Privacy Policy
Effective 9 August 2026. Last updated: 9 August 2026.
This policy explains what data the Thallos mobile app (the “app”) collects, why it is needed, who it is shared with, and how to delete it.
In short. We collect only what the health analytics need to work. We do not sell your data, do not share it with advertisers, do not embed advertising trackers, and do not build advertising profiles from your data. You can delete your account and all of its data from inside the app.
1. Who processes the data
The data controller is the owner of the Thallos app. You can reach us at avanesyan.a.a@icloud.com or through the Support section inside the app.
2. What we collect
2.1. Account data
- email address;
- password — stored only as an irreversible hash; we never see it in plain text;
- the name you provide;
- profile photo, if you upload one;
- interface language, theme, time zone;
- when signing in with Apple or Google — the provider account identifier and email address.
2.2. Health profile
- sex, age, height, weight, target weight;
- optionally — menstrual cycle data, pregnancy and menopause flags.
2.3. Health and activity metrics
- heart rate, heart rate variability (HRV), resting heart rate;
- blood oxygen saturation, respiratory rate, skin temperature;
- steps, distance, calories burned;
- sleep: stages, duration, bedtime and wake time;
- workouts: type, time, duration, heart rate zones, calories, distance;
- HRV measurements from a chest strap (for example, Polar H10);
- body weight and its trend.
2.4. Journal and nutrition
- habit entries (sleep, food, alcohol, caffeine, stress, walks and others);
- meals and calorie counts, including those recognised from a description or a photo;
- your free-text notes.
2.5. Medical documents
If you upload lab results (a photo or a PDF), we store the file itself and the values recognised from it: blood biomarkers, hormones, vitamins, lipids and other categories. This is sensitive health data and uploading it is entirely voluntary.
2.6. Devices and technical information
- identifier, model, firmware version and battery level of a connected band, ring or sensor;
- push notification token;
- last synchronisation time.
2.7. Communication with us
Your conversation history with the AI assistant and your support requests.
3. Where the data comes from
- You — during sign-up and when filling in your profile and journal.
- Wearables — bands, rings and chest straps over Bluetooth.
- Apple Health (HealthKit) and Health Connect — only the categories you explicitly allow. You can revoke access in your phone settings at any time.
4. Why we process the data
| Purpose | Data used |
|---|---|
| Calculating sleep, energy, strain and biological age | health and activity metrics, profile |
| AI assistant and personal insights | a summary of your metrics, the text of your question |
| Recognising food from a description or photo | description text, meal image |
| Recognising lab results | the uploaded file |
| Challenges with other users | name, avatar and the value of the chosen metric (steps, calories, kilometres) |
| Notifications and reminders | push token, time zone |
| Signing in and protecting your account | email, password hash, session tokens |
| Answering support requests | request text, email address |
5. Apple Health (HealthKit) data
We state explicitly and separately:
- HealthKit data is used only for your personal health and fitness analytics inside the app;
- we do not use it for advertising, marketing or any profiling;
- we do not sell it and do not disclose it to data brokers, insurers or employers;
- when you use the AI assistant, a summary of your metrics (including metrics originating from HealthKit) is sent to the language model provider so it can produce an answer — see section 6. Do not use the assistant if you do not want this transfer.
6. Who we share data with
We do not sell or rent data. Sharing happens only with providers without which the corresponding feature cannot work:
| Provider | What is shared | Why |
|---|---|---|
| DeepSeek | the text of your question and a summary of your metrics for the period | AI assistant answers and personal insights |
| OpenAI | a photo of a meal or of lab results | recognising calories and health markers |
| Google (Firebase Cloud Messaging) | device token and notification text | delivering push notifications |
| Apple, Google | account identifier and email | Sign in with Apple and Google |
We share only the minimum required to fulfil the request. We do not pass your contact details or complete medical documents to these providers, except for the image recognition case described above.
We may also disclose data where required by law or to protect the rights and safety of users.
7. How long we keep data
- Account data and health metrics are kept for as long as your account exists.
- After account deletion, data is removed from the live database immediately and from backups within 30 days.
- AI chat history is deleted together with the account, or earlier via the clear button in the chat.
8. Your rights
- Access and correction. Your profile and journal are editable in the app.
- Export. A report of your metrics and lab results can be exported to a file.
- Deletion. The account can be deleted in full — see the instructions. Data cannot be restored afterwards.
- Withdrawing permissions. Access to Apple Health, Bluetooth, location, camera, microphone and notifications can be revoked in your phone settings.
- Complaints. Write to us and we will try to resolve the issue; you also have the right to complain to the data protection authority in your country.
9. Security
- Traffic between the app and the server is encrypted with HTTPS (TLS).
- Passwords are stored only as hashes.
- Access tokens are kept on the device in the system secure storage (Keychain on iOS, Keystore on Android).
- Server access is limited to the service administrators.
No method of transmission or storage is absolutely secure, but we apply measures reasonably appropriate to the sensitivity of this data.
10. Children
The app is not intended for people under 16. We do not knowingly collect children’s data. If you believe a child has provided us with their data, contact us and we will delete it.
11. International transfers
The app’s servers are located in the Russian Federation. The providers listed in section 6 may process the data shared with them outside your country.
12. Changes to this policy
We may update this policy. The last update date is shown at the top of this page; we will announce material changes in the app.
13. Contact
Questions about your data: avanesyan.a.a@icloud.com or the Support section in the app.