Privacy policy
Last updated 7 September 2026 · Applies to the Bucket app for iPhone and iPad
The short version.
- Your health logs live on your devices and in your own iCloud. We hold no copy and cannot read them.
- Nothing you type, dictate or photograph leaves your phone unless you turn on smart parsing. When you do, each note or photo is read once by our server and by our AI provider, and is not stored by either.
- Data read from Apple Health is kept only on the device it was read on. It is never put into iCloud by Bucket and never sent anywhere.
- Your calendar is read, never written. Event titles are never stored.
- You can export everything, and delete everything — on this phone, in your iCloud, and on our server — from inside the app, at any time.
- No advertising, no trackers, no selling or sharing of data. Ever.
Who we are
Bucket is made and operated by SoleGrit [registered entity, address and ICO registration number to be confirmed before launch]. For anything in this policy, email bucket@solegrit.io. Where UK data protection law applies, we are the controller for the small amount of data described under What reaches us, and you are in control of everything else.
How Bucket is built, and why it matters here
Bucket is designed so that we cannot see your health data, rather than promising not to look. Everything you log — symptoms, food, exposures, life events, check-ins, conditions, patterns — is stored on your device and synced through Apple's CloudKit to your own iCloud account, in a private database that only your devices can read. Apple is your provider for that storage, not ours; we have no server that holds it and no means of access.
What stays on your device, and what syncs to your iCloud
| Data | Where it lives |
|---|---|
| Symptom, food, exposure and life-event entries; daily check-ins; your conditions; patterns Bucket finds; your settings | Your device and your own iCloud private database |
| Data read from Apple Health (heart-rate variability, resting heart rate, sleep, steps, stand hours, menstrual flow, workouts) | Your device only. Never placed in iCloud by Bucket, never sent to anyone. Apple Health syncs it between your devices under Apple's own terms. |
| Shifts and appointments read from your calendar | Only the derived type and time are stored (for example, "work shift, Tuesday 07:00"). Event titles and locations are never stored; what you teach Bucket about a title is kept as an irreversible hash. |
| Photos of meals or rotas you choose to attach | Your device, until parsed or deleted. See Smart parsing. |
What reaches us — smart parsing
Smart parsing is off until you turn it on, and turning it on happens on a screen that explains exactly what follows. With it on:
- The text of a note you save, or a photo of a meal or rota you choose to send, is sent to our server (a Cloudflare Worker) and from there to Anthropic, our AI provider, to be turned into structured entries. It is used to produce your result, read once, and not stored by us. Anthropic processes it under its commercial API terms, which do not permit training on it.
- A photo of a staff rota may show colleagues' names. It is sent only when you pick that photo for that purpose, and only your own shifts are kept — as plain entries with no names on them.
- To meter your allowance, our server keeps an account: a one-way hash of your Sign in with Apple identifier (not the identifier itself, and never your name or email, which we do not ask for), a running allowance balance, and a token that lets your device stay connected. That is all it holds — no health data of any kind.
Turning smart parsing off stops all of this immediately. Notes made while it is off never leave your phone.
Weather, air quality and pollen
If you enable local conditions, Bucket asks Open-Meteo for the day's air quality, pollen, pressure, temperature, humidity and UV for a coarse area — your location rounded to roughly 11 kilometres, or a postcode you type, geocoded on your device by Apple. No identifier accompanies the request. Bucket asks iOS for reduced-accuracy location by default.
Apple Health
With your permission, Bucket reads the measures listed above to give its pattern-finding a steady daily baseline, and can write the symptoms you log back into Apple Health so your records stay in one place. Health data is never used for advertising or marketing, never shared, and never placed in iCloud by Bucket. You control every category in the Health app, and can stop Bucket reading at any time in Bucket's settings.
Your rights, built in
- Export — a complete, documented file of everything you have logged, from Settings › Your data. It is yours to keep, move or hand to a clinician.
- Delete — Settings › Your data › Delete everything removes your data from this phone, from your iCloud, and from our server, and can also remove the symptoms Bucket wrote to Apple Health. Because we hold no copy, deletion is complete when it finishes.
- Correct — every entry can be edited or deleted individually.
- Withdraw consent — turn smart parsing off at any time; stop Apple Health or calendar access at any time.
- In the UK you can complain to the Information Commissioner's Office (ico.org.uk); elsewhere, to your local data-protection authority.
Lawful basis
Health data is special-category data. Everything Bucket stores for you is stored under your explicit consent, given when you set the app up and each time you grant a permission, and it never leaves your control. The transient processing for smart parsing is under your explicit, separate consent, given on the consent screen and withdrawable there.
Retention
Your data stays on your devices and in your iCloud until you delete it. Our server keeps the metering account until you delete it in the app. Nothing sent for smart parsing is retained after your result is produced.
Children
Bucket is for adults managing their own health and is not directed at children under 16.
Processors
| Who | What |
|---|---|
| Apple (iCloud, CloudKit, Sign in with Apple, App Store) | Your storage and sync, under your own Apple ID and Apple's terms. We have no access. |
| Cloudflare | Hosts our server and its small metering database. |
| Anthropic | Reads the text or photo you send for smart parsing, transiently. |
| Open-Meteo | Answers a coarse-area weather and air-quality request. |
Changes
We will update this page and its date when our practices change, and tell you in the app if a change affects what leaves your phone.