Privacy Policy
Last updated: 25 August 2026
CardialOS is a personal cardiac-monitoring app. This policy explains what data CardialOS uses and how it is handled. The short version: your health data stays on your device. CardialOS has an account so it can keep you signed in — signing in does not upload your health data, and we never receive, store, or transmit it. We do collect anonymized product-usage and crash diagnostics to keep the app working well — never your health values (see Analytics & diagnostics below).
Data CardialOS reads
With your permission, CardialOS reads health and fitness data from Apple Health (on iOS) or Health Connect (on Android), including:
- Heart rate, resting heart rate, and heart-rate variability (HRV)
- VO₂max / cardio-fitness, respiratory rate, and blood-oxygen (SpO₂)
- Sleep, wrist temperature, steps, active energy, and distance
- Workouts and their associated samples (e.g. heart rate, pace, power)
CardialOS reads this data read-only. It does not modify your health records. (A hidden, optional testing tool can write sample data on a device with no wearable; it is never used in normal operation and writes only synthetic, clearly-removable data.)
How the data is used
All processing happens on your device. CardialOS turns the data above into recovery, training-load, and fitness readings using on-device calculations. Your physiological settings (such as date of birth, sex, weight, and threshold heart rate) and your app preferences are stored locally on your device only.
Your account
CardialOS requires an account, created with Sign in with Apple or Sign in with Google. Either way the provider gives us two things: an identifier that stands for you within our apps, and an email address — your real one or, with Apple's Hide My Email, a private relay address Apple manages. We never see your Apple or Google password. Accounts made with different providers are joined only when their verified email addresses match; otherwise they are separate accounts.
On our server we store that identifier, that email address, and session records — which app you signed in to, an identifier for the device, and timestamps — so you stay signed in and can revoke your sessions. That is the complete list; your health data is not on it and signing in does not sync or upload anything the app has read from Apple Health.
What we do not do
- We do not sell, rent, or share your health data with anyone.
- We do not use your health data for advertising or marketing.
- We do not transmit your health data off your device or to any server.
- We do not link your account to your health data or to the diagnostics below.
Analytics & diagnostics
To understand how CardialOS is used and to fix problems, CardialOS sends anonymized product-usage and crash diagnostics to our analytics and crash-reporting providers, PostHog, Google Firebase Analytics, and Google Firebase Crashlytics. This includes:
- Which screens you open and which controls you tap (for example, "opened Vitals", "changed a method") — behaviour only, never the underlying health values.
- Crash and error reports (such as a stack trace, error type, and device model and OS version).
- A randomly-generated, anonymous device identifier so these events can be grouped — it is not linked to your name, your email, or your CardialOS account.
We do not send your heart rate, HRV, sleep, workouts, or any other health values to these providers, and we do not use this data for advertising. We use it only to improve the app.
Location & weather
CardialOS can use your device location to show how local weather is affecting your body — flagging when heat is inflating your heart rate and adjusting your daily hydration estimate. This is optional: if you decline the location permission, CardialOS simply omits the weather-based insights and everything else works as normal.
When you allow it, CardialOS sends your approximate coordinates to Open-Meteo (open-meteo.com), a weather service, to look up the current temperature and humidity for your area. The request carries no name, account, or identifier. We do not store your location, link it to any identity, sell or share it, or use it for advertising or tracking. You can change or revoke the location permission at any time in iOS Settings → Privacy & Security → Location Services → CardialOS (or Android Settings → Location).
Your control
You can review or revoke CardialOS's access to your health data at any time:
- iOS: Settings → Health → Data Access & Devices → CardialOS.
- Android: Health Connect → App permissions → CardialOS.
Deleting the app removes its local data from your device; your underlying Apple Health / Health Connect records are unaffected and remain under your control. Your account is separate: to delete it, email resources@thetinyapp.com and we will remove the account, its email and every session from our server within 30 days — existing sign-ins stop working once that is done.
Data retention & deletion
Your health data is processed on your device and is never stored on our servers, so there is no health data for us to retain. Your account data is kept until you ask us by email to delete the account. The anonymized product-usage and crash diagnostics described above are retained by our providers (PostHog and Google Firebase) for up to 12 months, after which they are deleted. To request deletion of any data associated with your device, email resources@thetinyapp.com and we will action it within 30 days.
Children
CardialOS is not directed to children under 13 and we do not knowingly collect data from them.
Changes to this policy
We may update this policy as the app evolves. Material changes will be posted on this page with a new "Last updated" date.
Contact
Questions about this policy? Email resources@thetinyapp.com.