Privacy Policy

Last updated: August 24, 2026


Tuwa ("the app") is developed by Hanwen Ma. This policy explains what data the app collects, how it is used, and your rights.

What Data We Collect

Data you provide

  • Account information: Email address and display name (used for authentication)
  • Workout logs: Exercises, sets, reps, weights, RPE, session duration, and notes you enter
  • Wellness check-ins: Self-reported sleep quality, soreness, energy, and stress ratings
  • Workout descriptions: The sentence you speak, type, or dictate when you log a session in words (see Workout Text Parsing below)

Data from HealthKit (read-only)

  • Heart rate variability (HRV)
  • Resting heart rate
  • Sleep duration
  • Body temperature
  • VO2 Max
  • Workout heart rate

Tuwa never writes data to HealthKit. HealthKit access is optional and requires your explicit permission.

Data we compute

Recovery scores, ACWR (Acute:Chronic Workload Ratio), training stress, and personal records are calculated on your device from the data above.

How Data Is Stored

  • On your device: All data is stored locally using SwiftData. The app works fully offline.
  • In the cloud: Composite scores (recovery score, workload snapshots, wellness ratings, workout session headers, and personal records) sync to Supabase (hosted on AWS) for multi-device access.
  • Raw HealthKit data is never uploaded. Only computed scores derived from HealthKit data are synced.

Workout Text Parsing

When you log a session by describing it — spoken in the app, typed, or dictated with the keyboard microphone — speech is converted to text on your device, and that text is sent to our parsing service so it can be turned into a draft of sets, reps, and weights for you to review.

The text is processed by a third-party language model provider (DeepSeek) on our behalf. Requests require a signed-in account and are limited by a daily quota per user.

  • What is sent: Only the workout description you submitted, and the units you train in.
  • What is never sent: No HealthKit data of any kind, no recovery or readiness scores, no email address, and no audio recording — only text.
  • It is optional: Manual entry does the same job. If you never describe a session in words, nothing is ever sent to the parsing service.

The parsed result is returned to your device as a draft. Nothing is saved to your log until you confirm it.

This is separate from the HealthKit rule above, which is unchanged: raw HealthKit data is never uploaded, to this service or to any other.

Data Sharing

Tuwa does not share your training or recovery data with coaches, other users, advertisers, or data brokers. If future sharing features are added, they will require your explicit consent.

Third-Party Services

We do not use any advertising networks, analytics trackers, or third-party data brokers.

Data Retention and Deletion

Your data is retained as long as your account exists. To delete all your data:

  1. Go to Profile → Sign Out in the app
  2. Contact us at the email below to request full account and data deletion from our servers

Upon deletion, all your data — including workout logs and scores — is permanently removed from our servers.

Your Rights

You have the right to:

  • Access the data we store about you
  • Request correction of inaccurate data
  • Request deletion of your account and all associated data
  • Withdraw HealthKit permissions at any time via iOS Settings → Privacy & Security → Health

Children

Tuwa is not directed at children under 13. We do not knowingly collect data from children.

Changes to This Policy

We may update this policy from time to time. Changes will be posted to this page with an updated date.

Contact

For privacy questions or data deletion requests:

Email: support@tuwa.app