Privacy Policy
Effective date: June 10, 2026 · Last updated: July 3, 2026
This Privacy Policy describes how Omniscient Labs (“Omniscient Labs”, “we”, “us”, or “our”) handles information in connection with the Cuff mobile application (the “App”) and the cuffapp.com website (the “Site”, and together with the App, the “Service”). By using the Service, you acknowledge this Policy. If you do not agree with it, do not use the Service.
1. The short version
Cuff is local-first by design. Your health data never leaves your device. The App has no account system, no backend server operated by us, no advertising SDK, and no third-party analytics SDK. We have no technical ability to see, access, recover, or disclose your blood pressure readings or any other health information you enter — it exists only on your phone.
2. Information stored on your device only
The App stores the following entirely on your device, under the operating system’s app sandbox. It is never transmitted to us or to any third party by the App:
- Blood pressure readings, pulse, and reading notes
- Water, sodium, caffeine, alcohol, food, sleep, weight, and step entries
- Heart rate, resting heart rate, heart-rate variability, blood oxygen, exercise, and cardio-fitness entries
- Medication names, schedules, reminder times, and adherence logs
- Daily lifestyle check-ins and the insights computed from them
- Data you import from files (CSV/JSON) or from Apple Health / Health Connect
- App settings and preferences
This data is deleted when you use “Delete all my data” in the App’s Settings or when you uninstall the App. Because we never receive this data, we cannot restore it, produce it in response to legal requests, or delete it on your behalf — see Data Deletion.
3. The limited information we do receive
We or our service providers receive only the following non-health information:
- Purchase data. Subscriptions are processed by Apple or Google. Our subscription-infrastructure provider, RevenueCat, receives a randomly generated anonymous app user ID, purchase receipt data, and basic device metadata (e.g., platform, app version, locale) to validate purchases and unlock Pro features. We never give RevenueCat your name, email, or any health data. See RevenueCat’s privacy policy.
- App update delivery. When the App checks for over-the-air updates (Expo/EAS Update), the update server receives standard request metadata such as IP address, app version, and platform — the same way any server sees a request. No health data is included.
- Support email. If you email us, we receive your email address and whatever you choose to include in your message.
- Site logs. Our website hosting provider keeps standard, short-lived server logs (IP address, user agent, pages requested) for security and operations.
4. What we do not do
- We do not sell or share personal information (as those terms are defined under the California Consumer Privacy Act), and we have not done so in the preceding 12 months.
- We do not serve ads and do not use advertising identifiers.
- We do not use third-party analytics or tracking SDKs in the App.
- We do not profile you or make automated decisions producing legal or similarly significant effects.
- We do not knowingly collect data from children (see Section 14).
- We do not use your data to train AI models, and no health data is processed by any AI system (see Section 21).
5. How we use the information we receive
We use the limited data described in Section 3 only to:
- Validate purchases and deliver the subscription you paid for
- Deliver app updates and keep the App functioning
- Respond to support requests and exercise-of-rights requests
- Secure and operate the Site, and prevent fraud and abuse
- Comply with legal obligations
6. Legal bases (EEA/UK users)
Where the EU/UK General Data Protection Regulation applies, our legal bases are: performance of a contract (purchase validation, update delivery, support); legitimate interests (Site security, fraud prevention, defending legal claims); and legal obligation (tax, accounting, lawful requests). Health data you enter in the App is processed only locally on your device by software under your control; we are not a recipient of that data.
7. Apple Health, Health Connect & Apple Watch
If you choose to connect Apple Health (HealthKit) or Android Health Connect, the App reads only the data types you explicitly approve (blood pressure, heart rate, resting heart rate, heart-rate variability, blood oxygen, steps, exercise, cardio fitness, sleep, hydration, nutrition such as sodium and caffeine, alcohol, weight). The optional Cuff Apple Watch app saves its heart-rate measurement sessions and the blood-pressure readings you log on the wrist to Apple Health on your devices — those are the only writes the Service performs, and they are how watch readings reach your iPhone. We commit to the following, consistent with Apple’s HealthKit requirements and Google’s Health Connect permissions policy, including its limited-use requirements:
- Health platform data is used solely to provide the App’s user-requested features: your private log, trends, insights, and doctor report — all generated on your device.
- It is processed and stored on your device only. It is never transmitted to us or anyone else, never used for advertising, never sold, and never disclosed to third parties.
- It is not used for machine learning, model training, credit, insurance, employment, or any eligibility determination.
- You can revoke access at any time in iOS Settings → Health or in the Health Connect app, and delete imported copies in Cuff’s Settings.
See Health Data & Permissions for a permission-by-permission explanation.
8. Sharing and service providers
We share the limited non-health data in Section 3 only with the service providers needed to run the Service: Apple (App Store, payments), Google (Google Play, payments), RevenueCat (subscription validation), Expo (app update delivery), our website hosting provider, and our email provider (support correspondence). Each acts under its own published terms or our instructions. We may also disclose information if required by law, to enforce our Terms, or in connection with a merger, acquisition, or asset sale — in which case this Policy continues to apply to previously collected data until amended. We may add or change service providers; the current list is available on request at the contact below.
9. Retention
- Health and app data: on your device only, retained until you delete it or uninstall the App. We hold none of it.
- Purchase records: retained by Apple/Google/RevenueCat per their policies; we retain associated anonymous transaction records as required for tax and accounting (typically 7 years).
- Support emails: retained up to 24 months after resolution, then deleted.
- Site logs: retained by our hosting provider for a short rolling window (typically ≤ 90 days).
10. Your rights (EEA/UK and similar jurisdictions)
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing, and you may withdraw consent at any time without affecting prior processing. Because we hold almost no personal data about you, most requests will be satisfied by confirming we hold nothing beyond what Section 3 describes. You also have the right to lodge a complaint with your local supervisory authority.
11. United States state privacy rights
Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Iowa, Tennessee, and other states with consumer privacy laws have rights to know, access, correct, delete, and obtain a portable copy of personal information, and to opt out of sale, sharing, targeted advertising, and certain profiling. We do not sell personal information, do not share it for cross-context behavioral advertising, do not use it for targeted advertising, and do not profile you, so there is nothing to opt out of — but you may still exercise your other rights using the contact below, and we will not discriminate against you for doing so. California residents: under the “Shine the Light” law (Civil Code §1798.83), you may request a notice of personal information shared with third parties for their direct marketing — we share none. The categories of personal information we collect (identifiers and commercial information, as described in Section 3) are collected for the business purposes in Section 5 and disclosed only to the service providers in Section 8.
12. Consumer health data laws (Washington My Health My Data and similar)
Laws such as Washington’s My Health My Data Act and Nevada’s SB 370 regulate “consumer health data.” Cuff is designed so that we do not collect, process, share, or sell consumer health data on our systems — your health data exists only on your device. To the extent these laws apply to us at all, this section serves as our Consumer Health Data Privacy Policy: the categories of consumer health data handled by the App are listed in Section 2; they are processed on-device only to provide features you request; they are not shared or sold; no affiliates, processors, or third parties receive them; and you may exercise rights of access, deletion, and withdrawal of consent through the App’s own controls or by contacting us. We do not use geofencing around health facilities or anywhere else.
13. How to exercise your rights
Email cuffapp@gmail.com with your request. We respond within 30 days (GDPR) or 45 days (CCPA and most state laws), extendable once where permitted with notice to you. We may need to verify your identity with reasonable means before acting; because the App has no accounts, verification is usually limited to confirming control of the email used to contact us. Authorized agents may submit requests with proof of authorization. If we deny a request, you may appeal by replying to our decision; we will respond to appeals within the period required by your state’s law and provide your regulator’s contact information if the appeal is denied.
14. Children’s privacy
The Service is not directed to children under 13 (or the higher minimum age in your jurisdiction, e.g., 16 in parts of the EEA), and we do not knowingly collect personal information from children. The App’s health-logging features are intended for adults. If you believe a child has provided personal information to us, contact us and we will delete it. Parents and guardians are responsible for supervising any use of the Service by minors.
15. International data transfers
We are based in the United States. The limited data described in Section 3 is processed in the United States and other countries where our service providers operate. Where required, transfers from the EEA/UK/Switzerland rely on adequacy decisions or Standard Contractual Clauses implemented by our service providers. Your on-device health data is not transferred anywhere by us.
16. Security
Your health data is protected by your device’s operating system sandbox and benefits from your device-level protections (passcode, biometrics, device encryption) — we strongly recommend enabling them. The small amount of data we do handle is encrypted in transit (TLS) and protected by access controls at our service providers. No method of storage or transmission is 100% secure; you use the Service with that understanding. Because the data lives on your device, the physical security of your device is your responsibility.
17. Data breach notification
If a breach affecting personal data we hold occurs, we will notify affected users and regulators as required — within 72 hours of becoming aware where GDPR applies, and without unreasonable delay under applicable US state breach-notification laws.
18. Cookies and local storage
The Site does not use advertising or analytics cookies. The only thing it stores in your browser is a single local-storage entry remembering your light/dark theme choice, which is strictly functional, never transmitted to us, and clearable in your browser settings. The App stores its data in local app storage as described in Section 2.
19. Do Not Track and Global Privacy Control
Because we do not track users across sites or apps and do not sell or share personal information, there is no tracking to disable. To the extent a Do Not Track or Global Privacy Control signal would apply, our practices already comply with the most restrictive interpretation of such signals.
20. HIPAA notice
Omniscient Labs is not a “covered entity” or “business associate” under the U.S. Health Insurance Portability and Accountability Act (HIPAA), and the Service is not a HIPAA-covered service. Information you store in the App is not “protected health information” under HIPAA. If you share a report with your clinician, the copy they receive becomes part of their records under their obligations, not ours.
21. AI disclosure
The current version of the Service contains no artificial-intelligence features, sends no data to AI providers, and uses no data for AI training. The App’s insights are deterministic calculations performed on your device. If a future version adds any feature that processes data through third-party AI inference providers, it will be optional, this Policy will be updated first, and health data will never be used to train models.
22. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted on this page with a new effective date, and where required by law we will provide additional notice. Your continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.
23. Contact us
Omniscient Labs — privacy contact: cuffapp@gmail.com. Data deletion instructions: cuffapp.com/delete-account.