Privacy Policy
N=Me App · Last updated: September 1, 2026
N=Me is a personal health tracking app. This Privacy Policy explains what information N=Me processes, where it goes, how long it is retained, and the choices available to you.
1. Data We Collect
N=Me processes only information you provide, authorize, or generate by using an optional feature:
- Profile name — An optional name you enter in the app. It is stored locally on your device.
- Apple Health data — Steps, heart rate, sleep, HRV, cycle and reproductive-health metrics, and other HealthKit types you authorize. N=Me reads this information from Apple Health and stores an imported copy locally.
- Oura health data — If you connect Oura, N=Me requests only the daily, heart-rate, daily blood-oxygen, workout, and session scopes. It converts supported responses into the health values and event timing needed by the app; it does not request your Oura email, personal profile, tags, or device configuration, and does not retain complete API responses. Imported values stay on your device. Access and refresh tokens are stored in the device Keychain.
- Location and environment data — When an environment import runs while the app is open, the current location is used with Apple WeatherKit for weather. Coordinates rounded to two decimal places are sent through N=Me's Cloudflare Worker to OpenAQ for nearby air-quality measurements. N=Me stores returned environmental values and source attribution, not coordinates, location accuracy, altitude, or location history.
- Habit and lifestyle records — Data you manually enter into the app (e.g., mood, energy, custom items you create).
- Lab investigations and saved reports — Experiments and reports you design or save, including notes, tracked field names, date ranges, results, and statistical summaries.
- Purchase information — When subscriptions are available, RevenueCat processes an anonymous app user identifier, App Store receipt and purchase or subscription status, basic device and operating-system information, and service timestamps to provide and restore Premium access. N=Me does not give RevenueCat your profile name or health records.
2. How We Use Your Data
- To power the core features of the app: trend analysis, correlation discovery, and personal experiments.
- To create a JSON backup or CSV export when you choose to export your local data. The current app does not restore these files.
- To sync eligible app data through your private iCloud database when you enable iCloud sync.
- To provide, validate, restore, and manage optional Premium subscriptions.
- We do not use your data for advertising, marketing, or analytics.
- We do not sell your data to any third party.
3. Data Storage
Your data is stored as follows:
- Locally on your device — in a private SQLite database.
- Raw health data — Imported Apple Health readings and normalized Oura values remain on this device and are excluded from N=Me CloudKit sync.
- iCloud (optional) — If you enable iCloud sync, custom items, manual records, saved reports, Lab investigations, environment records, and related app data are synced to your private CloudKit database managed by Apple. Saved reports may contain notes, health-field names, date ranges, and statistics derived on-device from health data, such as correlations, group means, or significance results. Raw Apple Health and Oura readings are not included.
- Backup and export files — Export files include local app datasets, including imported provider records. They are written to a temporary app file, presented through the iOS share sheet, and removed from the app cache after the share flow. Any copy you save is controlled by the destination you select.
N=Me operates two minimal services hosted by Cloudflare: an Oura OAuth broker and an OpenAQ proxy. The OAuth broker processes authorization codes and tokens in memory only to exchange, refresh, or revoke Oura access. The OpenAQ proxy receives rounded coordinates, keeps the OpenAQ API key out of the app, and returns supported nearby measurements and attribution. Neither service maintains a user database or persists tokens or health data. Cloudflare may process ordinary request metadata, such as an IP address, under its own privacy policy.
4. Data Sharing
We do not sell personal data, use health or location information for advertising, or run advertising or general product-analytics SDKs. Information is disclosed only when you use the related service: current location to Apple WeatherKit; rounded coordinates to the Cloudflare-hosted OpenAQ proxy and OpenAQ; Oura authorization credentials through the Cloudflare-hosted OAuth broker; authorized API requests to Oura; eligible app data to your private CloudKit database; purchase information to Apple and RevenueCat; or an export to the destination you choose. Where N=Me controls a processor, it limits processing to the service purpose and requires appropriate protection. Independent services also process information under the policies linked below.
5. Third-Party Services
- Apple HealthKit, WeatherKit, iCloud, and App Store — used for authorized health imports, local weather, optional private CloudKit sync, and subscription purchases. Weather attribution is shown in the environment screen. See Apple's Privacy Policy.
- Oura — used only after you connect an Oura account to authorize and import the selected Oura data. See Oura's Privacy Policy.
- Cloudflare — hosts the stateless Oura OAuth broker and OpenAQ proxy. See Cloudflare's Privacy Policy.
- OpenAQ — receives rounded coordinates from the proxy to return nearby public air-quality measurements. N=Me filters for sources marked as permitting commercial use and displays source attribution when available. See OpenAQ's Open Data information.
- RevenueCat — manages optional subscriptions and validates App Store receipts using an anonymous app user identifier. See RevenueCat's Privacy Policy.
6. Retention and Deletion
- Local app data — Retained until you delete individual records, clear imported health data, or use Settings → Data Management → Delete Local Data. Local deletion also removes locally stored Oura credentials, but does not delete iCloud data, Oura's source records, Apple purchase history, or records RevenueCat must retain for subscription administration or legal obligations.
- Oura access — Tokens remain in the device Keychain until they expire, you disconnect Oura, or you delete local data. Disconnecting waits for an active sync to finish, revokes access where the provider is reachable, removes credentials, and deletes Oura data imported into N=Me. It does not delete source records in Oura Cloud.
- iCloud data — Retained in your private CloudKit database until you use Delete iCloud Data or Apple deletes it under your iCloud account settings and policies. Turning off automatic sync alone does not delete existing iCloud data.
- OAuth broker — Does not persist authorization codes or tokens. Signed authorization state expires after approximately ten minutes.
- RevenueCat and other providers — Retention is governed by the linked provider policies and applicable purchase-record obligations. You may contact us about a provider-data request associated with N=Me.
7. Your Choices and Rights
- Access and export — View records in the app or use Settings → Data Management → Export Data for a JSON or CSV copy of local app datasets.
- Correct or delete local data — Edit or delete individual records, or use Settings → Data Management → Delete Local Data.
- Revoke Health access — In the Health app, open your profile → Privacy → Apps → N=Me. Clearing N=Me's local Health cache does not delete the source data in Apple Health.
- Revoke Location access — Go to iOS Settings → Privacy & Security → Location Services → N=Me.
- Disconnect Oura — Use Settings → Permissions → Oura Ring to revoke access and delete Oura data imported into N=Me.
- Delete iCloud data — Use Settings → Data Management → Delete iCloud Data while keeping local and raw health data intact.
- Manage subscriptions — Manage or cancel through your Apple ID subscription settings. Contact us for questions about RevenueCat processing associated with N=Me.
Depending on where you live, you may also have legal rights to request access, correction, deletion, restriction, or information about processing. Contact us using the address below. We may need enough information to verify and locate the relevant data.
8. Children's Privacy
N=Me is not directed at children under 13. If local law requires parental consent at a higher age, use by a minor should occur only with authorization from a parent or guardian. We do not knowingly operate an account service for children.
9. Security and International Processing
N=Me uses platform protections such as the iOS app sandbox, Keychain, TLS, and private CloudKit databases. No method is completely secure. Third-party services may process information in countries other than your own, as described in their policies.
10. Changes to This Policy
We may update this Privacy Policy as the app or legal requirements change. The date above identifies the current version. We will provide additional notice or request consent before a material new use when required by law.
11. Contact
For privacy questions or requests, email meme.265833@gmail.com. App provider and data controller: XIAOYING DING.