Effective September 16, 2026
Privacy Policy
Marrow is built so that there is almost nothing to collect. Your health data lives on your iPhone, in Apple Health and in Marrow's own local database. There is no Marrow account and no analytics. The only copy of your health data on a server we run is the optional Connect your AI mirror, which exists only if you turn it on and disappears when you turn it off.
The short version. Everything Marrow reads from Apple Health stays on your device. A few things leave your phone, and only when you ask for them: a meal photo, text or voice description you choose to log with AI, a barcode or food name you choose to look up, and, if you turn on Connect your AI (a Pro feature), a private copy your AI can read. We do not sell data, do not run ads, do not use analytics or tracking SDKs, and do not have a way to see your health history even if we wanted to.
This policy covers the Marrow iOS app and the services at skeletonarmy.tech. Marrow is published by Aidan Hall, sole proprietor, doing business as Skeleton Army. Questions: [email protected].
1. What stays on your device
All of it, by default. Specifically:
- Every Apple Health metric Marrow reads, including steps, heart rate, sleep, workouts, body measurements, and the rest of the categories you grant.
- Your food log, including meals, nutrients, portions, and any photo you took.
- Your workout log, goals, and app settings.
- Access tokens for any server or agent you pair with, held in the iOS Keychain.
This data is stored in Marrow's local database inside the app's sandbox on your iPhone. Marrow does not store your health data in iCloud. If you have iPhone backups enabled, your device backup is governed by Apple's privacy policy, not ours.
2. What leaves your device, and only when you ask
Meal photos you choose to scan
When you log food by photo, that one image is sent to Marrow's photo service and forwarded to Google's Gemini API, which returns a guess at what the food is and its nutrition. Details that matter:
- The image is re-encoded before it is sent, which strips EXIF metadata including GPS location, camera model, and timestamps.
- The photo is not written to disk on our server. It is held in memory for the duration of the request and discarded.
- Marrow uses a paid Google API tier, under which Google does not use submitted content to train or improve its models. Google may retain content briefly for abuse monitoring and legal compliance under the Gemini API Terms.
- No health data, no name, no email, and no account identifier is sent with the photo. Google receives the image and nothing else about you.
- AI logging is optional. Search and manual entry never send an image, text or audio anywhere.
Text and voice descriptions you choose to log
When you log food by typing a description or by speaking, that text or that short audio clip is sent to Marrow's food service and forwarded to Google's Gemini API, which returns a transcript (for audio) and a guess at the foods and their nutrition. The clip and text are held in memory for the request and discarded; nothing is written to disk on our server. The same Google API terms as for photos apply. No health data and no identity travels with it.
Connect your AI (Marrow Pro): a private copy on our server
This is optional, off by default, and the only case in which we hold health data. When you turn it on, the app creates a mirror on a server we run and keeps it current in the background: your Apple Health metrics, meals, workouts, strength sets and sleep, the same records the app shows. In return, ChatGPT, Claude or Gemini can read that copy any time, including while your phone is asleep. Details that matter:
- The link the app gives you identifies your mirror but cannot read it. Every AI must sign in, and the sign-in completes only when you type the code from the sign-in page into Marrow and approve it. You can deny any request.
- The mirror is stored on a server in the United States, protected by access tokens that are stored hashed. We can technically read it while it exists, we do not, and we log only request paths and status codes, never tokens or content. Traffic passes through Cloudflare, which terminates TLS.
- Tapping Disconnect and delete the copy deletes the mirror immediately. Revoking a connected AI stops its reads at once.
- What the AI does with what it reads is governed by that AI provider's terms, not ours.
Purchases
Marrow Pro is sold through Apple. Apple handles payment and we never see your card, name or Apple ID. The app checks your entitlement with Apple on the device; we run no purchase server and keep no purchase records tied to you.
Campus dining menus (Marrow Pro)
If you choose a school, the app downloads that school's published menus from a static file on our server. Your choice of school is stored on your device. The request carries no identifier and no health data.
A random device identifier, for rate limiting only
AI logging (photo, text and voice) costs us money per request, so it is capped per device per day: three a day on the free plan, a higher ceiling on Marrow Pro. To count requests, the app generates a random identifier the first time you scan, stores it in your Keychain, and sends it with photo requests. It is not your Apple ID, not your device serial, not an advertising identifier, and it is not derived from anything about you or your hardware. Our server keeps only a count for the current day, and yesterday's rows are deleted when the day rolls over. It is never shared, and it is never attached to health data because we never receive health data.
Barcodes and food searches
When you scan a barcode or search for a food, the barcode number or search text is sent to Open Food Facts, an open food database, to look up branded products. No identifier and no health data goes with it. Marrow also ships with a USDA FoodData Central database built into the app, so generic foods are found offline without any network request at all.
Anything you deliberately export
Marrow's whole point is letting you move your own data. When you export a file, run an automation, pair a server, or connect an AI agent over MCP, your data goes where you tell it to go. If you point an automation at your own server, that server receives your health data and its operator's rules apply. We are not in the middle of that connection, we do not see it, and we cannot retrieve it for you. Choose destinations you trust.
3. What our server logs
The food service writes one line per request containing: a timestamp, how long the request took, the HTTP status code, the size of the upload in bytes, the model name, how many foods were detected, and token counts. It does not log the image, the identified foods, your device identifier, your IP address in application logs, or any health data.
4. What we never do
These are commitments, not defaults we might quietly change. This section exists in part because Apple's App Store Review Guideline 5.1.3 governs health apps, and we hold ourselves to it explicitly:
- We never use health data for advertising. Marrow shows no ads of any kind, from us or anyone else.
- We never sell, rent, or trade your data, to data brokers or anyone else.
- We never share health data with third parties for marketing, and we never share it for their own independent use.
- We never store your health data in iCloud.
- We never use health data for any purpose beyond your direct benefit inside the app, such as research or profiling, without your separate consent.
- We run no analytics, no crash-reporting SDK, and no tracking of any kind. Marrow does not ask for App Tracking Transparency permission because it does not track you.
- We require no account, so we hold no email address, password, or profile for you.
5. Apple Health permissions
Marrow reads from Apple Health only in the categories you approve, and iOS controls that entirely. You can review or revoke any category at any time in Settings, Privacy & Security, Health, Marrow. Marrow also writes back to Apple Health, such as food you log and workouts you record, when you permit it. Revoking a permission stops new reads immediately. Data already synced into Marrow's local database stays there until you delete it or delete the app.
6. Deleting your data
Delete the Marrow app and everything it stored is deleted with it, since it all lives in the app's sandbox. There is no server-side account to close and nothing for us to erase on request, because we hold nothing tied to you. Data in Apple Health belongs to Apple Health and is managed in the Health app. Data you exported to your own destinations is yours to delete there. Files you exported to your own devices are, likewise, yours.
7. Security
All network requests use TLS. Paired servers and MCP agent connections are authenticated with bearer tokens generated on your device and stored in the Keychain. The on-device MCP server ships turned off and binds to your local network only when you turn it on. You can revoke a token by unpairing the server in the app.
8. Children
Marrow is not directed at children under 13, and we do not knowingly collect information from them. We do not have accounts, so we have no way to identify a user's age.
9. Your rights
Under laws such as the GDPR and the CCPA you have rights to access, correct, delete, and port your personal data, and to object to certain processing. Marrow's architecture satisfies these by design: your data is already in your possession, exportable in open formats at any time, and deletable by removing the app. We do not sell personal information, so there is nothing to opt out of. If you believe we hold something about you and want it removed, write to [email protected] and we will act within 30 days.
10. Changes
If this policy changes in a way that affects what leaves your device, we will update the effective date at the top and describe the change in the app's release notes. Continued use after a change means you accept the updated policy.
11. Contact
Aidan Hall, doing business as Skeleton Army
[email protected]
See also: Terms of Use and Support.