Privacy Policy
Last updated: 18 June 2026
CardialOS is a personal cardiac-monitoring app. This policy explains what data CardialOS uses and how it is handled. The short version: your health data stays on your device. CardialOS has no account and no sign-in, and we never receive, store, or transmit your health data. We do collect anonymized product-usage and crash diagnostics to keep the app working well — never your health values (see Analytics & diagnostics below).
Data CardialOS reads
With your permission, CardialOS reads health and fitness data from Apple Health (on iOS) or Health Connect (on Android), including:
- Heart rate, resting heart rate, and heart-rate variability (HRV)
- VO₂max / cardio-fitness, respiratory rate, and blood-oxygen (SpO₂)
- Sleep, wrist temperature, steps, active energy, and distance
- Workouts and their associated samples (e.g. heart rate, pace, power)
CardialOS reads this data read-only. It does not modify your health records. (A hidden, optional testing tool can write sample data on a device with no wearable; it is never used in normal operation and writes only synthetic, clearly-removable data.)
How the data is used
All processing happens on your device. CardialOS turns the data above into recovery, training-load, and fitness readings using on-device calculations. Your physiological settings (such as date of birth, sex, weight, and threshold heart rate) and your app preferences are stored locally on your device only.
What we do not do
- We do not sell, rent, or share your health data with anyone.
- We do not use your health data for advertising or marketing.
- We do not transmit your health data off your device or to any server.
- We do not require an account, name, or email to use CardialOS.
Analytics & diagnostics
To understand how CardialOS is used and to fix problems, CardialOS sends anonymized product-usage and crash diagnostics to our analytics and crash-reporting providers, PostHog, Google Firebase Analytics, and Google Firebase Crashlytics. This includes:
- Which screens you open and which controls you tap (for example, "opened Vitals", "changed a method") — behaviour only, never the underlying health values.
- Crash and error reports (such as a stack trace, error type, and device model and OS version).
- A randomly-generated, anonymous device identifier so these events can be grouped — it is not linked to your name, email, or any account (CardialOS has none).
We do not send your heart rate, HRV, sleep, workouts, or any other health values to these providers, and we do not use this data for advertising. We use it only to improve the app.
Location & weather
CardialOS can use your device location to show how local weather is affecting your body — flagging when heat is inflating your heart rate and adjusting your daily hydration estimate. This is optional: if you decline the location permission, CardialOS simply omits the weather-based insights and everything else works as normal.
When you allow it, CardialOS sends your approximate coordinates to Open-Meteo (open-meteo.com), a weather service, to look up the current temperature and humidity for your area. The request carries no name, account, or identifier (CardialOS has none). We do not store your location, link it to any identity, sell or share it, or use it for advertising or tracking. You can change or revoke the location permission at any time in iOS Settings → Privacy & Security → Location Services → CardialOS (or Android Settings → Location).
Your control
You can review or revoke CardialOS's access to your health data at any time:
- iOS: Settings → Health → Data Access & Devices → CardialOS.
- Android: Health Connect → App permissions → CardialOS.
Because CardialOS stores nothing on a server, deleting the app removes its local data from your device. Your underlying Apple Health / Health Connect records are unaffected and remain under your control.
Data retention & deletion
Your health data is processed on your device and is never stored on our servers, so there is no health data for us to retain. The anonymized product-usage and crash diagnostics described above are retained by our providers (PostHog and Google Firebase) for up to 12 months, after which they are deleted. To request deletion of any data associated with your device, email resources@thetinyapp.com and we will action it within 30 days.
Children
CardialOS is not directed to children under 13 and we do not knowingly collect data from them.
Changes to this policy
We may update this policy as the app evolves. Material changes will be posted on this page with a new "Last updated" date.
Contact
Questions about this policy? Email resources@thetinyapp.com.