DRAFT, pending legal review. This text is generated from a codebase audit and is not legal advice. Pending counsel review before publication.
Effective date: [YYYY-MM-DD, TBD before publication] Last updated: [YYYY-MM-DD, TBD before publication]
Apoyu is operated by Daryll Cheng, a sole proprietor doing business as Apoyu (“Apoyu,” “we,” “our,” or “us”). Apoyu is a personal recovery and wellness app that uses your health data to generate a daily recovery score, coaching cards, and wellness insights. This Privacy Policy explains what data we collect, why we collect it, who we share it with, and how you can control or delete it.
Apoyu is a general wellness product, not a medical device. Recovery scores and coaching content are not medical advice.
In ordinary operation, Apoyu processes raw Apple Health readings on your device and does not transmit those raw readings to our servers. Derived values and certain account-linked metadata are synced as described below. Raw HealthKit readings stay on device; server-synced data includes your derived recovery metrics, certain workout metadata, account identifiers, preferences, and related app-functionality records described in Section 2.2.
The following data is read from Apple Health, processed locally by the Apoyu app, and in ordinary operation is not transmitted to our servers:
This data is processed entirely on your device by our recovery algorithm and is stored only in encrypted local storage (MMKV) keyed to your account. It is cleared when you delete your account.
Account and identity data
Recovery and coaching data
App usage and preferences
Subscription data
Diagnostic data
We do not collect:
We use the data we collect to:
We do not currently use your data for advertising targeting, sell it to third parties, or use it for any purpose not described in this policy.
Lawful basis (GDPR Article 6). Where the EU or UK General Data Protection Regulation applies to our processing of your personal data, we rely on the following lawful bases:
You may withdraw consent at any time by disabling the relevant HealthKit categories in iOS Settings or by deleting your account.
We use Supabase to store account data, recovery scores, coaching content, and subscription records. Supabase is a U.S.-based company. Data is stored on Supabase’s cloud infrastructure.
We use OpenAI’s API to generate your daily morning briefing, daily dare suggestion, and trading card commentary. To personalize this content, we include:
OpenAI does not receive your Apple account information or any raw HealthKit data. OpenAI business and API data is not used to train models by default, and we configure API requests not to store response objects where supported (store: false). Provider terms may permit limited retention for abuse prevention; see OpenAI’s privacy policy for details.
Model used: GPT-4.1 Mini
We use Anthropic’s API to generate rare and legendary trading card commentary. The same recovery, biometric summary, and identity context described in Section 4.2 applies: recovery score, HRV summary value (ms), sleep duration (hours), resting heart rate (bpm), display name (if provided), intensity level, and archetype context. Daily training intention is not included in card commentary generation and is not sent to Anthropic.
Anthropic does not use commercial API inputs or outputs for model training by default. Provider terms may permit limited retention for abuse prevention; see Anthropic’s privacy policy for details.
Model used: Claude Haiku
We use RevenueCat to manage subscriptions, process purchase events from Apple, and verify entitlements. RevenueCat receives:
appUserIDRevenueCat does not receive health data or content generated by the app. RevenueCat retains your subscription transaction history on its own systems for its standard business and legal compliance period, even after Apoyu deletes its own records. See https://www.revenuecat.com/privacy for details.
We use Sentry to capture crash reports and application errors. We do not transmit personally identifiable information; specifically, we remove the following fields before transmission to Sentry:
We may still transmit non-identifying device characteristics (device model, iOS version, app version) and crash diagnostic data such as stack traces for debugging. Sentry does not receive recovery scores, health data, or content generated by the app.
We use Apple’s services for:
During active use: We retain your data for as long as your account exists.
Account deletion: When you delete your account through the app (Settings > Account > Delete Account), we:
The following records are retained after account deletion for legal and operational reasons:
Account deletion removes your data from our live systems immediately. Routine automated backups maintained by our database provider may contain copies of your data for up to 7 days (the standard Supabase backup window for our plan tier) before they are overwritten. We do not access these backups except to recover from a service-wide incident, and deleted user data will not be restored. Your card collection and recovery history cannot be recovered after deletion.
Deleting your Apoyu account does not cancel any App Store subscription; billing continues until you cancel through Apple. Before deleting your account, we recommend cancelling your subscription in Settings > [Your Apple ID] > Subscriptions > Apoyu.
We protect your data using:
expo-secure-store), not in unencrypted storage.No system is perfectly secure. If a breach affects your personal data, we will notify you and any required authorities within the timelines required by applicable law.
Apoyu is not designed for or directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us and we will delete it promptly.
This Privacy Policy describes our current practices. Additional region-specific notices may apply where required by law.
If you are located in the European Economic Area or the United Kingdom, the lawful bases described in Section 3 apply to our processing. You have the rights described in Section 9. You also have the right to lodge a complaint with the data protection authority in your country of residence.
If you are located in California, please see the “California Residents” subsection in Section 9.
If you are located in Washington State, please also see our separate Consumer Health Data Privacy Policy, which describes additional rights under the Washington My Health My Data Act.
Depending on your location, you may have rights regarding your personal data, including the right to:
To exercise these rights, email us at support@apoyu.app.
Notification preferences. You can enable or disable morning briefing and dare reminder notifications at any time in Settings > Notifications.
Intensity level. You can change the content intensity level for Apoyu’s coaching voice at any time in Settings.
Under the California Consumer Privacy Act (CCPA, as amended by the CPRA), California residents have the rights described in this Section 9. The following categories provide the structural disclosure required by California Civil Code Section 1798.110.
| Category of personal information we collect | Sources | Business or commercial purpose | Categories of third parties with whom shared |
|---|---|---|---|
| Identifiers (Apple account ID, Supabase user UUID, email address typically an Apple relay) | You via Sign in with Apple | Authenticate your account; deliver notifications | Service providers (Supabase, RevenueCat) |
| Customer records (display name, if provided) | You directly in onboarding | Personalize coaching content | Service providers (Supabase, OpenAI, Anthropic) |
| Commercial information (subscription status, transaction events) | Apple (via RevenueCat) | Manage subscription and entitlements | Service providers (Supabase, RevenueCat) |
| Internet or other network activity (app open timestamps, re-engagement state) | You via app use | Schedule notifications; measure engagement | Service providers (Supabase) |
| Health-related information (recovery score, component z-scores, summary biometric values, workout metadata) | You via Apple HealthKit, computed on-device | Compute recovery score; generate coaching content | Service providers (Supabase, OpenAI, Anthropic) |
| Inferences (archetype, comfort type, confidence level) | Derived from health-related and quiz data | Personalize coaching content | Service providers (Supabase, OpenAI, Anthropic) |
We have not sold or shared your personal information for cross-context behavioral advertising in the preceding 12 months. California residents have the right to know what personal information we collect, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information (we do not sell or share for advertising), the right to limit the use of sensitive personal information, and the right not to be subject to retaliation for exercising these rights.
To exercise California rights, email support@apoyu.app with the subject line “CCPA request.” Authorized agents may submit a request on your behalf with written authorization and verification of your identity.
If we make material changes to this Privacy Policy, we will update the effective date and post the revised policy at apoyu.app/privacy. If the changes materially affect your rights, we will require you to acknowledge the update on next app launch.
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:
Email: support@apoyu.app App: apoyu.app
This document is a draft generated from a codebase audit on 2026-04-29 and revised against second-pass AI review on 2026-05-20. It has not been reviewed by legal counsel and must not be published until reviewed and approved.