PRIVACY
Your training data remains yours.
This policy covers the KARDIOO iOS app, kardiooo.com and related services. It reflects the data flows implemented in the project, including connecting a Garmin, COROS, Polar, Wahoo or Zepp watch.
UPDATED · September 22, 2026
1. Controller
KARDIOO is published by AMINE ANSEUR CONSULTING, a French simplified joint-stock company (société par actions simplifiée unipersonnelle) with share capital of 500 €, registered with the Pontoise trade register under number 995 049 228 and having its registered office at 104 B avenue de Verdun, 95100 Argenteuil, France. VAT number FR50995049228. It is the controller for the processing described in this policy. Privacy questions and rights requests can be sent to amine@kardiooo.com.
KARDIOO is a fitness tracking and planning service. It is not a medical device, healthcare provider, diagnostic service or emergency service.
2. Data we process
Account and profile
Account identifier, email address, name, username, avatar, city, region, country, language, measurement and privacy preferences. Sign-in may be provided by Apple or Google.
Fitness and health data
With permission, KARDIOO may read workouts and metrics from Apple Health: sport, timestamps, duration, distance, energy, heart rate, speed or pace, cadence, power, elevation, swimming lengths and strokes, running dynamics, laps, time series, recording source and device.
If you connect a watch, the same categories arrive from the manufacturer as the activity file the watch recorded, together with daily summaries: sleep and its stages, heart-rate variability, resting heart rate, steps, energy expenditure, stress and VO₂max. Section 4 states, manufacturer by manufacturer, exactly what we receive.
Depending on enabled features, KARDIOO may also process weight, sex, date of birth, resting or maximum heart rate, sleep, blood oxygen, respiratory rate, FTP and other data needed for training-load and recovery features.
Location and user content
Precise GPS routes may be imported with a workout, from Apple Health or from a connected watch’s file; KARDIOO does not track location continuously. Posts, descriptions, comments, reactions, follows, chats, photos, videos, goals, planned sessions and planning-assistant requests are processed when you use those features.
Subscription, device and usage
Subscription and credit status, RevenueCat customer identifier, Apple push token, security logs, error diagnostics and limited product events. Analytics events do not include health measurements, routes or workout content.
3. Sources and connected services
- You, when you create an account or provide content.
- Apple Health / HealthKit, after granular iOS permission. Permissions can be withdrawn in Apple Health settings.
- Apple or Google, for identity details you approve during sign-in.
- Your watch — Garmin, COROS, Polar, Wahoo or Zepp — only if you pair it under Settings ▸ Watches and sensors and approve the scopes the manufacturer asks for.
While a watch is connected, KARDIOO no longer imports from Apple Health the workouts that manufacturer’s own app copied there: the same session would arrive twice. They stay in Apple Health, and the app offers to import them if you want them.
4. Watch and sensor manufacturers
KARDIOO requests only the permissions the features you use require, and processes what a manufacturer sends solely to serve the athlete who authorized it. Manufacturer data is never sold, never licensed, never shared with third parties or data brokers, never used for advertising or to build an advertising profile, and never used to train machine-learning models. It is not combined with other users’ data for any purpose outside the service.
Garmin
Activity summaries, activity details and the recorded activity file for over thirty activity types; daily health summaries such as steps, resting heart rate, intensity minutes, stress and Body Battery; sleep and its stages; heart-rate variability; VO₂max and fitness age; and intra-day activity intervals. With your permission KARDIOO also sends structured workouts and training plans to your Garmin Connect account so they sync to your device. Disconnecting in the app immediately deregisters KARDIOO with Garmin and erases the access tokens; workouts and summaries already imported stay in your account, as section 8 explains.
COROS
Workout records and the recorded workout file; daily data such as steps and energy expenditure; sleep duration; heart-rate variability. With your permission KARDIOO also sends structured workouts and training plans to your COROS account. Disconnecting in the app immediately revokes the authorization with COROS and erases the access tokens; workouts and summaries already imported stay in your account, as section 8 explains.
Polar
Exercises and their recorded files, daily activity, sleep and its stages, Nightly Recharge, continuous heart rate and cardio load. Polar’s interface does not accept structured workouts, so nothing is sent to a Polar device; your planned sessions stay in the app. Disconnecting immediately deletes the registration held with Polar and erases the access tokens; workouts and summaries already imported stay in your account, as section 8 explains.
Wahoo
Completed workouts and their recorded files. Wahoo does not share workouts that originated in a third-party application, so a session recorded through another app may not reach KARDIOO. Where the capability is enabled, KARDIOO also sends the day’s structured session to your Wahoo device. Disconnecting immediately revokes and erases the token; workouts already imported stay in your account, as section 8 explains. At Wahoo’s request, or at yours, Wahoo-sourced data is deleted within 30 days, under the conditions in section 8.
Zepp
Activities and daily summaries, where the connection is available. Nothing is sent to a Zepp device. On iOS, an Amazfit watch also writes to Apple Health, and that path is governed by your Apple Health permissions rather than by this connection.
5. Purposes and legal grounds
- Core service: synchronize and display activities, calculate insights, build and adapt plans, send planned sessions to your watch, provide social features and support — performance of our contract.
- Health data: personalized fitness insights — explicit consent, withdrawable at any time.
- Subscriptions: verify entitlements and App Store purchases — contract and legal accounting duties.
- Security and reliability: prevent abuse, diagnose failures and protect accounts — legitimate interests.
- Product measurement: improve flows using limited events — legitimate interests or consent where required. No advertising profile is created.
A KARDIOO subscription pays for the training plan and the analyses built on top of your data. Connecting a watch, receiving its activities and disconnecting it are never behind a payment.
6. Visibility and disclosure
Profiles and workouts follow the settings selected in the app. A workout can be public, relationship-limited or private, with separate controls for route, heart rate and pace. Chats remain available to their participants.
KARDIOO does not sell personal data and does not share it for cross-context behavioural advertising. It does not use Apple Health or manufacturer data for advertising, does not disclose either to data brokers, and does not transfer either to any third party except the processors named in section 7, acting on our instructions. Data may be disclosed to a public authority only where the law requires it.
7. Processors and international transfers
Service providers process only what they need for their role: Netcup for the servers and the database, Cloudflare for delivery and R2 for media storage, Apple for HealthKit, purchases and push delivery, Google for sign-in and Firebase Analytics, RevenueCat for subscription status, OpenRouter for the AI coach, Grafana Labs for technical logs and server operating metrics, and, for the manufacturers where it applies, Stridee for watch connections.
KARDIOO’s servers and its database are hosted in the European Union. Where a connection runs through Stridee, Stridee receives your Kardioo account identifier and, from the manufacturer, the activities and summaries you authorized; it forwards them to us encrypted and makes no other use of them on our behalf. Deleting your Kardioo account also deletes the reference Stridee keeps of you and revokes the corresponding connections.
Technical logs and server operating metrics are sent to Grafana Labs (Grafana Cloud) and hosted in the European Union, in Sweden (the “EU Sweden” region, AWS eu-north-1). They contain your account’s technical identifier, your IP address when rate limiting applies, timestamps and error messages — never the content of a workout, a health measurement or a conversation. They are kept for 30 days, on the basis of KARDIOO’s legitimate interest in securing and operating the service.
The AI coach runs through OpenRouter, a US company, which routes the request to the DeepSeek V4 Flash model. Inference is routed first to three hosts based in the United States — deepinfra, open-inference and parasail. KARDIOO also forbids any host handling a request from retaining its content: a host that does not accept that receives nothing.
What KARDIOO attaches to the request is anonymized: an age band by decade rather than your date of birth, sex, weight, height, heart rates, zones, paces, the sports practised over the last ninety days, and reported discomforts, with no date and no identifier. An automatic check strips every identifier, email address and UUID before sending. Manufacturer activity files and raw manufacturer measurements are never sent to the model provider.
One exception, and it matters: the message you write to the coach yourself is sent as you wrote it. If you put your name or a medical condition in it, that goes too.
The European hosting stated above does not cover the AI coach: a request sent to it leaves the European Union, OpenRouter routing it to one of the three pinned inference hosts. Other providers, including Apple, Google and RevenueCat, may also process data outside the EEA. For those transfers, KARDIOO relies on an adequacy decision, Standard Contractual Clauses or another lawful safeguard.
8. Retention and deletion
Account, training and content data is kept while the account is active and it remains necessary to provide the service. Technical logs are kept for 30 days (section 7) and notifications have limited lifetimes. Transaction evidence may be archived for applicable tax and accounting periods.
Disconnecting a watch immediately revokes the authorization with that manufacturer, erases the access tokens we held, and stops any further data arriving. What had already been imported from that watch — workouts and their activity files, nights, daily measurements — is not deleted: it stays in your account, with the rest of your history, until the account is deleted or until you ask for its erasure (see below). No other connection is touched.
Deleting your account first revokes every watch connection at the source, so no manufacturer keeps delivering to a deleted account. It then erases outright your workouts and their activity files, your GPS routes and time series, every daily health and sleep record — heart-rate variability, sleep stages, blood oxygen and the rest —, your photos and videos, your posts, comments and chats, your goals, your plans and your exchanges with the coach; the profile is reduced to an anonymous row with no name, email, photo or measurement; the identity held by the sign-in provider is deleted and, where applicable, your reference at Stridee. Your workouts are not retained, even anonymized; the app states this before you confirm. What you had created for a group — an event, a route, a report — stays with the group, detached from your identity.
Two things remain. The accounting records of subscriptions and credit purchases, kept for the statutory accounting retention period because the law requires it (Article 17(3)(b) GDPR). And the technical erasure register — a pseudonymous identifier, the timestamp of each step and the number of rows erased, with no personal data — which proves the erasure took place. Database backups are kept for two days: any copy still holding your data is overwritten within 48 hours.
At a manufacturer’s request, or at yours, the data that manufacturer provided — imported workouts and their activity files, nights and daily measurements — is deleted by us within 30 days, without touching the rest of your account, and KARDIOO confirms the deletion in writing. Write to the address in section 10; no account or app is needed to ask.
The app also lets you erase stored health metrics separately, and disconnect a watch without deleting anything else. An active App Store subscription may need to be cancelled before automated account deletion; contact us if this check prevents you from exercising your rights. Deletion can also be requested without the app — see Deleting your data.
9. Security
KARDIOO uses TLS in transit for every connection, account-level access controls, centralized authorization for private workouts, separate public and private media storage, and limited logging. Manufacturer access tokens are held encrypted on the server and are never sent to the mobile app. Incoming notifications from a manufacturer or from Stridee are verified before any content is processed, and where the transport provides it, signed in both directions and encrypted end to end. No system can guarantee absolute security; a breach affecting your rights would be notified to you and to the competent authority as the law requires.
10. Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability and objection, and withdraw consent without affecting prior lawful processing. Contact amine@kardiooo.com. You may also complain to the French CNIL or your local supervisory authority.
11. United States residents
If you live in California or another US state with a comprehensive privacy law, you may request to know the categories and specific pieces of personal information collected, their sources and purposes; to have them corrected or deleted; and to obtain a portable copy. You will not be discriminated against for exercising these rights, and the service will not be degraded or priced differently because you did.
KARDIOO does not sell personal information and does not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act, and has not done so in the preceding twelve months. Health and fitness data received from Apple Health or from a watch manufacturer is treated as sensitive personal information and is used only to provide the features you asked for. Requests go to the same address as above and are answered within the statutory deadline; an authorized agent may act for you with proof of authority.
12. Children and changes
KARDIOO is not intended for children under 16 and does not knowingly collect their data. Material policy changes will be communicated in the app or through another appropriate channel before taking effect.