Last updated · 13 July 2026

HWH Privacy Policy

Your day stays on your Mac. There is no HWH account, no HWH cloud sync, and no HWH server-side copy of your tasks, plans, notes, scores, or source context.

Data can leave your Mac through connected tools, AI, anonymous diagnostics, Game Center, App Store purchases, backups or exports, or the website waitlist. Performance and crash diagnostics are shared by default and can be turned off in Settings.

NO. 01

What stays local.

HWH is a native macOS app for bringing mail, calendar, tasks, tickets, notes, and habits into one plan. It does that on your Mac.

The following stays on your Mac unless a later section describes an off-device path you enable:

  • Tasks, plans, observations, goals, notes, and habit or metric entries you create in HWH.
  • Health, wealth, and happiness scores, point ledger entries, awards, streaks, and other progress state.
  • Settings and preferences, plus non-secret integration configuration.
  • Cached copies of items pulled from tools you connected.

Both HWH app targets include an Apple privacy manifest. The manifests declare no tracking or tracking domains. The main app's manifest declares product interaction, crash, performance, and other diagnostic data for analytics and app functionality; those categories are not linked to your identity and are not used for tracking. The manifests also declare local access to file timestamps and UserDefaults: HWH uses file timestamps to display dates and work with metadata for files inside its container or in locations you explicitly choose, and uses UserDefaults to store preferences accessible only to HWH. These APIs are used for app functionality, not fingerprinting or tracking.

Secrets such as API keys, passwords, personal access tokens, and OAuth refresh tokens are stored in the macOS Keychain on this Mac using HWH's this-device-only Keychain setting. HWH does not configure them for iCloud Keychain syncing.

If you delete the app, macOS removes HWH's in-sandbox data along with the app's sandbox. That does not necessarily remove Keychain items, backups, exports, or files HWH wrote outside its sandbox.

NO. 02

Connected tools.

HWH is a coordination layer, not a replacement for the tools you already use. Each connected service is off by default. You turn one on by adding an account, completing an OAuth flow, or pasting credentials.

Once enabled, your Mac talks directly to that service. HWH is not in the middle and does not receive the traffic. The network-connected tools currently enabled in the app are listed below in alphabetical order.

Asana

  • Credentials: personal access token stored locally.
  • Reads: current user, workspaces, projects, sections, and tasks in the project or section you select, including task ID, name, notes, completion state, due dates, permalink, assignee, and membership.
  • Writes at your direction: creates tasks, marks tasks complete, updates notes, adds comments, and deletes tasks.
  • Where: app.asana.com/api/1.0.

Gmail

  • Credentials: Google OAuth tokens stored locally. HWH requests openid, email, profile, and https://www.googleapis.com/auth/gmail.modify.
  • Reads: Gmail labels, matching message IDs, matching-message count estimate, and message metadata. The current message detail request reads Subject, From, Date, and Message-ID headers. It does not request full message bodies in the current sync query.
  • Writes at your direction: archives a message by removing the INBOX label, and moves a message to Trash when you choose delete.
  • Where: accounts.google.com, oauth2.googleapis.com, and gmail.googleapis.com.

Jira

  • Credentials: the Jira server URL you configure, plus email and API token or password used through HTTP Basic Auth.
  • Reads: filters, projects, current-user details, and issues from the selected filter or JQL preset, including key, ID, summary, description, status, project, created and updated dates, due date, labels, and components.
  • Writes at your direction: none in the current integration. Jira is currently read into HWH as source tasks.
  • Where: the Jira host URL you configure, including Atlassian Cloud if that is the server you use.

Microsoft 365 / Exchange Mail

  • Credentials: Microsoft OAuth tokens stored locally. HWH requests Mail.ReadWrite and offline_access.
  • Reads: mail folders and messages in the inbox or folder you select. The current Graph request reads message ID, subject, body preview, sender, received date/time, web link, and read/unread state. It does not request full message bodies in the current sync query.
  • Writes at your direction: moves messages, including archive-style moves, and deletes messages when you choose delete.
  • Where: login.microsoftonline.com and graph.microsoft.com.

Redmine

  • Credentials: the Redmine server URL you configure, plus username and password or token used through HTTP Basic Auth.
  • Reads: projects, saved queries, issue lists, and issue details, including subject, description, status, priority, dates, custom fields, assignee, and journal notes.
  • Writes at your direction: creates Redmine issues from HWH tasks. The create payload can include project, subject, description, due date, estimated hours, and parent issue ID.
  • Where: the Redmine host URL you configure.

TheBrain

  • Credentials: personal API token stored locally.
  • Reads: brains, pinned thoughts, graph data around selected seed thoughts, notes text, thought types, tags, and search results.
  • Writes at your direction: none in the current integration. TheBrain currently reads and maps thoughts into HWH tasks.
  • Where: api.bra.in.

Todoist

  • Credentials: personal API token stored locally.
  • Reads: projects, sections, and tasks in the project or section you select, including task ID, title/content, description, completion state, labels, priority, due date, URL, created date, parent task ID, and ordering.
  • Writes at your direction: creates tasks with title/content, description, project, section, due date or time, priority, labels, and duration. Can update or delete tasks when you choose actions that require it.
  • Where: api.todoist.com for API calls. Todoist links open in app.todoist.com.

You can disconnect a service at any time in HWH's Sources tab. Disconnecting stops further requests from your Mac to that service. Cached copies already pulled into HWH stay local until you delete them. Data already written to the source service, such as an Asana comment, an archived email, a Redmine issue, or a Todoist task, remains in that service and must be removed there.

NO. 03

Apple and Mac integrations.

HWH can read from and write to local Apple apps and Mac apps. These do not send data to HWH. They use permissions on your Mac, and macOS prompts you the first time access is needed.

  • Apple Calendar - read and write calendar events for Calendar task lists.
  • Apple Reminders - read reminders and mark them complete for Reminders task lists.
  • Apple Contacts - read contact groups and remove contacts from groups you configured in HWH.
  • Apple Mail - read message metadata and update flags or state via local automation.
  • Things 3 and OmniFocus - read and write tasks through local automation or local integration.
  • Apple Music - read playback state for activity tracking, only if enabled.
  • Safari Reading List - read the local Reading List file.

If you use iCloud sync for Calendar, Reminders, Contacts, or Reading List, Apple may sync that data between your devices. That is an Apple and iCloud behaviour, not an HWH server behaviour.

NO. 04

AI and automation.

Optional AI and automation features are off by default and require configuration by you.

In-app AI assistant

The optional AI assistant uses your own API key with the AI provider you choose: Anthropic (Claude), OpenAI or an OpenAI-compatible endpoint, Google Gemini, or xAI. The Founder Pack unlocks the feature; it does not include AI usage credits, and HWH is not the AI provider.

When you send a message, your Mac sends the message, the prior turns in the current chat, active AI skill instructions, and a context snapshot assembled from local HWH data directly to the provider you selected. HWH does not currently include observation records or point ledger entries in this AI snapshot.

Your AI provider's privacy policy and data-handling terms govern that payload. To stop sending data to AI providers, remove the API key in Settings or do not use AI features.

Codex CLI integration

HWH can hand a task to the locally installed codex CLI. When you trigger this, HWH builds a prompt from the task title, body, and metadata, then launches the local codex binary with that prompt as its first turn. Whether that data then leaves your Mac depends on your codex CLI configuration.

NO. 05

Game Center.

If you sign in to Game Center, leaderboards are handled by Apple. HWH submits your lifetime earned points total as a leaderboard score to Apple's Game Center service. HWH does not currently submit award details, task contents, plan contents, observation contents, or separate achievement progress to Game Center.

NO. 06

Purchases and Founder Pack.

In-app purchases are processed by Apple's App Store through StoreKit. HWH does not see, store, or transmit your payment details. HWH receives only the receipt information Apple provides to verify your entitlement.

The Founder Pack is optional and one-time. It unlocks features immediately; it does not create an HWH account or subscription.

NO. 07

Diagnostics and app analytics.

HWH uses TelemetryDeck to understand app launch health, sync performance, crashes, hangs, and high-level feature usage. Performance and crash diagnostics are shared by default and can be turned off in Settings → Diagnostics. Usage analytics is off by default and is sent only after you opt in.

Telemetry events can include an event name and category, app and macOS versions, a short hash of a locally generated install identifier, timings, counts, statuses, and high-level integration or feature keys. Before an event is stored or sent, HWH removes task titles, notes, URLs, email addresses, account names, file paths, credentials, external IDs, and raw UUIDs. TelemetryDeck also creates an anonymised per-install identifier and says it does not store IP addresses or use cookies or tracking technologies for app analytics.

HWH also uses Apple's MetricKit framework, which delivers performance, crash, and hang reports to the app on your Mac. HWH records the reports in the local macOS unified log and sends only aggregate payload counts, crash counts, hang counts, time ranges, and the latest app version through the performance-diagnostics pipeline. MetricKit and performance sharing are on by default and can be turned off separately in Settings → Diagnostics.

HWH keeps privacy-safe events in a local diagnostics database for up to 30 days and uploads eligible events in batches. Turning a sharing category off stops new events in that category from being recorded; pending events in that category are discarded rather than uploaded. Local metrics and breadcrumbs can be exported only after you accept the disclosure in Settings → Diagnostics; the support file is encrypted and its one-time key is shown separately.

macOS may separately offer to send crash reports to Apple and, if you opted in, to Apple Developer-account holders. That flow is controlled by macOS, not by HWH or TelemetryDeck.

NO. 08

Website, waitlist, and website analytics.

The website at healthwealthhappiness.today is separate from the Mac app. The app does not read from the website, and the website does not receive your app data.

The waitlist form collects the email address you submit and, if provided, your first name. It also sends basic attribution needed to operate the waitlist: source page, referrer, user agent, UTM fields, and HWH link ID when present.

The website sends waitlist submissions through its /api/waitlist endpoint to Loops, which creates or updates a Waitlist contact and records a waitlist_signup event. We use the waitlist to email you about launch, early access, founder pricing, and major milestones. We do not sell waitlist details.

The website uses PostHog EU for website analytics. It is configured with localStorage persistence, autocapture disabled, pageview autocapture disabled, pageleave capture disabled, session recording disabled, and person profiles set to identified-only. We fire named events for aggregate marketing measurement. These analytics do not link to in-app activity.

The site host may retain standard web-server access logs, such as IP address, user agent, request path, and timestamp, for operations and abuse prevention.

To request deletion of a waitlist entry, email support@healthwealthhappiness.today.

NO. 09

Backups and exports you create.

HWH can create backup packages and exports to a folder you choose with a standard macOS file picker. Those packages contain a copy of your HWH database.

  • If you choose a folder synced by iCloud Drive, Dropbox, OneDrive, Google Drive, or similar, that service receives a copy under its own terms.
  • Backup packages and exports are not removed when you delete HWH. You must delete them from wherever you saved them.
  • HWH also writes small migration safety and startup recovery backups inside its Application Support directory. Those are removed when you delete the app.
NO. 10

Your controls.

  • Stop syncing a service: disconnect it in the Sources tab.
  • Stop sending data to an AI provider: remove the API key in Settings.
  • Stop using Codex CLI: disable the Codex integration in Sources, or do not trigger Codex actions.
  • Stop sharing performance and crash diagnostics: turn off Share performance and crash diagnostics in Settings → Diagnostics.
  • Stop usage analytics: leave Share usage analytics off, or turn it off in Settings → Diagnostics.
  • Stop MetricKit processing: turn off MetricKit in Settings → Diagnostics.
  • Stop submitting to Game Center: sign out of Game Center in macOS.
  • Revoke macOS permissions: use System Settings -> Privacy & Security.
  • Delete local app data: quit HWH and delete the app.
  • Delete exported or cloud-synced copies: locate and delete any backup packages or exports you created.
  • Delete data already pushed to a connected service: remove it from that service directly.
  • Remove your waitlist email: email support@healthwealthhappiness.today.

Because HWH does not hold app data on a server we operate, there is no HWH app account to delete. Your source systems stay yours, and if you stop using HWH they remain usable on their own.

Children

HWH is a productivity tool for adults and is not directed at children under 13. We do not knowingly collect personal information from children.

International users

HWH is sold worldwide through the Mac App Store. HWH stores primary app data on your device, while connected services receive the data described in their sections. Anonymous app diagnostics are processed by TelemetryDeck on analytics servers in the European Union. Waitlist and website analytics data is handled separately by the website services described above.

Changes to this policy

We may update this policy as the app evolves. The Last updated date at the top reflects the latest revision. Material changes will be summarised in HWH release notes.

Contact

Questions about this policy? Email support@healthwealthhappiness.today.

Want launch updates?

The waitlist lives on the homepage. We will only email you about HWH launch updates, early access, founder pricing, and major milestones.

Join the waitlist