MIDNIGHT

Privacy Policy

Effective date: July 22, 2026

Midnight is a health companion app operated by Midnight Health LLC, a New Jersey limited liability company (“Midnight,” “we,” “us”). This policy explains what we collect, how we use it, who can see it, and the choices you have. It applies to the Midnight iOS app and the Midnight web app (together, the “Service”).

The shortest honest summary: we collect the health data you choose to share so the app can work, we never sell it, we never use it for advertising, and you can ask us to delete it at any time.

What we collect

What we do with it

What we never do with your health data

Sharing with your health professional

Midnight supports an optional relationship with an independent health professional (for example, a nutritionist or coach). This sharing only happens if you enter an invite code they give you. Once linked, your professional can see your goals, health metrics, logs, and checkpoints, and can set goals and checkpoints for you. To end this sharing, contact us at woody@mdnt.health and we will unlink the relationship. Professionals are independent providers, not employees or agents of Midnight Health LLC.

Service providers

We use a small number of infrastructure providers to run the Service, each of which processes data only on our instructions: Supabase (database and authentication; data stored on servers located in Canada), Vercel (web hosting), Anthropic and Google (AI processing, as described above), ElevenLabs (voice processing, as described above), Sentry (crash and error reporting), and PostHog (product analytics and web session replay). If you connect a third-party fitness or wearable account — Strava, Fitbit, Oura, or Whoop — that provider shares the metrics you authorize with us under its own privacy policy. We do not use third-party advertising or marketing SDKs.

Security

Your data is encrypted in transit (TLS) and at rest. Database access is protected by row-level security so your records are only readable by you and, if you have linked one, your health professional. Server-side access requires authenticated sessions verified on every request.

Retention and deletion

We keep your data for as long as your account exists. Delete your account and all associated data by contacting us at woody@mdnt.health; deletion removes your goals, health metrics, logs, chat history, check-ins, and any professional links. We aim to complete deletion requests within 30 days.

Your rights

Depending on where you live (including under the California Consumer Privacy Act and state consumer-health-data laws such as Washington’s My Health My Data Act), you may have rights to access, correct, delete, or receive a copy of your data, and to withdraw consent for the collection of consumer health data. To exercise any of these, email woody@mdnt.health. We will never discriminate against you for exercising a privacy right.

Children

Midnight is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

Not a medical service

Midnight is a wellness tool, not a healthcare provider, and is not covered by HIPAA. We do not provide medical advice, diagnosis, or treatment.

Changes

If we make material changes to this policy, we will update the effective date above and notify you in the app before the changes take effect.

Contact

Midnight Health LLC, New Jersey, USA — woody@mdnt.health