CardialOSby thetinyapp

Privacy Policy

Last updated: 18 June 2026

CardialOS is a personal cardiac-monitoring app. This policy explains what data CardialOS uses and how it is handled. The short version: your health data stays on your device. CardialOS has no account and no sign-in, and we never receive, store, or transmit your health data. We do collect anonymized product-usage and crash diagnostics to keep the app working well — never your health values (see Analytics & diagnostics below).

Data CardialOS reads

With your permission, CardialOS reads health and fitness data from Apple Health (on iOS) or Health Connect (on Android), including:

CardialOS reads this data read-only. It does not modify your health records. (A hidden, optional testing tool can write sample data on a device with no wearable; it is never used in normal operation and writes only synthetic, clearly-removable data.)

How the data is used

All processing happens on your device. CardialOS turns the data above into recovery, training-load, and fitness readings using on-device calculations. Your physiological settings (such as date of birth, sex, weight, and threshold heart rate) and your app preferences are stored locally on your device only.

What we do not do

Analytics & diagnostics

To understand how CardialOS is used and to fix problems, CardialOS sends anonymized product-usage and crash diagnostics to our analytics and crash-reporting providers, PostHog, Google Firebase Analytics, and Google Firebase Crashlytics. This includes:

We do not send your heart rate, HRV, sleep, workouts, or any other health values to these providers, and we do not use this data for advertising. We use it only to improve the app.

Location & weather

CardialOS can use your device location to show how local weather is affecting your body — flagging when heat is inflating your heart rate and adjusting your daily hydration estimate. This is optional: if you decline the location permission, CardialOS simply omits the weather-based insights and everything else works as normal.

When you allow it, CardialOS sends your approximate coordinates to Open-Meteo (open-meteo.com), a weather service, to look up the current temperature and humidity for your area. The request carries no name, account, or identifier (CardialOS has none). We do not store your location, link it to any identity, sell or share it, or use it for advertising or tracking. You can change or revoke the location permission at any time in iOS Settings → Privacy & Security → Location Services → CardialOS (or Android Settings → Location).

Your control

You can review or revoke CardialOS's access to your health data at any time:

Because CardialOS stores nothing on a server, deleting the app removes its local data from your device. Your underlying Apple Health / Health Connect records are unaffected and remain under your control.

Data retention & deletion

Your health data is processed on your device and is never stored on our servers, so there is no health data for us to retain. The anonymized product-usage and crash diagnostics described above are retained by our providers (PostHog and Google Firebase) for up to 12 months, after which they are deleted. To request deletion of any data associated with your device, email resources@thetinyapp.com and we will action it within 30 days.

Children

CardialOS is not directed to children under 13 and we do not knowingly collect data from them.

Changes to this policy

We may update this policy as the app evolves. Material changes will be posted on this page with a new "Last updated" date.

Contact

Questions about this policy? Email resources@thetinyapp.com.