In short
Rhythm Fit ("Rhythm", "we", "us") is an iPhone and Apple Watch app. It is made and run by Connor Matthew Otto, an individual (sole proprietor) in the United States. He decides how and why your data is used.
Rhythm is offered in the United States only. This policy is written for people in the United States.
This policy covers the Rhythm Fit app, the Apple Watch app, and our websites (rhythmfit.app, privacy.rhythmfit.app, terms.rhythmfit.app and links.rhythmfit.app).
All of these are optional. Before Rhythm connects Oura or Whoop, or asks Apple for Health access, the app tells you what it saves and asks you to agree.
Apple Health. Rhythm asks to read heart rate, resting heart rate, heart-rate variability (HRV), breathing rate, sleep, wrist temperature during sleep, active calories, period (menstrual flow) records, menopause records, protein and water. You choose which of these to allow. Rhythm writes your workouts, their active calories and your effort rating to Apple Health if you allow it. Rhythm reads Apple Health on your phone and does not copy those readings to our servers. The one exception: when you save a workout, its heart rate and calories are saved with that workout.
Oura. Rhythm asks Oura for the personal, daily, heartrate, workout and tag permissions. Our server gets your data from Oura and saves one summary per day: Oura's readiness, sleep and activity scores and the parts of the readiness score, sleep details (such as sleep stages and breathing rate), your skin-temperature change from your normal, HRV, resting heart rate, heart rate, calories, your resilience level, rest-mode days, and the start time and calories of your latest workout. Some older summaries also hold Oura's daytime stress summary. If you tag period days in Oura, our server passes those tags to your phone and does not save them.
Whoop. Rhythm asks Whoop for read:recovery, read:sleep, read:profile, read:cycles, read:workout, read:body_measurement and offline.
read:profile gives us your Whoop member ID. We keep it so Whoop can tell us when new data is ready.read:body_measurement is part of the permission set. Rhythm does not read or save Whoop body measurements.Heart-rate chest straps. Rhythm reads heart rate from a Bluetooth strap during a workout. Only the workout's summary is saved.
Sign-in tokens. When you connect Oura or Whoop, our server encrypts their sign-in tokens and keeps them in a table the app cannot read.
Cycle tracking is optional and open to anyone.
The two App Review demo accounts. Rhythm's own two test accounts for Apple's reviewers may keep a cycle phase on their saved workouts on our servers, so reviewers can see the cycle screens. Their cycle data is made up. No real person's cycle data is stored this way; the database refuses it for every other account.
If you email us, we keep your email and our reply so we can help you.
Our websites have no ads, no analytics and no tracking cookies. Our host, Cloudflare, sees the technical details every website sees (such as your IP address). Our websites load fonts from Google Fonts, so Google also sees your IP address when you open them. The links.rhythmfit.app page shows a shared routine's name and exercise count.
| Kept only on your phone | Kept in our database (United States) |
|---|---|
| All cycle data (section 2.6) and its Keychain copy | Account, profile and training (2.1-2.3) |
| Apple Health readings | App settings, without cycle settings (2.4) |
| Heart-rate strap readings | Oura and Whoop daily summaries, including skin temperature, and encrypted tokens (2.5) |
| Subscription records (2.9), shared routines (2.10) |
Our database is run by Supabase on Amazon Web Services in the United States (region us-east-1). We keep backup copies of the database in Cloudflare R2 storage. Cloudflare chooses which of its data centers holds them. Usage data and crash reports are kept by PostHog and Sentry in the United States.
We give each company only what it needs for the job below.
| Company | What it does for us | What it gets |
|---|---|---|
| Supabase (on Amazon Web Services) | Our database, sign-in, and sign-in emails | Everything in "our database" (section 3) |
| Apple | Sign in with Apple, Apple Health, App Store payments | What you choose to share with Apple; Rhythm writes workouts to Apple Health if you allow it |
| RevenueCat | Subscription status | Your random account ID, your App Store purchase records, and technical details about your device |
| PostHog | Usage data, only if you say yes | Usage events (section 2.7), your random account ID |
| Sentry | Crash reports | Crash reports and timing data (section 2.8), your random account ID |
| Cloudflare | Our websites, shared-routine links, and storage of our database backups | Website visit details; the backup copies of our database |
| Expo | App updates | When your phone checks for updates: app version, a random install ID and your IP address; not your account data |
| Google Fonts | Fonts on our websites | Your IP address when you open our websites |
| Porkbun and our email provider | Deliver and store email you send us | Your email messages |
| Oura, Whoop | Your wearable data, only if you connect them | We receive data from them. We send them only what is needed to connect, refresh and end the connection |
We use each company only as a service provider to run Rhythm, under its terms, and not for its own purposes.
We may also disclose data if the law requires it (for example, a valid court order), or to protect people's safety. If Rhythm is ever sold or merged, your data would move to the new owner under this policy, and we would tell you first.
| Data | How long |
|---|---|
| Account, profile, training, settings, shared routines | While your account is open. Deleted when you delete your account. |
| Oura and Whoop daily summaries, and their heart rate and calories on your saved workouts | While your account is open. You can delete them sooner: in Settings → Wearables & Live Data, open Oura or Whoop, tap Disconnect and choose "Disconnect and delete data". After you disconnect, the same screen shows "Delete stored Oura data" or "Delete stored Whoop data". |
| Oura and Whoop sign-in tokens | Deleted when you disconnect the wearable or delete your account. |
| Oura period tags | Never saved on our servers. |
| Whoop "new data ready" messages | 7 days. |
| Subscription event records | Until you delete your account. |
| Request counts (abuse limits) | 2 days. They are deleted at the next counted request after those 2 days. |
| Server logs | 1 day. |
| Database backups | Nightly copies: 35 days. Monthly copies: 180 days. |
| Usage data (PostHog) | Until PostHog deletes it automatically at the end of the retention period of our PostHog plan, or sooner if you ask us (section 8). We use it only for the purpose in section 2.7. |
| Crash reports (Sentry) | Until Sentry deletes them automatically at the end of the retention period of our Sentry plan, or sooner if you ask us (section 8). We use them only to find and fix bugs. |
| Messages you send us | As long as we need them to answer you and to keep a record of the requests you make under section 7. |
| Cycle data on your phone | Until you delete it, clear the app's data, or delete your account. |
Everyone who uses Rhythm has these rights, wherever in the United States you live.
| Right | How |
|---|---|
| See your data (access) | In the app: Settings → Legal & Data → Export My Data gives your workouts as a CSV file. Export My Data (JSON) gives your workouts, routines, goals and profile as a JSON file. For a full copy of everything we hold (including wearable summaries and subscription records) and a list of every company that received it, email us. |
| Take your data with you (portability) | The export above, or a full copy by email in a common file format. |
| Correct it | Edit your profile, workouts, routines and goals in the app. For anything else, email us. |
| Delete it | Delete your account in Settings → Legal & Data → Delete Account (section 8). Delete Oura or Whoop data in Settings → Wearables & Live Data (section 6). Clear the data on this phone in Settings → Legal & Data → Clear Local Data. Or email us. |
| Say no to usage data / withdraw consent | Settings → Legal & Data → Your Privacy. Turning it off stops collection at once. |
| Stop wearable or Apple Health access | Disconnect Oura or Whoop in Settings → Wearables & Live Data. Change Apple Health access in the iPhone Settings app → Privacy & Security → Health → Rhythm Fit. |
How to ask. Email team@rhythmfit.app from the email address on your account, and say what you want. If you write from another address, we will ask you to confirm the request from your account email, so no one else can get or delete your data.
How fast. We answer within 45 days. If we need more time, we will tell you why within those 45 days, and we will finish within 45 more days. Requests are free. We may refuse requests that are clearly unfounded or repeated, and we will say why.
Appeal. If we say no to a request, you can appeal: reply to our answer with the word "Appeal". We will answer your appeal in writing within 45 days and explain our decision. If we still say no, we will tell you how to contact your state Attorney General.
No penalty. We will never charge you more or give you a worse app because you used these rights.
Someone acting for you. An authorized agent can make a request for you. We will ask for your written permission and may ask you to confirm it from your account email.
Delete your account in Settings → Legal & Data → Delete Account. This:
What deletion does not reach. We are telling you this plainly:
No system is perfectly secure. We take reasonable care, and we will tell you if something goes wrong (section 11).
Rhythm is for people aged 18 and over. It is not directed to children. When you sign up, the app asks for your birthday and does not let anyone under 18 go past that step. We do not knowingly collect data from anyone under 18. If we learn that someone under 18 has an account, we will delete it. If you think a child is using Rhythm, email us.
If someone gets your health data without your permission — whether by a hack or by a disclosure you did not allow — we will tell you by email (and in the app when we can) within 60 days of finding out, as the Federal Trade Commission's Health Breach Notification Rule requires. We will also tell the Federal Trade Commission and, where the law requires, the media and state authorities.
Some web browsers send a "Do Not Track" signal. Our websites do not track you across other websites, with or without that signal, so there is nothing for the signal to turn off. We do not respond to it differently. The app does not track you across other apps or websites either.
California law requires us to list, at the point we collect data, what we collect, why, and how long we keep it. This section is that list. The details are in sections 2 and 6.
| Category (California terms) | Examples | Why | How long | Sold or shared for cross-context ads? |
|---|---|---|---|---|
| Identifiers | Email, name, username, random account ID, Whoop member ID, IP address | Account and sign-in | While your account is open | No |
| Personal records | Body weight, height, birthday | Personal training | While your account is open | No |
| Characteristics of protected classes | Gender, age | Personal training | While your account is open | No |
| Commercial information | Subscription status and history | Pro features | While your account is open; at RevenueCat until you ask us to delete it | No |
| Internet or other electronic activity | Usage data (opt-in), crash reports | Improve and fix the app | Until PostHog or Sentry deletes it at the end of its retention period | No |
| Sensitive personal information | Account login; health data (workouts, heart rate, HRV, sleep, skin temperature, mood, effort rating) | To give you the service you asked for | While your account is open; Oura and Whoop data until you delete it or your account | No |
| Inferences | Your daily readiness suggestion | Personal training | Made on your phone; in usage data only if you say yes | No |
Backup copies of our database hold the data above for up to 180 days after it is deleted (section 6).
Sources: you, your devices and wearables (section 2.5), and Rhythm itself when it works out suggestions. Who receives it: the companies in section 4, only to run Rhythm.
We do not sell or share personal information, and we have not done so in the past 12 months. We use sensitive personal information only to provide the service you asked for. We do not share personal information with other companies for their own direct marketing. Your rights and how to use them are in section 7. We will not treat you differently for using them.
Washington and Nevada have separate laws for consumer health data. Our Consumer Health Data Privacy Policy explains what health data we collect, why, who receives it, and how to use your rights: https://privacy.rhythmfit.app/health-data/
Connecticut residents have the rights in section 7. Before Rhythm saves health data from Oura or Whoop on our servers, or asks Apple for Health access, the app asks for your consent (section 2.5).
When we change this policy, we change the date at the top. If a change is important — for example, we start collecting a new kind of health data or use it for a new purpose — we will email you at your account address before the change takes effect, and we will ask for your consent again where the law requires it.
Questions, requests, or appeals: team@rhythmfit.app. Post: 7864 Camino Huerta, San Diego, CA 92122.