Marrow Get the beta

Effective August 16, 2026

Privacy Policy

Marrow is built so that there is almost nothing to collect. Your health data lives on your iPhone, in Apple Health and in Marrow's own local database. There is no Marrow account, no Marrow cloud, and no copy of your health history on any server we run.

The short version. Everything Marrow reads from Apple Health stays on your device. Two things leave your phone, and only when you ask for them: a meal photo you choose to scan, and a barcode or food name you choose to look up. We do not sell data, do not run ads, do not use analytics or tracking SDKs, and do not have a way to see your health history even if we wanted to.

This policy covers the Marrow iOS app and the services at skeletonarmy.tech. Marrow is published by Aidan Hall, sole proprietor, doing business as Skeleton Army. Questions: [email protected].

1. What stays on your device

All of it, by default. Specifically:

This data is stored in Marrow's local database inside the app's sandbox on your iPhone. Marrow does not store your health data in iCloud. If you have iPhone backups enabled, your device backup is governed by Apple's privacy policy, not ours.

2. What leaves your device, and only when you ask

Meal photos you choose to scan

When you log food by photo, that one image is sent to Marrow's photo service and forwarded to Google's Gemini API, which returns a guess at what the food is and its nutrition. Details that matter:

A random device identifier, for rate limiting only

Photo scanning is free and costs us money per scan, so it is capped per device per day. To count scans, the app generates a random identifier the first time you scan, stores it in your Keychain, and sends it with photo requests. It is not your Apple ID, not your device serial, not an advertising identifier, and it is not derived from anything about you or your hardware. Our server keeps only a count for the current day, and yesterday's rows are deleted when the day rolls over. It is never shared, and it is never attached to health data because we never receive health data.

Barcodes and food searches

When you scan a barcode or search for a food, the barcode number or search text is sent to Open Food Facts, an open food database, to look up branded products. No identifier and no health data goes with it. Marrow also ships with a USDA FoodData Central database built into the app, so generic foods are found offline without any network request at all.

Anything you deliberately export

Marrow's whole point is letting you move your own data. When you export a file, run an automation, pair a server, or connect an AI agent over MCP, your data goes where you tell it to go. If you point an automation at your own server, that server receives your health data and its operator's rules apply. We are not in the middle of that connection, we do not see it, and we cannot retrieve it for you. Choose destinations you trust.

3. What our server logs

The photo service writes one line per request containing: a timestamp, how long the request took, the HTTP status code, the size of the upload in bytes, the model name, how many foods were detected, and token counts. It does not log the image, the identified foods, your device identifier, your IP address in application logs, or any health data.

4. What we never do

These are commitments, not defaults we might quietly change. This section exists in part because Apple's App Store Review Guideline 5.1.3 governs health apps, and we hold ourselves to it explicitly:

5. Apple Health permissions

Marrow reads from Apple Health only in the categories you approve, and iOS controls that entirely. You can review or revoke any category at any time in Settings, Privacy & Security, Health, Marrow. Marrow also writes back to Apple Health, such as food you log and workouts you record, when you permit it. Revoking a permission stops new reads immediately. Data already synced into Marrow's local database stays there until you delete it or delete the app.

6. Deleting your data

Delete the Marrow app and everything it stored is deleted with it, since it all lives in the app's sandbox. There is no server-side account to close and nothing for us to erase on request, because we hold nothing tied to you. Data in Apple Health belongs to Apple Health and is managed in the Health app. Data you exported to your own destinations is yours to delete there. Files you exported to your own devices are, likewise, yours.

7. Security

All network requests use TLS. Paired servers and MCP agent connections are authenticated with bearer tokens generated on your device and stored in the Keychain. The on-device MCP server ships turned off and binds to your local network only when you turn it on. You can revoke a token by unpairing the server in the app.

8. Children

Marrow is not directed at children under 13, and we do not knowingly collect information from them. We do not have accounts, so we have no way to identify a user's age.

9. Your rights

Under laws such as the GDPR and the CCPA you have rights to access, correct, delete, and port your personal data, and to object to certain processing. Marrow's architecture satisfies these by design: your data is already in your possession, exportable in open formats at any time, and deletable by removing the app. We do not sell personal information, so there is nothing to opt out of. If you believe we hold something about you and want it removed, write to [email protected] and we will act within 30 days.

10. Changes

If this policy changes in a way that affects what leaves your device, we will update the effective date at the top and describe the change in the app's release notes. Continued use after a change means you accept the updated policy.

11. Contact

Aidan Hall, doing business as Skeleton Army
[email protected]

See also: Terms of Use and Support.