Privacy Policy
Last updated: July 17, 2026
1. Data Controller & Contact
Jauda ("we", "us", "our") is the data controller for personal data processed through the Jauda mobile application and related services. For privacy inquiries or to exercise your data rights, contact us at:
Email: ops@jauda.app
2. Data We Collect
We collect the following categories of personal data:
- Account data: Email address, display name, and authentication provider (Apple or Google). Obtained when you sign in via Sign in with Apple or Google Sign-In.
- Physiological data: Heart rate (BPM), heart rate variability (RMSSD, DFA-a1), and derived training metrics (TRIMP, CTL, ATL, TSB). Collected from Bluetooth chest straps during workouts.
- Location data: GPS trackpoints (latitude, longitude, speed, elevation) recorded during cycling sessions.
- Body metrics: Height, weight, age, gender, resting heart rate, and lactate threshold heart rate. Provided by you during onboarding or settings.
- Device data: Device model, OS version, and push notification token. Used for crash diagnostics and notification delivery.
- Usage telemetry: Feature usage events (e.g., ride started, tab visited, settings changed). Collected only if you opt in via Settings.
3. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Explicit consent (Art. 9(2)(a)): Physiological data (heart rate, HRV) and GPS location are processed only after you grant explicit consent during onboarding. You may withdraw consent at any time by deleting your account in Settings.
- Contractual necessity (Art. 6(1)(b)): Account data (email, display name) is processed to provide the service you signed up for.
- Legitimate interest (Art. 6(1)(f)): Anonymous crash diagnostics via Sentry, essential for service reliability.
- Consent (Art. 6(1)(a)): Usage telemetry (PostHog) is processed only if you opt in via Settings → Security & Privacy.
4. How We Use Your Data
- Generate real-time heart rate zone feedback, training load charts (CTL/ATL/TSB), and post-ride analytics.
- Calculate HRV-derived fatigue and recovery metrics (RMSSD, DFA-a1, TRIMP).
- Compute GPS-based distance, speed, elevation gain, and route maps for recorded rides.
- Sync workout summaries to Apple Health (HealthKit) when you enable the integration in Settings.
- Deliver push notifications for training reminders and readiness alerts (if enabled).
- Diagnose crashes and service issues (Sentry error tracking).
- Analyze anonymized feature usage to improve the app (PostHog, opt-in only).
5. Third-Party Services
We use the following service providers to operate Jauda. Each processes data according to its own privacy policy and our data processing agreements:
- Firebase Authentication (Google) — User identity and sign-in. Receives: email, display name. Privacy Policy
- Sentry (Functional Software, Inc.) — Crash and error reporting. Receives: device model, OS version, stack traces. No physiological or location data.
- PostHog (PostHog, Inc.) — Product analytics (opt-in only). Receives: anonymized feature usage events and aggregated workout metrics (current heart rate, average HRV RMSSD). No GPS location data. EU-hosted (eu.posthog.com).
- Railway (Railway Corp.) — Server and database hosting. Data at rest in PostgreSQL is encrypted at the column level for physiological metrics.
6. Data Storage & Encryption
- On-device: Workout data and physiological samples are stored in a local SQLite database encrypted with AES-256 via SQLCipher. Encryption keys are stored in the iOS Keychain / Android Keystore.
- Cloud (PostgreSQL on Railway): Session summaries and aggregate metrics are associated with your Firebase account identifier. The
metricscolumn is encrypted at the column level. Raw beat-to-beat (RR interval) data is never uploaded — only aggregate session statistics. - Transport: All communication between the app and our servers uses HTTPS (TLS 1.3).
7. Data Retention
- Account data: Retained until you delete your account.
- Workout and physiological data: Retained until you delete your account or individual sessions via the app.
- Crash reports (Sentry): Retained for 90 days.
- Usage telemetry (PostHog): Retained for 90 days. Only collected if you opt in.
- Server access logs: Retained for 30 days.
- Backups: Data deleted from our active systems is removed from encrypted backups within 30 days as backup rotation cycles complete.
8. Data Breach Notification
In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (GDPR Article 34).
9. Your Rights
Under GDPR (EU/EEA users):
- Right of Access (Art. 15): Request a copy of your personal data via Settings → Backup & GDPR Exports → "Request GDPR Personal Data Dump". Delivered as structured JSON.
- Right to Rectification (Art. 16): Update your body metrics and profile data at any time in Settings.
- Right to Erasure (Art. 17): Permanently delete your account and all associated data via Settings → "Delete Account". This cascadingly removes your cloud records, Firebase Auth identity, and telemetry archives.
- Right to Data Portability (Art. 20): Export your wellness logs as CSV or your full session history as JSON via Settings → Backup & GDPR Exports.
- Right to Object / Restrict (Art. 18, 21): Disable cloud sync and telemetry at any time via Settings → Security & Privacy.
Under CCPA/CPRA (California residents):
- Right to Know: Request disclosure of categories and specific pieces of personal data collected. Use the GDPR export in Settings or contact ops@jauda.app.
- Right to Delete: Delete your account via Settings for full data removal.
- Right to Opt-Out of Sale: We do not sell personal data, period. No opt-out is necessary.
- Non-Discrimination: Exercising your CCPA rights will not affect your access to Jauda.
10. Apple HealthKit
Jauda can optionally sync cycling workout summaries (duration, distance, average heart rate) to Apple Health. This integration is off by default and must be explicitly enabled in Settings → Integrations. HealthKit data is processed entirely on-device via Apple's HealthKit APIs and is governed by Apple's privacy policies. Jauda does not read data from HealthKit — it only writes workouts you choose to share.
11. Children's Privacy
Jauda is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact ops@jauda.app and we will delete it promptly.
12. International Data Transfers
Your data is stored on servers in the European Union (Railway, eu-west region). PostHog telemetry data is processed in the EU (eu.posthog.com). Firebase Authentication and Sentry may process data in the United States under Standard Contractual Clauses (SCCs).
13. Changes to This Policy
We will notify you of material changes to this policy via the app and update the "Last updated" date above. For non-material or administrative changes, continued use constitutes acceptance. For material changes that affect how we process your health, physiological, or location data, we will request your explicit consent before the changes take effect.