Effective August 16, 2026
Privacy Policy
Marrow is built so that there is almost nothing to collect. Your health data lives on your iPhone, in Apple Health and in Marrow's own local database. There is no Marrow account, no Marrow cloud, and no copy of your health history on any server we run.
The short version. Everything Marrow reads from Apple Health stays on your device. Two things leave your phone, and only when you ask for them: a meal photo you choose to scan, and a barcode or food name you choose to look up. We do not sell data, do not run ads, do not use analytics or tracking SDKs, and do not have a way to see your health history even if we wanted to.
This policy covers the Marrow iOS app and the services at skeletonarmy.tech. Marrow is published by Aidan Hall, sole proprietor, doing business as Skeleton Army. Questions: [email protected].
1. What stays on your device
All of it, by default. Specifically:
- Every Apple Health metric Marrow reads, including steps, heart rate, sleep, workouts, body measurements, and the rest of the categories you grant.
- Your food log, including meals, nutrients, portions, and any photo you took.
- Your workout log, goals, and app settings.
- Access tokens for any server or agent you pair with, held in the iOS Keychain.
This data is stored in Marrow's local database inside the app's sandbox on your iPhone. Marrow does not store your health data in iCloud. If you have iPhone backups enabled, your device backup is governed by Apple's privacy policy, not ours.
2. What leaves your device, and only when you ask
Meal photos you choose to scan
When you log food by photo, that one image is sent to Marrow's photo service and forwarded to Google's Gemini API, which returns a guess at what the food is and its nutrition. Details that matter:
- The image is re-encoded before it is sent, which strips EXIF metadata including GPS location, camera model, and timestamps.
- The photo is not written to disk on our server. It is held in memory for the duration of the request and discarded.
- Marrow uses a paid Google API tier, under which Google does not use submitted content to train or improve its models. Google may retain content briefly for abuse monitoring and legal compliance under the Gemini API Terms.
- No health data, no name, no email, and no account identifier is sent with the photo. Google receives the image and nothing else about you.
- Photo scanning is optional. Barcode scanning, search, and manual entry never send an image anywhere.
A random device identifier, for rate limiting only
Photo scanning is free and costs us money per scan, so it is capped per device per day. To count scans, the app generates a random identifier the first time you scan, stores it in your Keychain, and sends it with photo requests. It is not your Apple ID, not your device serial, not an advertising identifier, and it is not derived from anything about you or your hardware. Our server keeps only a count for the current day, and yesterday's rows are deleted when the day rolls over. It is never shared, and it is never attached to health data because we never receive health data.
Barcodes and food searches
When you scan a barcode or search for a food, the barcode number or search text is sent to Open Food Facts, an open food database, to look up branded products. No identifier and no health data goes with it. Marrow also ships with a USDA FoodData Central database built into the app, so generic foods are found offline without any network request at all.
Anything you deliberately export
Marrow's whole point is letting you move your own data. When you export a file, run an automation, pair a server, or connect an AI agent over MCP, your data goes where you tell it to go. If you point an automation at your own server, that server receives your health data and its operator's rules apply. We are not in the middle of that connection, we do not see it, and we cannot retrieve it for you. Choose destinations you trust.
3. What our server logs
The photo service writes one line per request containing: a timestamp, how long the request took, the HTTP status code, the size of the upload in bytes, the model name, how many foods were detected, and token counts. It does not log the image, the identified foods, your device identifier, your IP address in application logs, or any health data.
4. What we never do
These are commitments, not defaults we might quietly change. This section exists in part because Apple's App Store Review Guideline 5.1.3 governs health apps, and we hold ourselves to it explicitly:
- We never use health data for advertising. Marrow shows no ads of any kind, from us or anyone else.
- We never sell, rent, or trade your data, to data brokers or anyone else.
- We never share health data with third parties for marketing, and we never share it for their own independent use.
- We never store your health data in iCloud.
- We never use health data for any purpose beyond your direct benefit inside the app, such as research or profiling, without your separate consent.
- We run no analytics, no crash-reporting SDK, and no tracking of any kind. Marrow does not ask for App Tracking Transparency permission because it does not track you.
- We require no account, so we hold no email address, password, or profile for you.
5. Apple Health permissions
Marrow reads from Apple Health only in the categories you approve, and iOS controls that entirely. You can review or revoke any category at any time in Settings, Privacy & Security, Health, Marrow. Marrow also writes back to Apple Health, such as food you log and workouts you record, when you permit it. Revoking a permission stops new reads immediately. Data already synced into Marrow's local database stays there until you delete it or delete the app.
6. Deleting your data
Delete the Marrow app and everything it stored is deleted with it, since it all lives in the app's sandbox. There is no server-side account to close and nothing for us to erase on request, because we hold nothing tied to you. Data in Apple Health belongs to Apple Health and is managed in the Health app. Data you exported to your own destinations is yours to delete there. Files you exported to your own devices are, likewise, yours.
7. Security
All network requests use TLS. Paired servers and MCP agent connections are authenticated with bearer tokens generated on your device and stored in the Keychain. The on-device MCP server ships turned off and binds to your local network only when you turn it on. You can revoke a token by unpairing the server in the app.
8. Children
Marrow is not directed at children under 13, and we do not knowingly collect information from them. We do not have accounts, so we have no way to identify a user's age.
9. Your rights
Under laws such as the GDPR and the CCPA you have rights to access, correct, delete, and port your personal data, and to object to certain processing. Marrow's architecture satisfies these by design: your data is already in your possession, exportable in open formats at any time, and deletable by removing the app. We do not sell personal information, so there is nothing to opt out of. If you believe we hold something about you and want it removed, write to [email protected] and we will act within 30 days.
10. Changes
If this policy changes in a way that affects what leaves your device, we will update the effective date at the top and describe the change in the app's release notes. Continued use after a change means you accept the updated policy.
11. Contact
Aidan Hall, doing business as Skeleton Army
[email protected]
See also: Terms of Use and Support.