Privacy Policy
Seized ("the App") is a personal seizure-logging tool for iPhone, iPad, and Apple Watch. This policy explains what data the App handles and how.
Last updated: October 6, 2026
Summary
Seized does not have a server, does not use analytics or advertising SDKs, and does not sell or share your data with anyone. Everything you log stays on your own devices and, optionally, in your own Apple Health data and calendar. The only exception is an HTTP or Email action you create yourself, which sends event details to the server address or email recipients you configure.
What Data Is Collected
The App stores the information you explicitly enter while logging an event, including:
- Seizure/event type (built-in or custom types you define)
- Date and time the event ended (the start is derived from the duration)
- Duration
- Focal awareness (Aware/Unaware)
- Cognitive impairment flag
- Any free-form notes you add to an event, including notes auto-filled by the optional Speech-to-Text Notes feature
- Any recorded voice note you attach to an event
No other personal information (name, contact details, location, etc.) is collected by the App itself.
Where Data Is Stored
- On-device: All logged events are stored locally in the App's private data store on your iPhone, iPad, and/or Apple Watch, encrypted at rest using iOS/iPadOS/watchOS Data Protection.
- Apple Health (optional): If you add a HealthKit action (globally or to a seizure type), that event's data is also written to your Health app. This is off by default. Nothing is ever read back out of Health into the App.
- Between your own devices: If you use both an iPhone and an Apple Watch, events logged on either device are relayed directly to the other using Apple's WatchConnectivity framework. This transfer happens only between your own paired devices and never passes through a third-party or developer-operated server.
- Device Sync between your iPhones and iPads (optional): If you turn on Device Sync (Library > Device Sync) and enter the same sync code on your devices, your events, Library types, categories, and attributes are exchanged directly between those iPhones and iPads over Wi-Fi or Bluetooth using Apple's Multipeer Connectivity, only while the app is open on both and they're nearby. Every message is encrypted with a key derived from your sync code (which is stored only in each device's Keychain), so devices without the code can't read or change your data. Nothing passes through a server, and the developer never receives it. Your Apple Watch's events reach your iPads through your iPhone. Records of deleted items are kept on-device only until every synced device confirms the deletion. Voice note recordings and HTTP action credentials are not synced. Sync is off until you set it up, and you can turn it off at any time.
Data the Developer Never Sees
The developer of Seized has no server, backend, or analytics pipeline. The developer cannot see, access, or receive any of your logged events, notes, or Health data. There is no account creation, sign-in, or cloud sync to a developer-controlled service.
Speech-to-Text Notes
Speech-to-Text Notes is an off-by-default feature (with a global switch on the Library tab and an optional per-type override) that listens while you hold the icon to save an event - for as long as you keep holding, saving when you let go after at least 3 seconds - using Apple's on-device speech recognition to auto-fill a note if you speak during the hold. Recognition happens entirely on-device - on iPhone and iPad, audio is never saved, written to disk, or transmitted anywhere, even to Apple - only the recognized text is kept, and only as that event's note. If no speech is detected during the hold, nothing is kept at all.
Apple Watch has no on-device speech recognition, so when you log from the watch it records the hold to a temporary file and sends it directly to your own paired iPhone over Apple's WatchConnectivity (never to a server or the developer). The iPhone transcribes it on-device and adds the text to the event's note; the recording is deleted from both devices as soon as the transfer and transcription finish, and is never attached to the event.
Calendar Events
You can optionally add a Calendar action (Library > Global Actions, or a type's own Action Sequence). When present, logging that type also creates an entry spanning the event's start to end in the calendar you chose. With write-only access Seized can only create entries; if you grant full access, it is used solely to update or remove entries Seized itself created when you edit or delete the matching event - Seized never reads your other calendar entries.
HTTP Actions
You can optionally create an HTTP action that sends event details (for example type, times, duration, awareness, and notes - you choose exactly what via the payload template) to a web address you configure, such as a home automation server. This is off unless you create one. Data sent this way leaves Seized and is handled by that server under its own policies; the developer never receives it. Credentials for these actions (username/password, API key, OAuth client ID/secret, and access tokens) are stored only in the iPhone or iPad Keychain - they are never synced to Apple Watch, included in exports, or shown in task details. HTTP and Calendar actions run only on iPhone or iPad. A record of each attempt (status, error, and the request sent, with credentials masked) is kept on-device for the event's History screen.
Testing builds may additionally allow unencrypted http:// addresses, unverified HTTPS, or certificates you trust manually for a specific action; these are clearly marked as insecure in the app.
Email Actions
You can optionally create an Email action that emails event details (you choose exactly what via the subject and message templates) to recipients you choose, such as a caregiver. This is off unless you create one. Messages are sent from the iPhone or iPad directly through the mail server (SMTP) of the email account you configure, always over an encrypted connection; the developer never receives them. Email is not end-to-end encrypted, so your mail provider and your recipients' providers may store the message under their own policies. Your mail server username and password are stored only in the iPhone or iPad Keychain - never synced, included in exports, or shown in task details. A record of each attempt (status, error, and the message sent, with the password hidden) is kept on-device for the event's History screen.
Voice Notes
You can optionally attach a recorded voice note to an event from the History screen's event editor. Voice notes are stored locally on-device, encrypted at rest the same way the rest of your event log is. They are never relayed to your paired Apple Watch and are never included in JSON/CSV exports (only a note that a voice recording exists is included).
Exporting Your Data
The App lets you export your event history (including notes) as JSON or CSV from the History or Report screens. Exported files are unencrypted, and you choose where they go (e.g. Files, AirDrop, Mail) via the system share sheet. The App warns you before exporting that the resulting file is not encrypted, since you are responsible for keeping it secure once it leaves the App.
Deleting Your Data
You can permanently delete events within a chosen date range from the Purge Data screen (available from the Log tab), delete or archive a set of events matching filters you choose from Clear History (available from the History tab), or swipe an individual event to Archive or Delete it directly (a swiped delete shows a brief Undo option before it actually commits). Archived events are kept but hidden from the main History list, and can be restored or permanently deleted from the Archive tab. Deleting an event removes it (and any attached voice note) from your iPhone, paired Apple Watch, and any iPhones or iPads you sync with using Device Sync. Deletion cannot be undone once committed. Uninstalling the App removes all of its locally stored data from that device.
App Access Protection
The App requires Face ID, Touch ID, or your device passcode to unlock whenever it returns from the background, to help keep your health data private if your device is shared or accessed by someone else.
Audit Log
The App keeps a local, on-device record of when you export or delete data and of action successes and failures, viewable from the Audit Log screen, so you always know what has happened to your data on that device. This log is not transmitted anywhere.
Children's Privacy
Seized is not directed at children and does not knowingly collect data from children. Any data entered is entered directly by the user or their caregiver on their own device.
Changes to This Policy
If this policy changes, an updated version will be included with future releases of the App and posted on this page.
Contact
Questions about this policy or the App's data handling can be directed to: blaine_mcdonnell@yahoo.com
Medical Disclaimer
Seized is not a medical device. It does not diagnose, treat, cure, or prevent any disease or medical condition, and it does not detect seizures automatically. It is a personal logging and record-keeping tool intended to support conversations with a qualified healthcare provider, not to replace professional medical advice.