Effective date: 2026-08-03
HopRabbit Privacy Policy
HopRabbit helps users understand fitness readiness, sleep, stress, training load and lifestyle recovery from Apple Health and Apple Watch signals.
HopRabbit is operated by Shanghai SoulDigger Information Services Co., Ltd., the SoulDigger operator responsible for HopRabbit support and legal notices.
Data We Access
With your permission, HopRabbit may read Apple Health data such as heart rate, HRV, resting heart rate, respiratory rate, oxygen saturation, sleep analysis, workouts, active energy, body profile, nutrition and water intake. The Apple Watch app may write workout data only when you explicitly start and stop a workout; HopRabbit does not write nutrition records to Apple Health. If Apple Health has no record for your latest sleep, you may add its time window and an optional feeling inside HopRabbit. This entry stays in HopRabbit and is not written to Apple Health; it does not create stages, interruptions or overnight vital measurements, and a later Apple Health record for the same sleep takes priority. Meal recognition processes only a compressed library photo you select or a camera photo you take and confirm.
AI features and account deletion require Sign in with Apple. HopRabbit receives the Apple account subject and may receive an email or private relay address; the app also supplies an App Account Token for App Store entitlement association. HopRabbit creates a hashed support ID, signed session, AI quota and entitlement state.
For a signed-in account, HopRabbit records when the account was first recognized by the backend, the server time of the latest in-app account-state check, and the app version and build. Only for accounts that already have invited access, the app also sends a minimal “Health dashboard refresh finished” event and its server receipt time. That event contains no HealthKit value or sample, body-state score, permission state, success or failure result, device health database or advertising identifier.
Recommend to a Friend is standard sharing only. It uses the system share sheet and HopRabbit’s App Store download URL, requires no account, creates no invitation code, claim, qualification or reward, and never places HealthKit, meal-log or other personal body data in the shared content.
How Data Is Used
Health data is used to calculate readiness, body energy, body-age context, stress, exertion, sleep, food, activity/training and recovery guidance inside the app. When date of birth is available through Apple Health, HopRabbit converts it to age for local estimates and does not store the exact birth date. HopRabbit does not use HealthKit data for advertising, tracking or selling user profiles. Meal photos are used only to estimate editable food items, portions, calories, macro nutrients and training fuel guidance. HealthKit source data is not uploaded with the meal photo by default.
Apple account, App Account Token, purchase transaction and installation identifiers are used only for authentication, entitlement verification, quota enforcement, abuse prevention, deletion and support—not ordinary sharing, advertising or cross-app tracking.
Account activity and invited-account refresh times are used only for invited-test support, version confirmation, service troubleshooting and deciding whether to ask a user to check sync on their own device. They are not used for ad targeting, marketing profiles, public rankings or health-status inference.
Research and Product Improvement Permission
Research and product improvement sharing is off by default and requires your separate consent. You can withdraw this permission at any time in the app, and withdrawal stops future uploads for this purpose.
When enabled, HopRabbit may upload only a minimized daily health summary linked to the signed-in HopRabbit support account. Authorized HopRabbit operators may view that summary for product support, algorithm quality checks and app improvement. It is not used for advertising, marketing targeting, sale of user data or public rankings.
The daily health summary does not include your name, email address, Apple ID, exact date of birth, raw heart-rate time series, routes or photos.
To compare algorithm quality across days, a summary carries a one-way hash of a separate research-install identifier and an account-link hash used only for authenticated support, export, deletion and the internal operator console. The server automatically deletes research summaries after at most 365 days. Withdrawal stops future uploads; the user can separately delete stored summaries in the app, and account deletion also removes linked summaries.
Storage
HopRabbit stores app preferences, language settings, lifestyle goal selections, dashboard snapshots and journal tags locally on device and in the app group container used by the iPhone app, Apple Watch app and widgets. HopRabbit does not store original meal photos by default. Confirmed meal entries are stored as structured food records on your device.
For signed-in accounts, HopRabbit stores only the minimum profile, session, quota and App Store entitlement data, plus the first/latest account activity times, app version, and latest invited-account refresh-event time described above. Ordinary sharing stores no friend, invitation-code or claim record in a HopRabbit account. Rewarded referrals have been removed from the public product scope.
HopRabbit does not intentionally retain the original meal photo after recognition. A short-lived one-way-hash-keyed structured result cache may be used for speed and duplicate protection. Operational logs may include request ID, timing, model, token use, quota window and error code, but not the photo or raw HealthKit records.
Retention and Deletion
Most HopRabbit data is stored locally on your devices. You can delete local HopRabbit data by deleting the app from iPhone and Apple Watch. Apple Health source data is controlled by Apple Health and can be reviewed or deleted in the Health app.
If you email support, we use your email address and message only to handle the support request. You can request deletion of support correspondence by emailing hoprabbit-support@souldigger.cn.
HopRabbit may create an anonymous install identifier for AI quota, abuse prevention and service stability. This identifier is not your Apple ID, is not used for advertising or tracking, and is not used to build marketing profiles.
In-app account deletion removes the account profile, email/private relay email, App Account Token and purchase-transaction associations, AI quota, account activity times and invited-account refresh-event times, and revokes current HopRabbit sessions. A hashed session-revocation marker is kept only until the longest issued session would have expired (up to 31 days), then pruned. If an allowlisted internal test record was created before rewarded referrals were removed, deletion removes its account and device links. A de-identified record needed solely for security auditing and replay prevention may be kept for up to 730 days; it contains no account ID, health data or meal data and creates no public reward. App Store subscriptions remain controlled by Apple.
AI and Coaching
After you separately enable AI Coach, your question and a normalized body-state summary are sent to HopRabbit's server and processed by Tencent Cloud TokenHub to generate that response. The summary may include recovery and stress, HRV and resting heart rate, sleep, workouts, nutrition, lifestyle events you record, and your selected goals; HopRabbit does not send the full HealthKit database. When coaching uses a manually added sleep, the summary labels it as user-reported and includes only the reported duration and optional feeling—not exact sleep times, stages, interruptions or overnight vital measurements. The same source label and minimization apply only if you separately opt into research sharing. After you select a library photo or take and confirm a camera photo for recognition, the compressed image is sent to HopRabbit's server and Tencent Cloud TokenHub. The service checks consistency across items, ingredients, calories and macros, but estimates can still be wrong; confirm portions before saving.
Subscriptions
HopRabbit Premium purchases are processed by Apple through the App Store. HopRabbit does not receive or store your payment card information.
Ordinary sharing does not change your subscription or a friend’s subscription and creates no free Premium access, redemption code or other digital entitlement.
Your Control
You can change Apple Health permissions at any time in the Health app or iOS Settings. You can manage subscriptions in Apple ID subscriptions.
Medical Disclaimer
HopRabbit is for fitness planning and wellness education. It is not a medical device and does not diagnose, treat, cure or prevent disease. Consult a qualified medical professional for health concerns.