The short version
PDHD does not collect your data. There are no accounts, no servers of ours, no analytics, no advertising, and no third-party SDKs.
Everything you enter stays on your device, in Apple Health, or in your own private iCloud. The developer cannot see any of it.
The app makes no network connections of its own.
Who this policy covers
This policy applies to the PDHD — Dialysis Companion apps for iPhone, iPad, Apple Watch, and Mac, published by Arthur Kahwa ("the developer", "we").
PDHD is a self-management tool for people on peritoneal dialysis. It is not a medical device and does not provide medical advice.
What the app handles
You may choose to enter or grant access to the following. All of it is health-related and treated as sensitive:
- Dialysis session records
- Fill volume, drain volume, ultrafiltration, dwell time, glucose concentration, exchange number, notes.
- Health measurements
- Weight, blood pressure, blood glucose, and laboratory values such as creatinine, potassium, phosphate and calcium.
- Supply and delivery records
- Deliveries, bag sizes, quantities, suppliers, and reorder timing.
- Care-team contacts
- Names, phone numbers, email addresses and postal addresses you add or import for your clinic, supplier or hospital.
Where it is stored
- On your device
- App records are stored in the app's own container using SwiftData, protected by iOS file protection (complete protection), so they are encrypted while the device is locked.
- In Apple Health
- Weight, blood pressure and blood glucose are read from and written to HealthKit, so they stay consistent with the rest of your health data. HealthKit data is governed by Apple and by your Health app permissions.
- In your own iCloud
- If you are signed in to iCloud, app records sync through your personal private CloudKit database (container iCloud.de.chapter.pdhd). This is your Apple account, not ours — the developer has no access to it and cannot read its contents. If iCloud is unavailable, the app runs fully local and tells you so in Settings.
- Between your own devices
- iPhone and Apple Watch exchange records directly over Apple's WatchConnectivity, device to device. Nothing is routed through a server of ours.
What we never do
- We do not collect, receive, transmit, sell, rent or share your data.
- There is no analytics, telemetry, crash reporting, attribution or advertising SDK in the app.
- There is no tracking as defined by Apple's App Tracking Transparency. The app's privacy manifest declares no tracking and no tracking domains.
- Health data is never used for advertising or marketing, and is never shared with third parties.
- The app contains no code that contacts a server operated by the developer or by anyone else.
Permissions the app asks for, and why
- Apple Health
- To read weight, blood glucose and blood pressure for charts, and to write values you record so they reach the rest of your health data. Optional — the app works without it.
- Contacts
- Only when you tap to import a care-team contact, so you don't have to retype it. The app reads the contact you pick; it does not browse or upload your address book.
- Reminders
- Only if you switch on supply reorder reminders. The app creates reminders in your own Reminders app so supplies arrive before you run out.
- Face ID / Touch ID
- To lock the app behind biometric authentication, with your device passcode as the fallback. Biometric data never leaves the Secure Enclave and is never seen by the app.
You can change or withdraw any of these at any time in the iOS Settings app. Withdrawing a permission does not delete data already saved on your device.
Protections built into the app
- Biometric lock
- Optional Face ID / Touch ID gate with passcode fallback.
- Encryption at rest
- iOS complete file protection on the app's stored records.
- Privacy screen
- Sensitive views are obscured before the app appears in the App Switcher.
- Contact masking
- Phone numbers and email addresses are masked in lists and revealed only on explicit tap.
- Redacted logs
- Diagnostic logging marks user values as private, so they are stripped from system diagnostic archives.
Keeping and deleting your data
Because we never receive your data, we cannot retain or delete it for you. You are in control:
- In the app
- Settings → Delete All Health Data removes every dialysis session, lab result, delivery record and saved contact from the device.
- Health data
- Data written to Apple Health is managed in the Health app, under Profile → Apps, where you can revoke access and delete what PDHD has written.
- iCloud copies
- Deleting records in the app removes them from your private CloudKit database too. Deleting the app alone may leave iCloud data in place; use the in-app delete first if you want it gone.
Children
PDHD is not directed at children and we do not knowingly collect information from anyone. The app is intended for adults managing their own dialysis care, or for a carer acting on their behalf.
Your rights
Under the GDPR and comparable laws you have rights of access, rectification, erasure, restriction, portability and objection.
In PDHD these rights are exercised directly on your device: the data is yours, it is in your possession, and the developer holds no copy to disclose, correct or erase. If you believe otherwise, contact us using the details below.
The developer is based in Germany. No personal data is transferred to the developer, so no international transfer of your data to us takes place.
Changes to this policy
If this policy changes, the updated version will be published at this address with a new effective date. Material changes will also be noted in the app's release notes.
Contact
Questions about this policy or about privacy in PDHD:
Developer: Arthur Kahwa · pdhd_privacy@chapter.de