MIDNIGHT

MIDNIGHT

Security

Midnight handles health data, so we treat security as a baseline requirement, not an afterthought.

How your data is protected

  • Data is encrypted in transit (TLS) and at rest.
  • Database access is protected by row-level security — your records are only readable by you and, if you've linked one, your health professional.
  • Server-side access requires an authenticated session verified on every request; no endpoint trusts a client-supplied user ID.
  • Sensitive account changes never happen from the client — they run only through server-side, service-authenticated code paths.

Connected health data

You choose which Apple Health categories to share, in iOS Settings, and can revoke access at any time. Midnight only reads the categories you authorize — it never writes to Apple Health. The same applies if you connect a third-party account (Strava, Fitbit, Oura, or Whoop): you authorize the connection, you can disconnect it at any time, and Midnight only reads what that provider's permissions allow.

No ad tracking

Midnight does not use advertising or data-broker SDKs, and never uses your health data for advertising or marketing.

Questions

See our Privacy Policy for the full picture, or contact support.