1. Introduction
Tab0 Inc. ("Tab0," "we," "us," or "our") provides Health Bridge, an iOS app that lets you access Apple Health data you approve through local tools you control. This Privacy Policy explains what information Health Bridge accesses, how it is used, and what choices you have.
Health Bridge is designed as a local-first technical tool. It does not require a Tab0 account, does not include an analytics SDK, and does not upload your Apple Health data to Tab0 by default.
2. Information Health Bridge Accesses
2.1 Apple Health Data
Health Bridge can read Apple Health data only after you grant explicit permission through Apple's HealthKit permission sheet. The app may expose approved categories such as sleep, heart rate, HRV, workouts, activity, glucose, nutrition, body measurements, respiratory metrics, and other HealthKit types supported by the app and available on your device.
You choose which HealthKit types are available. You can revoke access at any time in the Apple Health app or iOS Settings.
2.2 Local Bridge and Pairing Information
Health Bridge runs a local HTTP bridge on your iPhone while the app is active. It uses Bonjour/local network discovery so a device you control can find the iPhone on the same network. Requests require a bearer-style pairing token shown in the app.
- The pairing token is stored on your device.
- You can regenerate the pairing token in the app.
- Regenerating the token invalidates saved pairings.
- The local bridge is intended for devices and tools you control.
2.3 Optional Decis Sync
If you configure Decis sync, Health Bridge may collect recent approved Health and Fitness samples and send them over HTTPS to the Decis ingest endpoint and account you configure. This sync is separate from the local bridge. It requires a valid Decis upload key and an endpoint configured in the app.
2.4 Diagnostics and App Settings
Health Bridge stores app preferences, bridge state, Decis sync settings, and recent in-app request information locally so the app can operate and show status. The app does not include third-party analytics or tracking.
3. How We Use Information
Information is used only to provide Health Bridge functionality:
- To request and display the HealthKit permission state selected by you.
- To answer local CLI, MCP, and API requests from paired devices on your network.
- To export or query approved Apple Health data at your direction.
- To upload approved Health and Fitness samples to your configured Decis endpoint if you enable Decis sync.
- To maintain app settings, pairing state, and security tokens.
4. Local Processing and Network Behavior
By default, Health Bridge serves approved HealthKit data from your iPhone to a paired client on the same local network while the app is foregrounded. Local bridge requests are authenticated with the pairing token.
The local bridge, LAN request contents, local device identifiers, and local query results are not sent to Tab0 or a third-party analytics provider by the app.
5. Apple HealthKit Data Policy
In compliance with Apple's HealthKit requirements, Health Bridge follows these rules:
- HealthKit data is accessed only after explicit permission from you.
- HealthKit data is used only to provide app functionality requested by you.
- HealthKit data is not used for advertising, marketing, or tracking.
- HealthKit data is not sold to third parties, advertising platforms, or data brokers.
- HealthKit data is not shared with third parties for their marketing or advertising purposes.
6. Information Sharing
We do not sell your personal information. Health Bridge does not send local bridge data or analytics events to Tab0. Information may be shared only in the following limited cases:
- At your direction: With a paired local client, CLI, MCP server, script, or Decis endpoint that you configure.
- Service providers: With service providers that process data for a feature you choose to use, such as the configured Decis ingest endpoint.
- Legal requirements: When required by law, court order, or governmental regulation.
- Business transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and data protection obligations.
7. Security
Health Bridge uses local-network access, HealthKit system permissions, and a pairing token to limit access to approved data. Decis sync uses HTTPS when sending approved samples to the configured endpoint.
You are responsible for protecting your devices, networks, pairing token, Decis upload key, exported files, scripts, and any downstream tools that receive data from Health Bridge. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Data Retention
Health Bridge stores settings, pairing state, tokens, and recent request status on your device for as long as needed to provide the app. You can remove app-local data by deleting the app, regenerating the pairing token, removing saved Decis settings, or changing Health permissions.
If you use Decis sync, retention of uploaded samples is governed by the Decis service and account you configure.
9. Your Choices and Rights
- You can grant, limit, or revoke HealthKit access through Apple Health or iOS Settings.
- You can stop local serving by closing or disabling the app.
- You can regenerate the pairing token to invalidate previously paired clients.
- You can remove Decis sync settings and upload keys from the app.
- Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of personal information.
To exercise privacy rights or ask questions, contact us at support@tab0.ai.
10. Children's Privacy
Health Bridge is intended for adults and technical users. It is not intended for children under 18, and we do not knowingly collect personal information from children under 18.
11. International Data Transfers
Health Bridge's local bridge data stays on your devices unless you direct it elsewhere. If you use Decis sync or contact Tab0 for support, information may be processed in countries other than your country of residence, including the United States, subject to appropriate safeguards where required by law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update this page and may provide additional notice where appropriate.
13. Contact Us
If you have questions about this Privacy Policy or Health Bridge data handling, please contact:
Tab0 Inc.
Email: support@tab0.ai
Terms: Health Bridge Terms