Privacy Policy

Effective September 23, 2026

Summary

Teo is an Apple Watch and iPhone app for training readiness and run tracking. Your health and fitness data stays on your devices: readiness, fitness, heart rate zones, training load, and every workout metric are computed locally. Teo has no analytics SDK, no advertising, and no data sales. A Teo account and a Strava connection are optional; connecting Strava is the only feature that sends workout data anywhere. Support requests go to our website only when you send them.

Health Data

Teo reads data from Apple HealthKit to compute your readiness score, fitness score, heart rate zones, cardiac load, sleep debt, and workout metrics. This includes heart rate, heart rate variability, resting heart rate, respiratory rate, sleep analysis, workout history, running metrics, and workout routes. During a run the Apple Watch app records heart rate, motion, and location and writes the workout to HealthKit.

All HealthKit data is processed entirely on your devices. Teo does not transmit HealthKit data to its servers or to any third party, with one exception that you explicitly control: if you connect Strava, the runs you choose to sync are sent to Strava (see “Strava” below). HealthKit data is never used for advertising, data mining, or any purpose other than the features described in the app.

Location

The Apple Watch app uses Location Services during a run to record your route, elevation, and compass heading, and to power the map, breadcrumb trail, pins, and backtrack features. Routes are stored on your devices and in HealthKit. Pins you drop are stored on your watch and synced to your iPhone. Location is not sent to Teo's servers.

Maps and Weather

Map pages use Apple Maps, and weather shown on watch faces comes from Apple Weather. Those requests go to Apple with your approximate location and are governed by Apple's privacy policy. If you download an offline map pack, the iPhone app fetches the map tiles for that area from OpenTopoMap, which receives the tile coordinates requested; the pack is then stored on your devices and used without a network connection. Teo does not receive any of these requests.

Apple Analytics and Diagnostics

Teo does not include a third-party analytics SDK or any Teo-hosted event client in its iPhone app, Apple Watch app, or this website. We do not receive page views, screen views, feature taps, device identifiers, or crash reports directly from your devices.

Apple may provide Teo with aggregated App Store usage statistics and Xcode Organizer diagnostics, such as sessions, active devices, crashes, hangs, launch performance, memory, disk, and energy metrics. This collection is operated by Apple and depends on whether you choose to share analytics with app developers in Settings → Privacy & Security → Analytics & Improvements. Apple applies privacy protections and minimum-volume thresholds. Teo does not create an identifier for this service or control Apple's collection setting.

Teo Account

A Teo account is optional and uses Sign in with Apple only. It is required to connect Strava, because our Strava connection capacity is limited and we track who holds a connection. You can also optionally connect your account to a feedback submission in the app so the creator can follow up. When you sign in, we store the account identifier Apple issues, your email address (or Apple's private relay address if you chose Hide My Email), and sign-in timestamps with Supabase in the United States. No health data is ever associated with your account.

When you create an account you can choose to receive product updates by email: a few messages a year about new faces, features, and fixes. The choice is stored on your account, is on by default on the sign-up screen, and can be turned off any time in Settings → Account or with the unsubscribe link in any message. We do not send marketing email to anyone who has not made that choice.

You can delete your account at any time in the app (Settings → Account → Delete Account). This immediately deletes your account and all server-side data associated with it, and disconnects Strava. You can also request deletion through Support (see Contact) from the address on the account; those requests are completed within 30 days.

Strava

Connecting Strava is optional and off by default. Teo's integration is upload-only: we send your runs to Strava; we do not read your Strava activities, your profile, or anyone else's data.

What we send to Strava: when you sync a run (manually or via auto-sync), Teo uploads an activity file containing its route, heart rate stream, timestamps, distance, sport type, and activity name. Once uploaded, that data lives on Strava and is governed by Strava's Privacy Policy.

What we store: your Strava authorization tokens are kept in the secure Keychain on your device, never on our servers. Our server stores your numeric Strava athlete ID and connection timestamps (connected, last used, disconnected), which we use to manage our limited number of Strava connections. Your device also remembers the IDs of activities Teo has uploaded, to prevent duplicates and link you to them on Strava. Teo requests only the activity:write permission and calls only Strava's upload endpoints.

Disconnecting: disconnect any time in Teo's settings, or revoke Teo at strava.com/settings/apps; Strava notifies us of revocations automatically. Either way, the tokens on your device are destroyed and your Strava athlete ID is deleted from our server immediately. Strava monitors usage of its API (such as call volume) under its own privacy policy.

Support and Feedback

Bug reports and ideas are sent through the form at trainwithteo.com/support, which also opens inside the app from Settings. We store what you type, whether it is a bug or an idea, an optional email address if you leave one, and an optional image. Images are re-encoded on the way in, which strips location and other metadata. Submissions are private, are held with Supabase in the United States, and are deleted automatically after 180 days. To limit abuse, the form keeps a keyed one-way hash of the sending network address. It cannot be turned back into an address. It is stored with your submission and deleted with it, and the separate rate-limit record that uses it is deleted after a day.

After sending from the app you can choose to connect your Apple Account so we can reply. That links the submission to your Teo account and stores the reply address Apple provides. It is optional, and deleting your Teo account also deletes any feedback connected to it. Feedback sent by email goes to teo@santekotturi.com and is handled as ordinary correspondence.

Storage, Sync, and Backup

Teo stores your preferences (heart rate zones, watch face and screen configuration, units, display settings) on your devices. Your Apple Watch and iPhone exchange computed scores, workout summaries, pins, and settings over Apple's WatchConnectivity framework, directly between the two devices on Apple's encrypted channel; nothing passes through Teo's servers.

If you turn on the optional iCloud backup, app settings and training-load summaries are stored in your personal iCloud, never raw health samples or routes. We have no access to your iCloud data.

On-Device Intelligence

Features such as automatic run naming and training-plan explanations run with Apple's on-device models; nothing leaves your phone. Any future feature that sends data to a server for coaching will be opt-in, with its own clear disclosure before anything is sent. No Strava data is used with any intelligence feature.

Your Rights (GDPR, UK GDPR, CCPA)

Where you use optional features that involve our servers (accounts, Strava connections, the Strava waitlist, and support submissions), we process that data on the legal bases of consent and legitimate interest in operating Teo. Depending on where you live, you have the right to access, correct, export, restrict, or delete your personal data, and the right to lodge a complaint with your local supervisory authority. California residents additionally have the rights described in the CCPA; we do not sell or share personal information as defined there.

To exercise any of these rights, contact us (see Contact). We respond within 30 days. Our servers are hosted in the United States; where data of EU/UK residents is transferred, it is protected by our providers' standard contractual clauses.

Data Deletion

Local data (health computations, preferences, workout history, routes, pins, offline map packs): delete the app from your Apple Watch and iPhone. Strava connection: disconnect in settings; server-side Strava data is deleted immediately. Teo account: delete it in the app (Settings → Account → Delete Account); server-side deletion is immediate and removes any feedback connected to the account. Feedback sent without an account expires after 180 days, or sooner on request. Apple-hosted analytics and diagnostics are controlled through your Apple device settings.

Security

Authorization tokens are stored in the iOS Keychain. Server data is held with Supabase behind row-level security, with privileged access limited to our backend. If we discover a breach affecting your data, we will notify affected users and relevant parties (including Strava, for Strava-related data) promptly and within the timelines the law and our partner agreements require.

Children's Privacy

Teo is not directed at children under 13 and does not knowingly collect data from children.

Changes to This Policy

If this policy changes, the updated version will be posted here with a new effective date. Material changes to how health data is handled will be communicated through an app update.

September 23, 2026: the support form also opens inside the app; the abuse hash stays with a submission until it is deleted; support submissions and the Strava waitlist listed among server-side features; the support email lists everything it pre-fills. September 14, 2026: removed the identifier-free daily usage counts added two days earlier; the app now sends Teo nothing. September 12, 2026: documented support and product-feedback submissions, private image attachments, abuse prevention, and retention. August 29, 2026: removed Teo-hosted analytics and MetricKit forwarding from the native apps and website, deleted the analytics event store, and documented Apple-hosted diagnostics. July 17, 2026: first policy covering beta usage analytics, Teo accounts (Sign in with Apple), and the Strava integration.

Contact

Questions about this policy, or a data request? Email us at teo@santekotturi.com or use the support form. Inside the Teo app, Settings → Support opens a message with your app version, build, iOS version, and device model filled in; you can edit or remove them before sending.