ShadowGraph Back to home

Privacy Policy

Last updated: September 2026

What we collect

ShadowGraph collects only what it needs to work. Here is the full list:

  • Events and timestamps -- the things you track and when they happened.
  • HealthKit data -- only the categories you choose to enable (workouts, sleep, etc.). We never read anything you have not explicitly configured.
  • Location data -- only for geofence triggers you create. We do not continuously track your location or store location history.
  • Email address -- used for authentication. That is it.
  • Account identifiers -- an internal user ID to keep your data separate from everyone else's.

Why we collect it

Everything we collect exists for one reason: to make the app work for you.

  • HealthKit data powers your health tracking features.
  • Location data triggers geofence-based event logging.
  • Your email lets you sign in and recover your account.

We do not use your data for advertising. We do not sell your data. We do not build profiles to serve you ads. None of that.

How we store it

Your data is stored in a PostgreSQL database hosted on Neon. All data is encrypted in transit using TLS. Each user's data is isolated by account -- you can only access your own.

The iOS app also stores data locally on your device using SwiftData so you can use it offline. Local data syncs to the server when you are back online.

Third-party services

We use a small number of third-party services:

  • Clerk -- handles authentication. Clerk processes your email address and auth tokens. They do not receive your event data.
  • Our own backend API -- all event data is processed by our servers. We do not send your data to any other third party.

We do not use advertising SDKs, data brokers, or analytics platforms that share data with third parties.

Your rights

You are in control of your data:

  • View -- all your data is visible in the app at any time.
  • Export -- in the iOS app, Settings › Export My Data produces a single JSON file containing everything we hold about your account: your events with their notes and properties, your event types, geofences, targets, achievements, streaks and insights. The web app at app.shadowgraph.app also exports your events as CSV or JSON, filtered by date range or event type.
  • Delete -- delete your account from Settings in the iOS app. This erases your account and all of its data immediately and permanently.

Data retention

Active account: your data is kept for as long as your account exists.

Deleted account: deletion is immediate and permanent. When you delete your account we erase your sign-in identity and every row of your data -- events, event types, properties, geofences, targets, achievements, streaks and settings -- from our database straight away. There is no grace period and no recovery: we cannot restore a deleted account even if you ask us to. You are welcome to sign up again with the same email address, but you will start with an empty account.

Encrypted database backups may retain residual copies for up to RETENTION_WINDOW before they age out. Those backups exist only for disaster recovery and are never used to restore an individual deleted account.

HealthKit

ShadowGraph integrates with Apple HealthKit to let you track health-related events automatically. Here is how we handle HealthKit data:

  • We only read the HealthKit categories you explicitly enable in Settings.
  • When you enable workout tracking we also read heart rate, solely to record the average and peak heart rate for each workout we log for you.
  • HealthKit data you share with ShadowGraph is stored on our servers to power your tracking features.
  • We do not share HealthKit data with third parties.
  • We do not use HealthKit data for advertising or marketing.
  • You can disconnect HealthKit at any time in the app's Settings.

Location data

ShadowGraph uses location data exclusively for geofence triggers -- for example, automatically logging an event when you arrive at the gym.

  • We do not continuously track your location.
  • We do not store a history of your locations.
  • Location is only used to detect when you enter or leave a geofence you created.
  • You can remove geofences at any time to stop location-based triggers.

Contact

Questions about this policy or your data? Reach us at support@shadowgraph.app.

Effective date: September 2026