Legal

Privacy Policy

Last updated: October 4, 2026

Our promise, in plain language:

  • —Hydrate is a paid app. We make money from subscriptions, never by selling your data.
  • —No advertising trackers, ever. We use one analytics service, PostHog, to learn how the app is used, with a random ID that isn't your name or email, and never for ads. You can switch it off in Settings.
  • —Your cycle, pregnancy, weight and HealthKit activity data never leave your device — they are never sent to our AI, our analytics, or any server.
  • —You can export or delete everything, at any time, from inside the app.

Hydrate ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect through the Hydrate iOS app and this website (hydrateai.app), how we use it, and your rights regarding that data.

By using the app or visiting this website, you agree to the practices described in this policy. If you are a Washington, Nevada, or other US-state consumer, please also see our Consumer Health Data section, which serves as our Consumer Health Data Privacy Policy.

1. Information We Collect

Profile & Onboarding Data

When you set up the app, we collect your name, age, weight (in lbs), activity level, wake and sleep times, and any health considerations you choose to share (such as whether you are pregnant or breastfeeding). We also store your preferred AI coaching personality. This information is used solely to calculate your personalised hydration goal and tailor in-app coaching messages. It is stored on your device.

Hydration Logs

Every water entry you log is stored on your device. Each entry includes the amount (fl oz), timestamp, drink type (e.g. water, coffee, herbal tea), an optional note, and whether it came from the app or Apple Health. This data is used to track your progress, calculate streaks, and generate coaching messages.

Cycle Phase Data

You may choose to enable cycle-aware hydration goals. If you do, we store the following information locally on your device:

  • —Current cycle phase: self-reported (menstrual, follicular, ovulatory, or luteal), or automatically derived from your period start date.
  • —Period start date: optionally provided so the app can automatically advance your phase day-by-day without requiring manual updates.
  • —Cycle length preference: an integer between 21 and 40 days (default 28) used to calibrate automatic phase detection for your individual cycle.

All cycle data is stored exclusively on your device and is never transmitted to our servers, the AI coaching API, or any third party. Cycle tracking requires explicit consent, which you can provide or withdraw at any time from Settings › Cycle Tracking. Withdrawing consent and tapping "Clear" removes all stored cycle data immediately.

Your Reads: Hydration Read & Milestone Photos

Your Reads holds two kinds of photo: a daily Hydration Read, which you can take on any day, and milestone photos at days 1, 7, 14, 30, 60 and 90. Both are stored as JPEG files inside the app's sandboxed storage on your device and are never uploaded to our servers. Metadata (milestone day, optional note, hydration percentage, and for a read the number the on-device analysis produced) is stored locally alongside the photo.

Device & Usage Preferences

We store app preferences locally on your device: streak data, milestone achievements, selected theme, notification settings, and subscription status. This data does not leave your device except via your private iCloud sync (see below).

Apple HealthKit Data

With your permission, we read the following data from Apple Health: active energy burned, step count, exercise minutes, and water intake logged by other apps. We use this to adjust your daily hydration goal based on your activity level. We also write your water logs back to Apple Health as dietary water samples. HealthKit data is never sent to our servers or any third-party service.

2. How We Use Your Information

  • —Calculate and personalise your daily hydration goal
  • —Generate personalised AI coaching messages and daily recaps
  • —Track streaks, milestones, and hydration progress over time
  • —Schedule smart hydration reminders based on your patterns and preferences
  • —Sync your data across your own devices via your private iCloud account

We do not use your data for advertising, profiling, or any purpose beyond operating and improving the Hydrate app and website. We do not sell or share your personal information for cross-context behavioural advertising.

3. Third-Party Services

OpenRouter / Google Gemini AI

To generate personalised coaching messages, the app sends a limited set of data to our coaching server at hydrateai.app, which forwards it to the OpenRouter API and on to Google's Gemini AI model. Our server stores nothing; it briefly holds your IP address in memory to limit how many requests one device can make. This includes your first name, current hydration percentage, streak count, time of day, AI coaching mode, and aggregated hydration patterns (e.g. weekly averages). We never send your cycle phase, health considerations, weight, exact activity data, or HealthKit data to this or any other external service. No persistent account is created with OpenRouter or Google on your behalf. Messages are cached on-device to minimise API requests. Responses are not used to train AI models.

Apple CloudKit

We use Apple CloudKit solely to sync your data between your own devices. Your profile, water logs, and app preferences are stored in your private CloudKit database, tied to your personal Apple ID, using Apple's encrypted infrastructure. We do not operate a public database and do not have access to the contents of your private iCloud data. Hydrate has no public, shared, or social database.

Apple HealthKit

HealthKit integration is subject to Apple's own privacy framework. Data exchanged with HealthKit remains under your control and is governed by your iOS Health settings. We only access HealthKit data you explicitly authorise.

PostHog (App and Website Analytics)

We use PostHog, a product analytics service, to understand how Hydrate is used so we can improve it. PostHog acts as our service provider (processor) and does not use the data for its own purposes. Data is sent with a random ID generated on your device. We do not send your name, email, or Apple ID, and we never use it for advertising. So we can see whether trials turn into subscriptions, the same ID is attached to your subscription record at RevenueCat, and RevenueCat reports subscription events (trial started, renewed, cancelled) to PostHog under it. Because PostHog and RevenueCat records can be connected, Apple's privacy label lists this data as linked to you.

  • —In the app: which screens you open and features you use; onboarding progress; purchase and subscription events; reminder taps; streak milestones; and when you log a drink (the time and how you logged it, e.g. from a widget). We also record coarse settings such as your coaching mode, theme, and whether reminders, widgets, Apple Watch and Apple Health are in use, plus device model, iOS and app version, and approximate country.
  • —Session recordings (app): short recordings of screen layout and taps, used to find confusing screens. Every piece of text and every image is masked, so recordings never show your numbers, name or messages. The camera, Hydration Read scan and your photos are never recorded.
  • —Never sent: cycle or period data, pregnancy or breastfeeding status, weight, age, HealthKit data, your photos, or coach message text.
  • —On the website: pages viewed, clicks, and waitlist sign-ups. Website recordings are off, and Do Not Track is honoured.

Drink details are opt-in. The amount and type of each drink, your progress toward your goal, and your goal range are sent only if you choose "Share drink details" — we ask once during setup, and it is off unless you say yes. Hydrate works exactly the same either way.

You can change either choice at any time in Settings › Privacy & Data: Share usage analytics turns app analytics and recordings off entirely, and Share drink details controls drink amounts and types.

RevenueCat (Subscriptions)

We use RevenueCat to process and verify App Store subscriptions. It receives a random app user ID, your purchase and subscription history, and device information needed to validate receipts, plus the random PostHog ID described above. It reports subscription events to PostHog. It receives no health data.

Sentry (Crash Reports)

Sentry receives crash and performance diagnostics (the error, the app state at the time of the crash, device model and iOS version) so we can fix bugs. Crash reports are not linked to your identity and contain no health data.

Google Analytics (Website Only)

We also use Google Analytics 4 on hydrateai.app to understand how visitors use the website (pages viewed, clicks, general location by country). The iOS app does not use Google Analytics. GA4 data is governed by Google's privacy policy.

4. Consumer Health Data (Washington, Nevada & other US states)

This section serves as our Consumer Health Data Privacy Policy under the Washington My Health My Data Act, Nevada SB 370, and comparable US state laws. "Consumer health data" means personal information linked to your past, present, or future physical or mental health — for Hydrate, this can include your hydration logs, cycle phase information, period start date, pregnancy or breastfeeding status, and the activity data you grant via HealthKit.

What we collect and where it comes from

We collect consumer health data directly from you (information you enter during onboarding and logging) and, with your permission, from Apple HealthKit. We do not purchase or acquire consumer health data from data brokers or other third parties.

How we use it

We use consumer health data to provide the app's core functionality: calculating your hydration goal, adjusting it for your cycle phase or activity, tracking your progress, and generating on-device coaching. Only if you give your consent by choosing "Share drink details" (asked once during setup, off unless you say yes) do we also use your drink amounts and types to understand how the app is used and improve it, as described in Section 3. Sensitive health data (cycle, period, pregnancy/breastfeeding status, weight, and HealthKit data) is processed on your device only and is never transmitted to our servers, our AI provider, our analytics provider, or any third party.

Who we share it with

We do not sell consumer health data, and we do not share it with any third party for their own use. Your private iCloud sync is handled by Apple as a processor under Apple's terms; no human at Hydrate can read it. If you have consented to share drink details, your drink amounts and types are sent with an anonymous ID to PostHog, which processes them only on our behalf; you can withdraw that consent at any time with the Share drink details switch. We will never collect, share, or sell consumer health data without your consent, and we do not condition use of the app on consent to any secondary use of that data.

Your rights

You have the right to access the consumer health data we hold, to withdraw consent, and to have it deleted. Because this data lives on your device, you can exercise these rights directly:

  • —Access / export: Settings › Privacy & Data › Your Data › Export (JSON or CSV).
  • —Withdraw cycle consent: Settings › Cycle Tracking › Clear.
  • —Withdraw drink-details consent: Settings › Privacy & Data › Share drink details.
  • —Delete everything: Settings › Privacy & Data › Delete My Data, or simply uninstall the app.
  • —Revoke HealthKit access: iOS Settings › Health › Data Access & Devices › Hydrate.

You may also email privacy@hydrateai.app to make a request or appeal a decision. We will respond within the timeframe required by applicable law. You will not be discriminated against for exercising any of these rights.

5. Data Storage & Security

  • —All personal data is stored primarily on your device, protected by iOS's built-in data protection.
  • —iCloud sync uses your private CloudKit database. Data is encrypted in transit and at rest by Apple, and is accessible only through your Apple ID. For end-to-end encryption of eligible iCloud data, you can enable Apple's Advanced Data Protection in iOS Settings.
  • —Your reads and milestone photos are stored in the app's sandboxed directory and are not accessible to other apps.
  • —We do not run any database that stores your personal data. Our only server is the stateless coaching relay described above.
  • —API keys used to access third-party services are not stored in the app bundle.

6. Data Sharing

We do not sell, rent, or trade your personal information. We share data only as described in this policy:

  • —With OpenRouter/Google Gemini AI to generate coaching messages (limited, non-health data, as described above)
  • —With Apple via CloudKit, solely to sync your data to your own private iCloud account
  • —With PostHog, our analytics processor, to understand how the app and website are used (random ID; can be switched off in the app)
  • —With RevenueCat, to process and verify your subscription
  • —With Sentry, to receive crash reports (no health data)
  • —As required by law, valid legal process, or to protect the safety of users or others

7. Your Rights & Controls

You have meaningful control over your data:

  • —Export your data: Download your profile, water logs, and read and milestone photo metadata as JSON or CSV from Settings › Privacy & Data › Your Data.
  • —Delete your data: You can delete your profile and all associated data from the Settings screen inside the app. Uninstalling the app removes all locally stored data.
  • —HealthKit access: Revoke at any time in iOS Settings › Health › Data Access & Devices.
  • —Notifications: Disable in iOS Settings › Notifications › Hydrate, or within the app's Settings screen.
  • —iCloud sync: Manage in iOS Settings › Apple ID › iCloud.
  • —App analytics: Turn usage analytics and session recordings off in Settings › Privacy & Data › Share usage analytics.
  • —Website analytics: Enable Do Not Track in your browser (PostHog honours it), or opt out of Google Analytics with Google's browser add-on.

8. Data Retention

Your data is retained on-device for as long as you use the app. iCloud data is retained according to Apple's iCloud policies and remains under your control through your Apple ID. If you delete the app, all local data is removed. Deleting your data from within the app removes it from your device and, on next sync, from your private iCloud database.

9. Children's Privacy

Hydrate is not directed at children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify you via an in-app notice. Your continued use of the app after changes are posted constitutes your acceptance of the updated policy.

11. Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your data, please reach out: