Privacy Policy

Last updated: 2026-08-15

Rowan holds health information, which is about the most sensitive data a phone can carry. So this policy is written to be checkable rather than reassuring: every statement below about the app and its backend was checked against the code on the date above. Where a statement describes what a third party does with data we send them, it reports their published terms, which we do not control. Where something leaves your device, we say so plainly instead of burying it. Three are easy to miss, so they are stated here rather than buried: your recent conversation history — up to about 14,000 characters of it — is re-sent to the AI provider with each new message so the reply follows the thread; asking Rowan to read a reply aloud sends your device identifier and that message's id to our backend, though no text goes with it; and if you use the microphone button to speak instead of typing, that recording is sent to OpenAI to be turned into text.

Who we are

Rowan is an iOS app from HyperSage AI Labs, built by an independent developer. There is no account and no login — your install is identified by a random identifier generated on your device, not by your name or email. Contact: support@hypersage.ai.

The short version

What is sent off your device — and why

1. Your messages to Rowan

When you talk to Rowan, your message is sent to our backend and forwarded to an AI provider to generate a reply. Along with it we send a profile payload — your registered conditions, medications, allergies, recent symptom entries, preferred name, and the notes under "What Rowan knows" — so the reply fits your situation rather than being generic. We also send your device's locale so emergency resources can be resolved to your region.

We use Anthropic (Claude) as the primary provider and OpenAI as a failover. Failover is enabled by default, it is automatic, and you are not asked again when it happens: if Anthropic fails to open the stream, the same message and the same profile payload — conditions, medications, allergies, recent symptoms — go to OpenAI instead. Be clear-eyed about what that means: OpenAI can receive your health context on any turn, not just in some notional edge case. Under these providers' current API terms, your content is not used to train their models, and the provider retains it for up to 30 days for abuse monitoring before deleting it. We do not control their policies, so please also read their privacy links below.

The consent screen you see during onboarding now names both: Anthropic, because that is where your messages go on a normal turn, and OpenAI as the failover that can receive them on any turn. You are told who receives your health context in the step where you agree to it, not only here.

2. What we store on our own server

So a conversation picks up where it left off from one turn to the next, your conversations, messages, and symptom logs are stored in our own database, tied only to your random device identifier. Because there is no sign-in and no sync, these rows cannot be moved to a new phone — they are our working copy, not a backup of yours. Your trends and your visit brief are assembled on your device, from your device's copy — we do not compute them. We hold no name, email, or login that could connect that identifier to you.

What Rowan remembers about you is not stored on our server — but it is not sealed on your phone either, and the difference matters. Your device is the record of truth for those notes: when Rowan learns something it hands the updated list back to your phone and keeps no copy, so clearing a note in the app really is the end of it rather than a request to a server. A table is reserved in our database for a future signed-in sync and nothing writes to it today. However, your phone sends that list back to us on every message you write, because it is what lets Rowan remember you between conversations — so the notes travel through our backend and into the prompt sent to the AI provider on each turn, exactly like the rest of the profile payload above. They are transmitted every turn and retained by us on none of them.

Retention is bounded and swept automatically:

There is no indefinite retention. Expired rows are deleted on a recurring sweep.

3. A content-free safety log

Rowan runs an independent safety check on messages so it can surface emergency resources reliably. When a check fires, we record a content-free event: a hashed form of your device identifier, your tier, which route was involved, which layer of the check produced the verdict, the kind of event it was, a short reason code, and the time. Every one of those is a bounded code or a hash — none of them is text you wrote. It never contains your message text, your symptoms, or your conditions. This exists to keep the safety system honest and auditable. Safety and emergency turns are never metered and never paywalled — the daily cap and any subscription stop applying the moment the safety check fires. One narrower limit is worth naming: the per-minute flood limiter runs before that full check, so it can only waive what a fast first-pass scan recognises.

4. Voice — Rowan reading aloud, and you speaking to Rowan

These are two different things with two different answers, so they are stated separately. Rowan reading a reply aloud sends no text anywhere. You speaking to Rowan does send a recording of your voice off your device, and only ever when you tap the microphone.

When Rowan reads a reply aloud, the voice is your device's own speech synthesis — no text leaves your phone to produce it. One thing does go out first: for a reply that came from our server, the app asks our backend whether a cloud voice is available, and that ask carries your device identifier and that message's id and nothing else. The backend declines every such request today (see below), and your phone then speaks the reply itself — which is also why read-aloud still works with no signal.

There is also a cloud text-to-speech route on our backend that would use OpenAI. It is switched off, and the switch is ours, not yours — there is no setting in the app that turns it on, and the route refuses every request while it is off. We are not describing a control you have; we are telling you a capability exists and is disabled. It stays disabled until this policy and the consent screen name OpenAI as a recipient of Rowan's spoken replies specifically. The consent screen names OpenAI today, but only as the failover that generates reply text when Anthropic is unavailable — that is a different permission, and it does not unlock this one. If that changes we will say so here first.

Speaking to Rowan works the other way round, and this is the one place in the app where a recording of you leaves your device. There is a microphone button next to the message box. Nothing is recorded until you tap it, nothing is recorded after you tap it again to stop, and iOS asks for microphone permission the first time — you can refuse, or withdraw it later in iOS Settings, and Rowan keeps working exactly as before by typing. There is no always-listening mode, no wake word, and no background recording; if a recording is running, iOS shows its own orange indicator whether we like it or not.

When you stop, that clip is sent to our backend and straight on to OpenAI, whose transcription service turns it into text. Be clear-eyed about what that means: OpenAI already receives your message text on some turns as the failover, and this is a third route to them — the first one that carries your voice rather than your typing. Nothing else rides along with the clip: your conditions, medications, allergies, notes and symptom history are not attached to a transcription request. What travels with it is the recording, your random device identifier, and the same App Store subscription identifiers every other request to our backend already carries — no health context, and none of your typed history.

The recording is not stored — not by us, and not on your phone. It is held in memory for the length of that one request and written to no database, no log, and no file; there is no audio column anywhere in our database and no audio file anywhere in the app. Our error reporting cannot pick it up either, because request bodies are dropped before an event is sent (see "Crash reporting"). We do not keep it to improve accuracy, and OpenAI's API terms say your content is not used to train their models. When the request ends, the clip is gone.

The text comes back to the message box, not to Rowan. It is typed into the box for you, and that is where it stops: you read it, fix anything it misheard, and press send yourself. Rowan itself is never given the words until you send them: the transcript is handed straight back to your phone, not into a conversation, and nothing about it is stored on the way past. This is deliberate and it is the point of the design — a mis-transcription in a health app becomes a symptom record, so the words that end up in your record are words you actually looked at. Once you send it, it is an ordinary message and is treated exactly like one you typed: it runs through the same safety check, and it is stored and deleted on the same terms as everything else in "What we store on our own server". A recording you never send leaves no trace at all. A single recording is also capped at about a minute, so the mic is for a sentence or two rather than a monologue.

What we do not collect

Crash reporting

Rowan's backend can send crash and error reports to Sentry. Three things are enforced in code, on every event: personally identifying data is not attached, the request body is dropped — that is the field your message would be in — and the authorization, cookie, device-id and receipt headers are removed.

Being precise about the limit of that: the scrubber rewrites the request attached to an event. It does not filter Sentry's breadcrumb trail, which is assembled from the backend's own log lines. Those log lines are written not to contain message text, symptoms or conditions, and we review them for that — but it is a discipline we hold ourselves to, not a filter that would catch us if we slipped, so we are not going to tell you breadcrumbs are health-content-free by construction. There is no product analytics of any kind — no PostHog, no Firebase, no ad networks.

How your health information is treated

Your conversations and logs may include sensitive health information. We encrypt it in transit (TLS), keep what we store on infrastructure that encrypts data at rest, bound how long we keep it, and minimize what we ask for in the first place.

Consumer health data

Some U.S. states — Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's health-data amendments among them — treat consumer health data as its own category with its own consent requirements. Rowan is built to that standard: collection begins only after you affirmatively consent during onboarding, having been told in that step that your messages and health context are sent to Anthropic to generate replies, and to OpenAI when Anthropic is unavailable. Recording your voice is a separate choice, taken separately. The onboarding screen tells you before you ever reach the app that the microphone sends a recording to OpenAI to be turned into text; nothing is recorded until you tap the mic button; iOS asks its own permission the first time you do; and refusing or later revoking it in iOS Settings leaves the rest of Rowan working. We do not treat your agreement to AI replies as agreement to be recorded. We do not sell your consumer health data, and we do not share it for anyone else's purposes. You can view what Rowan remembers, remove any single note or clear the whole list, export what's on your phone, and delete everything — on the device and on our server — from inside the app.

Third parties

Your choices & rights

Children

Rowan is intended for adults 18 and older and is not directed at children. We do not knowingly collect data from children. If you believe a minor has used the app, contact support@hypersage.ai.

Changes

If we change this policy we will update the date above and post the new version here. Material changes will be noted in the App Store update notes.

Contact

Questions about privacy: support@hypersage.ai

In an emergency, don't type — call 911. Rowan is not an emergency service and is not monitored by a human. If you are having a medical emergency, call 911 or your local emergency number. If you are thinking about harming yourself, call or text 988 (US Suicide & Crisis Lifeline). Never delay care because of something in this app.