Marrow Get the app

Effective September 16, 2026

Privacy Policy

Marrow is built so that there is almost nothing to collect. Your health data lives on your iPhone, in Apple Health and in Marrow's own local database. There is no Marrow account and no analytics. The only copy of your health data on a server we run is the optional Connect your AI mirror, which exists only if you turn it on and disappears when you turn it off.

The short version. Everything Marrow reads from Apple Health stays on your device. A few things leave your phone, and only when you ask for them: a meal photo, text or voice description you choose to log with AI, a barcode or food name you choose to look up, and, if you turn on Connect your AI (a Pro feature), a private copy your AI can read. We do not sell data, do not run ads, do not use analytics or tracking SDKs, and do not have a way to see your health history even if we wanted to.

This policy covers the Marrow iOS app and the services at skeletonarmy.tech. Marrow is published by Aidan Hall, sole proprietor, doing business as Skeleton Army. Questions: [email protected].

1. What stays on your device

All of it, by default. Specifically:

This data is stored in Marrow's local database inside the app's sandbox on your iPhone. Marrow does not store your health data in iCloud. If you have iPhone backups enabled, your device backup is governed by Apple's privacy policy, not ours.

2. What leaves your device, and only when you ask

Meal photos you choose to scan

When you log food by photo, that one image is sent to Marrow's photo service and forwarded to Google's Gemini API, which returns a guess at what the food is and its nutrition. Details that matter:

Text and voice descriptions you choose to log

When you log food by typing a description or by speaking, that text or that short audio clip is sent to Marrow's food service and forwarded to Google's Gemini API, which returns a transcript (for audio) and a guess at the foods and their nutrition. The clip and text are held in memory for the request and discarded; nothing is written to disk on our server. The same Google API terms as for photos apply. No health data and no identity travels with it.

Connect your AI (Marrow Pro): a private copy on our server

This is optional, off by default, and the only case in which we hold health data. When you turn it on, the app creates a mirror on a server we run and keeps it current in the background: your Apple Health metrics, meals, workouts, strength sets and sleep, the same records the app shows. In return, ChatGPT, Claude or Gemini can read that copy any time, including while your phone is asleep. Details that matter:

Purchases

Marrow Pro is sold through Apple. Apple handles payment and we never see your card, name or Apple ID. The app checks your entitlement with Apple on the device; we run no purchase server and keep no purchase records tied to you.

Campus dining menus (Marrow Pro)

If you choose a school, the app downloads that school's published menus from a static file on our server. Your choice of school is stored on your device. The request carries no identifier and no health data.

A random device identifier, for rate limiting only

AI logging (photo, text and voice) costs us money per request, so it is capped per device per day: three a day on the free plan, a higher ceiling on Marrow Pro. To count requests, the app generates a random identifier the first time you scan, stores it in your Keychain, and sends it with photo requests. It is not your Apple ID, not your device serial, not an advertising identifier, and it is not derived from anything about you or your hardware. Our server keeps only a count for the current day, and yesterday's rows are deleted when the day rolls over. It is never shared, and it is never attached to health data because we never receive health data.

Barcodes and food searches

When you scan a barcode or search for a food, the barcode number or search text is sent to Open Food Facts, an open food database, to look up branded products. No identifier and no health data goes with it. Marrow also ships with a USDA FoodData Central database built into the app, so generic foods are found offline without any network request at all.

Anything you deliberately export

Marrow's whole point is letting you move your own data. When you export a file, run an automation, pair a server, or connect an AI agent over MCP, your data goes where you tell it to go. If you point an automation at your own server, that server receives your health data and its operator's rules apply. We are not in the middle of that connection, we do not see it, and we cannot retrieve it for you. Choose destinations you trust.

3. What our server logs

The food service writes one line per request containing: a timestamp, how long the request took, the HTTP status code, the size of the upload in bytes, the model name, how many foods were detected, and token counts. It does not log the image, the identified foods, your device identifier, your IP address in application logs, or any health data.

4. What we never do

These are commitments, not defaults we might quietly change. This section exists in part because Apple's App Store Review Guideline 5.1.3 governs health apps, and we hold ourselves to it explicitly:

5. Apple Health permissions

Marrow reads from Apple Health only in the categories you approve, and iOS controls that entirely. You can review or revoke any category at any time in Settings, Privacy & Security, Health, Marrow. Marrow also writes back to Apple Health, such as food you log and workouts you record, when you permit it. Revoking a permission stops new reads immediately. Data already synced into Marrow's local database stays there until you delete it or delete the app.

6. Deleting your data

Delete the Marrow app and everything it stored is deleted with it, since it all lives in the app's sandbox. There is no server-side account to close and nothing for us to erase on request, because we hold nothing tied to you. Data in Apple Health belongs to Apple Health and is managed in the Health app. Data you exported to your own destinations is yours to delete there. Files you exported to your own devices are, likewise, yours.

7. Security

All network requests use TLS. Paired servers and MCP agent connections are authenticated with bearer tokens generated on your device and stored in the Keychain. The on-device MCP server ships turned off and binds to your local network only when you turn it on. You can revoke a token by unpairing the server in the app.

8. Children

Marrow is not directed at children under 13, and we do not knowingly collect information from them. We do not have accounts, so we have no way to identify a user's age.

9. Your rights

Under laws such as the GDPR and the CCPA you have rights to access, correct, delete, and port your personal data, and to object to certain processing. Marrow's architecture satisfies these by design: your data is already in your possession, exportable in open formats at any time, and deletable by removing the app. We do not sell personal information, so there is nothing to opt out of. If you believe we hold something about you and want it removed, write to [email protected] and we will act within 30 days.

10. Changes

If this policy changes in a way that affects what leaves your device, we will update the effective date at the top and describe the change in the app's release notes. Continued use after a change means you accept the updated policy.

11. Contact

Aidan Hall, doing business as Skeleton Army
[email protected]

See also: Terms of Use and Support.