Effective October 2026. Applies to the Photophore iPhone app and Apple Watch app. The first seven sections are the same as Settings > Privacy in the app; the last two cover TestFlight reports and how to reach the developer.
Data Read
Heart rate, resting heart rate, HRV (RMSSD, SDNN), respiratory rate, blood oxygen, sleeping wrist temperature, and sleep analysis; detail and Stress pages also read workouts (start and end times only; routes are not read).
The Overview page also reads steps, active energy, environmental sound levels (decibels, volume numbers only; Apple Watch does not record audio), and time in daylight (estimated by watch light sensors, without location), displaying on screen only values since midnight that day, not stored separately, and not sent from iPhone to the watch (the watch reads them on its own; see the next paragraph).
Stress values also read steps and heart rate from approximately the past 120 days, used only to exclude HRV readings caused by movement: readings during 10-minute intervals with movement and for 10 minutes after do not count, nor do readings for 30 minutes after sustained walking; readings with movement in the preceding 30–40 minutes where heart rate remains higher than your usual also do not count; readings with no step records but noticeably elevated heart rate are calculated as usual and only marked on the chart.
These steps, heart rate, and movement intervals are likewise not stored separately and not sent from iPhone to the watch; the only items sent to the watch and widgets are the cooldown end time calculated from them, and the heart rate reference values described under “Where Data Goes” below.
Photophore on the watch directly reads heart rate, HRV (RMSSD), sleep analysis, steps, active energy, environmental sound levels, and time in daylight on the watch, as well as workout start and end times.
Heart rate and HRV query data from the past 24 hours, sleep queries the past 30 hours, and steps and workouts query up to 1 hour further back (used to mark sleep on curves, suppress stress-related notifications during sleep, and exclude readings right after walking or exercising); steps, active energy, environmental sound levels, and time in daylight on the “Today” card are still calculated from midnight of the current day.
In addition to when the watch app is opened, the watch also rereads periodically in the background (frequency determined by watchOS) to update stress levels on the watch face; when stress-related notifications switch to being sent by the watch (see “Notifications” below), it is also used to check on the watch whether to notify.
These readings are only displayed and used on the watch and are not transmitted back to iPhone (stress-related notifications sent by the watch carry the ms, level, and time of the triggering reading in the title; see “Notifications” below); the watch app’s stress, HRV, and heart rate curves plot the past 24 hours, including readings during sleep from the previous night.
Only the latest HRV reading (ms and time) is saved to the same-day cache file for watch faces to display on the “HRV” watch face, with values older than 60 minutes not shown.
Stress levels, hourly levels, reading times, and cooldown times on the watch face are converted from these readings, displaying only values for the current day and no other readings.
When the watch is worn, it remains unlocked; anyone who gets hold of the watch can open the app and see them.
When lowering your wrist (always on), the watch app screen displays neutral content by default; if you turn on “Show in Always On” at the bottom of the watch app list, the app screen (including detail pages) displays normally when lowering your wrist, visible to others nearby.
This switch exists only on the watch and is not transmitted to iPhone.
The watch face always shows only the icon when lowering your wrist.
Morning Recovery Check
The morning recovery check also reads records you take with Apple's ECG app.
This Health read permission covers all your ECG recordings and Apple's classification results (such as sinus rhythm and atrial fibrillation); the permission itself is not limited by date; Photophore queries only the past 35 days and uses only recordings classified as sinus rhythm to find heartbeat intervals from the waveform and calculate HRV (RMSSD) and average heart rate.
The app does not display, interpret, or store classification results or waveforms; calculated values are not written to files on iPhone and do not appear in widgets; on iPhone they are kept only in memory and recalculated from Health each time the app opens.
Today's morning values, 7-day average, and comparison results are sent to your Apple Watch with the next update, exist only in Photophore on the watch, are displayed only in the watch app, do not appear on watch faces, are no longer displayed after the day changes, and are deleted the next time the watch app runs; classification results and waveforms are not sent to the watch.
This is not a heart rhythm check and cannot detect atrial fibrillation or other heart conditions; refer to Apple's ECG app for ECG results, and seek medical attention if you feel unwell.
Cardio Fitness & Recovery
The Heart Rate page, HRV page, and Cardio Fitness card additionally read three items written to Health by Apple: Cardio Fitness estimates (VO2max, estimated by Apple Watch from heart rate during outdoor walks, runs, or hikes), “Low Cardio Fitness” events (present only when Apple determines the estimate is below the threshold it sets based on age and sex, including the estimate and threshold at the time), and Cardio Recovery (the 1-minute heart rate drop estimated by Apple after you manually end a workout).
These read permissions are not inherently limited by date; Photophore only queries the past 365 days, only uses records generated by Apple, and separately reads monthly averages of HRV over the past 12 months statistically.
Low Cardio Fitness events are only relayed on the Cardio Fitness detail page.
Post-walk heart rate recovery time is calculated from heart rate and steps already read by the app, without requesting additional permissions.
The above values and results are retained only in iPhone memory: not written to files, not sent to the watch, do not appear in widgets, watch faces, or notifications, not included in composite scores, and recalculated from Health each time the app opens.
These are Apple’s estimates and self-observations, not fitness assessments or medical examinations, and do not assess health risks; seek medical care if you feel unwell.
On an unlocked iPhone, anyone who opens the app can see this content, and screenshots will also capture it.
Where Data Goes
All calculations are performed on your iPhone and Apple Watch.
There are no servers, no accounts, no third-party packages, and nothing is saved to iCloud.
Derived stress values (level, score, hourly level, reading time, cooldown end time, and the level and time of the latest reading not included) are sent to the watch.
iPhone saves them as a cache file for that day for iPhone widgets to display; the watch stores the received values in Photophore on the watch and saves a separate cache file for that day for watch faces.
When the watch can calculate them, the watch face level, hourly level, and reading time are instead calculated from the watch's own readings for that day (identical to the stress card in the watch app, with no score).
These files are readable only when the device is unlocked, are not included in backups, are not uploaded to iCloud, are no longer displayed after the day changes, and are deleted the next time the app runs on that device.
Also sent to the watch are your personal HRV reference tables for today and yesterday (ms boundaries for each level and baseline days) and usual heart rate reference values for the same two days (the median heart rate while awake and not exercising or moving over the preceding 28 days for each, used by the watch to exclude readings right after movement; yesterday's is used only to grade yesterday's readings on the watch so the curve for the past 24 hours matches iPhone), both of which exist only in Photophore on the watch, do not enter widget or watch face cache files, are likewise readable only when the watch is unlocked, are not included in backups, and are deleted the next time the watch app runs after the day changes.
The watch also receives daily stress levels for the past 7 days (level only), which exist only in Photophore on the watch and are displayed only in the watch app.
When you turn on notifications, iPhone also sends stress-related notification settings to the watch: enabled types, Quiet Hours, whether the watch can take over sending if iPhone has not checked for too long, the time of iPhone's most recent notification check (time only, without readings or results), and two yes/no flags (whether the baseline is still provisional, and whether step records exist in the past 28 days), which exist only in Photophore on the watch, do not enter widget or watch face cache files, are likewise readable only when the watch is unlocked, are not included in backups, and are deleted the next time the watch app runs after the day changes; when notifications are turned off, iPhone no longer includes these settings in its next transmission.
The only thing the watch sends back to iPhone is a single yes/no flag for “whether the watch can send notifications” (whether Photophore on the watch is authorized to send notifications, and whether the Health read permission prompt on the watch has been answered), containing no readings, levels, times, or notification logs.
Aside from check-ins and tags you enter manually (see the next paragraph), the last night summary described below, watch face caches, and the single HRV ms reading in the title of stress-related notifications (which stays in Notification Center with the notification; see “Notifications”), raw HRV values and other health data are not stored separately; they are recalculated from Health whenever the app opens, new sleep or HRV data arrives in Health, or the watch requests an update; Health is not available for reading when iPhone is locked, and updates only after unlocking.
When iPhone is locked, widgets on the Lock Screen (including an always-on Lock Screen) and StandBy still show content, such as stress level, reading time, or last night’s status phrase and sleep duration, visible to anyone holding or viewing iPhone without unlocking; they do not update while locked, and after midnight they no longer show values from the previous day.
When the watch is locked, the watch face only shows placeholder content; when lowering your wrist, the watch face only shows an icon.
After unlocking, widget content appears on the Home Screen and watch face.
Widgets may also appear on the CarPlay screen (including when iPhone is locked), iPhone widgets on Mac, screenshots, and screen sharing, visible to others nearby.
If you do not want this visible, do not add widgets to these locations; you can also go to Settings > Face ID & Passcode and turn off Lock Screen Widgets under Allow Access When Locked, and Lock Screen widgets will only show placeholder content.
Last night's status sentence (for example, “2 outside usual”), sleep start and end times, and date are sent to your Apple Watch, and are also saved in cache files for the day on iPhone and the watch for “Last Night” widgets and watch faces to display.
Values, status, and respective usual ranges for last night's seven metrics are sent only to the watch, exist only in Photophore on the watch, and are displayed only in the watch app, without appearing in widgets or watch faces.
These files are readable only when the device is unlocked, are not included in backups, and are not uploaded to iCloud; a new night replaces the old one.
The watch is unlocked while worn; anyone holding the watch can open the app and view them.
If you report an issue through TestFlight and include screenshots, they are sent to the developer via Apple; please describe issues in text whenever possible.
Notifications
Notifications are off by default; notification permission is requested only after you turn them on in Settings or from the prompt on the Overview page.
When enabled, the app checks whether to notify: stress score rises noticeably, comes down after rising, fluctuates widely within an hour, stays in a low range for an entire hour, stays high for half an hour, or last night’s metrics differ from usual.
Stress-related notifications have no daily limit and notify only once per state episode, except that sustained high notifications will notify again after a full half-hour from the previous one if high levels persist; when multiple stress-related notifications qualify during the same check (including readings caught up together after unlocking), only one is sent: in the order stress rising, sustained high, stress settling, staying steady, big swings, with the rest treated as already notified; these notifications are not sent during Quiet Hours (default 22:00–08:00, adjustable in Settings) or during sleep, nor are they backfilled for readings during those times; last night notifications are limited to at most one per day.
Stress-related notifications are primarily handled by iPhone: iPhone checks and sends them each time it recalculates from Health while unlocked (including background updates).
Health cannot be read while iPhone is locked, so iPhone cannot check during this time; after unlocking, iPhone retroactively checks readings within the past 2 hours since the last check based on reading timestamps, and sends at most one stress-related notification together with the current check, with the title displaying the reading timestamp.
When Photophore on the watch is also allowed to send notifications and a Photophore watch face widget is on your current watch face, if iPhone has not checked for more than one hour, Apple Watch takes over, checking using the watch’s own readings from that day and sending notifications on the watch: checking when the watch periodically rereads in the background (frequency determined by watchOS); the watch does not generate stress-related notifications when unworn, out of battery, or locked, nor before iPhone unlocks and delivers the current day’s data after the date changes.
The watch relies on the timestamp of the latest check sent by iPhone to decide whether to take over; this timestamp may arrive late, so around the handover and during catch-up checks, the same state episode may notify once on iPhone and once on the watch.
Last night notifications are always checked and sent by iPhone.
Notifications are generated entirely on your iPhone or Apple Watch, without going through servers.
Titles of stress-related notifications reflect the latest included awake reading at the time of the check: HRV (RMSSD) in ms, stress level, and reading time, such as “HRV 31ms · Stress Low · 09:19”; readings well above usual omit the level and show “Well above usual” instead; when no reading is available, the title is “Photophore”.
Notification bodies do not contain numerical values or levels; the title for last night notifications is “Photophore”, without numerical values or levels.
Stress-related notifications attach a graph plotting included awake readings from the 2 hours on which the notification is based, using level colors and vertical positions, with the horizontal axis labeled only with “hours ago” and no scores or ms on the graph; when there are fewer than 3 readings in those 2 hours, a fixed sample image labeled “Example” is attached instead, containing none of your data.
Last night notifications do not attach a graph.
Graphs are drawn on the spot by the iPhone or Apple Watch that sends the notification, saved first as a temporary file readable only when that device is unlocked and excluded from backups, and handed over to iOS or watchOS to be kept by the system alongside the notification; Photophore does not keep a separate copy; if drawing or attaching fails, text-only notifications are sent as usual.
According to Apple, attached images are deleted together when notifications are removed from Notification Center; Apple has not published how attached images are protected while held by the system, or whether attached images are included in device backups.
Notification titles and body text are likewise held by the system alongside notifications; Apple has not published their protection methods.
iPhone and the watch each record only the timestamp when each notification type was last determined to apply (including types that qualified at the same time but were not sent separately and were treated as already notified; retroactive checks on iPhone record reading timestamps), the timestamp when it was sent (types not sent separately record the timestamp of the notification sent at that same time), and the actual count sent that day; iPhone separately records the timestamp of the last check to determine where to begin retroactive checks after unlocking.
These records contain only timestamps and counts, not readings or levels, and are used to prevent duplicate notifications and determine when to remove them from Notification Center; each is readable only when that device is unlocked, excluded from backups, and deleted when notifications are turned off in the app (the watch’s copy is deleted when the watch receives new settings).
When iPhone is locked, the Lock Screen only shows “New Notification”; but if Always is selected in Settings > Notifications > Show Previews or Settings > Notifications > Photophore > Show Previews, the Lock Screen and StandBy directly show the full notification, visible to others nearby.
Widgets display content when locked, but notifications do not change accordingly and depend solely on Show Previews.
Notifications sent from iPhone are forwarded to the watch when iPhone is locked and Apple Watch is worn, and may show the full text on wrist raise.
Notifications may also be read aloud by Siri, or appear in notification summaries, screenshots, screen recordings, and iPhone Mirroring on Mac.
Stress-related notifications are removed from Notification Center on the next update after more than 2 hours since sending or after the day changes; last night notifications are removed when data for the next night appears; new notifications of the same category, or when only one notification is sent among several stress-related notifications that hold simultaneously, replace older ones; you can also clear them yourself.
The title of stress-related notifications (HRV in ms, level, and reading time) and the graph are displayed along with the notification body: when iPhone is locked, if Show Previews is When Unlocked (default), only “New Notification” is shown, without the title or graph; according to Apple, when set to Always, the Lock Screen and StandBy directly display the title and graph, visible to others nearby.
On an unlocked iPhone, banners and Notification Center both display the title and this graph; backfilled notifications are sent on the next recalculation after iPhone is unlocked.
The title and graph may also appear in notification summaries, screenshots, screen recordings, screen sharing, and iPhone Mirroring on Mac.
According to Apple, when notifications sent from iPhone are forwarded to Apple Watch, raising your wrist displays the title, and the watch may also display this graph.
Stress-related notifications sent by Apple Watch appear only on that watch, and will not appear on iPhone, in notification summaries, or in iPhone Mirroring on Mac; iPhone's Show Previews does not affect them.
The watch has no “New Notification” placeholder.
Observed: when raising your wrist, the app name and notification title (HRV ms value, level, and reading time) appear first, followed a few seconds later by the full notification text and curve graph, visible to bystanders; according to Apple, notifications sent by iPhone and forwarded to the watch behave the same way.
According to Apple, after turning on “Tap to Show Full Notification” in Settings > Notifications on the watch, the full text and curve graph appear only after a tap, but the title still displays when raising your wrist.
New notifications are not generated while the watch is locked; when “Wrist Detection” is on, the watch locks automatically after being removed; if “Wrist Detection” is off, a removed watch resting on a surface may also show notifications.
If you turn off notifications for Photophore on the watch in the Apple Watch app on iPhone, the watch will no longer take over, and stress-related notifications will be sent only by iPhone.
To turn them off, switch off the master toggle or individual types in Photophore's Settings, or turn them off in Settings > Notifications > Photophore; when turned off in the app, notifications already sent on iPhone are removed as well; notifications sent by the watch on Apple Watch will stop and be removed once the watch receives the new settings from iPhone.
Data You Entered
Fatigue level, tension level, and time entered on the “How are you feeling” card, along with optional tags (took one-off medication today, routine medication changed, alcohol, illness, staying up late / little sleep, late caffeine; records only whether present or not, not medication names, doses, or condition names), exist only within Photophore on this iPhone: not written to Health, not sent to the watch, do not appear in widgets, not uploaded to iCloud, and not included in iCloud or computer backups.
Tags are also used to decide which days to exclude from subsequent “usual”; this calculation takes place only on iPhone, and tags themselves are not sent to the watch or displayed in widgets.
Stress levels, usual ranges, and “Calibrating” on the watch and widgets will reflect the exclusion results, for example, after you log “Routine medication changed”, it recalibrates over about a week.
Files are readable only when iPhone is unlocked; retained for up to roughly 90 days, with older records deleted the next time the app opens.
Deleting the app or tapping “Delete All Check-ins” deletes everything immediately.
On an unlocked iPhone, anyone who opens the app can see this content on the Overview, Check-ins, and Stress pages, and screenshots will also capture it.
Revoke and Delete
You can revoke read access at any time in Settings > Health > Data Access & Devices.
Go to Settings and tap “Delete All Check-ins” to delete your entered check-ins and tags; on the Overview page, tap “How are you feeling” to open Check-ins, where you can swipe left on an entry to delete it individually.
To turn them off, switch off the master toggle or individual types in Photophore's Settings, or turn them off in Settings > Notifications > Photophore; when turned off in the app, notifications already sent on iPhone are removed as well; notifications sent by the watch on Apple Watch will stop and be removed once the watch receives the new settings from iPhone.
Problem Reports and Screenshots
When you send feedback through TestFlight, you can attach screenshots and a written description; these reach the developer through Apple’s TestFlight, are stored in Apple’s App Store Connect, and come with device and system information that Apple provides.
A screenshot may capture health values or entries you made in the app, so please check what is on screen before sending; you can also describe the problem in words only.
If the app crashes, Apple may also provide the crash log to the developer.
The developer uses these reports only to track down problems, shares them with no one, and deletes the feedback in App Store Connect once the problem is handled.
Contact
For any question about this privacy policy or your data, email photophore@nyanako.com.