MIDNIGHT
Privacy Policy
Effective date: July 22, 2026
Midnight is a health companion app operated by Midnight Health LLC, a New Jersey limited liability company (“Midnight,” “we,” “us”). This policy explains what we collect, how we use it, who can see it, and the choices you have. It applies to the Midnight iOS app and the Midnight web app (together, the “Service”).
The shortest honest summary: we collect the health data you choose to share so the app can work, we never sell it, we never use it for advertising, and you can ask us to delete it at any time.
What we collect
- Account information. Your email address, a password (stored as a secure hash by our authentication provider — we never see or store your plaintext password), and a device push token if you enable notifications.
- Health data from connected sources. Metrics like weight, body fat percentage, steps, active and resting energy, sleep, resting heart rate, heart rate variability, exercise minutes, VO2 max, blood glucose, water, and alcohol consumption — from Apple Health (only the categories you explicitly authorize in iOS, revocable anytime in iOS Settings) and, if you choose to link them, third-party accounts you connect via OAuth: Strava, Fitbit, Oura, or Whoop. You can disconnect any provider at any time; disconnecting stops future syncing but doesn’t delete metrics already synced.
- Profile basics. Optionally, your birthdate, sex, and height — used only to calculate metabolic estimates like BMR.
- Content you create. Your stated health goal, food and habit logs, chat and voice conversations with the Midnight companion, day-planning sessions, and progress check-ins.
- Professional relationship data. If you link with a health professional using an invite code: the link itself, the goals and checkpoints they set with you, and their session notes.
What we do with it
- Build your dashboard, watch-list, trends, and metabolic estimates.
- Generate AI responses: your goal text, chat messages, logs, and recent health metrics are processed by Anthropic’s Claude API and Google’s Gemini API to interpret goals, respond in chat, and decide whether to send you a nudge. Neither provider uses this data to train their models by default.
- Power voice conversations: if you talk to Midnight instead of typing, your voice audio and transcripts are processed by ElevenLabs to convert speech to text and text to speech in real time.
- Send you in-app nudges when your data drifts from your stated goal.
- Understand product usage through analytics, so we can fix bugs and improve the app.
- Operate, debug, and secure the Service.
What we never do with your health data
- We never sell it — to anyone, for any reason.
- We never use it for advertising or marketing.
- We never share it with data brokers.
- We use PostHog for product analytics, and session replay on the web app, to understand how the Service is used and to fix bugs — this may include on-screen content during a replay. PostHog never receives this data for advertising, never sells it, and we never share it with anyone outside Midnight.
- We never use Apple HealthKit or connected-provider data for any purpose other than providing the Service to you, consistent with Apple’s Health app guidelines and each provider’s developer terms.
Sharing with your health professional
Midnight supports an optional relationship with an independent health professional (for example, a nutritionist or coach). This sharing only happens if you enter an invite code they give you. Once linked, your professional can see your goals, health metrics, logs, and checkpoints, and can set goals and checkpoints for you. To end this sharing, contact us at woody@mdnt.health and we will unlink the relationship. Professionals are independent providers, not employees or agents of Midnight Health LLC.
Service providers
We use a small number of infrastructure providers to run the Service, each of which processes data only on our instructions: Supabase (database and authentication; data stored on servers located in Canada), Vercel (web hosting), Anthropic and Google (AI processing, as described above), ElevenLabs (voice processing, as described above), Sentry (crash and error reporting), and PostHog (product analytics and web session replay). If you connect a third-party fitness or wearable account — Strava, Fitbit, Oura, or Whoop — that provider shares the metrics you authorize with us under its own privacy policy. We do not use third-party advertising or marketing SDKs.
Security
Your data is encrypted in transit (TLS) and at rest. Database access is protected by row-level security so your records are only readable by you and, if you have linked one, your health professional. Server-side access requires authenticated sessions verified on every request.
Retention and deletion
We keep your data for as long as your account exists. Delete your account and all associated data by contacting us at woody@mdnt.health; deletion removes your goals, health metrics, logs, chat history, check-ins, and any professional links. We aim to complete deletion requests within 30 days.
Your rights
Depending on where you live (including under the California Consumer Privacy Act and state consumer-health-data laws such as Washington’s My Health My Data Act), you may have rights to access, correct, delete, or receive a copy of your data, and to withdraw consent for the collection of consumer health data. To exercise any of these, email woody@mdnt.health. We will never discriminate against you for exercising a privacy right.
Children
Midnight is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
Not a medical service
Midnight is a wellness tool, not a healthcare provider, and is not covered by HIPAA. We do not provide medical advice, diagnosis, or treatment.
Changes
If we make material changes to this policy, we will update the effective date above and notify you in the app before the changes take effect.
Contact
Midnight Health LLC, New Jersey, USA — woody@mdnt.health