Privacy Policy
Last updated: July 17, 2026
Summary
Your health and fitness data stays on your device — Teo's readiness, fitness, and training computations all run locally. Beyond that, Teo collects a small, specific set of data: anonymous usage analytics, and — only if you opt in — a Teo account (Sign in with Apple) and a Strava connection. This policy lists exactly what that data is, where it lives, how long we keep it, and how to delete it. We never sell data or show ads, and we never will.
HealthKit Data
Teo reads data from Apple HealthKit to compute your readiness score, fitness score, heart rate zones, cardiac load, training plan, and workout metrics. This includes heart rate, heart rate variability, resting heart rate, respiratory rate, sleep analysis, workout history, running metrics, and GPS routes.
All HealthKit data is processed entirely on your device. Teo does not transmit HealthKit data to our servers or any third party, with one exception that you explicitly control: if you connect Strava, the workouts you choose to sync are sent to Strava (see “Strava Integration” below). HealthKit data is never used for advertising, data mining, or any purpose other than the features described in the app.
Usage Analytics
The Teo apps and this website collect anonymous usage analytics so we can see which features are used and whether the app is working correctly. Each install generates a random identifier (a UUID we create — not your Apple advertising identifier, not your name or email). Events include things like “app launched” or “workout started” together with app version, platform, OS version, device model, and a per-session identifier.
If the app crashes or hangs, we also receive a technical diagnostic report through Apple's MetricKit framework (exception codes and a truncated call stack — details about the failure, never about you or your data).
Analytics events never contain health data, workout measurements, locations, or anything typed into the app. They are stored with Supabase on servers in the United States, are not shared with anyone, are not used for advertising, and are not linked across other apps or websites. We retain analytics events for up to 24 months, after which they are deleted or reduced to aggregate statistics.
You can turn this off in the app under Settings → Privacy. Turning it off stops analytics on both iPhone and Apple Watch (including crash reports), discards anything queued, and permanently deletes the random identifier — if you later re-enable it, you start over as a brand-new anonymous device with no link to prior history. To have already-collected events deleted from our servers, email us (see Contact).
Teo Account
Creating a Teo account is optional and uses Sign in with Apple only. It is currently required for one thing: connecting Strava, because our Strava connection capacity is limited and we track who holds a connection. When you sign in, we store the account identifier Apple issues, your email address (or Apple's private relay address if you chose Hide My Email), and sign-in timestamps with Supabase in the United States. No health data is ever associated with your account.
You can delete your account at any time in the app (Settings → Account → Delete Account). This immediately deletes your account and all server-side data associated with it, and disconnects Strava. You can also request deletion by email (see Contact) from the address on the account; emailed requests are completed within 30 days.
Strava Integration
Connecting Strava is optional and off by default. Teo's integration is upload-only: we send your runs to Strava; we do not read your Strava activities, your profile, or anyone else's data.
What we send to Strava: when you sync a run (manually or via auto-sync), Teo uploads an activity file containing its GPS route, heart rate stream, timestamps, distance, sport type, and activity name. Once uploaded, that data lives on Strava and is governed by Strava's Privacy Policy.
What we store: your Strava authorization tokens are kept in the secure Keychain on your device — never on our servers. Our server stores your numeric Strava athlete ID and connection timestamps (connected, last used, disconnected), which we use to manage our limited number of Strava connections. Your device also remembers the IDs of activities Teo has uploaded, to prevent duplicates and link you to them on Strava. That is the complete list — Teo requests only the activity:write permission and calls only Strava's upload endpoints.
Disconnecting: disconnect any time in Teo's settings, or revoke Teo at strava.com/settings/apps — Strava notifies us of revocations automatically. Either way, the tokens on your device are destroyed and your Strava athlete ID is deleted from our server immediately.
Strava monitors usage data related to our use of the Strava API (such as API call volume) in accordance with its own privacy policy.
Data Storage
Teo stores your preferences (heart rate zone thresholds, display settings, screen order) locally on your device using UserDefaults and iCloud Key-Value Storage for cross-device sync. If you use the optional iCloud backup feature, only app settings and training-load summaries are synced to your personal iCloud — never raw health samples or GPS routes. We have no access to your iCloud data.
Watch-to-Phone Sync
Teo uses Apple's WatchConnectivity framework to sync computed scores (readiness, fitness, training load, training plan) between your Apple Watch and iPhone. This communication happens directly between your devices over Apple's encrypted channel. No data passes through Teo's servers.
AI & Coaching Features
Teo's training-plan explanations run on-device using Apple's on-device models — nothing leaves your phone. Server-side coaching features are in development; if and when they launch, they will be strictly opt-in with their own clear disclosures before any data is sent. No Strava data is used in connection with any AI feature.
Your Rights (GDPR, UK GDPR, CCPA)
Where you use optional features that involve our servers (analytics, accounts, Strava connections), we process that data on the legal bases of consent and legitimate interest in operating and improving Teo. Depending on where you live, you have the right to access, correct, export, restrict, or delete your personal data, and the right to lodge a complaint with your local supervisory authority. California residents additionally have the rights described in the CCPA; we do not sell or share personal information as defined there.
To exercise any of these rights, email us (see Contact). We respond within 30 days. Our servers are hosted in the United States; where data of EU/UK residents is transferred, it is protected by our providers' standard contractual clauses.
Data Deletion
Local data (all health computations, preferences, workout history): delete the app from your Apple Watch and iPhone. Strava connection: disconnect in settings — server-side Strava data is deleted immediately. Teo account: delete it in the app (Settings → Account → Delete Account) — server-side deletion is immediate. Analytics: email us and we'll delete everything associated with your device identifier within 30 days.
Security
Authorization tokens are stored in the iOS Keychain. Server data is held with Supabase behind row-level security, with privileged access limited to our backend. If we ever discover a breach affecting your data, we will notify affected users and relevant parties (including Strava, for Strava-related data) promptly and within the timelines the law and our partner agreements require.
Children's Privacy
Teo is not directed at children under 13 and does not knowingly collect data from children.
Changes to This Policy
If this policy changes, the updated version will be posted here with a new date. Material changes related to health data handling will be communicated through an app update.
July 17, 2026: first policy covering usage analytics, Teo accounts (Sign in with Apple), and the Strava integration. Earlier versions predate those features.
Contact
Questions about this policy, or a data request? Email sante@hey.com