Effective date: 2026-08-19 Last updated: 2026-08-19


1. Introduction

Apoyu is operated by Daryll Cheng, a sole proprietor doing business as Apoyu (“Apoyu,” “we,” “our,” or “us”).

Apoyu is an iPhone and Apple Watch wellness app for people who train hard. With your permission, it reads health data from Apple Health, computes a daily recovery score on your device, and delivers a short daily briefing, a collectible card, one training-intensity suggestion for the day, and one small evening recovery action.

Apoyu is a general wellness product, not a medical device. Recovery scores, briefings, and training suggestions are not medical advice. See our Health Data Disclosure and Medical Disclaimer.

The three sentences that govern everything below:

  1. Your individual readings never leave your phone. Sample-level data (individual heart rate variability readings, heartbeat and sleep-stage samples, intra-night series, raw workout sensor data) is read from Apple Health, processed on your device, and never uploaded. There is no server copy of your raw readings.
  2. Per-day results are stored in your private account. Your daily recovery score, plus the daily summary values behind it (average overnight HRV, resting heart rate, sleep duration and quality, respiratory rate, training load), sync to our servers so your history and collection survive reinstalls.
  3. To write the daily coaching, the day’s derived values, a short history of your recent activity (recent workouts, evening dares, day tags, recent scores, and your recent briefings), and your display name go to our AI providers (Anthropic and OpenAI). They never receive your individual sample-level readings, they do not train on your data, and we ask them not to keep it.

The rest of this policy is the detail behind those three sentences.


2. What data we collect and why

2.1 Data that stays on your device (not transmitted to Apoyu servers)

With your explicit permission through the iOS Health permission sheet, Apoyu reads the following from Apple Health. It is processed locally by our recovery algorithm, stored only in encrypted local storage on your device, and is not transmitted to our servers:

The one thing Apoyu writes to Apple Health: when you finish an in-app breathing exercise, Apoyu saves a single mindfulness session to Apple Health so it counts toward your mindful minutes. It writes nothing else.

You can revoke any of these permissions at any time in iOS Settings under Health, Data Access and Devices, Apoyu.

2.2 Data we collect and store on our servers

Account and identity data

Daily recovery record (derived values, computed on your device)

Training and check-in data (the athlete layer)

Cards, coaching, and collection data

App usage and preferences

Purchase data

Diagnostics and quality data

2.3 Data we do not collect

We do not collect:

We use no third-party analytics, attribution, or advertising SDKs of any kind.


3. How we use your data and lawful basis

We use the data we collect to:

We do not use your data for advertising, do not sell it, and do not share it with data brokers. We do not use your data to train AI models, and we contractually and technically request that our AI providers do not either (Section 4.2).

Lawful basis (GDPR Article 6), where the EU or UK GDPR applies:


4. Third-party services

We use a small, fixed set of service providers. None of them may use your data for their own advertising, and none of them sells it.

4.1 Supabase (database and server infrastructure)

We use Supabase (United States) to store the account and derived data described in Section 2.2, to authenticate you, and to run the server functions that produce coaching content. Access is protected by row-level security so no user can read another user’s data.

4.2 AI providers: Anthropic and OpenAI (content generation)

Apoyu uses large language models from Anthropic and OpenAI to phrase the daily briefing, evening dare, and some card commentary in the character’s voice. Which provider phrases which surface can change as models improve; the data they may receive is the same fixed list:

They never receive: individual readings or sample-level data, your email, your Apple account identifier, your date of birth, or your location.

Two honesty notes. First, most standard daily cards are served from pre-written lines with no AI call at all; the values above reach a provider only when content is actually model-generated. Second, the training suggestion itself (push, hold, ease, rest) is computed by fixed rules in the app, never by an AI; the AI only phrases it.

Neither provider uses our API data to train models by default. We configure requests not to store response objects where the provider supports it. Provider terms may permit limited retention for abuse prevention; see the Anthropic and OpenAI privacy policies for details.

4.3 RevenueCat (purchases)

We use RevenueCat (United States) to process purchase events from Apple and verify entitlements. RevenueCat receives your Apoyu account identifier (an internal UUID, not your Apple ID or email) and purchase event payloads (product, transaction ID, expiration where applicable, and event metadata such as currency, country code, and environment). RevenueCat receives no health data and no generated content. RevenueCat retains transaction history on its own systems for its standard business and legal compliance period, even after Apoyu deletes its own records.

4.4 Apple

4.5 Sentry (error monitoring)

We use Sentry (United States) to capture crash reports and application errors. Before transmission we remove: email address, IP address, username, Apple account identifier, Apple Sign-In tokens, OAuth tokens, provider strings, and user metadata beyond a small allowlist of non-identifying flags. Sentry may still receive non-identifying device characteristics (device model, iOS version, app version) and stack traces. Sentry does not receive recovery scores, health data, or generated content.


5. Data retention and deletion

During active use: we retain your data for as long as your account exists, with two automatic exceptions: AI service quality logs have their prompt text scrubbed after 90 days and are deleted entirely after 365 days.

Account deletion: delete your account at any time in the app under Settings, Account, Delete Account. When you do, we:

  1. Revoke your Sign in with Apple authorization with Apple before deleting any data. In rare cases where the sign-in must be re-verified, the app will direct you through iOS Settings and then retry.
  2. Delete all your user-keyed records from our database: recovery records, cards, dares, briefings, check-ins, goals, receipts, events, notifications, purchase records, and all other personal records, including the pseudonymous AI quality logs linked to your account.
  3. Clear all locally stored data on your device (recovery history, baselines, card state, settings) and remove authentication tokens from the iOS Keychain.
  4. Sign you out.

What survives deletion (neither item contains health data):

Deletion removes your data from live systems immediately. Routine automated backups maintained by our database provider may contain copies for up to 7 days before being overwritten. We do not access backups except to recover from a service-wide incident, and deleted user data will not be restored. Your collection and recovery history cannot be recovered after deletion.

Deleting your Apoyu account does not cancel an App Store subscription. If you have an active auto-renewing subscription, cancel it first in iOS Settings under your Apple ID, Subscriptions, Apoyu. One-time purchases (such as the Founding Keeper) belong to your Apple ID and can be restored if you later create a new account.


6. Data security

No system is perfectly secure. If a breach affects your personal data, we will notify you and any required authorities within the timelines required by applicable law.


7. Children’s privacy

Apoyu is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, contact us at support@apoyu.app and we will delete it promptly.


8. International users

If you are in the European Economic Area or the United Kingdom, the lawful bases in Section 3 apply, you have the rights in Section 9, and you may lodge a complaint with your local data protection authority.

If you are a California resident, see the California section in Section 9.

If you are a Washington State resident, see our separate Consumer Health Data Privacy Policy, which describes additional rights under the Washington My Health My Data Act. Where the two documents overlap for consumer health data, that one controls.


9. Your rights and choices

Depending on your location, you may have the right to:

To exercise any right, email support@apoyu.app. We will verify the request against the email or sign-in linked to your account and respond within the time required by applicable law (and in practice, usually within a few days; Apoyu is run by one person and every request is read).

In-app controls: notification toggles (Settings, Notifications), intensity level, hide-score mode, and the soreness check-in and goal features are all optional and skippable.

California residents

Under the California Consumer Privacy Act (CCPA/CPRA), the categories below describe our collection in the structure California law requires:

Category of personal information Sources Purpose Third parties shared with
Identifiers (Apple account ID, internal user UUID, email, typically an Apple relay) You, via Sign in with Apple Authentication, account operation Service providers (Supabase, RevenueCat)
Customer records (display name, if provided) You, in onboarding Personalize content Service providers (Supabase, Anthropic, OpenAI)
Commercial information (purchase status, transaction events) Apple, via RevenueCat Purchases and entitlements Service providers (Supabase, RevenueCat)
Internet or network activity (app open events, named product events) You, via app use Notification timing, honest feature measurement Service providers (Supabase)
Health-related information (recovery score, z-scores, daily summary values, soreness check-in, effort ratings, goal context, workout metadata, coarse age band, biological sex) You, via Apple Health and in-app inputs, computed on-device Compute the score and call; generate coaching content Service providers (Supabase, Anthropic, OpenAI)
Inferences (archetype, comfort word, confidence level) Derived from the above Personalize content Service providers (Supabase, Anthropic, OpenAI)

We have not sold or shared personal information for cross-context behavioral advertising in the preceding 12 months. California residents have the rights to know, delete, correct, opt out of sale or sharing (we do neither), limit use of sensitive personal information, and be free from retaliation for exercising these rights. To exercise them, email support@apoyu.app with the subject line “CCPA request.” Authorized agents may act for you with written authorization and identity verification.


10. Changes to this policy

If we make material changes, we will update the effective date and post the revised policy at apoyu.app/privacy. If changes materially affect your rights, we will ask you to acknowledge the update on next app launch. Prior versions remain available on request.


11. Contact

Email: support@apoyu.app Web: https://apoyu.app Related documents: Terms of Service, Health Data Disclosure and Consumer Health Data Privacy Policy, Support