← Back to Attuno

Privacy Policy

Last updated: 20 June 2026 · Effective: 20 June 2026

This Privacy Policy explains how Attuno ("Attuno", the "app", "we", "us", "our") collects, uses, and protects your information, and the rights you have over it. It is written to align with the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). Attuno is a local-first wellness app for iPhone: wherever possible, your data is processed and stored on your device and never reaches us.

1. Who is responsible for your data

The data controller is Attuno, operated by its developer Antons Aleksandrovs (sole proprietor), Kupricu iela 1B-43, LV-1021, Riga, Latvia. You can reach us at aleksandrovs.antons@gmail.com for any privacy request. If we are required to designate an EU/UK representative under Article 27 GDPR, their details will be listed here.

2. The short version

3. What we process, and why

The table below lists each category of data, its purpose, and — for users in the EEA/UK — our legal basis under the GDPR.

a. Health & fitness data (special category)

Heart rate, heart-rate variability, sleep, respiratory rate, blood oxygen, steps, active energy, and workouts read from Apple Health with your explicit permission. This is processed and stored only on your device to compute your scores and trends. It is special-category data (GDPR Art. 9) and "sensitive personal information" (CCPA). Legal basis: your explicit consent (Art. 9(2)(a)), which you give in the Health permission prompt and can withdraw at any time in the iOS Health app.

b. Account data

When you first open Attuno the app creates an anonymous identifier for your installation (Firebase Authentication). It holds no name, email or contact detail, and it is not linked to you as a person. We use it for two things: to sync your app preferences to your own device(s), and to count how many installations are active, on which app version, and in which country — the country comes from your device's own region setting, and we do not look up or store your IP address to determine it. If you later sign in, that identifier becomes your account rather than a second one. Deleting the app or your account removes it. Legal basis: legitimate interests (Art. 6(1)(f)) in operating and maintaining the app. No health data is ever attached to it.

If you create an account for the AI tier, we process your email address and a user identifier from Sign in with Apple, Google, or email/password (via Firebase Authentication). Purpose: to create and secure your account. Legal basis: performance of a contract (Art. 6(1)(b)).

c. Settings sync & support

If signed in, your app preferences (e.g. sleep target, dashboard layout) sync across your devices via Cloud Firestore. If you use the in-app support form, we process the name, email, message, app version, and platform you submit. Purpose: to provide the service and respond to you. Legal basis: performance of a contract and our legitimate interest in supporting users (Art. 6(1)(b) and 6(1)(f)).

d. Optional AI insights

If you subscribe to the AI tier, we send a small, aggregated daily summary (such as your scores and averages and how they differ from your own baseline) to Google's Gemini model via Firebase AI Logic to generate a written insight. We do not send raw heart-rate or sleep recordings. Legal basis: your explicit consent for this special-category processing (Art. 9(2)(a)), withdrawable by cancelling or not using the feature.

We also count how many insights each account requests per day. That count is a number and a date — it contains nothing about your health and no part of the summary or the insight text. Purpose: to enforce a daily fair-use limit and to understand how much the feature is used. Legal basis: legitimate interests (Art. 6(1)(f)) in preventing abuse and operating the service.

If you tag a day on the Today screen (for example "alcohol" or "late night"), those labels are stored only on your device. For AI-tier subscribers, the previous day's labels and the resulting averages form part of that same aggregated summary, so the insight can refer to them. Tagging is optional, and Settings → Account can delete every tag you have ever logged.

e. Subscriptions

Purchases are processed by Apple through the App Store and managed via RevenueCat using a pseudonymous identifier linked to your account. We do not receive or store your payment-card details. Legal basis: performance of a contract (Art. 6(1)(b)).

f. Security & integrity

We use Firebase App Check to verify that requests come from a genuine, unmodified app. Legal basis: our legitimate interest in preventing abuse (Art. 6(1)(f)).

4. Apple Health

Access to Apple Health is read-only and can be revoked at any time in the Health app under Sharing → Apps. In line with Apple's requirements, data obtained from HealthKit is never used for advertising or marketing, and is never sold or shared with data brokers.

5. Service providers (processors)

We share data only with providers that process it on our behalf under contract, for the purposes above:

We do not sell your data and do not allow these providers to use it for their own purposes.

6. International transfers

Some providers process data on servers in the United States. Where data is transferred out of the EEA/UK, it is protected by appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the providers' Data Processing Agreements.

7. How long we keep it

On-device data stays until you delete it or uninstall the app (Settings → Clear cache removes locally cached metrics). Account and synced settings are kept until you delete your account; support messages are kept only as long as needed to handle your request. Aggregated AI summaries are not retained as identifiable records beyond generating your insight.

8. Your rights

If you are in the EEA or UK (GDPR): you have the right to access, rectify, erase, restrict, and port your data, to object to processing, and to withdraw consent at any time (without affecting prior processing). You may also lodge a complaint with your local supervisory authority.

If you are in California (CCPA/CPRA): you have the right to know, access, delete, and correct your personal information; to opt out of its sale or sharing; and to limit the use of sensitive personal information. We do not sell or share personal information and do not use sensitive information beyond providing the app, so there is nothing to opt out of — but you may still exercise the other rights. We will not discriminate against you for exercising any right.

To exercise any right, email aleksandrovs.antons@gmail.com. Because most data lives on your device, you can also action much of this yourself (revoke Health access, clear the cache, delete the app, or use Export data). We respond within the timeframes required by law.

9. Children

Attuno is not directed to children. We do not knowingly collect data from anyone under 16 (or the minimum age of digital consent in your country, and under 13 in the United States). If you believe a child has provided us data, contact us and we will delete it.

10. Automated decisions

We do not make decisions producing legal or similarly significant effects about you by solely automated means. AI insights are informational wellness suggestions, not decisions, diagnoses, or treatment.

11. Security

We use on-device storage, encrypted transport (HTTPS/TLS), authenticated access controls (owner-only database rules), and App Check. No method of transmission or storage is completely secure, but we work to protect your information.

12. Changes

We may update this policy. Material changes will be reflected by the "Last updated" date above and, where required, brought to your attention in the app. Significant new processing (such as expanded AI features) will be described here before it takes effect.

13. Contact

Privacy questions or requests: aleksandrovs.antons@gmail.com.