HealthClaw appears purpose-built for Apple Health syncing, but it asks users to expose and route sensitive health data through public webhooks and Discord with insufficient security and privacy guidance.
Review before installing. Use only if you are comfortable giving an external webhook server and beta iOS app access to Apple Health data. Set a strong ADMIN_TOKEN before exposing the server, prefer VPN/private access where possible, protect or encrypt the health-data directory, limit shared HealthKit categories, keep Discord alerts minimal and private, and know how to stop the tunnel, server, background sync, and cron jobs.