §4 payload and generated response; the gateway’s own retention terms may apply
AnthropicGenerating cloud-AI text — only if you opt inThe §4 payload and generated response; standard API retention is within 30 days unless an exception or different approved agreement applies
NotionStoring feedback you choose to sendFeedback message, optional contact, app version, locale, submission time and random per-install quota identifier

9. How we store and protect your data

Your raw Apple Health records and local logs live in an on-device database. iOS encrypts Apple Health data on your device behind your passcode. Perigee deliberately disables iCloud sync for its health store, and all network traffic is encrypted in transit. Optional cloud-AI payloads are the limited exception described in §4. No system is perfectly secure, but we keep the surface small by design.

10. Retention

On-device data stays until you delete it or remove the app. Website delivery and security logs follow the hosting provider’s applicable retention terms. For optional cloud AI, the Perigee Worker does not persist request bodies in application storage, but its quota/tier counters and the upstream providers have separate retention: the production gateway’s terms apply, and Anthropic’s standard API policy says inputs and outputs are deleted from its backend within 30 days, subject to its stated exceptions or a different approved agreement. Diagnostic and pseudonymous analytics data are retained only as long as needed for their purpose. Feedback is stored in Notion for support and product-improvement use; an automatic deletion period is not currently implemented, so contact us to request deletion. Deleting your app account does not automatically identify or delete a separate feedback row. Provider copies already in their retention windows follow the provider terms above.

11. Your rights and choices

  • Withdraw Health access for any category anytime in iOS Settings/Health.
  • Stay fully on-device — decline cloud briefings.
  • Export your data (including the doctor-ready PDF) from within the app.
  • Delete your account and associated data from within the app (You → AI & privacy).
  • Opt out of analytics in the app.
  • Request deletion of submitted feedback by emailing us with enough information to locate it, such as the contact address and approximate submission date.

Depending on where you live, you may also have rights under the GDPR (EEA/UK) or the CCPA/CPRA (California) — including access, correction, deletion, portability, and the right not to be sold or “shared” for cross-context advertising. We do not sell or share your personal information in that sense. To exercise any right, email [email protected].

12. International data transfers

Some of the service providers in §8 (for example, Cloudflare, Notion, the API gateway and the AI provider) are based in the United States. If you opt in to cloud AI, the pseudonymous health-derived summary described in §4 — not your raw Apple Health records, name or email — is processed there. If you send feedback, the §7 fields are processed there as well. Where we transfer data internationally, we rely on appropriate safeguards recognized under applicable law (such as the relevant standard contractual clauses). Your raw Apple Health data itself stays on your device.

13. Children

Perigee is intended for adults and is not directed to anyone under 18. We do not knowingly collect data from children.

14. Not a medical device

Perigee is a wellness and self-knowledge companion, not a medical device. It does not diagnose, treat, or prevent any condition, and it does not provide medical advice. Always consult a qualified healthcare professional about your symptoms or any decision about treatment.

15. Changes to this policy

If we make material changes, we’ll update the date above and, where appropriate, notify you in the app. Continued use after an update means you accept the revised policy.

16. Contact

Questions about your privacy or your data? Email us at [email protected]. We read every message.

Perigee

Your watch records the night. Read it back.

Download on the App Store
Product
How it works Pricing Signals The science
Learn
Perimenopause fatigue and HRV: what a low reading isn’tHow long does perimenopause last? What the averages hideApple Watch respiratory rate in perimenopause All articles →
Company
About Support Privacy Terms [email protected]
© 2026 Perigee

Perigee doesn’t provide medical advice or diagnose any condition. It organizes your Watch readings so you and your doctor can review them together.