Privacy Policy
The short version. Your health data is yours. It lives on your phone first and syncs to our database so you don't lose it. We don't sell it, we don't share it for advertising, and the only third party that ever sees the sensitive parts is the AI provider that answers your coach questions — and only after you've explicitly said yes.
Tvara is operated by the developer of the Tvara app ("we", "us"). This policy explains what the app collects, why, who else touches it, and what you can do about it. It describes the app as it actually behaves — where something is a limitation, we say so rather than leaving it out.
1. What we collect
Account
Your email address, and a display name and avatar if you set one. If you sign in with Apple or Google, we receive whatever that provider gives us — for Apple this may be a private relay address rather than your real one, which is fine; we never need the real one.
What you log
Workouts, sets and weights, cardio sessions, meals and their nutrition, body measurements, sleep, habits, meditation and yoga sessions, soreness and wellbeing check-ins, and notes you write.
Health and fitness data from your device
With your permission, we read from Apple Health or Health Connect: steps and active energy, heart rate and heart-rate variability, resting heart rate, sleep, VO₂max, respiratory rate, blood oxygen and skin temperature. We store these at the granularity we actually use — daily and per-session aggregates — not as continuous streams. Raw sleep stages are read on your device and never sent to our servers.
Special-category data
Some of what Tvara handles is what the GDPR calls special-category data, and it gets extra handling:
- Menstrual cycle data — stored on your device first and synced under access rules that scope it to your account alone. Writing it back to Apple Health or Health Connect is a separate opt-in and is off unless you turn it on.
- GLP-1 medication data — dose and date. Sending this to the AI coach requires its own explicit opt-in, separate from every other AI consent, and it is off by default. When it is off, the data is omitted entirely rather than replaced with a note, because a note saying "withheld" would itself disclose that you take one.
Location
Only for cardio sessions you start, and only while one is running. GPS traces are stored with the session so you can see your route. There is no background location tracking when you are not recording.
Photos and voice
If you use AI food logging, a photo or voice recording is sent to our server and on to our AI provider for recognition. Photos are re-encoded before they leave your device, which strips EXIF metadata including location. Neither the photo nor the recording is stored on our servers or used to train any model. The file your camera or microphone produced stays in your phone's own temporary cache, which the operating system reclaims — the app does not delete it, and we would rather tell you that than imply otherwise.
Diagnostics
Crash reports and basic usage analytics. Neither ever carries a health value — no HRV, no weights, no sleep durations, no food names. Crash reports carry an opaque user id, not your email, and we disable screenshots, session replay and console breadcrumbs.
2. Why we're allowed to process it
- To provide the service — your account, your logged data and its sync. You cannot opt out of this and still have a working app.
- Your consent — AI processing, GLP-1 data in AI requests, cycle write-back to Apple Health or Health Connect, marketing email. Each is separate and each is revocable.
- Legitimate interest — crash reporting, so we can fix what breaks. You can switch it off in Settings → Your data.
Analytics collection begins at first launch and you can switch it off at onboarding or in Settings → Your data. Switching it off also resets the analytics identity on your device.
3. Where your data is stored
Our database is in the European Union — Frankfurt, Germany
(eu-central-1). Your account, everything you log, and any files you upload are
stored there. Crash reports go to Sentry's EU region.
Some data still leaves the EU, and we would rather say so than bury it: AI requests go to OpenAI in the United States, and only after you give the separate AI consent; purchase and subscription records go to RevenueCat; analytics events go to Google. Each one, and exactly what it receives, is listed on the subprocessors page.
Data on your phone is protected by the operating system's own encryption — iOS Data Protection and Android File-Based Encryption — which means it is encrypted at rest whenever your device is locked. Everything in transit uses TLS.
4. Who else sees it
We do not sell your data and we do not share it for advertising. A short list of processors handle specific jobs on our behalf, and two third parties are contacted directly from your phone. All of them, and what each one receives, are listed on the subprocessors page.
The one worth naming here: when you use the AI coach or AI food logging, the request goes through our server to OpenAI, and depending on what you ask it can include a summary of your recent training, sleep, weight and nutrition. That is why the AI consent is explicit, versioned, and enforced at the server rather than at each screen — a new AI feature cannot reach OpenAI without passing the same check.
5. How long we keep it
- While your account is open — your logged history is kept as history. That is the point of it. You can delete any individual entry at any time.
- When you delete your account — we mark it immediately and permanently erase everything after 30 days. Signing back in during those 30 days cancels the deletion. After that it is not recoverable.
- Data exports — download links expire after 24 hours.
- Payment records — subscription event records are retained for up to 180 days after purge for accounting integrity.
6. Your rights
If you are in the EEA or UK you have rights of access, rectification, erasure, restriction, portability and objection. We have built the first two of those into the app rather than making you email us:
- Export — Settings → Your data → Export my data. Three formats: JSON, CSV (one file per table), and GPX/TCX for cardio sessions. Very large accounts are capped at 50,000 rows per table.
- Deletion — Settings → Delete my account, with the 30-day window above.
For anything else, email hello@tvara.health. You also have the right to complain to your local data protection authority.
7. Age
Tvara is not for children. The minimum age is 16 in the EEA, the UK, Switzerland, Norway and Iceland, and 13 elsewhere. We check date of birth during onboarding and block accounts below the floor for that region.
8. Changes
If we change this policy materially we will say so in the app before the change takes effect, not only by editing this page. Where a change broadens what we do with data you have already consented to, we ask again rather than assuming the old consent carries over.
9. Contact
Privacy questions: hello@tvara.health
Anything else: hello@tvara.health