Privacy Policy
Last updated: 18 July 2026
Orizo ("Orizo", "we", "us") is a training app that adapts your running, lifting and nutrition to how ready your body is. To do that, it works with data that is personal — including health data. This policy explains exactly what we collect, why, where it goes, and how to get rid of it. The short version: we collect only what the features need, we never sell your data, and we don't show ads.
1. Who is responsible
Orizo is the controller of your personal data. For anything privacy-related, contact us at support@orizo.app.
2. What we collect and why
Account and profile
- Email, username, password (stored only as a salted hash) — to create and secure your account.
- Profile details you choose to add: display name, photo, training goals and answers to the setup wizard (e.g. your sport focus and experience level), and body metrics such as weight or height if you enter them — to personalise your plan and home screen.
Training and activity data
- Workouts and lifts you log: exercises, sets, reps, weights, personal records.
- Runs and walks: distance, pace, duration, and — if you use GPS tracking — your route (precise location). Location is collected only while you are recording an activity; background location is used solely so tracking continues when your screen is locked. We never track your location outside an activity you started.
- Treadmill and sensor sessions: if you connect a heart-rate monitor or treadmill over Bluetooth, we receive the metrics those devices broadcast during the session.
Health data (Health Connect / Apple Health)
If — and only if — you connect a health source, Orizo reads the following record types: heart rate, heart-rate variability (RMSSD), resting heart rate, sleep sessions, steps, and exercise sessions. We use them for one purpose: computing your daily readiness and adjusting your training load. Orizo never writes to your health store, never uses health data for advertising or marketing, and never sells or shares it with third parties. You can disconnect the integration at any time in your device's health settings, and Orizo keeps working without it.
Nutrition data
- Meals, diet preferences and plans you log — to power meal tracking and daily targets.
- Barcodes you scan are looked up against the Open Food Facts database (see section 4). If you contribute a product that isn't in the community database, the product information you submit (name, nutrition values, barcode) is shared with other Orizo users — never anything about you or your diet.
Social and community features
- Posts, photos, videos, comments and reactions you share to the feed are visible to other Orizo users, along with your username and profile photo.
- Leaderboards, leagues, levels and achievements display your username and training statistics (XP, distances, streaks) to other participants. Personal records may appear on your shared activities.
Messages
Direct messages in Orizo are end-to-end encrypted, including voice messages and attachments. We cannot read their content — encryption keys exist only on your devices. We process the minimum metadata needed to deliver messages (who is talking to whom, timestamps, delivery state).
Coaching
If you connect with a coach on Orizo, they can see the training data needed to coach you: your plans, logged workouts and progress. Your nutrition data is shared with a coach only after your explicit consent, which you can withdraw at any time in the app. Coaches are independent users, not Orizo staff.
Device and technical data
- Push notification tokens and delivery receipts — to send you notifications and to detect when a device silently stops receiving them.
- Basic device information and logs (device model, OS version, app version, error reports) — to keep the app working and fix bugs.
3. What we do NOT do
- We do not sell or rent your personal data. To anyone. Ever.
- We do not show ads and do not share data with advertisers or data brokers.
- We do not use your health data for anything except the readiness and training features you see in the app.
- We do not read your messages — we couldn't if we wanted to.
4. Service providers and third parties
We keep the list short. Data leaves our servers only for these purposes:
- Google Firebase Cloud Messaging — delivers push notifications. Receives your device's push token. Message notifications are delivered as encrypted payloads that are decrypted on your device.
- Open Food Facts (openfoodfacts.org) — when you scan a barcode, the barcode number (nothing else) is sent to look up the product.
- Open-Meteo (open-meteo.com) — if you enable the weather widget, approximate coordinates (rounded, not your exact position) are sent to fetch a forecast. No account information is included.
- Health Connect / Apple Health — the on-device health store operated by your OS; we read from it with your permission as described above.
Your media (photos, videos, voice messages) and all training data are stored on infrastructure we operate ourselves.
5. Legal bases (GDPR)
- Performance of a contract — account, training, social and coaching features you signed up for.
- Consent — health data, location during tracked activities, sharing nutrition data with a coach, notifications. Each of these is opt-in and can be withdrawn.
- Legitimate interest — security, abuse prevention, and keeping notifications reliable (delivery receipts).
6. Retention and deletion
We keep your data for as long as your account exists. When you delete your account, your personal data — profile, training history, health-derived metrics, nutrition logs, messages and media — is permanently deleted from our systems, except for the minimum we are legally required to retain (and community food products you contributed, which contain no personal data). To delete your account, contact support@orizo.app from your account email and we will complete the deletion within 30 days.
7. Your rights
You can ask us at any time to access, correct, export, restrict or delete your personal data, and you can object to processing based on legitimate interest. Write to support@orizo.app and we'll respond within 30 days. If you are in the EU/EEA, you also have the right to lodge a complaint with your local data-protection authority.
8. Security
All traffic between the app and our servers is encrypted in transit (TLS). Passwords are stored hashed, direct messages are end-to-end encrypted, and access to production systems is restricted. No system is perfectly secure, but if a breach affects your data we will notify you as required by law.
9. Children
Orizo is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child is using Orizo, contact us and we will delete the account.
10. Changes to this policy
If we change this policy in a way that matters, we'll tell you in the app before the change takes effect. The date at the top always reflects the latest version.
11. Contact
Questions, requests, complaints: support@orizo.app.