Effective 12 July 2026 · Version 1.0
Vigil reads your heart rate and heart rate variability from Apple Health while a session is running. Everything it produces stays on your Apple Watch. There is no server, no account, no analytics, and no third party.
We cannot see your data, because we never receive it.
From Apple Health, with your permission:
Vigil requests read access only, and only for these types. You can revoke it at any time in the Watch app on your iPhone, under Privacy & Security → Health → Vigil.
Vigil also starts an Apple workout session while you are monitoring. This is what lets the watch sample your heart rate often enough to be useful and keep working when your wrist is down. Vigil does not save a workout to Apple Health.
At the end of each session, Vigil saves one record to your watch: the scenario you chose, start and end times, average heart rate, average and lowest variability, your session baseline, the time and values at each alert, which reset action you chose, your mental-effort rating, and any note you typed.
Vigil does not store the underlying stream of heart-rate samples. Individual readings are used to compute your rolling baseline and are then discarded.
In the app's private container on your Apple Watch, protected by the operating system and your device passcode. Identifying information — any alias, any note you typed — is held separately from physiological data and is excluded from device backup.
Delete the app from your Apple Watch. Everything Vigil stored goes with it. There is no copy anywhere else.
Vigil is designed to support institutional research in future versions. Those features are switched off in this release — the app cannot enrol you in a study and contains no code that could transmit data anywhere.
When they are enabled, the following will be true, and are already enforced in the architecture:
Any future cloud sync, research export, or team feature will be opt-in, will be described here before it is enabled, and will require your explicit consent. We will not quietly begin uploading data that a previous version kept local.
Vigil is not directed at children under 13 and we do not knowingly collect their data.
Because Vigil holds no data about you on any system we control, there is nothing for us to disclose, correct, export, or erase in response to a request under the GDPR, the Australian Privacy Act, the CCPA, or similar law. Your data is in your hands, literally.