Privacy Policy
Effective Date: [Launch date — to be confirmed] · Version: 1.0
1. Overview
Kreev Informatics Inc. ("Kreev", "we", "our", "us") makes the Kreev iOS application ("App"). This Privacy Policy explains what information the App handles, what reaches us, and your rights.
Kreev is a personal health informatics tool. It is not a medical device and does not provide medical advice, diagnosis, or treatment.
Availability. The App is offered to residents of the United States and of Canada, excluding the Province of Quebec. This Policy is provided in English only.
1.1 The short version
Kreev runs on your iPhone.
- Your health data is read from Apple Health, analysed on your device, and stored on your device. It is never transmitted to Kreev, and we have no means of seeing it.
- There is no Kreev account. No sign-in, no username, no password, no email address, and no user record on any server of ours.
- We operate no database of user health information. There is nothing for us to lose in a breach, hand over, or sell.
- Your wellness narratives are produced by a rule-based generator that runs on your phone. Kreev sends your health data to no one — not to an artificial-intelligence service, not to an analytics provider, not to any third party.
- We do not sell personal data. The App shows no advertising and contains no advertising or tracking SDKs.
- You can erase everything the App holds, permanently, from inside the App, at any time — and deleting the App removes it too.
Two services receive limited, non-health information from the App, and both are described in full below: RevenueCat, which manages your subscription (Section 2.4), and Aptabase, which counts anonymous feature usage (Section 2.5). The App also fetches one public notice file from our own website (Section 2.6). Our website, and the waitlist you can join there, are covered in Section 2.7.
1.2 What this means in practice, including the trade-off
Because your history lives on your device rather than on our servers, we cannot recover it for you. If you lose your iPhone, erase it, or delete the App without a backup or an export, your Kreev history is gone permanently. We have no copy. Section 6 explains how to protect against that, and Section 4 of our Terms of Service states the same point in contractual terms.
2. Information the App Handles
2.1 Health data (from Apple Health), read and kept on your device
With your explicit permission, Kreev reads the following from Apple Health:
| Category | Data types |
|---|---|
| Cardiovascular | Resting heart rate; heart-rate variability (SDNN); heart-rate samples, including the daily minimum, average and maximum, and heart-rate series recorded during workouts |
| Respiratory | Respiratory rate |
| Sleep | Sleep duration and sleep stages (Awake, REM, Core/Light, Deep), including unstaged sleep, and the times you fall asleep and wake |
| Fitness and activity | VO2 Max; step count; active energy burned; exercise time; workouts; daily activity summaries; physical effort (on iOS 17 and later) |
| Characteristics | Date of birth and biological sex, as recorded in the Health app |
Why date of birth and biological sex are read. Both are used only to place your VO2 Max against published ACSM population norms for your age group and sex, and to set the age-based reference heart rate used in training-load estimation. If you have not recorded them in the Health app, or do not grant access to them, you may enter them in the App instead, or leave them out — the App works without them and simply omits the age- and sex-adjusted ranking.
All of this is processed and stored locally. These readings are used to compute your Recovery Score, Strain score, and related analytics on your device. Kreev does not transmit them — to itself or to anyone else.
Kreev supports Apple Health only. Data must be synced to Apple Health by an Apple Watch or another compatible source. Support for other platforms may be added in future releases and would be disclosed here at that time.
You may revoke access at any time in iPhone Settings → Privacy & Security → Health → Kreev.
2.2 Data you enter yourself, kept on your device
You may optionally provide:
- Age and biological sex — if not available from Apple Health, for the purpose described in Section 2.1
- Sport / training profile — your primary sport or training style. Entirely optional, offered in Settings, never requested during onboarding
- Subjective wellness check-in — an optional daily 1–5 rating of how you feel, used to show how your felt state compares with your biometric signals
All of it is stored only on your device and treated with the same protections as health data. None of it reaches us.
2.3 What the App records locally about itself
The App stores a small number of settings and flags on your device: your notification preferences, whether you have completed onboarding, your confirmation that you are 18 or older and eligible to use the App, the version of the Terms you accepted and when, your device's timezone (used to compute daily metrics and deliver notifications in local time), and internal bookkeeping such as when data was last read from Apple Health.
These are local records, not submissions. They stay on your device. Because there is no account, they are re-created if you reinstall the App — which also means a reinstall will ask you to confirm eligibility and accept the Terms again.
2.4 Subscription information (RevenueCat)
Subscription payments are processed by Apple through in-app purchase (StoreKit). Kreev never receives, stores, or has access to your payment card number or payment credentials.
To determine whether your device is entitled to Sentinel features, the App uses RevenueCat, a subscription-management provider. RevenueCat receives:
- an anonymous identifier generated on your device — not your name, email address, Apple ID, or any Kreev account (there is none)
- the transaction receipt and subscription status issued by Apple
- basic technical information about the request, such as your device's App Store country and the app version
RevenueCat receives no health data of any kind. Its privacy policy is at revenuecat.com/privacy. RevenueCat processes this information in the United States.
2.5 Anonymous product analytics (Aptabase)
To understand which parts of the App are used, Kreev sends a small number of anonymous, non-identifying events — for example, that the Today tab was opened, or that a daily narrative was expanded — to Aptabase, a privacy-focused analytics provider.
What these events contain: an event name, a timestamp, and basic technical context (app version, operating-system version, device model, and country).
What they never contain: any health value, score, narrative text, or metric of any kind; any name, email address, or account identifier; any advertising identifier; and any location data. Aptabase's design uses no cookies, no advertising identifiers, and no device fingerprinting, and its identifiers derive from a salt that rotates daily, so events cannot be assembled into a profile of you over time or across apps.
Aptabase's privacy policy is at aptabase.com/legal/privacy. Aptabase processes this information in the United States.
We use this only to decide what to build. It is never combined with health data — it cannot be, because health data never leaves your device.
2.6 The in-app announcement check (kreev.app)
Because Kreev has no accounts and no push infrastructure, the only way we can tell you something — a new version, a change to these documents — is a notice inside the App. When you open the App with a network connection, it downloads one small public file from our website, www.kreev.app, and shows any message it contains. The request carries no identifier, no health data, and nothing about you or your device beyond what any web request carries (your IP address and the App's user-agent string), and it is the same for every user. Our website is hosted by Vercel (Section 2.7), whose servers keep standard, short-lived request logs. Kreev does not use these logs to identify or track anyone. The App works normally if the request fails.
2.7 Our website
This Policy also covers www.kreev.app. The website sets no cookies, uses no analytics or advertising services, and does not track you across sites. It is hosted by Vercel, which processes standard web-server request logs (IP address, browser user-agent, pages requested) for security and operation, in the United States.
If you choose to join a waitlist or mailing list on the website, you provide your name and email address, and optionally your Apple Watch model and a short note. We use this only to send you the messages you signed up for — launch and beta announcements — and never to build a profile of you. It is stored by Brevo, our email service provider, in the European Union. You can unsubscribe from any message we send, or ask us to delete your details, by using the link in the email or writing to privacy@kreev.app. Website sign-ups are never linked to anything in the App: the App does not know your email address, and the website does not know your health data.
2.8 What we do not collect
- No account information. There is no sign-in, so we hold no Apple ID, email address, name, or authentication identity.
- No health data. None reaches our systems.
- No location data, precise or approximate, and we do not infer your location from your health data.
- No advertising identifiers, no advertising SDKs, and no advertising.
- No access to your contacts, photos, microphone, or camera.
- No cross-app or cross-site tracking.
- No push-notification tokens. Kreev's notifications, including Guardian Alerts, are generated on your device and delivered by iOS locally. We operate no push infrastructure.
3. How Information Is Used
Everything in the first table happens entirely on your device. We do not see the inputs or the outputs.
| Purpose | Data used |
|---|---|
| Compute your daily Recovery Score | HRV, resting heart rate, sleep, steps, respiratory rate |
| Compute your daily Strain score | Heart-rate data, active energy, exercise time, workouts |
| Estimate VO2 Max and its ACSM ranking | Workout heart-rate data, resting heart rate, date of birth, biological sex |
| Compute the Healthspan Index | VO2 Max, HRV, resting heart rate, sleep duration, sleep stages, sleep timing, date of birth, biological sex |
| Generate your daily, weekly and monthly narratives | Your computed metrics and scores |
| Show how your felt state tracks your biometrics | Subjective wellness check-in |
| Show Guardian Alerts | Recovery Score and HRV deviation from your baseline |
| Deliver notifications at the right local time | Device timezone |
| Contextualize analytics (optional) | Sport / training profile, if you provide one |
| Confirm eligibility and Terms acceptance | Your confirmation, stored as a local flag |
Only these purposes involve anything leaving your device:
| Purpose | Data used | Recipient |
|---|---|---|
| Determine your subscription entitlement | Anonymous identifier, Apple transaction receipt, subscription status | RevenueCat (Section 2.4) |
| Understand which features are used | Anonymous, non-identifying feature events | Aptabase (Section 2.5) |
| Show you in-app notices | A request for one public file, carrying no identifier | Our website, hosted by Vercel (Section 2.6) |
We do not use your data to train artificial-intelligence models, and we do not permit anyone else to.
We do not use your health data to improve our own algorithms — not in identified form, and not in de-identified or aggregated form. No health data reaches us in any form. Improvements come from published research, our own testing, and what you choose to tell us directly.
4. Wellness Narratives Are Generated on Your Device
Kreev's daily, weekly, and monthly narratives are produced by a rule-based generator that runs entirely on your iPhone. It selects and orders wording from a fixed library of phrases according to your own metrics.
No artificial-intelligence or large-language-model service is involved, and no narrative data is transmitted anywhere. Because the generator is deterministic and local, the same inputs always produce the same narrative, and narratives remain available with your device offline or in airplane mode.
Narratives are observational statements about your own measurements. They are not medical advice; Section 8 of our Terms of Service describes their limits.
5. Where Your Data Lives, and How It Is Protected
Your Kreev data — every metric, score, narrative, and check-in — is stored in a database file inside the App's private storage area on your iPhone.
Protections that apply:
- iOS app sandboxing. Other apps on your iPhone cannot read Kreev's storage.
- Device encryption. The file is protected by iOS Data Protection. When your iPhone has a passcode set, its storage is encrypted, and the data is protected by that encryption whenever the device is locked.
- Nothing in transit. Health data is never transmitted, so there is no network path to intercept.
Your device's security is the security of your data. Setting a passcode and keeping iOS current are the meaningful protections, and we recommend both. Anyone with access to your unlocked iPhone can open the App and see your data.
5.1 iCloud Backup
If you have iCloud Backup enabled in iOS, your device backup includes Kreev's data file along with your other app data. That backup is stored by Apple, encrypted, and governed by Apple's Privacy Policy and your own iCloud settings — including Advanced Data Protection, which, when enabled, end-to-end encrypts iCloud backups so that Apple cannot read them.
Kreev has no access to your iCloud backup, cannot read it, and cannot restore it for you; it is restored by iOS when you set up a new iPhone. If you disable iCloud Backup, no copy of your Kreev data exists anywhere but on your device.
5.2 Exports you create
If you use Settings → Export My Data, the App writes a file containing your data and hands it to iOS so you can save or share it. Where that file then goes is your choice — the App does not upload it, and once you have shared it (to iCloud Drive, email, another app, or anywhere else), it is governed by that destination's terms, not by this Policy.
5.3 Breach notification
We hold no user health data, so a breach of Kreev systems cannot expose it. In the event of a security incident affecting whatever personal information we do hold — for example, correspondence you have sent us, or information held by the providers in Section 7 — we will notify affected users and the appropriate regulators without unreasonable delay and within the timelines required by applicable law, including the U.S. FTC Health Breach Notification Rule, applicable U.S. state breach-notification laws, and the breach-of-safeguards provisions of Canadian privacy law (PIPEDA and Alberta PIPA).
6. Losing Your Data, and How to Avoid It
Because Kreev holds no copy of your history, these are the only ways it survives the loss of a device:
- iCloud Backup (Section 5.1) — restores automatically onto a new iPhone set up from that backup. It restores at device migration; it does not sync continuously, and it will not keep two devices in step.
- Export My Data (Section 5.2) — a file you keep yourself, and can bring back into the App on any device with Settings → Import My Data. An import never deletes anything already on the device: days the device has already rebuilt from Apple Health keep their measurements, and the file fills in what is missing.
If neither is in place and your device is lost, erased, or the App deleted, the data is unrecoverable, including by us. Apple Health remains a separate source: if your underlying measurements are still in the Health app, a fresh install of Kreev can rebuild recent history from them, though anything Kreev computed or you entered yourself — narratives, check-ins, and older history no longer in Apple Health — will not come back.
7. Who Receives Anything
We do not sell personal data. Only these providers receive anything at all, and none receives health data:
| Provider | What they receive | Purpose | Location |
|---|---|---|---|
| RevenueCat | Anonymous identifier, Apple transaction receipt, subscription status, app and device technical context — no health data | Subscription entitlement management | United States |
| Aptabase | Anonymous, non-identifying feature events — no health data, no identifiers | Product analytics | United States |
| Vercel | Standard web-server request logs (IP address, user-agent, pages requested) for www.kreev.app, including the App's announcement check (Section 2.6) — no health data, no identifiers | Website hosting | United States |
| Brevo | Name, email address, and any optional details you give when you join a waitlist on our website (Section 2.7) — no health data; never linked to the App | Email delivery for messages you sign up for | European Union |
Apple additionally processes your purchase as the seller of record and, if you enable it, stores your device backup, in each case under Apple's own terms.
Each provider is contractually required to protect the information it receives and to use it only to provide services to Kreev. No health data is shared with anyone — not with advertisers, data brokers, insurers, employers, analytics companies, artificial-intelligence providers, or any other third party.
7.1 Law enforcement requests
We will not voluntarily disclose personal data to any government entity, and we will provide data only in response to a valid, legally binding request. Where permitted by law, we will notify you first.
In practice there is very little to compel. We hold no health data, no account, no name, and no email address unless you have written to us. A demand for a Kreev user's health information cannot be satisfied by us, because that information exists only on that person's own device.
8. Retention and Deletion
On your device. Your data stays on your iPhone until you delete it. There is no expiry and no server-side retention schedule, because there is no server.
You can erase it in three ways:
- Settings → Reset This Device — permanently erases all Kreev data on the device: metrics, scores, narratives, check-ins, profile, and settings. This is irreversible.
- Delete the App — iOS removes the App's storage, including the database, with it. A copy may remain in an iCloud backup taken before deletion until that backup is replaced or removed in your iCloud settings.
- Delete your exports — any file you created under Section 5.2 is yours to delete wherever you put it.
With our providers. RevenueCat retains subscription records associated with your anonymous identifier for as long as needed to manage entitlements and to meet Apple's and its own record-keeping obligations; you may ask us to request their deletion at privacy@kreev.app. Aptabase events are anonymous and aggregate, cannot be traced back to you, and therefore cannot be individually deleted. Vercel's request logs are retained only for the short period its platform keeps them. Waitlist details held by Brevo are kept until you unsubscribe or ask us to delete them, or until the list they belong to is closed. Apple retains purchase records under its own terms.
Correspondence. If you email us, we keep the correspondence for as long as needed to handle your request and for a reasonable period afterwards.
9. Your Rights
Every user has the following rights, wherever you live. Because Kreev holds almost nothing about you, most of them you exercise yourself, immediately, without contacting us.
- Access. Your data is on your device and visible in the App. Settings → Export My Data produces a copy in a commonly used, machine-readable format. For the limited information held by our providers (Section 7), contact privacy@kreev.app.
- Correction. Profile data — age, biological sex, sport profile — is edited in the App. Health measurements are corrected in the Apple Health app, which is their source.
- Deletion. Erase everything at any time: Settings → Reset This Device, or delete the App (Section 8).
- Withdraw consent. Revoke health access in iPhone Settings → Privacy & Security → Health → Kreev at any time. You may also disable notifications in iOS Settings.
- Portability. Settings → Export My Data gives you your data directly.
- Non-discrimination. Exercising any right never results in a lower quality of service, a different price, or any other penalty.
- Appeal. If we decline a request, we will explain why, and you may appeal by replying to our decision. If your appeal is denied, you may contact the privacy regulator in your jurisdiction (Sections 10–11).
For requests that do require us — those concerning provider-held information or correspondence — we will respond within the timeline required by the law of your jurisdiction, and in any case within 45 days for US residents and 30 days for Canadian residents. Where a request is complex, we may extend once by a further 45 days (US) or 30 days (Canada) where the law permits; we will tell you before we extend and explain why.
10. United States Privacy Rights
10.1 All US residents
We extend the rights in Section 9 to all US residents, regardless of state, and we do not discriminate against anyone for exercising them. These are our own operational commitments, offered as a matter of policy; they are not an assertion that one state's statute applies in another. Where a state law grants additional statutory rights, those appear below.
Kreev does not sell personal information and does not share personal information for cross-context behavioral advertising.
10.2 California residents (CCPA/CPRA)
California residents have the right to know the categories of personal information collected (Section 2), the purposes (Section 3), and the categories of third parties with whom it is shared (Section 7). We do not sell or share personal information as those terms are defined by the CCPA. We do not use or disclose sensitive personal information for purposes other than providing the service you requested.
Automated decision-making technology (ADMT). Kreev computes your Recovery Score, Strain score, and other analytics automatically. This processing happens on your own device, and its outputs are shown only to you. You have the right to:
- Opt out of automated processing — stop it at any time yourself, by revoking health access in iOS Settings or by deleting the App. Doing so disables the scores and narratives, which cannot be produced without it.
- Meaningful information about the logic — see Section 13.
- Access the outputs — they are on your device and in your export.
10.3 Washington residents (My Health My Data Act)
If you are a Washington resident, additional protections apply to your consumer health data. See our standalone Consumer Health Data Privacy Policy for your full rights, including your right to appeal to the Washington Attorney General.
10.4 Nevada residents (SB 370)
Nevada residents have statutory rights regarding consumer health data under a separate law, set out in the same Consumer Health Data Privacy Policy. Kreev does not sell consumer health data.
11. Canadian Privacy Rights
Kreev Informatics Inc. is an Alberta company. Our handling of personal information in Canada is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Alberta, the Personal Information Protection Act (Alberta PIPA).
- Accountability. Kreev has designated a Privacy Officer responsible for compliance with Canadian privacy law, reachable at privacy@kreev.app.
- Consent. Health data is read only with your express consent — your Apple Health permission grant — and is processed only on your own device. You may withdraw that consent at any time (Section 9).
- Access and correction. As described in Section 9.
- Cross-border processing. Your health information does not leave your device and is not transferred outside Canada by us. The limited non-health information described in Sections 2.4 and 2.5 is processed in the United States by RevenueCat and Aptabase, where it may be subject to access by US authorities under US law.
- Complaints. If you are unsatisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner of Alberta.
Quebec. The App is not offered in Quebec at this time.
12. European Residents (GDPR)
Kreev is offered in the United States and Canada. If you nonetheless use the App from the European Economic Area or the United Kingdom, our legal basis for processing health data is your explicit consent (Article 9(2)(a) GDPR), given when you grant Apple Health permissions — and that processing occurs solely on your own device. You have the rights of access, rectification, erasure, restriction, objection, and portability; Section 9 explains how to exercise each directly. For anything involving us, contact privacy@kreev.app.
13. Algorithm Transparency
Every process below runs on your device. None of it uses artificial intelligence, and none of it transmits anything.
13.1 Recovery Score
Your daily Recovery Score (0–100) compares each biometric metric against your own rolling baseline using Z-score normalization — how today compares to your recent history, not to a population average. It does not use your age, sex, ethnicity, or any demographic attribute.
When a metric is missing (a night the watch was not worn, for example), the App substitutes your own baseline average, producing a neutral contribution. Your score is never penalized for missing data.
13.2 Strain score
Your daily Strain score estimates cardiovascular training load from your heart-rate data (a TRIMP-based method), active energy, and exercise time, normalized against your personal baseline. Elevated strain on one day informs the recovery expectation applied to the next.
13.3 Wellness narratives
Narratives are produced by a deterministic rule-based generator on your device, which selects wording from a fixed library according to your metrics. No language model is involved and no text leaves your phone. Narratives use analytical, observational language and do not provide medical advice or diagnoses. See Section 4.
13.4 VO2 Max and its ranking
Kreev estimates VO2 Max on your device from the ratio of your maximum to your resting heart rate (the Heart Rate Ratio method, Uth et al. 2004), using peak heart rates observed in your own workouts where those are near-maximal enough to be plausible, and an age- and sex-based reference otherwise. The App tells you which of the two your current estimate rests on, because an estimate built from your own measured peak is more informative than one built from a population formula.
If your date of birth and biological sex are available, the App also shows where your reading falls against published ACSM reference tables. This ranking is a Sentinel-tier feature; your VO2 Max value is shown on all tiers.
13.5 Subjective check-in
If you submit daily check-ins, the App compares them with your biometric signals to show you how your felt state tracks your recovery. Check-ins are not an input to your Recovery Score. They are used only on your device, only for your own display, and are never compared against other users.
13.6 Healthspan Index
The Healthspan Index is a composite score from 0 to 100, available on the Sentinel tier, combining five components scored 0–20 each:
| Component | Computed from |
|---|---|
| Aerobic capacity | Your VO2 Max positioned against ACSM population norms for your age group and biological sex |
| Heart-rate variability | Your 30-day HRV average and recent 7-day trend |
| Resting heart rate | Your 30-day resting heart-rate average and recent 7-day trend, scored inversely |
| Sleep | Duration adequacy and restorative staging (deep + REM) |
| Sleep regularity | Consistency of the time you fall asleep, across 30 days |
Each component is a whole number, and when all five are available your score is exactly their sum. Each requires at least 5 days of data; where fewer than five are available, the ready components are scaled to the 0–100 range and the App shows how many contributed (a scaled score will not equal the sum shown).
Two of the five components are not self-referenced. Aerobic capacity compares you against population norms for your age and sex, and sleep regularity is scored against fixed reference bands rather than your own history. The other three are computed from your personal baseline.
The Healthspan Index is a summary of fitness measures. It is not a medical assessment, does not diagnose anything, and does not predict health outcomes, disease risk, or life expectancy. Full methodology is in Section 22.5 of our Terms of Service.
13.7 Guardian Alerts
Guardian Alerts are evaluated on your device when it analyses new health data. When your Recovery Score falls below a defined threshold at the same time as a significant drop in HRV relative to your personal baseline, iOS shows you a local notification. No server is involved and no notification data leaves your device. Thresholds are set by Kreev and are not user-configurable; you may turn notifications off entirely in iOS Settings.
14. Children's Privacy
Kreev is intended for adults. You must be at least 18 years of age to use Kreev. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, contact privacy@kreev.app and we will delete it.
15. Cookies and Tracking Technologies
The Kreev iOS app uses no browser cookies, no advertising identifiers, and no tracking technologies, and does not track you across other companies' apps or websites. Our website sets no cookies and uses no analytics or advertising services (Section 2.7).
16. Changes to This Policy
We will notify you of material changes via an in-app notification before they take effect. Where a change involves a new purpose for collecting or using personal information, we will seek your consent as required by applicable law.
17. Contact
Privacy Officer — Kreev Informatics Inc.
- Email: privacy@kreev.app
- Website: www.kreev.app