Data Security

Your data never leaves your phone.

We cannot see it — even if we wanted to. This page explains exactly how that works, in plain language.

Illustration of a shield and botanical shapes symbolising privacy

The model in one paragraph

PeriWise stores every piece of your health data exclusively on your iPhone, inside an encrypted database. The encryption key is generated on your device and held only in the iOS Keychain. The app makes no network calls involving your data, contains no analytics or tracking SDKs, and has no accounts. As the developer, we have no technical ability to access your data.

The five commitments

  • 100% local storage. No accounts, no login, no backend for health data. There is simply no server to breach.
  • Zero tracking. No analytics, no advertising SDKs, no crash reporters that phone home, no fingerprinting.
  • Strong encryption at rest. Your database is encrypted with AES-256 (SQLCipher). The master key lives in the iOS Keychain, protected so it is only available when your device is unlocked and never leaves that device — hardware-backed by the Secure Enclave where available.
  • Excluded from cloud backups. The health database is deliberately excluded from iCloud and iTunes backups, so it never silently ends up on a server.
  • No network calls with your health data — ever. This is enforced in our engineering process: the codebase is automatically checked so that no networking or analytics frameworks can slip in.

What we store — and what we collect

Stored on your iPhone only: your symptom logs, and an optional profile. That's it.

Collected by us: nothing. We have no servers for your data. On the App Store, PeriWise targets the privacy label "Data Not Collected."

Sharing is always your explicit choice

Only you can move data out of the app, and only deliberately: a PDF report or a JSON export via the iOS share sheet. Nothing is ever shared automatically.

Deletion

Settings → Delete all data removes everything instantly and irreversibly. Because there is no cloud copy, there is nothing left anywhere once you delete.

An honest trade-off

True privacy has one consequence we state openly: because your health database is excluded from backups and we hold no copy, if you lose your phone without exporting, the data is gone. You can export a backup anytime from Settings.

Purchases

The monthly subscription (€1.49/month) is handled entirely by Apple (StoreKit). We never see your payment details, and purchases do not change the "Data Not Collected" model.

A note on HIPAA

US law (HIPAA) does not apply to consumer apps that keep health data only on your personal device, so we make no HIPAA compliance claim. We simply implement the same level of technical security it demands: AES-256 encryption at rest, hardware-backed keys and backup exclusion.

This website

The same philosophy applies to peri-wise.app itself:

  • No cookies, no analytics, no ad networks and no third-party embeds. All fonts, images, styles and scripts are served from this domain.
  • The one commercial element is on Things That Helped: the Amazon links there are affiliate links, labelled as such on that page. They are ordinary links — nothing loads from Amazon until you click, and no data about you is shared. Once you land on Amazon, Amazon's own policy applies.
  • The only thing stored in your browser is a single first-party flag remembering that you dismissed the cookie notice (kept in local storage on your device; you can clear it in your browser settings at any time).
  • Our hosting provider (Vercel Inc.) processes standard technical request data — such as your IP address — transiently, as is technically necessary to deliver any website (legal basis: Art. 6 (1)(f) GDPR). We run no server-side analytics on top of it.

Not a medical device

PeriWise is not a medical device and does not provide medical advice, diagnosis or treatment. Always consult a qualified healthcare professional.

Questions about privacy or security? Contact us — we answer these first.