Privacy policy
The short version
- Intero exists to hold your own body data for you. It is not an advertising business: we do not sell your data, share it for advertising, or use it to track you across apps or websites.
- The app contains no third-party analytics, advertising or crash-reporting SDKs.
- Your data is stored on a private server operated for you, and on the operator's own Mac, not in a shared database with other people's data.
- You can ask for a full export, and you can ask for everything to be deleted.
- Intero describes signals from your devices. It is not a medical device and does not give medical advice.
What data Intero processes
Health and fitness data from your devices
- Nightly measurements: overnight heart-rate variability, resting heart rate, sleep duration, sleep efficiency, skin temperature deviation and overnight breathing rate, as each device reports them.
- Training sessions: start time, duration, distance, sport, heart rate and power, where your devices record them.
- The raw records themselves. Intero keeps every record a source sends exactly as received, including fields it does not use, so any number can be traced back and recomputed. This can include data beyond the measurements listed above, depending on what the vendor includes in its export.
- Device details: vendor, device and firmware or algorithm era, where the source reveals them.
- Time zones: the zone each night was recorded in, so nights are dated correctly. Time zones can reveal travel.
Things Intero computes
Estimates, error bands, refusals, forecasts and their scores, and the receipts that explain each one. These are stored in an append-only ledger linked to your account's identifier.
Profile details you provide
Optional details kept in a settings file on the server, such as time zone history, event dates and changes in how a device is worn, used to date and interpret your data.
Credentials
- Vendor access: an Oura personal access token and a WHOOP authorisation (client credentials and a refresh token that WHOOP rotates). These are stored as private files readable only by the server process, and as encrypted secrets with the hosting provider. They are never written to logs.
- Garmin: Intero never receives your Garmin username or password. Garmin data arrives as export files prepared on the operator's Mac and sent to the server over HTTPS with a separate upload-only token.
- App sign-in: when the iPhone app is enrolled, it receives a device token. The server stores only a hash of it. On the iPhone the token is kept in the iOS Keychain, on that device only (not synchronised to iCloud), and is sent only to the server you signed in to.
Technical and security records
- Server request log: for each request, the method, route, response status, timing, the kind and identifier of the token used, a coarse class of network peer, and a shortened user agent. Tokens, enrolment codes and IP addresses are not written to this log.
- Security audit log: refused requests, sign-ins, revocations and server events, with the reason and the network address involved, so abuse can be investigated.
- Rate limiting: network addresses are held briefly in memory to slow down password-guessing style attacks, and are not stored.
Where the data comes from
- Oura: read from Oura's API with a personal access token you create in your Oura account.
- WHOOP: read from WHOOP's developer API after you authorise access.
- Garmin: from Garmin data exported on the operator's Mac, then uploaded to the server.
- intervals.icu: optionally, activity files exported from intervals.icu and imported on the operator's Mac.
Intero only reads from these services; it does not write back to them. Your use of each vendor is governed by that vendor's own privacy policy. You can withdraw Intero's access at any time from each vendor's account settings.
The iPhone app does not use Apple HealthKit.
Where it is stored
- A private server run for you on Fly.io, in a data centre in the United States (Virginia). One machine and one encrypted-at-rest storage volume, reachable only over HTTPS, with every data route requiring a valid token.
- Nightly backups on the same server volume. Off-site backups are not in place yet; if they are added, this policy will say where and how they are encrypted.
- The operator's Mac, which holds a working copy of the data and the local tools that import it.
- Your iPhone and Apple Watch, which keep the most recent summaries they have read, and any signed snapshot files you open on them.
Data is not pooled across athletes. Every stored record carries the athlete's identifier, and the code refuses to mix them.
The iPhone and Apple Watch app
- The app reads your data from your server, from a paired Mac on the same network (over an encrypted connection pinned to that Mac's certificate), or from signed snapshot files you choose to open. It sends no health data anywhere else.
- It refreshes in the background, at most about every 30 minutes, only while it is signed in to a server or paired with a Mac.
- The Apple Watch app receives a summary from the iPhone.
- On-device settings, such as your choice of metric or imperial units, are stored locally.
- No tracking, no advertising identifier, no third-party SDKs.
TestFlight beta
The app is distributed as a private beta through Apple's TestFlight. When you install a TestFlight build, Apple shares certain information with the operator under Apple's own terms, such as your name and email address as a tester, the build you installed, and crash reports and feedback you choose to send. That information is handled by Apple under Apple's privacy policy and used by the operator only to run the beta.
Language models
Intero does not send your data to language-model or other AI services. If you choose to connect an AI assistant of your own to Intero's local interface, what that assistant does with the data is governed by its provider's policy.
Who data is shared with
- We do not sell personal data and do not share it for advertising.
- Service providers that host or deliver the service, only as needed to run it: Fly.io (server hosting) and Apple (TestFlight distribution).
- Legal requirements: if the law requires it. We would tell you unless we are legally prevented from doing so.
This website
- No cookies, no analytics, no tracking pixels, no forms.
- If you use the theme switch, your choice is saved in your browser's local storage, on your device only.
- Pages load typefaces from Google Fonts, so your browser contacts Google's servers, which receive your IP address. No referrer is sent.
- The site's hosting provider may keep standard connection logs for security and operations. The site's own web server keeps no access log.
Export, correction and deletion
- Export: the full record, including raw source records and the ledger with receipts, can be exported at any time. Ask at support@endurosync.com.
- Correction: the ledger is append-only, so a correction is added as a new entry rather than by editing the past. Raw records from a vendor can be re-imported if the vendor corrects them.
- Deletion: ask at support@endurosync.com. The operator deletes your data from the server volume, its backups and the Mac. Because the ledger is hash-chained, deletion removes your whole record rather than individual entries. We aim to confirm deletion within 30 days.
- Sign out on iPhone: Settings › Server › Sign out deletes the token and enrolment from the Keychain. Deleting the app removes its local data and snapshots.
- Revoke vendor access: remove Intero's token or authorisation in your Oura or WHOOP account at any time.
Depending on where you live, you may have further rights, such as to object to or restrict processing, or to complain to a data-protection authority.
How long data is kept
Your health data and ledger are kept until you ask for deletion, because the point of Intero is a long, continuous record. Security audit records are kept for as long as the operator needs them to investigate abuse. [Operator to set a retention period for audit and request logs.]
Security
Connections use HTTPS. Tokens are random, stored hashed on the server and revocable. Enrolment codes expire and are single-use. The server process runs without administrator rights. No system is perfectly secure; if a breach affects your data, we will tell you without undue delay.
Children
Intero is not intended for anyone under 16, and we do not knowingly process children's data.
Changes and contact
If this policy changes in a way that matters, the new version will be posted here with a new effective date before it applies. Questions or requests: support@endurosync.com.