Is it a record, a programme, or a claim?
Three things get bundled together in most briefs and are not the same product. An activity or habit record is an observation: a session, a count, a check against something the member said they would do, typed in or read from a device with permission. Coaching content is material you publish, authored by someone you can name. Progress is a presentation of what was recorded over a period the member chose. Keeping them apart is most of the scoping work, since each carries different data, permissions and responsibility.
The boundary that matters is between describing what the software does and describing what happens to a person. Verbs such as record, display, remind and review stay on the software side. Verbs such as diagnose, treat, prevent, cure or improve do not. That is a drafting habit that keeps the boundary visible, not legal, regulatory or clinical assurance, and the final wording belongs to your own advisers.
The platforms draw a similar line. Apple treats health, fitness and medical data as especially sensitive and attaches extra conditions to it. Google Play requires health apps to complete a health apps declaration and publish a privacy policy in the Console and inside the app, expects an app that is not a medical device to carry a clear disclaimer in its listing saying it does not diagnose, treat, cure or prevent any medical condition, and requires an app presenting itself as a medical device to produce approval, clearance or certification on request. Those rules are a quick way to see which product you are proposing.
| Decision | Non-clinical tracking | Coaching programme | Clinical claim boundary |
|---|---|---|---|
| Activity records | Entered or imported with permission, stored with its source | The same records, read against a published programme | Becomes evidence about a person once a health conclusion is attached |
| Content | Optional and generic, clearly authored | Structured programmes with a named author and review date | Advice for a condition needs a qualified author and a review process we do not provide |
| Progress | What was recorded, over a period the member chose | Completion against the programme they joined | Saying progress means a health improvement crosses the line |
| Device permissions | Optional, with the manual path kept usable | Optional, since completion can be recorded by hand | Platform health data carries extra restrictions on its use |
| Sensitive data | Collect only what the feature needs | Coach access is a permission decision, never a default | Clinical records are outside what we take on |
| Wording | The app records and displays | The app delivers a programme someone else authored | Diagnosis, treatment or outcome claims, which we do not build |
Three things people call a fitness app
Primary-source guidance. The first two are software. The third is a regulated product and we do not build it.
Source: Apple: App Review Guidelines. Reviewed .
Read the graphic as text
- A record. The user logs what they did
- A programme. Structured plans a coach designed
- A claim. Asserting a health outcome or diagnosis
Habits, streaks and what happens on a bad day
Reminders, member-set targets, streaks, badges and weekly summaries are ordinary features with a lot riding on their details. The question worth arguing about is what the app does on the day somebody misses. A streak that resets to zero after one missed day gives that person the least reason to open the app tomorrow, which is the opposite of what the feature is for. Forgiveness rules are cheap: a rest day, a freeze that can be spent, a weekly target instead of a daily one, or counting the total rather than the run. That is a design judgement rather than a research finding, and it is your call rather than a default we pick.
Reminders need the same care. Timing, frequency, quiet hours and switching off one category without losing the rest are the difference between a useful nudge and an uninstall. Shared challenges and leaderboards deserve a separate decision, because they turn a private record into something other members see, which is a consent question before it is a feature.
Half of Malaysia is online nine hours a day
Published statistic. The share online more than nine hours a day went from 38.5% in 2022 to 49.7% in 2024. Another notification is not a neutral addition to somebody’s day.
Source: MCMC: Internet Users Survey 2024, internet user behaviour. Reviewed .
Read the graphic as text
- Under 1h: 3.1%.
- 1 to 4h: 21.5%.
- 5 to 8h: 25.6%.
- 9 to 12h: 20.5%.
- 13 to 18h: 17.1%.
- Over 18h: 12.1%.
Chart scale: Daily internet use among Malaysian internet users, 2024.
Where each record came from
There are three provenances and they behave differently: typed in by the member, imported from a platform they connected, or read from a wearable. Store the source and timestamp on every record, because the first support message will be why the app says 6,000 steps when the watch says 7,400.
Then decide the conflicts in advance. A phone and a watch both counting the same walk. An import backfilling a day already entered by hand. Set precedence per data type, show the source in the interface, let people correct an entry rather than overwriting it silently, and leave an incomplete record visibly incomplete. Day boundaries need a decision too: what counts as today for someone who flew overnight, and whose time zone decides.
Platform data is borrowed rather than owned. On Android, Health Connect stores and structures health and fitness data for apps the member has granted access to, per data type, and that permission can be withdrawn at any time. Apple asks that HealthKit be used for health and fitness purposes, and its privacy rules ask for an alternative where possible when someone declines access. Both point the same way: the manual path stays usable and nothing breaks when permission is turned off. Progress views should name their source, period and gaps, since a chart that quietly drops three missing days looks like a signal when it is an absence.
Consent, storage and who can see it
Apple's review guidelines require consent before collecting user or usage data, an accessible way to withdraw it, purpose strings describing the actual use, and collection limited to what the feature needs. The privacy policy has to identify what is collected and how it is used, and explain retention, deletion and how consent is revoked. For health specifically, Apple prohibits using or disclosing health and fitness data for advertising, marketing or other use-based data mining, requires the specific health data collected to be disclosed, and does not permit personal health information in iCloud.
Internal access is the part most briefs forget. Which staff role can open a member's log. Whether a coach sees every member or only their own. Whether that access is recorded. What happens when a coach leaves. Who may export. Our position is that defaults should be closed, staff access logged, and an export a deliberate act by a named person rather than a button everyone has.
Who can see a health record
Primary-source guidance. Decide each of these before collecting the first measurement, not after.
Source: Apple: App privacy details. Reviewed .
Read the graphic as text
A health record
- The person. Always, and can export or delete it
- Their coach. Only what they explicitly shared
- Support staff. Only with a reason, and it is logged
- Advertising. Never, and both stores prohibit it
A worked non-medical example
Take a fictional activity journal with an optional, permitted import. The roles and policies are teaching assumptions, and the last column lists observations to collect before sign-off, not results anyone has achieved.
| Workflow step | Assumed actor | Proposed system response | Exception | Acceptance evidence to collect |
|---|---|---|---|---|
| Choose data permissions | Member | Access is requested per data type, with manual entry offered as an equal path | Permission is declined, so the manual workflow stays fully usable | Consent wording, permission prompt and denial-path observations on both platforms |
| Record activity | Member | Entries show their source and time, and the summary states the period and any gaps | A conflicting or incomplete entry is flagged rather than overwritten | Provenance, duplicate and correction tests, including an import over a hand-entered day |
| Withdraw access or delete data | Member, with a named support owner | Revocation stops new imports and deletion applies the agreed retention rules | Copies already exported, or records held for an unresolved billing question, need explaining | Revocation and deletion observations, with no benefit or certification claimed |
Twelve years, four surveys, one direction
Published statistic. Four national surveys, one line. An app cannot move this on its own, and any product that claims it will is selling something it cannot deliver.
Source: Institute for Public Health: NHMS 2023 key findings. Reviewed .
Read the graphic as text
- 2011: 44.5%.
- 2015: 47.7%.
- 2019: 50.1%.
- 2023: 54.4%. Past half
Chart scale: Malaysian adults overweight or obese, body mass index 25.0 and above.
What we will not build
We do not build medical, clinical or diagnostic software, and we do not write claims about diagnosis, treatment, prevention or outcomes into anything we do build. We would also decline to read clinical values from phone sensors alone, which Apple names directly when it says apps claiming to measure blood pressure, blood glucose, blood oxygen or body temperature using only the device sensors are not permitted. We do not build products that use health or fitness data to target advertising, and we do not take on research involving human participants without the sponsor's own ethics and consent process.
If your product needs clinical evidence or regulatory clearance, the right partner is one who works inside that regime every day, and we would rather say so in the first conversation.
What the national survey actually found
Published statistic. These are clinical measurements from a national survey, and they are exactly why we will not let an app imply a diagnosis. Encouraging a habit is a product. Interpreting a reading is medicine.
Source: Institute for Public Health: NHMS 2023 fact sheet, non-communicable diseases. Reviewed .
Read the graphic as text
- Overweight or obese: 54.4%.
- High cholesterol: 33.3%.
- Hypertension: 29.2%.
- Diabetes: 15.6%. A third undiagnosed
Chart scale: Prevalence among Malaysian adults, National Health and Morbidity Survey 2023.
What to bring
Useful first conversations start with the member task, where the data comes from, whether device permissions are optional, the wording you intend to use and who signs it off, who may see member records, and your position on retention and deletion. Bring what you have to the contact page and we will tell you which parts are ready to scope and which need a decision first. Mobile app development covers the platform, backend and ownership decisions underneath it, and accounts and portals covers the membership side that usually comes with a tracking product.


