Privacy Policy
Last updated: 2026-08-15
Rowan holds health information, which is about the most sensitive data a phone can carry. So this policy is written to be checkable rather than reassuring: every statement below about the app and its backend was checked against the code on the date above. Where a statement describes what a third party does with data we send them, it reports their published terms, which we do not control. Where something leaves your device, we say so plainly instead of burying it. Three are easy to miss, so they are stated here rather than buried: your recent conversation history — up to about 14,000 characters of it — is re-sent to the AI provider with each new message so the reply follows the thread; asking Rowan to read a reply aloud sends your device identifier and that message's id to our backend, though no text goes with it; and if you use the microphone button to speak instead of typing, that recording is sent to OpenAI to be turned into text.
Who we are
Rowan is an iOS app from HyperSage AI Labs, built by an independent developer. There is no account and no login — your install is identified by a random identifier generated on your device, not by your name or email. Contact: support@hypersage.ai.
The short version
- No account, no email, no password. The only name Rowan has is the one you choose to tell it, sent with each message so replies sound like they are for you. We keep no name column in our database — though anything you type in a message is stored as part of that message, a name included.
- No advertising SDKs and no third-party analytics touching your health content. We do not sell or share your data.
- Your messages do leave your device — they go to our backend and on to an AI provider so Rowan can reply. Today that is Anthropic, or OpenAI when Anthropic is unavailable.
- If you tap the microphone instead of typing, that recording leaves your device too: it goes to OpenAI to be turned into text, the text lands in the message box for you to read and send, and the audio is not stored by us or by your phone. Nothing is recorded unless you tap it.
- Your conversations and symptom logs are stored on our server, keyed to that random device identifier. The notes Rowan keeps about you are never filed on our server — your phone is the record of truth for them. They are still sent with every message so Rowan can remember you, and so reach the AI provider like the rest of your context; see "What we store on our own server" below.
- Everything has a retention limit, and one tap in the app deletes it.
What is sent off your device — and why
1. Your messages to Rowan
When you talk to Rowan, your message is sent to our backend and forwarded to an AI provider to generate a reply. Along with it we send a profile payload — your registered conditions, medications, allergies, recent symptom entries, preferred name, and the notes under "What Rowan knows" — so the reply fits your situation rather than being generic. We also send your device's locale so emergency resources can be resolved to your region.
We use Anthropic (Claude) as the primary provider and OpenAI as a failover. Failover is enabled by default, it is automatic, and you are not asked again when it happens: if Anthropic fails to open the stream, the same message and the same profile payload — conditions, medications, allergies, recent symptoms — go to OpenAI instead. Be clear-eyed about what that means: OpenAI can receive your health context on any turn, not just in some notional edge case. Under these providers' current API terms, your content is not used to train their models, and the provider retains it for up to 30 days for abuse monitoring before deleting it. We do not control their policies, so please also read their privacy links below.
The consent screen you see during onboarding now names both: Anthropic, because that is where your messages go on a normal turn, and OpenAI as the failover that can receive them on any turn. You are told who receives your health context in the step where you agree to it, not only here.
2. What we store on our own server
So a conversation picks up where it left off from one turn to the next, your conversations, messages, and symptom logs are stored in our own database, tied only to your random device identifier. Because there is no sign-in and no sync, these rows cannot be moved to a new phone — they are our working copy, not a backup of yours. Your trends and your visit brief are assembled on your device, from your device's copy — we do not compute them. We hold no name, email, or login that could connect that identifier to you.
What Rowan remembers about you is not stored on our server — but it is not sealed on your phone either, and the difference matters. Your device is the record of truth for those notes: when Rowan learns something it hands the updated list back to your phone and keeps no copy, so clearing a note in the app really is the end of it rather than a request to a server. A table is reserved in our database for a future signed-in sync and nothing writes to it today. However, your phone sends that list back to us on every message you write, because it is what lets Rowan remember you between conversations — so the notes travel through our backend and into the prompt sent to the AI provider on each turn, exactly like the rest of the profile payload above. They are transmitted every turn and retained by us on none of them.
Retention is bounded and swept automatically:
- Conversations and messages — 90 days, measured from the last message in a thread. A thread you keep replying to keeps its older messages until the whole thread goes quiet for 90 days.
- Symptom logs — 365 days
- Safety events — 90 days
- The reserved memory table — 365 days, if it ever holds a row. It is empty today.
There is no indefinite retention. Expired rows are deleted on a recurring sweep.
3. A content-free safety log
Rowan runs an independent safety check on messages so it can surface emergency resources reliably. When a check fires, we record a content-free event: a hashed form of your device identifier, your tier, which route was involved, which layer of the check produced the verdict, the kind of event it was, a short reason code, and the time. Every one of those is a bounded code or a hash — none of them is text you wrote. It never contains your message text, your symptoms, or your conditions. This exists to keep the safety system honest and auditable. Safety and emergency turns are never metered and never paywalled — the daily cap and any subscription stop applying the moment the safety check fires. One narrower limit is worth naming: the per-minute flood limiter runs before that full check, so it can only waive what a fast first-pass scan recognises.
4. Voice — Rowan reading aloud, and you speaking to Rowan
These are two different things with two different answers, so they are stated separately. Rowan reading a reply aloud sends no text anywhere. You speaking to Rowan does send a recording of your voice off your device, and only ever when you tap the microphone.
When Rowan reads a reply aloud, the voice is your device's own speech synthesis — no text leaves your phone to produce it. One thing does go out first: for a reply that came from our server, the app asks our backend whether a cloud voice is available, and that ask carries your device identifier and that message's id and nothing else. The backend declines every such request today (see below), and your phone then speaks the reply itself — which is also why read-aloud still works with no signal.
There is also a cloud text-to-speech route on our backend that would use OpenAI. It is switched off, and the switch is ours, not yours — there is no setting in the app that turns it on, and the route refuses every request while it is off. We are not describing a control you have; we are telling you a capability exists and is disabled. It stays disabled until this policy and the consent screen name OpenAI as a recipient of Rowan's spoken replies specifically. The consent screen names OpenAI today, but only as the failover that generates reply text when Anthropic is unavailable — that is a different permission, and it does not unlock this one. If that changes we will say so here first.
Speaking to Rowan works the other way round, and this is the one place in the app where a recording of you leaves your device. There is a microphone button next to the message box. Nothing is recorded until you tap it, nothing is recorded after you tap it again to stop, and iOS asks for microphone permission the first time — you can refuse, or withdraw it later in iOS Settings, and Rowan keeps working exactly as before by typing. There is no always-listening mode, no wake word, and no background recording; if a recording is running, iOS shows its own orange indicator whether we like it or not.
When you stop, that clip is sent to our backend and straight on to OpenAI, whose transcription service turns it into text. Be clear-eyed about what that means: OpenAI already receives your message text on some turns as the failover, and this is a third route to them — the first one that carries your voice rather than your typing. Nothing else rides along with the clip: your conditions, medications, allergies, notes and symptom history are not attached to a transcription request. What travels with it is the recording, your random device identifier, and the same App Store subscription identifiers every other request to our backend already carries — no health context, and none of your typed history.
The recording is not stored — not by us, and not on your phone. It is held in memory for the length of that one request and written to no database, no log, and no file; there is no audio column anywhere in our database and no audio file anywhere in the app. Our error reporting cannot pick it up either, because request bodies are dropped before an event is sent (see "Crash reporting"). We do not keep it to improve accuracy, and OpenAI's API terms say your content is not used to train their models. When the request ends, the clip is gone.
The text comes back to the message box, not to Rowan. It is typed into the box for you, and that is where it stops: you read it, fix anything it misheard, and press send yourself. Rowan itself is never given the words until you send them: the transcript is handed straight back to your phone, not into a conversation, and nothing about it is stored on the way past. This is deliberate and it is the point of the design — a mis-transcription in a health app becomes a symptom record, so the words that end up in your record are words you actually looked at. Once you send it, it is an ordinary message and is treated exactly like one you typed: it runs through the same safety check, and it is stored and deleted on the same terms as everything else in "What we store on our own server". A recording you never send leaves no trace at all. A single recording is also capped at about a minute, so the mic is for a sentence or two rather than a monologue.
What we do not collect
- Your name, email, or login credentials — the app has no account.
- Your location, contacts, photos, or calendar.
- Any audio you did not deliberately record. Rowan never listens in the background, has no wake word, and cannot start the microphone on its own. Tapping the mic button records until you stop it — that clip is sent to be turned into text and then discarded, and it is the one item on this list with an exception, described in full in "4. Voice" above.
- Any advertising identifier. There are no ad SDKs and no third-party analytics attached to your health content.
- Your Apple Health data or your iPhone medication list. Rowan does not read them — everything it knows is something you told it.
- Data about you from anywhere outside Rowan.
Crash reporting
Rowan's backend can send crash and error reports to Sentry. Three things are enforced in code, on every event: personally identifying data is not attached, the request body is dropped — that is the field your message would be in — and the authorization, cookie, device-id and receipt headers are removed.
Being precise about the limit of that: the scrubber rewrites the request attached to an event. It does not filter Sentry's breadcrumb trail, which is assembled from the backend's own log lines. Those log lines are written not to contain message text, symptoms or conditions, and we review them for that — but it is a discipline we hold ourselves to, not a filter that would catch us if we slipped, so we are not going to tell you breadcrumbs are health-content-free by construction. There is no product analytics of any kind — no PostHog, no Firebase, no ad networks.
How your health information is treated
Your conversations and logs may include sensitive health information. We encrypt it in transit (TLS), keep what we store on infrastructure that encrypts data at rest, bound how long we keep it, and minimize what we ask for in the first place.
- Rowan is not a HIPAA-covered entity, and we make no HIPAA claim. HIPAA governs healthcare providers, health plans, and their business associates; Rowan is a consumer wellness app and is not one of those. Any app claiming otherwise should be treated with suspicion.
- The U.S. FTC Health Breach Notification Rule may apply to apps like ours. If a breach affecting your health-related data occurs, we will — within the timeframes the Rule sets — post notice here, note it in the App Store update notes, ship an app update that carries the notice, and notify the FTC (and the media where the Rule requires). Because we hold no email or contact details for you, those are the most direct ways we can reach you.
Consumer health data
Some U.S. states — Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's health-data amendments among them — treat consumer health data as its own category with its own consent requirements. Rowan is built to that standard: collection begins only after you affirmatively consent during onboarding, having been told in that step that your messages and health context are sent to Anthropic to generate replies, and to OpenAI when Anthropic is unavailable. Recording your voice is a separate choice, taken separately. The onboarding screen tells you before you ever reach the app that the microphone sends a recording to OpenAI to be turned into text; nothing is recorded until you tap the mic button; iOS asks its own permission the first time you do; and refusing or later revoking it in iOS Settings leaves the rest of Rowan working. We do not treat your agreement to AI replies as agreement to be recorded. We do not sell your consumer health data, and we do not share it for anyone else's purposes. You can view what Rowan remembers, remove any single note or clear the whole list, export what's on your phone, and delete everything — on the device and on our server — from inside the app.
Third parties
- Anthropic — primary AI provider for Rowan's replies. anthropic.com/legal/privacy
- OpenAI — AI failover provider and transcription provider. It can receive your content by three separate routes: as the reply failover described above, enabled by default; as the failover for the independent safety check, which sends the recent transcript to a model of its own; and — only when you tap the microphone — as the transcription service that turns your recording into text. That third route is the only one that carries audio rather than text, and the recording is not stored by us before or after it (see "4. Voice"). Its text-to-speech route exists in our backend but is switched off, so nothing is sent to it for Rowan to speak today. openai.com/policies/privacy-policy
- Fly.io — hosts our backend and database. fly.io/legal/privacy-policy
- Sentry — backend error reporting, with PII disabled. sentry.io/privacy
- Apple App Store — app distribution. apple.com/legal/privacy
Your choices & rights
- See what Rowan knows: the app shows a plain list of everything it remembers about you, lets you remove any single note, and clears the whole list on request.
- Export: the app's Export button writes a JSON file of what is on your phone — your entries, your conversations, and the notes Rowan keeps about you. It also pulls the rows we hold on our server under your device identifier, so one tap gives you both halves. If our server cannot be reached, the file says so and contains your device's copy alone.
- Delete: "Delete all my data" erases your on-device record and asks our backend to purge your conversations, messages, symptom logs, safety events, and usage counters in a single transaction — plus the reserved memory table, which is empty — returning a per-table receipt. One honest exception: a rate-limiting row keyed to your network address, which contains no health content and expires on its own, is not covered by that purge. Deleting the app removes everything held on the device.
- EU/UK (GDPR) & California (CCPA/CPRA): you can exercise these rights from inside the app, without asking us: Export downloads everything tied to your device identifier including the rows on our server, Delete erases it here and there, and Settings › Withdraw consent stops the processing until you agree again. You can still write to us if you would rather. We do not sell or share your personal information, and we will not discriminate against you for exercising these rights. The categories we hold on our server are: your random device identifier; your messages and conversations, each thread titled with the first few words of the message that started it; your symptom logs; content-free safety events; your own daily usage counters; and rate-limiting counters keyed to a one-way hash of your network address. No recording of your voice appears in that list, because we keep none — a clip you dictate is transcribed and discarded within the one request, and what is stored afterwards is the message text you chose to send. Rowan's notes about you are stored on your device rather than by us, though your phone transmits them to us and on to the AI provider with each message (see "Your messages to Rowan" above). Our legal basis (GDPR) for processing your health information — which is special-category data under Article 9 — is your explicit consent, given during onboarding. We rely on legitimate interest only for the limited, health-content-free processing needed to operate and secure the service, such as rate limiting and error monitoring.
- Email support@hypersage.ai with any request.
Children
Rowan is intended for adults 18 and older and is not directed at children. We do not knowingly collect data from children. If you believe a minor has used the app, contact support@hypersage.ai.
Changes
If we change this policy we will update the date above and post the new version here. Material changes will be noted in the App Store update notes.
Contact
Questions about privacy: support@hypersage.ai