Dalmet · Japanese Walk · Cardio Protocol

Privacy Policy

Cardio Protocol

Last updated August 31, 2026


Cardio Protocol asks for exactly what each feature needs, and asks in plain language before the system prompt appears, not on first launch. There are no user accounts, no advertising, no analytics or tracking SDKs, and nothing is sent to any server we operate, because we don't operate one.

Data we collect

  • Apple Health, if you allow it: your age (from date of birth), resting heart rate, weight, and live heart rate during a session — used to calculate your personal effort zones and coach against them in real time. We also request permission to write completed sessions back to Health as workouts, and to write heart rate and active energy samples, so a session counts toward your Activity rings.
  • A Bluetooth heart rate strap, if you pair one: live BPM from the device while it's connected. Preferred over the Health-sync fallback for lower lag.
  • What you type in: your name, entered once during setup to personalize the app. It's stored only on your device.
  • Session history: the protocol, duration, phases completed, and heart rate samples for each session you run, kept on-device so History and your profile stats work.

How we use it

Every piece of data above exists to run one feature: comparing your live heart rate against a protocol's target zone and coaching you toward it by voice ("pick it up," "good, you're in zone," "ease off a bit"). That comparison, and the speech that comes out of it, happens entirely on your device using Apple's on-device speech synthesis — nothing about your session, your voice coaching, or your heart rate is sent anywhere, including to us.

What we don't collect

Cardio Protocol has no location feature of any kind — no GPS, no route tracking, no request for your location, ever. There's also no account system: nothing here requires a login, an email address, or a phone number.

  • Location — never requested.
  • Contacts, photos, microphone — never requested.
  • Analytics or crash-reporting SDKs — none integrated.
  • Advertising identifiers — none, no ads.
  • A server-side account or database — none exists.

Third parties

We don't share, sell, or transmit your data to any third party, because there's no infrastructure on our end to send it to. Two exceptions worth naming explicitly, both Apple's own systems rather than ours: Apple Health, which you separately control from iOS Settings → Health → Data Access & Devices, and the App Store, which handles subscription payment (see Subscriptions & payment below).

Where it's stored

Your name, settings, and session history are stored locally on your device using iOS's standard app storage, and — if you turn it on — backed up to your own private iCloud account. Heart rate and workout data you authorize also lives in Apple Health, under Apple's own protections. None of it is backed up to any server we operate, because we don't operate one.

Subscriptions & payment

Cardio Protocol offers an optional auto-renewable annual subscription with a 7-day free trial. Payment is handled entirely by the App Store — we never see or store your card details. Your subscription auto-renews unless cancelled at least 24 hours before the current period ends; manage or cancel anytime in iOS Settings → your name → Subscriptions.

Your choices

  • Health access can be granted, denied, or revoked anytime from Settings → Permissions in the app, or iOS Settings → Privacy & Security → Health.
  • A paired heart rate strap can be forgotten from Settings → Fitness Devices.
  • iCloud backup can be turned off from Settings → iCloud Backup, without affecting data already saved on-device.
  • Any saved session can be deleted individually from its detail screen, and all local data — sessions, profile, settings — can be wiped from Settings → Reset All Data.

Retention & deletion

Session history and settings stay on your device until you delete a session, use Reset All Data, or delete the app itself — any of which removes them immediately and completely. Deleting the app also removes everything Cardio Protocol stored locally; data separately saved to Apple Health follows Health's own retention, which you control from the Health app.

Children's privacy

Cardio Protocol is not directed at children under 13 and we do not knowingly collect data from anyone in that age group.

Changes to this policy

If this policy changes, the date at the top of this page will update. Continued use of Cardio Protocol after a change means you accept the revised policy.

Contact

Questions about this policy or your data can be sent to sanjay.almeida@gmail.com.