Privacy Policy

Stabilize Health · Last updated 27 August 2026

Stabilize Health keeps your health record on your phone. We do not run a server that stores it, we do not have an account system, and we cannot read what you log.

The short version. Everything you enter — symptoms, energy, flare days, medications and doses, lab values, measurements, cycle entries, notes — is stored in the app's own storage on your device. It is not uploaded to us. There is nothing for us to sell, share, or lose.

Who we are

Stabilize Health is published by 8 O'Clock Labs. You can reach us at support@8oclock.app.

No account, no sign-up

The app has no login screen. You never give us an email address, a name, or a password. There is no profile on our side to attach anything to.

What stays on your device

All of it. Specifically:

This data is written to the app's private storage area. Other apps on your phone cannot read it. Deleting the app deletes it.

Optional iCloud backup

The app can back your data up to your own private iCloud storage, in a container that belongs to this app. This is switched off, and this version of the app ships with it disabled. If it is ever enabled and you turn it on, the backup lives in your Apple account, under Apple's terms, and we still have no access to it.

Apple Health

This version of the app does not connect to Apple Health. It requests no Health permission and reads nothing from HealthKit. If a future version adds it, the connection will be read-only, it will be off until you turn it on, and data read from Apple Health will stay on your device and will never be shared with us or with anyone else.

What we would receive if optional services are switched on

The app is built so that analytics, crash reporting, and advertising attribution are all optional and are switched off unless a key is configured when the app is built. In this release they are off. We are describing them here so this page stays honest if that ever changes.

If they are ever enabled, a hard-coded filter runs on every outgoing event and strips health details before they leave the device. That filter blocks symptom names and severities, exact dates, cycle lengths, diagnosis context, medication and supplement names, doses, lab names and values, body measurements, notes and free text, report contents, and your name, age, or birth year. Development builds crash rather than send a blocked value.

What each optional service would receive if enabled
ServiceWhat it would receiveWhy
RevenueCat Your App Store purchase and receipt information, an anonymous app-user identifier, and which membership you hold To know whether your membership is active, and to restore it on a new device
Mixpanel A random anonymous identifier, app version and build, which screens were opened, and coarse counts and buckets (for example "logged between 5 and 10 symptoms") To see which parts of the app get used and where people get stuck
Firebase Analytics The same filtered events and screen views, plus checkout and purchase events with a price and currency Same as above
Firebase Crashlytics Crash reports and the log breadcrumbs leading up to a crash, keyed to the anonymous identifier To find and fix crashes
AppsFlyer Device and advertising identifiers, install and purchase events, and price and currency To tell which advert or link led to an install
Meta App Events A small set of conversion events (app opened, checkout started, purchase, restore) with a price and currency, plus advertising identifiers Same as above
Statsig A random anonymous identifier and which version of an onboarding or paywall variation you were shown To compare two versions of a screen
Feedback endpoint Only the text you deliberately type into a feedback box, plus app version, device model, language, and timezone To read your feedback. Nothing is sent unless you type something and submit it.

Where any of these services process data for us, they are bound by their contracts with us to protect it to at least the standard described on this page and to use it only for the purpose above. Health data is never sent to any of them, so none of them can be used to advertise to you based on your health. We do not sell your data, and we do not share it with data brokers.

Notifications

Check-in reminders are scheduled by your phone, on your phone. There is no push server. Reminder text is deliberately neutral and never names a symptom or a condition. You can turn reminders off in the app or in iOS Settings.

Getting your data out, and deleting it

Retention

Your health data is retained on your device for as long as you keep it, and no longer. We do not hold copies. Where an optional service is enabled, that service retains the limited, non-health data described above under its own retention schedule, and we delete data we no longer need for the purpose it was collected for.

Children

Stabilize Health is for adults. It is not intended for, and must not be used by, anyone under 18. The app asks for a birth year during setup and will not proceed for anyone under 18. We do not knowingly collect anything from a child. If you believe a child has used the app, email us and we will help.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete personal data we hold about you, and to object to certain processing. Because we hold essentially nothing, the practical answer to most of these requests is "there is nothing here" — but ask us and we will confirm it in writing. Contact support@8oclock.app.

Changes to this policy

If we change how the app handles data, we will update this page and change the date at the top. Material changes will also be described in the app's release notes.

Contact

support@8oclock.app