Today's Workout — Privacy Policy

Where this translation and the Korean original differ, the Korean version governs.

The conditions for using the Service are set out in our Terms of Service.


1. In short

  1. Your health data never leaves your iPhone or Android device. Sleep, heart rate, heart rate variability, wrist temperature and workout records are read, analysed and stored on your device only. We do not operate a server that receives them.
  2. The only things stored on a server are account details and, if you opt in, error reports. Account details are your email address, a hash of your password, and your display language. Error reports are off by default; only if you turn them on in the app do we receive which screens you opened, what you tapped, and what went wrong (§2-3). Health values and your daily score are in neither.
  3. You can use every analysis feature without an account. Signing up is optional.
  4. We use no advertising identifier, include no third-party analytics, advertising or crash-reporting SDK whatsoever, and never sell or share your data with third parties. Error reports go only to our own server — no vendor sits in between.

  5. On Android we read from Health Connect, not Apple Health. We read fewer items than on iOS (11 read types), and the only thing we write to Health Connect is a nap you entered yourself. See §3-A.

  6. The Android build has no account feature and no error reporting. The Android app does not declare the internet permission, so it sends no data off the device. The server-related parts of this document — §2-1 (accounts), §2-3 (error reports), §5 (automatic logs), §7 (processors), §8 (international transfers), the server-side entries in §9 and §10 (account deletion) — therefore do not apply on Android.

2. What we collect

2-1. Stored on the server (only if you create an account)

Item Required / optional When Purpose Retention
Email address Required to have an account Sign-up Identifying your account, signing in, sending password-reset mail Until you delete your account
Password Required to have an account Sign-up Authentication Until account deletion (stored only as a hash — the plain password is never stored and cannot be recovered from what we hold)
Display language (one of ko/en/ja/es) Required (set from your device language, changeable) Sign-up, settings change Showing the app and authentication emails in the same language Until account deletion
Account identifier (UUID), sign-up time, email confirmation time, last sign-in time Required (generated automatically) Sign-up, sign-in Account management, spotting abuse Until account deletion

If you never create an account, none of the above is collected.

2-2. Stored on your device only (never transmitted)

Item Required / optional Purpose
Health data read from Apple Health (HealthKit, iOS) or Health Connect (Android) Optional — the app runs without this permission (it simply cannot compute a score) Calculating your readiness score, condition level and workout suggestion. Android reads fewer items than iOS — see §3-A
Values derived from that data (daily summaries, scores, personal baselines) Optional (automatic once health access is granted) Reproducing calculations, showing your last 7 days
Today's step count counted by the device's motion sensor (iOS) Optional — only if you allow Motion & Fitness Showing steps on the step card when today's steps are not available from the Health app. Not stored on the device and not used in the score (§3, “Built-in pedometer”)
Naps (start and end time), caffeine (mg) and drinks (count) you enter yourself Optional — only if you log them Counting the nap towards your sleep, and caffeine and drinks towards that day's lifestyle record. Anything you allow write access for is saved into Apple Health; anything you do not stays on this device only (write access is asked for all three types together during first-time setup, and one type at a time on devices set up before this revision — see §3)
Date of birth (year, month, day) and biological sex Optional — the app works without them (you simply lose the age-based guidance) Working out the weekly activity range and target heart-rate zone that match your age. If you turn on the Saju reading, your date of birth is also used for that calculation (§3-B)
Time of birth (hour and minute), country and time zone of birth Optional — asked only if you turn on the Saju reading; you can answer “don't know” for the time Calculating the Saju reading (§3-B). The country and time zone are used only to apply the standard time in effect when you were born
App settings (display language, notification time, sleep goal, onboarding state, celebration-card state, flags that stop us asking the same thing twice) Required for the app to work App behaviour
Target bedtime (if you set one) Optional — the app works without it Used only to check whether a nap close to your target bedtime affected that night's sleep. Stored on your device only and never sent to a server
Morning check-in — how refreshed you felt on waking (1–5) and afternoon sleepiness (if you answer) Optional — the app works if you skip it Used to show your past answers by date. Stored on your device only and never sent to a server. If you tap 'Export as file', a file containing only your answers is handed to the place you choose
Your device's time zone Required Determining which day counts as "today". If your device's time zone changes by two hours or more, the app reads it as travel or jet lag and detects it automatically — it keeps only the time-zone offset from UTC (not city names) for the last 28 days, on your device only, never sent to a server, and you can turn it off any time in Settings
Sign-in session token Only if you have an account So you don't have to sign in every time

Date of birth and sex are looked for in your Apple Health profile first. If they are already written there, the app reads them (so you are not asked to type in something you have already entered); if they are missing, or you did not grant access, the app asks you once, at the point where the value is actually used. You may leave it unanswered, and if you decline we do not ask again. Either way, these values never leave your device.

We never ask for location access. The time zone is read from the iOS time-zone setting; we do not look up where you are. We also never ask for contacts, photos, microphone or camera access.

2-3. Error reports (opt-in, off by default)

These are the records that tell us what went wrong when the app freezes or a screen misbehaves. We ask once, on first launch, and if you do not turn them on nothing is ever sent — nothing is even queued on your device. You can turn them off at any time in Settings → Error reports; sending stops immediately and anything still held on the device is deleted.

What we send

Item Example
Screens and actions Which screens you opened, which buttons you tapped, which onboarding step you reached
App state Whether the analysis succeeded, found no data, or lacked permission; whether today's score appeared on screen
Error details Error kind, code and message; the sequence of function calls at the moment of a crash; the names of your last 20 actions
Device and app iOS version, device model (e.g. iPhone16,2), app version and build number, display language
Install identifier A random value (UUID) the app generates to tell this installation apart, together with a random secret that proves the identifier belongs to this installation. The server stores only an irreversible hash of the secret, never the secret itself. Neither is a device serial number or an advertising identifier

What we never send

Sleep duration, heart rate, heart rate variability, wrist temperature, respiratory rate, body weight, step count, workouts, nap times — every health value, and the daily score and condition level computed from them. Nor your email address, your password, or any free text you typed.

For the score we record a state, never a value: one of "score ready / still computing / no data / no permission". The number itself is never transmitted. Anything time-based is converted to a range (e.g. "0.5–2 s") before it leaves the device.

Email addresses, file paths and long random strings are replaced with placeholders on your device before an error message or call sequence is sent.

Link to your account: reports sent while you are signed in are linked to your account. If you are not signed in, only the install identifier remains and we cannot tell who you are. Deleting your account deletes the linked reports with it.

Deletion: Settings → Error reports → "Delete sent records" removes this device's records from the server; anything sent afterwards uses a new install identifier.

Only this device can delete or add to the records it sent. Knowing the install identifier alone is not enough to delete those records or to send records under that identifier — sending and deleting both require the secret above. The identifier and the secret are created when you turn error reports on and are kept in this device's iOS Keychain. They stay there after you turn error reports off, so that you can still delete what was already sent, and because they are in the Keychain they may survive deleting and reinstalling the app.

What remains after deletion: when this device's records are deleted from the server (by “Delete sent records”, by deleting your account, or when the retention period ends), an irreversible hash of the deleted install identifier and the time of deletion remain, plus — if you deleted the records yourself — a verification value used to confirm again that the deletion was completed. They exist so that no records build up again under a deleted identifier and so that a completed deletion can be confirmed; they contain no account, IP address, record content or secret. These values are kept and not deleted (§9).

IP address: to block excessive requests we use the IP address a request comes from, but we do not store it as is. The server turns it into an irreversible value used only to count requests in 5-minute windows, and counts older than one day are deleted (§9).

3. Health data, in detail

The app reads the data below, strictly within what you allow on Apple's Health permission screen. What it reads is used only to compute your readiness score on the device.

What it writes to Apple Health is the three things you enter yourself in the app — naps, caffeine and drinks.

What you enter Stored in Apple Health as Unit
A nap (start and end time) Sleep analysis (sleepAnalysis) a time span
Caffeine Caffeine intake (dietaryCaffeine) mg
Drinks Alcoholic beverages (numberOfAlcoholicBeverages) number of drinks

A write happens when you fill a value in and tap save, and what is stored is exactly the value you entered. The app never writes back the health values it read or the score it calculated.

There is one exception, and it only runs if you switch it on. If you turn on Days with none in Settings, then for any day that ends with no caffeine or drink entry at all, the app records a zero on your behalf at 11:59 PM that day. The switch is off by default, applies only to days after you turn it on, and can be turned off again at any time.

The only value ever written this way is zero. Days another app already wrote to are left alone, today is never touched because it has not ended, and days before you turned it on stay as they are. Like every other write, this one only reaches Apple Health for the types you granted write access to; anything you did not stays on this device only.

Why record a zero: if a day you drank nothing looks the same as a day with no record at all, then abstaining gets buried as missing data when the recovery score is calculated. This feature exists to keep those two apart.

There are two moments when write access is requested. If you are setting the app up for the first time, we ask for write access to these three types (naps, caffeine, drinks) together with read access, right there in the same step. On a device that finished setup before this revision, you were not asked then, so we ask the first time you try to save an entry of that kind — and only for that one type: saving a nap asks only for the sleep type, saving caffeine asks only for caffeine.

Either way, the question comes from iOS's own permission prompt and you can decline. If you decline, that entry is not written to Apple Health, stays on this device instead, and the app carries on working. Allowing reading and allowing writing are two different things — granting one does not grant the other.

No entry you did not enter here is ever modified or deleted. A record you just saved can be removed with "Undo" for a short moment right after saving, and only that one record is removed. After that moment the app cannot remove it and you would delete it in Apple Health.

What is read (17 types, verified against the code, plus 2 profile characteristics):

The types the readiness score is built from:

  1. Heartbeat series (beat-to-beat intervals) — so the app can compute heart rate variability (rMSSD) itself
  2. Heart rate variability (HRV SDNN) — a fallback for days when the above is insufficient
  3. Resting heart rate
  4. Heart rate
  5. Respiratory rate
  6. Wrist temperature during sleep
  7. Sleep analysis (stages and duration)
  8. Workouts (type, duration, average heart rate)
  9. Step count — walking you never logged as a workout is counted toward this week's activity

Everyday entries that only nudge the score (it works fine without them):

  1. Breathing disturbances during sleep — this type only exists on iOS 18 and later, so it is not requested below that
  2. Alcohol entries (number of drinks)
  3. Caffeine entries — only what lands late in the day is counted
  4. Mindful minutes
  5. Blood pressure entries (systolic and diastolic)
  6. Blood glucose entries

Types that never enter the score at all, and are used only for the guidance text:

  1. Time spent in daylight — this type only exists on iOS 17 and later, so it is not requested below that
  2. Body composition entries (weight, lean body mass, body fat percentage) — whichever of the three exist

The app also reads the two characteristics written in your Apple Health profile. They are listed apart from the numbered types because they are not entries that accumulate day by day, but values recorded once in the profile.

You allow each type separately, and anything you leave off is never read. Items 10–15 are not needed to produce a readiness score; they only move a score that has already been worked out slightly up or down. Items 16–17 and the two characteristics do not change the score at all — they are used only for the single line of guidance under the daily health card, as a reference alongside the workout suggestion, for the card that congratulates you on a new measurement, and to work out the activity range and target heart-rate zone that match your age.

What the on-device database keeps is derived values and summaries:

None of this is sent to any server, and none of it is stored in iCloud. Signing in changes nothing about this — your account and your health data are not linked.

Built-in pedometer — Motion & Fitness (iOS)

When today's step count is not available from the Health app (because you have not connected it, or there is no value for today yet), the app counts your steps since midnight with the iPhone's motion sensor and shows them on the step card in the Today tab. At that point iOS asks for the Motion & Fitness permission.

3-A. Health data read and written on Android (Health Connect)

On Android the app reads health data from Health Connect instead of Apple Health. The principle is the same as on iOS — we read only the items you explicitly allow on the permission screen, and we use them only to compute your readiness score on your device. Neither that data nor anything derived from it is sent to any server, stored in any cloud, shared with or sold to third parties, or used for advertising.

3-A-1. What we read (11 types)

Items that build the readiness score:

  1. Sleep sessions (stages and duration) — actual sleep time and sleep efficiency
  2. Exercise sessions (type and duration) — this week's cardio and strength load
  3. Steps — so walking that was never recorded as a workout still counts toward the week
  4. Resting heart rate
  5. Heart rate variability (rMSSD) — we read the value your device maker has already computed. Unlike iOS, the app does not read raw heartbeat intervals and compute it itself
  6. Respiratory rate

Items we only show you — they never move the score:

  1. Heart rate (samples through the night) — the shape of your heart rate while you sleep. Item 4 is a single value per day and cannot describe a night, so we read this separately. It does not raise or lower your readiness score
  2. Skin temperature — we only show how far it drifted from your own usual. There is no absolute reference for it, so it stays out of the score

Context items that only nudge the score (it works without them):

  1. Blood pressure records
  2. Blood glucose records
  3. Nutrition records — the caffeine total only. Nutrition records can hold other values; we do not use them

You can allow each item separately, and anything you leave off is not read.

3-A-2. What we write (1 type)

The only thing we write to Health Connect is a nap you entered yourself (one sleep session). It is written at the moment you press save, with exactly the start and end time you entered — as a single interval without sleep stages, marked as a manually entered record and tagged with an identifier this app assigns.

Write permission is requested together with the read permissions when you first connect. If you did not allow it then, we ask again at the moment you try to save a nap. If you decline, the nap is not written to Health Connect and stays on your device only; it still counts towards your readiness score. You can write that same entry later with "Save to Health Connect again" on the nap log screen — the app never resends it on its own. The Settings screen also shows you how to turn write access on.

The nap log kept on your device. To confirm that a save really finished, and to retry without writing the same nap twice when a response is lost, the app keeps two things in its on-device database:

Sleep records read from Health Connect are not kept in this log. A nap that has not been confirmed as written to Health Connect is never shown as written.

Entries are deleted automatically after 180 days. Log entries for a nap whose day is more than 180 days in the past are deleted from the device the next time the app reads your health data. Records already written to Health Connect are not touched.

You can undo naps one at a time. Pressing undo in the list on the nap entry screen deletes that nap only. In Health Connect the app finds and deletes that record by the identifier it assigned — never by a time range — so sleep records written by other apps are not deleted.

We never write back values we read or scores we computed, and we do not modify or delete records you did not enter in this app.

3-A-3. One special permission

Health Connect has special permissions that are separate from the data types; this app asks only for reading historical data. The app works if you decline it.

If you uninstall and reinstall the app, all permissions are gone and the 30-day limit starts over.

3-A-4. How this differs from iOS, and why

iOS and Android users read the same document, so we spell out what differs and why. We did not choose to make them different; the two platforms offer different things.

iOS (§3) Android (§3-A) Why
17 read types + 2 profile characteristics 11 read types ① Health Connect has no data type at all for some items — alcohol, sleep breathing disturbances, time in daylight. ② Body composition was left out of the first release. Skin temperature was added on 2026-09-05 (item 8 in §3-A-1). ③ Mindfulness is not yet available in the stable client. ④ What iOS reads as two types (beat-to-beat intervals and HRV SDNN), Android reads as one (rMSSD — see the next row)
Reads raw heartbeat intervals and computes rMSSD in the app Reads the rMSSD the device maker computed Health Connect does not expose raw heartbeat intervals. Same name, different number
Writes 3 types to Apple Health (nap, caffeine, drinks) Writes 1 type (nap) Health Connect has no data type for alcohol, and caffeine writing has not been added yet
Reads date of birth and sex from the Apple Health profile Does not read them from the health app. The app asks you once, where the value is actually used, and stores the answer on your device only Health Connect has no profile fields such as date of birth or sex
Cannot tell whether read access was granted, so it infers from arriving data The app knows the actual permission state Health Connect reports it. The connection screen states a fact instead of a guess

Items that cannot be read are left out and the remaining ones re-normalised. So the same person can get different scores on an iPhone and on an Android phone. Neither platform is systematically more generous — the direction depends on which items happened to be readable that day. The score detail screen shows what the app is actually looking at.

3-A-5. Revoking access, and deletion

You can revoke access at any time: device Settings → Security & privacy → Health Connect (or the Health Connect app, depending on your device) → App permissions → Today Workout.

Deleting the app deletes the derived data on your device. The original data in Health Connect is not affected — manage it in Health Connect itself.

3-B. Today's Saju reading (optional, off by default)

If you turn on Today's Saju reading in Settings, the app calculates your Saju (the Four Pillars) from your date of birth — and your time of birth, if you know it — on your device and shows today's reading as a card. If you do not turn it on, none of the following happens. It has no effect on the readiness score, condition level or workout recommendation.

What is used Your date of birth (§2-2 — already used to work out your age), plus the time of birth (hour and minute) and country and time zone of birth we ask for when you turn it on. You can answer “don't know” for the time, and it is then calculated without it. You choose the country yourself; we do not request location permission or look up your location
Where it is calculated On your device only. The calculation uses no network, and the reading is built from fixed wording shipped in the app. Nothing is sent to a server or an AI service to write or polish Saju text
What stays on the device Time, country and time zone of birth and whether the feature is on; a record of when we suggested the feature (so we do not keep asking); and the day's Saju entry in your feed (pillar values calculated from your date of birth — six or eight integers). The home screen widget receives one line of today's reading (§12)
Does it leave the device No. Even with error reports on, only the fact that you changed the Saju setting is recorded — never your date of birth, time or country of birth, or the Saju characters
Turning it off or clearing it You can turn it off or clear it in Settings → Today's Saju reading. Turning it off deletes the pillar values of past Saju entries; clearing it also deletes the time, country and time zone of birth. Your date of birth stays, because it is used for the age-based activity range

4. Notifications

There are no notifications on Android (as of 2026-09-04). The app requests no notification permission and contains no code that creates one. The home screen widget draws whatever the app last computed and stored on the device, so seeing the widget update does not mean a notification is coming.

5. Logs created automatically

When you use account features (sign-up, sign-in, password reset, account deletion), the server platform records the logs below automatically. We do not gather these deliberately — the authentication service writes them itself, and we consult them only to diagnose failures and check for abuse.

Log What it contains Retention
Authentication audit log Event type (sign-up, sign-in, reset request…), email address, timestamp, user agent (app and OS version), IP address 7 days (the log retention period of our Supabase Pro plan)
API request log Request path, method, response code, timestamp 7 days (same)

No health data appears in these logs — it never reaches the server, so it cannot be logged.

6. Tracking, advertising, third parties

7. Processors

We rely on the following processors to provide account features.

Processor Service Data handled Location
Supabase, Inc. Account authentication, database hosting, sending authentication email Email address, password hash, display language, account identifier, the logs in §5 AWS Seoul region (ap-northeast-2)
Amazon Web Services, Inc. Cloud infrastructure underneath the above Same Seoul region

8. International transfers

9. Retention and deletion

Data Retention How it is destroyed
Account details (email, password hash, language, identifier) For as long as the account exists; deleted immediately on request Removed from the database at once. It may persist in operational backups for up to 7 days and disappears as those backups expire
Authentication and API logs 7 days Deleted automatically by the platform
Error reports — screens and actions 90 days Deleted automatically each day
Error reports — errors and crashes 180 days Deleted automatically each day (we need this long to see whether the same fault comes back a season later)
Error reports — install identifier and device details 400 days after last activity Deleted automatically each day. You can also delete them yourself in Settings (§2-3)
Error reports — deletion ledger (hash of a deleted install identifier, time of deletion, verification value) Kept Not deleted. It cannot be turned back into the original identifier and contains no account, IP address, record content or secret (§2-3)
Error reports — request counts (an irreversible value derived from the IP address) 1 day The IP address itself is not stored. Counts older than one day are deleted while new requests are processed
Derived health data on your device Until you remove it Deleted when you delete the app
Time-zone offset log (for automatic travel/jet-lag detection) 28 days Used only to automatically detect travel or jet lag; entries older than 28 days are deleted automatically on your device. We do not store city names or location, and turning it off in Settings deletes it immediately
Per-night detailed metric records on your device (each night's derived metric values and that night's stage assessment) 180 days Each time the app loads your health data, records for nights older than 180 days are deleted automatically on the device. This does not apply to the other derived data in the row above, such as readiness scores and sleep records
Original data in Apple Health Not managed by us Managed by you in the Apple Health app

10. How to delete your account

In the app: Settings → Account → Delete account → confirm.

The app calls a server function, which verifies from your session token that you are the account holder and then deletes the account. When the account goes, your profile row (email and language) is deleted along with it by a database constraint. Afterwards you may sign up again with the same email address; the old account's data is not recoverable.

By email: write to contact@apochopo.com. Please send it from the address you signed up with so we can verify it is you.

Health data on your device is independent of your account. Deleting the account leaves device data in place; deleting the app removes device data but leaves the account. To remove both, delete the account and then delete the app. Original data in Apple Health is unaffected either way.

11. Your rights and how to exercise them

You may at any time ask to see, correct, delete, or stop the processing of your personal data.

What you want How
See what is stored Settings → Account shows your email address and display language. For a copy of anything else, ask us by email
Change display language Settings → Language
Change password Sign-in screen → Forgot your password → reset via the emailed link
Change email address By email (in-app change is not yet available)
Delete account and personal data §10
Cut off health data access iOS Settings → Privacy & Security → Health → Today's Workout, and revoke permission
Stop notifications iOS Settings → Notifications → Today's Workout, or in the app's settings

12. Storage used on your device

Storage Contents
App database (app-private area) The derived health values in §3, app settings, your morning check-ins (if you answered)
One file in the app group container Today's score, level and suggestion text for the widget, plus one line of today's reading if you turned on the Saju reading
iOS Keychain Sign-in session token; the error report install identifier and secret (§2-3). Keychain items may remain after the app is deleted
Device settings store Display language and similar display preferences

All of these sit inside the iOS app sandbox, so no other app can read them, and iOS file protection encrypts them when your device has a passcode or Face ID set. Deleting the app deletes the app database, the app group file and the stored settings.

Storage works differently on Android.

Storage Contents
App-private database (SQLite) The derived values and summaries described in §3-A — daily metrics, personal baselines, workout records, daily readiness scores, feed entries, sync position markers, your morning check-ins (if you answered — how refreshed you felt and afternoon sleepiness for each date, and whether you skipped)
App-private settings file Display language, date of birth and sex (if you entered them), your target bedtime (if you set one), your error report choice, and flags so we do not ask you the same thing twice
The same database — app usage (only if you turned usage access on) One row per day of totals: the seconds and sessions during which the screen was on and unlocked, how many of those a shopping app was in front, the measurement quality, the time zone, and the interval actually measured. No package names, no screen class names, no raw events (§13)
The same database — nap log (only if you entered a nap) The start and end time and time zone of naps you entered, and the progress record of each save (whether it was written to Health Connect, the record ID returned, the affected dates, the readiness score before and after). Sleep records read from Health Connect are not kept here, and entries are deleted automatically after 180 days (§3-A-2)

13. Security measures

Only measures actually in place are listed.

Additionally, on Android

Android — app usage (digital habits)

Besides the Health Connect permissions above, the Android build declares one more: usage access (android.permission.PACKAGE_USAGE_STATS). It is not a runtime permission — you have to turn it on yourself, in the system Settings screen called "Usage access" — and the app only checks whether it is on. If you do not turn it on, none of what follows happens.

What is read The moments an app comes to the foreground and leaves it, the moments the screen turns on and off, the moments the device locks and unlocks, and the moments it shuts down and starts up. Those events also carry the app's package name and the screen (Activity) class name
What is stored One row per day, in the app-private database on your device only. That row holds the date, the measurement quality, the seconds and the number of sessions during which the screen was on and unlocked, how many of those seconds and sessions a shopping app was in front, the version of the shopping-app list, the version of this layer, the time zone, whether the day is closed, the start and end of the interval actually measured, and when it was computed
What is not stored Package names, screen (Activity) class names and raw events are not stored — the table has no columns for them at all, and a test reads the table definition to keep it that way. The events exist only in memory while the daily totals are counted, and there is no logging path that could write them down
How long it is kept Until you delete it. The window used to judge your stage is the seven days up to yesterday, but older daily rows are kept so we can show you a trend, and the app does not delete them on its own
Does it leave the device No. The Android build declares no internet permission at all (first item above) and automatic backup of app data is off
Can you delete it Yes. Deleting from the digital-habits detail screen removes the daily rows, the stage-decision journal and the related settings in one action. If you revoke usage access in system Settings, the app deletes those records by itself. Uninstalling the app removes them too

One thing does keep package names. For the apps you yourself switched on or off in the shopping-app list, the package name stays in the app-private settings file, because that is your choice (§12). It does not leave the device either, and the deletion above removes it as well.

iOS does not have this feature. The iOS build does not read app usage — we are waiting on Apple's Screen Time entitlement — so this section applies to Android only.

14. Responding to a breach

15. Children under 14

16. Medical notice

Today's Workout is not a medical device and does not diagnose, treat or prevent any disease. The scores and guidance it shows are information to help you decide how hard to train and when to rest — they are not medical determinations. For health decisions, consult a healthcare professional.

17. Contact

18. Changes to this policy

Version Effective Main changes
v1 2026-08-14 First draft
v2 2026-08-18 Rewritten against the actual implementation. Added display language; new sections on automatic logs, retention, processors, international transfers, exercising your rights, security measures, breach response and children. Published in 4 languages
v3 2026-08-20 Covers the new self-entered nap. §3 and §13 now state that the app writes to Apple Health for that one nap (a sleep entry) only, correcting the earlier "never writes" wording
v4 2026-08-20 Adds six everyday entry types to what is read (breathing disturbances during sleep, alcohol, caffeine, mindful minutes, blood pressure, blood glucose). Because the set of types read has grown, §3's list and the on-device storage description were updated together
v5 2026-08-30 Error reports (opt-in) introduced. The app can now send screens, actions and error details to our server when it freezes or fails, so §1, §2-3, §6, §9 and §11 were updated along with the privacy manifest shown on the App Store. Off by default; even when on, no health values and no score are sent. Announced in-app seven days before it takes effect
v6 2026-08-30 More is now stored on the device. Time spent in daylight and body composition (weight, lean body mass, body fat percentage) were added to what is read, and biological sex and date of birth are now read from the Apple Health profile — or asked for, if they are not there — so §2-2 and §3 were updated. Nothing changed about what is transmitted: every new value stays on the device and none of it appears in error reports. Takes effect on the same day as v5 (revised 2026-08-27, before v5 took effect)
v7 2026-09-11 Step count was added to what the app reads, and what the app writes to Apple Health grew from one type (naps) to three (naps, caffeine, drinks). Step count is used so that walking you never logged as a workout still counts toward this week's activity, which means it does enter the score (§3, item 9). Caffeine and drinks are written only when you enter them yourself and tap save, and write access is asked for one type at a time (§3, §13). Neither is ever sent to a server.
This entry was broadened before it took effect. As revised on 2026-08-28 it covered step count alone and was due to take effect on 2026-09-06. On 2026-09-03, before that date, writing caffeine and drinks was added (the direct-entry feature on the Today tab), so it was folded into the same v7 and the effective date moved to 2026-09-11 — leaving it at 09-06 would have given only three days' notice, which would break the seven days §18 promises (revised 2026-09-03)
v8 2026-09-21 If you turn on Days with none in Settings, the app may now write a zero to Apple Health without you tapping save. Until this revision, every write this app made was the result of a person tapping save. The switch is off by default; it applies only to days after you turn it on, only to days with no caffeine or drink entry at all, and the only value it writes is zero (§3). Nothing is sent to a server.
The same revision also rewrites how §2-2, §3 and §13 describe when write access is asked for. Since 2026-09-11 the app asks for write access to naps, caffeine and drinks together with read access during first-time setup. Until now this document described only the other path — asking for a single type the first time you try to save that kind of entry — which is still exactly what happens on devices that finished setup before this revision, so both cases are now written out. The number and kinds of types asked for are unchanged (three), and no new permission is requested
v9 2026-09-16 Revised in one go for 1.3.0.Android support: the app reads from Health Connect rather than Apple Health; the 11 read types, 1 write type (a nap you entered) and 1 special permission (historical reads) are set out in the new §3-A. Naps you enter stay in an on-device log that is deleted automatically after 180 days, and can be undone one at a time. App usage on Android (digital habits, usage access permission) is described in §13. The Android build has no account, no error reporting and no internet permission. ② Built-in pedometer on iOS: when steps are not available from the Health app, the app counts steps on the device with the Motion & Fitness permission and shows them — nothing is stored or sent (§3). ③ How error reports identify an installation: the install identifier is paired with a secret only this installation holds, which protects sending and deleting (the server keeps only a hash); after deletion an irreversible deletion ledger remains; and the IP address is used, never stored as is, for one day of request counting (§2-3, §9, §12). The content sent in error reports has not grown
This version took effect on the day it was published (2026-09-16), and changes how changes are announced from this version on. Other changes are announced in the app when we make them and take effect on the day they are published (start of §18). Until now this document promised notice 7 days before other changes took effect; this version was not given that period — an operator's judgement for a very early stage with very few users. The content of v8 (Days with none), which was due to take effect on 2026-09-21, is included unchanged in this version and takes effect with it. v8 was never published on the web and never took effect on its own
Added 2026-09-16 — ④ Today's Saju reading (optional, off by default): if you turn it on, the app calculates Saju on your device from your date of birth and your time and country of birth. Nothing is sent to a server or an AI service, and turning it off deletes the pillar values of past Saju entries (§2-2, §3-B, §12).
Added 2026-09-17 — ⑤ Target bedtime (optional): if you set one, it is stored on your device only and used only to check whether a nap close to that time affected that night's sleep. It is not sent to a server (§2-2, §12).
Changed 2026-09-16 — on Android the app no longer requests background reads. It does not read Health Connect while it is not open, and the only special permission is reading historical data (§3-A-3, §13).
Changed 2026-09-17per-night detailed metric records are kept on your device for 180 days, and records for older nights are deleted automatically on the device. Retention of other derived data is unchanged (§9).
Added 2026-09-18 — ⑦ Morning check-in (optional): if you answer how refreshed you felt on waking (1–5) and how sleepy you were in the afternoon, the answers are stored on your device only and used to show your past answers. They are never sent to a server (§2-2, §12).
Added 2026-09-18 — ⑦ Morning check-in: only when you tap 'Export as file' yourself, the app creates a file containing just your answers (how refreshed you felt, afternoon sleepiness, and whether you skipped) numbered by day instead of dated, plus the type of device, and hands it to the app you choose (Files, Mail, etc.). The app never sends it on its own; once handed over, the file is kept according to that app's practices.
Added 2026-09-19 — ⑨ Automatic travel and jet-lag detection: if your device's time zone changes by two hours or more, the app detects travel or jet lag automatically. It keeps only the time-zone offset from UTC (not city names) for the last 28 days, on your device, never sent to a server, and you can turn it off any time in Settings (§2-2, §9).