The short version. Your health data lives on your device and syncs only through your own private iCloud. There are no analytics or tracking SDKs, no advertising networks, and no accounts required for the free features. We never sell or share your health data. If you subscribe to Sulis Premium, the health context needed to answer your AI requests passes through the Sulis server to Anthropic to generate each response — we don't keep the content of those requests, only anonymous usage counts (see "Sulis Premium and the Sulis backend" below). You can export or delete everything, including your server-side account, from inside the app at any time.
In this policy, "Sulis," "we," "us," and "our" refer to the developer of the Sulis iOS app. "You" means the person using the app. By using Sulis you agree to the practices described here.
What Sulis stores, and where
Sulis is an on-device app. The information you put into it or connect to it — your supplement stack, logged doses, workouts, recovery and vitals, nutrition, bloodwork, appointments, notes, daily readiness scores, daily reads, and (if you choose to track it) cycle information — is stored on your device.
If you are signed in to iCloud and have it enabled, this data syncs across your own Apple devices through Apple's private iCloud (CloudKit) in your personal iCloud account. This sync happens between you and Apple. By default, we do not operate servers that receive, store, or have access to this data, and we cannot read it. (Sulis Premium AI requests are the exception: the context they need transits our server without being stored — see "Sulis Premium and the Sulis backend" below.)
Sulis does not require you to create an account with us, and we do not collect names, email addresses, or contact information through normal use of the app. (Sign in with Apple is available only for optional features and uses Apple's private relay; we do not receive your real email unless you choose to share it.)
Apple Health and connected wearables
With your permission, Sulis reads data from Apple Health — which may include heart rate variability (HRV), resting heart rate, sleep, steps, VO₂ max, respiratory rate, wrist temperature, workouts, and related metrics — and from connected services such as Apple Fitness, Oura, WHOOP, and nutrition apps you link.
This data is used solely to render your readiness score, trends, and insights inside the app. HealthKit data is never sold, never shared with third parties for advertising or marketing, and is never used for any purpose other than providing the app's features to you. You control exactly which Health categories Sulis can read in the iOS Health app or Settings, and you can revoke access at any time.
Bloodwork files
When you import a lab report (for example, a PDF), Sulis reads the markers so it can track your values over time. Imported bloodwork is stored encrypted in your private iCloud alongside your other Sulis data and stays under your control. We do not receive copies of your lab files.
How AI insight works
Sulis can generate plain-language insight in two ways:
- Apple Intelligence (on-device, free). When you use Apple Intelligence, processing happens on your device. Your health context is not sent to us.
- Sulis Premium (subscription). Premium features — the daily read, Ask Sulis, bloodwork import, and AI training plans — are generated by Claude, Anthropic's AI model, via the Sulis server. When you use a Premium AI feature, the relevant health context (for example, your recent metrics, supplement stack, notes, or an imported lab report) is sent from your device to the Sulis server, which forwards it to Anthropic's API and streams the response back to you. We do not store the content of these requests or responses on our server — the server keeps only your subscription status and per-request usage metering (token counts, feature name, timestamps) needed to run the service fairly. Anthropic's handling of API data is governed by their Privacy Policy and applicable commercial terms; API inputs are not used to train Anthropic's models. Sulis uses this data only to generate the insight you requested and for no other purpose.
Sulis Premium requires Sign in with Apple so the server can associate your subscription with your requests. Apple's private relay means we do not receive your real email address unless you choose to share it.
What we do not do
- We do not include third-party analytics, advertising, or tracking SDKs in the app.
- We do not build advertising profiles or track you across other apps or websites.
- We do not sell, rent, or trade your data.
- We do not store the content of your Premium AI requests on our servers, and the free tier sends us no health data at all. (See "Sulis Premium and the Sulis backend" below for exactly what the server does hold.)
This website (sulisapp.com) is a static informational site. Visiting it does not require you to provide personal information.
Sulis Premium and the Sulis backend
The free tier of Sulis works fully standalone: tracking, Apple Health, and on-device Apple Intelligence insights send none of your data to a Sulis server. Subscribing to Sulis Premium uses the Sulis backend as described here:
- Authentication. Sign in with Apple issues an identity token that the server verifies against Apple to create your session. The server stores your anonymous Apple account identifier — not your name or (unless you shared it) your real email.
- Subscription state. The server stores your App Store subscription status (product, expiry) — verified from Apple-signed receipts and Apple's server notifications — so it knows which requests to serve.
- AI requests. The health context sent with each Premium AI request transits the server to Anthropic and is not stored server-side. Bloodwork files you import transit the server for extraction and are likewise not retained there; the extracted values are stored only on your device and in your private iCloud.
- Usage metering. The server records per-request usage (feature, model, token counts, timestamp) tied to your account, used solely for fair-use limits and service cost accounting.
- Wearable connections. When you connect a wearable service, the OAuth token exchange transits the server so the connection can complete. The server relays the exchange and does not retain your wearable access tokens.
- Optional health sync. If you additionally configure a backend sync URL in Settings (off by default), your Apple Health metrics, sleep, and workout data are sent to and stored on the backend to compute insights. This remains entirely opt-in.
- Deletion. "Delete Account" in the app's Settings permanently deletes your server-side account and every record associated with it (subscription cache, usage metering, and any synced health data), and invalidates your sessions. On-device and iCloud data are deleted separately from within the app.
Your control over your data
Because your data lives on your device and in your iCloud, you remain in control of it:
- Export. You can export your data from within the app.
- Delete. You can delete your data from within the app. Deleting the app removes its on-device data; you can also remove its iCloud data from your iCloud settings.
- Revoke access. You can revoke Health and connected-service permissions at any time in iOS Settings.
Children's privacy
Sulis is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. Sulis is intended for use by adults managing their own health. If you believe a child has provided information to us, please contact us so we can help.
Changes to this policy
If we update this policy, we will revise the effective date above and post the updated version on this page. Material changes will be made clear.
Contact
Questions about privacy? Email privacy@sulisapp.com.