Legal
Privacy Policy
1. About this privacy policy
This privacy policy explains what data Tentava collects, what we use it for, who we share it with and what rights you have. We have written it as specifically as we can. Where we state a retention period, we mean it.
Sections 1 to 27 apply to all Tentava users in the current launch markets. Section 28 contains the Swiss addition and section 29 the EU/EEA addition. Where a regional addition differs from the general part, the regional addition applies.
Language versions
This English version is the primary reference version. All other language versions are translations of this text and are provided so that you can read this policy in your own language.
This English text is our primary reference for maintaining consistent translations. Each published language version is intended to provide the same information. Nothing in this clause limits rights that you have under mandatory local law or prevents you from relying on information provided to you in a language required by that law.
Tentava is not a medical application. The app does not replace medical advice, diagnosis or treatment. Details are set out in our medical disclaimer.
2. Who is responsible for your data
| Controller | KITAV Vuong, sole proprietorship |
|---|---|
| Owner | Kim Tai Vuong |
| Address | Allmendstrasse 3b, 6048 Horw, Switzerland |
| Company identification number | CHE-337.875.632 |
| Privacy | privacy@tentava.app |
| Support | support@tentava.app |
| Website | https://tentava.app |
We are a controller within the meaning of Art. 4(7) GDPR and a responsible person under Art. 5(j) of the Swiss Federal Act on Data Protection.
3. Privacy contacts and representatives
For any privacy matter, contact us at privacy@tentava.app. We respond within the statutory time limits.
Representative in the EU and EEA (Art. 27 GDPR)
Representative details will be added shortly.
Legal representative under the Digital Services Act (Art. 13 DSA)
Representative details will be added shortly.
Data protection officer
We have not appointed a data protection officer. Having assessed Art. 37 GDPR and Art. 10 of the Swiss Federal Act on Data Protection, we are not required to do so. For any privacy matter you can reach us directly at privacy@tentava.app.
4. Who and what this policy covers
This policy covers the Tentava iOS app, the website tentava.app and all associated features. These include your account and profile, workout planning and logging, progress, statistics and goals, friend, coach and chat features, public workouts, custom exercises, training locations, health and fitness integrations, AI-generated insights, subscriptions, and support and reporting.
It does not cover third-party services you use yourself. If you connect Tentava to Apple Health or Wahoo, the data held in those services is governed by the privacy policies of Apple and Wahoo respectively.
5. Terms used
| Term | What it means in this policy |
|---|---|
| Personal data | Any information that relates to you or makes you identifiable. |
| Health data | Information about your physical condition — in Tentava this mainly means workout data, body measurements, heart rate, respiratory rate, sleep and injuries. It is a special category of data under Art. 9 GDPR and sensitive personal data under Swiss law. |
| Processing | Anything we do with data: collecting, storing, using, sharing, deleting. |
| Processor | A company that processes data on our behalf and on our instructions — for us, mainly Google and OpenAI. |
| Consent | Your voluntary, informed and explicit agreement, which you can withdraw at any time. |
6. Where your data comes from
| Source | What comes from it |
|---|---|
| From you | Registration, profile details, logged workouts, custom exercises, goals, messages, photos and videos, feedback. |
| From your sign-in provider | If you sign in with Apple or Google: an identifier and basic profile details. We never receive your password. |
| From your device | Device details, app version, language setting, time zone, IP address, push token, and your location when you search for a place. |
| From Apple Health | Only with your permission. See section 10. |
| From Bluetooth sensors | Only if you connect a sensor. See section 12. |
| From Wahoo | Only if you set up the connection. See section 11. |
| From FIT files | Only if you import a file. See section 13. |
| From Apple (App Store) | Subscription status and receipt information. We never receive payment details. |
| From other users | When someone sends you a friend request, messages you, invites you to a workout or reports you. |
7. What data we process
7.1 Account and profile data
| Data | Required or optional |
|---|---|
| Email address | Required |
| Username | Required |
| First and last name | Optional, if this field is available in the app version you use |
| Date of birth or birth year | Required for age eligibility and age-dependent calculations; the app collects only the level of detail shown in the registration flow |
| Gender | Optional, including an option not to state it |
| Height and weight | Optional |
| Profile picture | Optional |
| Bio and linked social media profiles | Optional |
| Training profile, experience level, goals, preferred training days | Optional |
| Injury profile | Optional — health data |
| Identifier, sign-in method, account status | Technically required |
| Consent records with timestamp and text version | Technically required |
7.2 Workout and health data
Planned and completed workouts, exercises, muscle groups, sets, repetitions, weights, intensity and RIR, duration, rest periods, training volume, estimated one-repetition maximum, progress, goals and target values, statistics and your full workout history. In addition, body measurements, heart rate, respiratory rate, calories burned, power, cadence, speed, distance and elevation, where those values come from the sources listed in section 6.
Some of these data are health data. Where special-category or sensitive-data rules apply, we process them on the basis of your explicit consent and the ordinary consent basis under Article 6(1)(a) GDPR, unless a different lawful basis is expressly stated for a specific operation.
7.3 Social, chat and coach data
Friendships and friend requests, follower relationships, group invitations, blocks, public and joinable workouts and join requests, coach assignments and the individual permissions you grant to a coach, coach notes, activity likes and views, and the content of your chat messages including attachments.
7.4 Content you create
Custom exercises, workout titles, notes, and photos and videos attached to your workouts and exercises.
7.5 Location data
We use your device location only when you search for a training location or attach a location to a workout. It serves to centre the place search on your surroundings. We do not track your location in the background. We use Google Places and Apple MapKit for the place search. We save the locations you mark as favourites.
If you make a planned workout public, the location attached to it becomes visible to other users so that they can find the workout. You can grant or withdraw location access at any time in your iOS settings.
7.6 Device and technical data
Device model, operating system version, app version, language setting, time zone, IP address, log data, security events and a push token for notifications. We use Firebase App Check and Apple App Attest to verify that requests come from genuine instances of our app.
7.7 Subscription and transaction data
Subscription status, plan, renewal information and the receipt information needed to verify your subscription. Payment is handled entirely by Apple. We never receive or store credit card or bank details.
7.8 Support, reports and moderation
Feedback you submit in the app, including category, free-text message, app version, platform, country or region and your account identifier; messages you send to support@tentava.app; and reports you submit about content or users, together with our decision on them. To help our administrators classify and summarise feedback, the feedback message and its category and technical context can be processed through the OpenAI API. This internal classification is separate from the personalised AI features in section 14 and does not use your workout history. Please do not include health data or other sensitive information that is not necessary for your feedback.
7.9 Usage data
With your analytics consent, Firebase Analytics records a limited set of product events together with an app-instance identifier and technical context such as device type, operating system, app version, language and approximate country or region derived from the network connection. Details are in section 18. We do not use this information to track you across third-party apps or websites and we do not show advertising.
8. Purposes, legal bases and retention at a glance
This table assigns each processing activity its purpose, legal basis, recipients and retention period.
| Purpose | Data | Legal basis | Recipients | Retention |
|---|---|---|---|---|
| Provide and operate your account | Account and profile data | Contract, Art. 6(1)(b) GDPR | Life of the account | |
| Plan, log and analyse workouts | Workout and health data | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Life of the account | |
| Read data from Apple Health | HealthKit data | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Not shared | Display only; imported activities for the life of the account |
| Write values back to Apple Health | Body measurements, energy, heart rate, water, workouts | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Apple, on your device | Controlled by you in Health |
| Import Wahoo workouts | Wahoo workouts, access token | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Google, Wahoo | Until you disconnect |
| Process FIT files | Time series and metrics from the file | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | File deleted immediately; metrics for the life of the account | |
| Record heart rate live | Bluetooth measurements | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | For the duration of the workout | |
| Generate AI insights | Minimised workout records and aggregates, goals, relevant heart-rate summaries and comparison context described in section 14 | Separate consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR | OpenAI Ireland Ltd. and approved subprocessors; Google | AI result until deletion or account deletion; OpenAI abuse-monitoring logs for up to 30 days under standard API controls |
| Friends, feed and public workouts | Social data | Contract, and consent for public content | Google, other users | Life of the account |
| Chat | Messages and attachments | Contract, Art. 6(1)(b) GDPR | Google, recipient | Life of the chat |
| Coaching | Data released per permission | Explicit consent | The coach you choose | Until you withdraw the permission |
| Send notifications | Push token, event data | Contract and consent | Google, Apple | Until you opt out or after 180 days of inactivity |
| Manage subscriptions | Subscription and transaction data | Contract and legal obligation | Apple, Google | 10 years under Art. 958f Swiss Code of Obligations |
| Provide support | Feedback, messages | Contract and legitimate interest | 24 months | |
| Handle reports | Report, reported content, decision | Legal obligation under the DSA and legitimate interest | Report and decision for 12 months, or 24 months for repeat cases; copied evidence normally for 180 days unless a case requires longer | |
| Prevent abuse, maintain security | Logs, security events, App Check | Legitimate interest, Art. 6(1)(f) GDPR | Google, Apple | 30 to 90 days |
| Analyse usage | Named events, app-instance identifier, device/app context and approximate country or region | Consent | 14 months | |
| Classify and summarise support feedback | Feedback message, category, app version, platform and country or region | Contract and legitimate interest in improving support and product quality, Art. 6(1)(b) and (f) GDPR | OpenAI Ireland Ltd. and approved subprocessors; Google | Feedback record for 24 months; OpenAI abuse-monitoring logs for up to 30 days under standard API controls |
Legitimate interest means we have a genuine interest of our own in the processing and have assessed that your interests do not override it. You can object to such processing — see section 24.
9. Health and fitness data
Your health and fitness data is the most sensitive data Tentava processes. We treat it as a special category under Art. 9 GDPR and as sensitive personal data under Swiss law.
We process it solely on the basis of your explicit consent, and only to provide the features you choose to use.
What we do not do with your health data
- We do not sell it and we do not share it for advertising.
- We do not use it for advertising, marketing or data mining.
- We do not pass it to insurers, employers or data brokers.
- We do not store health data in iCloud.
- We use data from Apple Health only for the features you open in the app.
Your consent
Where consent is required for health and fitness processing, we ask for it through a clearly marked action in the app. Consent is not hidden in our terms. You can refuse or withdraw it at any time in Settings. Withdrawal applies to future processing and does not make earlier processing unlawful. Features that require the withdrawn data will stop working; unrelated parts of Tentava remain available.
10. Apple Health (HealthKit)
When you connect Apple Health, iOS asks for your permission. You decide for each data type individually whether we may read or write it. You can change these permissions at any time in the Health app.
10.1 Data we can read
We request permission for the data types below. Whether we actually receive them depends entirely on what you allow.
| Area | Data types |
|---|---|
| Activity | Steps, walking and running distance, cycling distance, flights climbed, exercise minutes, move minutes |
| Energy | Active energy burned, basal energy burned |
| Body | Body mass, body mass index, body fat percentage, waist circumference |
| Heart and circulation | Heart rate, resting heart rate, walking heart rate average, heart rate variability, VO2 max |
| Nutrition | Water intake |
| Running metrics | Running power, running speed, stride length, ground contact time, vertical oscillation |
| Cycling metrics | Cycling power, cycling speed, cadence, functional threshold power |
| Sleep | Sleep analysis |
| Workouts | Workouts recorded by other apps and devices |
| Routes | Route data attached to workouts |
| Important note on route data Route data from Apple Health contains precise location information. We read it solely so that imported workouts can be displayed in full. We do not store route coordinates on our servers. This data never feeds into AI insights. Our software explicitly blocks the transmission of location and route information to AI services. |
|---|
10.2 Data we can write
If you allow it, we write values you have recorded back to Apple Health: body mass, body mass index, body fat percentage, waist circumference, active energy burned, water intake, heart rate and your workouts. We only ever write values that you recorded yourself or that came from a sensor you connected.
10.3 Withdrawing permission
You can withdraw permission at any time in the Health app under Data Access & Devices. Access ends immediately. Workouts already imported remain in Tentava until you delete them or delete your account.
11. Wahoo
When you connect your Wahoo account, we open a sign-in page hosted by Wahoo. We never receive your Wahoo password. After you approve, Wahoo issues us an access token.
We request the following permissions: read power zones, read workouts, read routes, access stored data, and read basic account information.
We use these to import your Wahoo workouts and display them in Tentava as activities. The token and the import are handled by our backend, not by the app. The token is stored encrypted and is never delivered to your device.
You can disconnect at any time in your settings. We then delete the token and the connection record immediately. Workouts already imported remain until you delete them. Disconnecting does not delete any data held in your Wahoo account — for that, contact Wahoo.
12. Bluetooth sensors
You can connect a heart rate sensor over Bluetooth, such as a chest strap. Tentava uses the standard Bluetooth heart rate service for this.
| Question | Answer |
|---|---|
| What values are read? | Only heart rate in beats per minute. When connecting, we also process the device name and identifier. |
| Are the values stored? | Yes. During the workout we display them live. Afterwards we store the average, minimum and maximum, and the series of readings, as part of the workout record. |
| What are they used for? | Live display during the workout, analysis afterwards, statistics, and — if you have consented to AI features — as a summarised value in AI insights. |
| How do I withdraw? | You can withdraw Bluetooth access at any time in your iOS settings, or disconnect the sensor in the app. |
13. Importing FIT files
You can import workout files in FIT format. The file is transmitted to our backend over an encrypted connection, processed there and deleted immediately afterwards — whether or not the import succeeded.
From the file we read heart rate, speed, power, cadence, elevation and respiratory rate as time series, together with distance, duration and the corresponding average and maximum values.
| We do not store location data from FIT files FIT files often contain GPS coordinates. Our processing only checks whether route points are present at all, and stores nothing more than the fact that the activity included a route. The coordinates themselves are never stored, processed further or displayed. |
|---|
14. AI features
Tentava offers insights generated with the help of a language model. For this we work with OpenAI. We describe it in full here so that you can decide whether you want to use these features.
14.1 Which features use AI
| Feature | What it does | When it runs |
|---|---|---|
| AI Training Review | Produces a written assessment of load, progress and recommendations after a workout. | When you request it in the app. |
| AI Weekly Summary | Summarises your training week in plain language and puts your goals in context. | Automatically once a week in the background, if you have consented. |
The personalised OpenAI-powered user features covered by this consent section are AI Training Review and AI Weekly Summary. AI Training Review runs only when you request it. AI Weekly Summary runs automatically once per week only while your separate AI consent remains active and the feature is enabled. No other user-facing training or health feature sends personal data to OpenAI unless this policy and the in-app consent notice are updated before that processing begins. The separate internal classification of support feedback is described in sections 7.8 and 22 and does not use your workout history.
14.2 What data is transmitted
Depending on the feature, the request can contain the minimised records and aggregates listed below. We do not send your name, username, email address, Firebase user ID, date of birth, free-text bio, private messages, photos, videos, payment data, precise location or route coordinates. Training and goal references in the AI payload use technical aliases rather than the real account or training-document identifiers. The remaining data can still relate to your account, so we treat it as personal data and, where applicable, health data.
- Training dates and types; exercise names; sets, repetitions, weights, duration, intensity, training volume, RIR and progression values relevant to the requested analysis
- Summaries of relevant performance and fitness metrics, including average, minimum and maximum heart-rate values; raw sensor time series are not sent
- Your training goals, target values, timeframes and recorded progress
- Aggregated comparison values from relevant current and previous workouts, muscle-group load indicators and data-quality indicators
- No injury free text, contact details, social graph, chat content, media, location or route data
- The language in which the output should be written and technical instructions needed to format the response
| AI data minimisation Tentava constructs a defined feature payload and is designed to exclude direct account identifiers, contact details, private communications, precise location, route data and user-uploaded media. Only data categories described in section 14 may be included. We maintain server-side access controls and tests for this boundary. Because the remaining information can still relate to your account, we treat it as personal and health data rather than claiming that it is anonymous. |
|---|
14.3 What happens to the data at OpenAI
| Question | Answer |
|---|---|
| Who is the recipient? | OpenAI Ireland Ltd., acting as a processor for KITAV Vuong, together with approved affiliates and subprocessors required to provide the API service. |
| Is the data used to train AI models? | No. OpenAI states that API data is not used to train or improve its models unless the customer expressly opts in. KITAV Vuong does not opt in. |
| Is the data stored permanently? | No. Tentava sends Responses API requests with store=false. Under standard controls, abuse-monitoring logs that may contain inputs and outputs can be retained for up to 30 days, subject to the exceptions described above. |
| Where is the data processed? | Through OpenAI Ireland Ltd. and approved affiliates or subprocessors in disclosed locations. International transfers are protected as described in section 23. |
| Does the AI make decisions about me? | No. The output is explanatory guidance. It does not produce legal or similarly significant effects, and it must not be treated as medical advice. |
| Are the results stored? | Yes. Tentava stores the generated review or summary in your account until you delete it or delete your account, subject to the retention exceptions in section 25. |
For customers in Switzerland and the EU/EEA, OpenAI Ireland Ltd. acts as a processor under the OpenAI Services Agreement and Data Processing Addendum. Tentava uses the Responses API with store=false so that no response application state is requested. OpenAI states that API data is not used to train or improve its models unless the customer expressly opts in; KITAV Vuong does not opt in. Under the standard API controls, abuse-monitoring logs that may include inputs and outputs can be retained for up to 30 days, unless longer retention is required by law or reasonably necessary to protect the service or third parties. Processing can involve approved OpenAI affiliates and subprocessors. International-transfer safeguards are described in section 23.
14.4 Your choice
AI processing is optional and is not activated merely because you purchase or enable the Peak subscription. Before the first AI transfer under this consent version, the app shows a separate AI consent view describing the two features, data categories, OpenAI processing and your choices. You must actively confirm the consent text and choose to allow the AI features. We store the decision status, consent version, decision time, language, source, app version and a decision identifier in your account and decision history. If you do not consent, the two OpenAI-powered features remain disabled; unrelated Tentava functions remain available. You can withdraw consent at any time under My Profile > AI Features. Withdrawal stops future transfers and disables the automatic weekly summary. Existing AI results remain in your account until you delete them, use an available deletion control, or delete your account. AI outputs can be incomplete or incorrect and are not medical advice, diagnosis or treatment.
15. Social features and public content
Tentava has social features. What you share there can be seen by others. Below is exactly what is visible to whom.
| Content | Who can see it |
|---|---|
| Username | All signed-in users — it exists so that people can find you. |
| Profile picture | All signed-in users. A profile picture is optional. You can remove it at any time. |
| Bio | According to your setting: only you, your friends, or everyone. Private by default. |
| Activity list | According to your setting: only you, your friends, or everyone. Private by default. |
| Linked social media profiles | According to your setting. Private by default. |
| Goals and goal progress | Not public. Visible only to a coach to whom you have granted the relevant permission. |
| Public workouts | Visible to everyone, including the attached location — that is the purpose of the feature. |
| Chat messages | Only to the people involved. See section 16. |
| Photos and videos attached to workouts | Only you, unless you explicitly make the workout public. |
You can block other users. Blocking prevents contact and mutual visibility.
16. Chat messages
We will say this plainly: chat messages in Tentava are not end-to-end encrypted. They are stored on our servers and are encrypted in transit and at rest. Technically, we are able to access them.
We do so in three situations only: when a message is reported to us and we have to review the report, when we are legally required to, or when it is unavoidable in order to fix a technical fault. Every such access is logged.
We deliberately chose not to use end-to-end encryption, because otherwise we could not review reported content or protect you from harassment. Please do not treat chat messages as a confidential channel for highly sensitive information.
17. Coaches
You can connect with a coach. When you do, you decide for each individual permission what the coach may see or do.
| Permission | What the coach can see or do with it |
|---|---|
| Training overview | Your completed and planned workouts |
| Goals | Your goals and their progress |
| Exercise statistics | Your performance history per exercise |
| Plan workouts | Create workouts for you |
| Log workouts | Record workouts on your behalf |
| Profile details | Your profile information |
Without a granted permission, a coach sees nothing beyond an ordinary profile. Permissions are enforced on our servers, not only in the app. You can withdraw any permission individually at any time, or end the connection entirely — the effect is immediate.
We do not automatically share your injury profile or body measurements with coaches.
18. Usage analytics and diagnostics
We use Firebase Analytics from Google and record a limited number of named events:
- Sign-in — including the method used and whether it was a new registration
- Completion of onboarding
- Opening the subscription screen
- Starting, changing or restoring a subscription
- Requesting account deletion, and its completion
These events help us measure registrations, account deletions, subscription conversion and where people stop in a flow. Google assigns an app-instance identifier and may process device/app context and an approximate country or region derived from the network connection. We do not attach your workout content, health metrics, private messages, name or email address to analytics events.
What we explicitly do not do
- We do not track you across other apps or websites. No App Tracking Transparency prompt is therefore required.
- We show no advertising and work with no advertising network.
- We do not sell your data and do not share it for advertising.
- We use no crash reporting or performance monitoring.
- Our website uses no analytics tools and no cookies that would require consent.
Analytics collection is disabled until you consent where consent is required. You can withdraw consent at any time in Settings; collection then stops for the future. Event-level analytics data is retained for up to 14 months, subject to shorter technical logs and aggregated reports that no longer identify an app instance.
19. Push notifications
If you allow notifications, we receive a push token for your device. We use it for messages, friend requests, workout reminders, achievements and streaks. Each of these categories has its own switch in your settings. You can disable notifications entirely at any time in your iOS settings. A token with no active device is deleted after 180 days at the latest.
20. Subscriptions and Apple
Subscriptions are purchased through the App Store. Apple handles payment. We receive your subscription status and receipt information from Apple, but no payment details.
| Important: deleting your account does not cancel your subscription An active subscription continues after you delete your Tentava account and will continue to be charged. Cancel it before deleting your account, in your Apple ID settings under Subscriptions. We cannot cancel your subscription for you — technically, only Apple can. |
|---|
21. Support, reports and moderation
You can report content and users through the app. We review reports without undue delay, prioritising credible threats to safety, unlawful content and matters involving minors. Where applicable, we provide the notices, reasons and redress information required by the Digital Services Act and other law.
Where legally required, we inform the affected person if we restrict content or an account and explain the principal reasons. We do not generally review all user content before publication. We act when content is reported, detected through proportionate safety measures or otherwise brought to our attention.
We generally keep reports and moderation decisions for 12 months after closure, or up to 24 months for repeat abuse, disputes, legal claims or authority requests. An immutable copy of reported content is normally kept for 180 days so that later edits do not alter the evidence. It may be retained longer where a live case, safety need, legal claim or authority request requires it, and is then deleted or de-identified.
22. Service providers and recipients
| Recipient | Service | Role | Location and place of processing |
|---|---|---|---|
| Google LLC / Google Ireland Limited | Firebase: database, storage, authentication, server functions, notifications, abuse prevention, analytics, hosting | Processor | Selected Google Cloud/Firebase regions and other Google processing locations, including the United States depending on the service |
| OpenAI Ireland Ltd.; OpenAI affiliates and approved subprocessors | Language model for AI Training Review, AI Weekly Summary and internal classification of support feedback | Processor | Ireland, United States and other locations disclosed by OpenAI |
| Apple Inc. | App Store, subscriptions, Sign in with Apple, push delivery, HealthKit on your device | Independent controller for App Store and account services; device-level platform provider for HealthKit and push delivery | Locations described by Apple for the relevant service |
| Wahoo Fitness LLC | Only where you have set up the connection: providing your workout data | Independent controller for the data in your Wahoo account | USA |
| Google (Places) | Place search when selecting a training location | Provider role depends on the Google Maps Platform service and applicable terms | Google processing locations, which may include the United States |
| Coaches | Only the data you have released | Recipient acting on your instruction | Depends on the coach |
Where a provider processes personal data on our instructions, we use data-processing terms that address confidentiality, security, subprocessors, assistance with rights and deletion. Some recipients, such as Apple for App Store transactions or Wahoo for its own account service, act as independent controllers for their own processing. We otherwise disclose data only where required by law, needed to protect people and the service, or necessary to establish, exercise or defend legal claims.
Our use of the OpenAI API is governed by the OpenAI Services Agreement and Data Processing Addendum. For KITAV Vuong in Switzerland, OpenAI Ireland Ltd. is the contracting processor. The processing description covers the minimised health-related data described in section 14 and the support-feedback classification described in section 7.8. The API projects are configured not to opt in to model training.
23. International data transfers
Tentava is operated from Switzerland. Google Firebase and Google Cloud process data in the project regions selected by KITAV Vuong and in other locations needed to provide particular services. Some processing, support, security and subprocessors may be located in the United States or other countries. OpenAI processing is contracted through OpenAI Ireland Ltd. and may involve affiliates and subprocessors in the United States and other disclosed locations.
This means that personal data, including health-related data where a feature requires it, can be transferred outside Switzerland or the EU/EEA. A destination country may not provide an equivalent level of legal protection, and public authorities may have lawful access powers.
Depending on the recipient and destination, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses with the Swiss adaptations, or another lawful safeguard. Where required, we assess transfer risks and apply supplementary measures such as encryption in transit and at rest, access controls, data minimisation and contractual limits on purpose and retention. You may request information about the applicable safeguards at privacy@tentava.app.
KITAV Vuong maintains the applicable provider contracts, transfer safeguards and subprocessor information separately from this public policy and reviews them when a provider, destination or processing configuration changes.
24. Your rights
| Right | What you can ask for |
|---|---|
| Access | A copy of the data we process about you, together with details of purposes, recipients and retention periods. |
| Rectification | Correction of inaccurate details. You can change many of them directly in your profile. |
| Erasure | Deletion of your data. The simplest way is to delete your account in the app. |
| Restriction | That we temporarily only store certain data without using it further. |
| Objection | To object to processing that we base on a legitimate interest. |
| Data portability | Your data in a common, machine-readable format. |
| Withdrawal | To withdraw any consent at any time, with effect for the future. |
| Complaint | To lodge a complaint with a supervisory authority. The relevant bodies are listed in sections 28 and 29. |
Write to us at privacy@tentava.app. We respond within one month. If a request is particularly complex, we may extend that period by two months and will tell you if we do. Where we have doubts about your identity, we may ask for further information — solely to protect your data. Handling requests is free of charge, except for manifestly unfounded or repetitive requests. The relevant supervisory bodies are listed in sections 28 and 29.
You can create a machine-readable ZIP export of your Tentava data directly in the app under My Profile > Settings > My Data. You may also request access or portability by writing to privacy@tentava.app.
25. Deleting your account
You can request account deletion at any time in the app under Profile and Settings. Access to the account is disabled when the deletion is confirmed, and deletion from active systems is initiated without undue delay. The process cannot be undone once completed. Limited exceptions and backup periods are listed below.
What is deleted
Your profile, your workouts and planned workouts, your goals and statistics, your custom exercises, imported activities, your photos and videos, your AI insights, your friendships and requests, your coach connections, your settings, your push tokens, your directory entry, your Wahoo connection including the token, and your sign-in credentials.
What remains
| Data | Why | For how long |
|---|---|---|
| Your chat messages in the other person’s chat | So that the other person keeps their own conversation history. Your name is replaced with “Deleted user”. | Until the other person deletes the chat |
| Subscription and invoicing data | Statutory retention obligation under Art. 958f Swiss Code of Obligations | 10 years |
| Reports and moderation decisions | Evidence for authorities, the reporting person and the affected person; immutable copied evidence is normally retained for 180 days | Decision record 12 or 24 months; copied evidence normally 180 days, longer only where the case requires it |
| A record of the deletion with no personal reference | So that we can demonstrate the deletion took place | 24 months |
| Data in backups | Backups and provider recovery systems cannot always be edited selectively | Overwritten or removed under the applicable backup cycle, no later than 180 days unless law or a security incident requires isolation for longer |
Remember to cancel your subscription through your Apple ID first — see section 20.
26. Data security
We protect your data through, among other things: encryption in transit and at rest, access rules enforced on our servers, verification of app authenticity through Firebase App Check and Apple App Attest, rate limiting against abuse, an optional device lock using Face ID, and automated validation and minimisation controls that prevent direct account identifiers and excluded content from reaching the personalised AI features described in section 14.
No system is completely secure. We assess suspected personal-data breaches, contain and document them, and notify affected people and competent authorities when the applicable legal thresholds are met and within the legally required timeframes.
27. Minimum age
Tentava is intended for people aged 16 and over. The registration flow asks for a date of birth or birth year, depending on the app version, to apply the age gate and age-dependent calculations. People under 16 may not create or use an account.
We do not knowingly collect data from children under 16. If we learn that a younger person is using an account, we disable it and delete the data unless retention is legally required. A parent or guardian who believes a child under 16 has an account may contact privacy@tentava.app.
Users under 18 have the same privacy-friendly defaults as everyone else: bio, activity list and linked profiles are private by default, and goals are never published.
28. Additional information for Switzerland
If you live in Switzerland, the Swiss Federal Act on Data Protection applies. Health data is sensitive personal data under Art. 5(c) FADP; we process it only with your explicit consent under Art. 6(7) FADP.
You have the rights set out in Art. 25 to 28 FADP, in particular the right of access and the right to data release or transfer. Complaints may be addressed to the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.
29. Additional information for the EU and EEA
The General Data Protection Regulation applies. The legal bases are set out in section 8. For health data we always rely on Art. 9(2)(a) GDPR — your explicit consent.
The appointment of our representative under Art. 27 GDPR is in progress; details will be added to section 3 shortly. You may lodge a complaint with the supervisory authority of your country of residence, your place of work or the place of the alleged infringement. The European Data Protection Board maintains a list of all authorities at edpb.europa.eu.
We do not take decisions based solely on automated processing that produce legal effects or similarly significantly affect you within the meaning of Art. 22 GDPR.
Digital Services Act
You and the authorities can reach our point of contact at privacy@tentava.app, in German or English. The appointment of our legal representative under Art. 13 DSA is in progress; details will be added to section 3 shortly. Our reporting procedure and response commitments are set out in section 21.
30. Changes to this policy
We update this policy when the app, our service providers or the law change. The version in force is always available in the app and at tentava.app. We will notify you in advance of material changes, in the app or by email. Where a change affects processing based on your consent, we will ask for your consent again.