Ashik Bhandari ("I", "me", or "my") built Attune as a free app. This page informs you of my policies regarding the collection, use, and disclosure of personal data when you use the app.
Information We Access
Apple HealthKit
Attune requests read-only access to the following Apple HealthKit data:
Step count
Active energy burned
Walking + running distance
Heart rate
This data is used solely to display your daily health metrics within the app. Attune does not write any data to HealthKit.
Account Information
When you create an account, Attune collects:
Email address (for login)
Name, date of birth, height, and weight (for personalized meal and exercise plans)
Fitness goals and dietary preferences
How Your Data Is Used
Meal & exercise plans: Your plan is built on our own backend server from a curated content library. No third party is involved unless you turn on AI personalization โ see the section below.
Quit challenges, journal entries, task lists, meditation progress, and tracking: This data is stored locally on your device. If you create an account and sign in, it is also synced to our backend server so your data is backed up and available across your devices. It is used only to provide the app's features and is never sold or shared with any other parties.
AI Personalization & Our Third-Party AI Provider
Attune offers an optional feature called AI personalization ("Tailor with AI"). It is off by default. We ask for your explicit permission in the app, and show you exactly what will be shared, before anything is sent. You can decline and keep using every part of the app.
Who receives the data
Anthropic PBC, via its Claude API. Anthropic acts as our service provider (processor) and handles the data on our behalf. Anthropic states that it does not use data submitted through its commercial API to train its models. Anthropic's own privacy policy is available at anthropic.com/legal/privacy.
Anthropic is bound by its commercial terms to protect this data to a standard equivalent to the one described in this policy: it may use the data only to provide the service to us, may not sell it or use it for advertising, and may not use it to train its models. We do not permit any third party to use your data for its own purposes.
What is sent, if you turn it on
Your first name
Your age, biological sex, height, and weight
Your goal, activity level, and training experience
Your workout setting and eating pattern
Your dietary restrictions and any dietary notes you typed
The habit you are quitting, if you have set a quit challenge
The request is made from our server, not directly from your device, and is used only to generate your plan.
What is never sent to the AI provider
Your email address or password
Your journal entries and any photos you attach
Apple HealthKit data (this never leaves your device at all)
Your mood entries, tasks, streaks, and tracking history
Withdrawing permission
You can turn AI personalization off at any time in Me โ Privacy & AI. We stop sending your details immediately. Turning it off cannot recall information already sent for plans generated earlier.
Data Storage
Local data: Journal entries, tasks, quit challenges, daily tracking progress, meditation progress, and motivational preferences are stored on your device using standard app storage. They remain on your device even if you never create an account.
Server data: If you create an account and sign in, the following are stored on our backend server: account credentials (email and encrypted password), profile information, AI-generated plans, and a synced copy of your journal entries, tasks, meditation progress, and quit-challenge/tracking data. Health data from Apple HealthKit is never sent to the server.
Data We Do NOT Collect
Attune does not:
Use analytics, advertising, or tracking SDKs
Sell your data, or share it for advertising or marketing
Share your data with any third party other than our AI provider, and then only for AI personalization, only with the data listed above, and only if you have turned it on
Track your location
Access your contacts or photo library, except for a photo you explicitly choose to attach to a journal entry (which stays on your device)
HealthKit Data
In compliance with Apple's HealthKit guidelines, health data accessed through HealthKit is:
Never shared with third parties
Never used for advertising or marketing purposes
Never sold to anyone
Never stored on external servers โ HealthKit data remains on your device
Data Security
Passwords are encrypted using industry-standard hashing (bcrypt)
Authentication uses secure JWT tokens
API communications use encrypted connections
Data Deletion
You can permanently delete your account and all associated server data directly in the app: go to Profile โ Delete Account. This removes your account, profile, AI-generated plans, and all synced data from our server. You can also request deletion by contacting me at the email below. Local data can be removed by signing out or by deleting the app from your device.
Changes to This Policy
I may update this privacy policy from time to time. Changes will be posted on this page with an updated date.
Contact
If you have questions about this privacy policy, you may contact me at kirk.ashik@gmail.com.