Privacy Policy

Your health data belongs to you.

Last updated: March 2026

The short version

  • RIKOOP has no backend servers that store your health data
  • We do not collect your name, email, or any personal identifiers
  • We do not require account creation
  • Your biometric data never leaves your device
  • We do not sell your data — ever
  • We do not use your data for advertising
  • All health data processing happens locally on your iPhone
  • Journal entries and preferences may optionally sync via your personal iCloud account if you enable iCloud Sync

RIKOOP was built on a simple principle: your health data belongs to you. We do not collect it, store it on our servers, sell it, or share it with anyone. Everything RIKOOP does happens on your iPhone — privately, locally, and entirely under your control.


This Privacy Policy explains what data RIKOOP accesses, how it is used, and your rights as a user. The current version is always available at rikoop.com/privacy.

1. Data We Access

RIKOOP reads data from Apple HealthKit with your explicit permission. You control which data types RIKOOP can access. You may grant or revoke any permission at any time in iPhone Settings → Privacy & Security → Health → RIKOOP.

1.1 Health and Biometric Data

RIKOOP requests access to read the following from Apple HealthKit:

Heart and Cardiovascular

  • Heart rate (continuous samples)
  • Resting heart rate
  • Heart rate variability (HRV — SDNN)
  • Heart rate recovery
  • Walking heart rate average
  • High / low heart rate events
  • Irregular heart rhythm events
  • Blood oxygen saturation (SpO2)
  • Electrodermal activity (Apple Watch Ultra)

Activity and Movement

  • Step count
  • Flights climbed
  • Active energy burned
  • Basal energy burned
  • Distance walking/running/cycling
  • Walking and running speed and power
  • Cycling power

Sleep

  • Sleep analysis (Core, Deep, REM, Awake stages)
  • Sleep duration goal

Body Measurements

  • Body mass (weight)
  • Height

Respiratory

  • Respiratory rate
  • Body temperature (sleeping wrist temperature — Series 8+)

Nutrition

  • Dietary caffeine
  • Dietary water
  • Dietary protein
  • Number of alcoholic beverages

Fitness

  • VO2 Max
  • Workout data (type, duration, heart rate)
  • Workout routes (GPS)
  • Mindful sessions

Biological Characteristics

  • Biological sex (read from Apple Health profile)
  • Date of birth (read from Apple Health profile)

Reproductive Health (female users only, if available)

  • Menstrual flow data
  • Ovulation test results

1.2 Why We Access Each Data Type

Data TypePurpose
Heart rate, HRV, RHRRecovery Score, Biological Reserve, illness detection, stress detection
Sleep analysisSleep Score, overnight sleep window calculation, nap detection
Steps, flights, active caloriesBiological Reserve depletion (Layer 2 movement cost)
VO2 MaxHeart rate zone calibration, HRMax calculation
WorkoutsStrain Score, post-workout budget depletion
Body mass, heightPersonalized BMR calculation for baseline existence cost
Biological sex, ageSex-specific algorithm calibration (HRMax formula, sleep targets, population defaults)
Menstrual flowCycle-phase-aware HRV thresholds — prevents false illness alerts during luteal phase
Respiratory rate, wrist tempIllness and anomaly detection
Dietary caffeine, alcoholAutomatic Biological Reserve deductions
Mindful sessionsAutomatic Reserve earnings
Blood oxygenEnhanced illness detection signal

1.3 Characteristic Data from Apple Health

RIKOOP silently reads your biological sex and date of birth from your Apple Health profile to calibrate algorithms to your biology. This data is read once on first launch, stored only on your device in UserDefaults, never transmitted anywhere, and can be changed by updating your Apple Health profile.

2. How Your Data Is Used

All data accessed from HealthKit is processed locally on your iPhone.

2.1 On-Device Processing Only

RIKOOP's algorithms — including Recovery Score calculation, Sleep Score calculation, Strain Score calculation, Biological Reserve computation, illness detection, and all other features — run entirely on your iPhone. No biometric data is transmitted to any server, cloud service, or third party.

2.2 Local Storage

Computed scores and app state (your daily Biological Reserve, Recovery Score, Sleep Score, and settings) are stored locally on your device. This data never leaves your device, is included in your iPhone's encrypted local backup if iCloud Backup is enabled, and is deleted when you delete the RIKOOP app.

2.3 Optional iCloud Sync

RIKOOP offers an optional iCloud Sync feature, enabled by default, which stores the following in your personal iCloud account:

  • Your daily journal entries (lifestyle logs including alcohol, stress, caffeine, screens before bed, food quality, and notes)
  • Your app preferences (height, weight, notification schedules, training level, sleep target, and notification settings)

iCloud Sync never stores Recovery scores, HRV, heart rate, sleep data, or any Apple Health data. iCloud data is stored in your private iCloud container — only your Apple ID can access it. RIKOOP cannot access this data.

Disable iCloud Sync at any time in Profile → iCloud Sync. To delete iCloud data: iPhone Settings → Apple ID → iCloud → Manage Account Storage → RIKOOP.

2.4 Algorithm Personalization

Your biometric history is used to build a personal baseline stored locally. It is used to calculate your personal normal for HRV, resting HR, respiratory rate, and sleep; personalize your Recovery Score relative to your own history; detect anomalies; and calibrate your Biological Reserve. This personalization never requires your data to leave your device.

3. Data We Do Not Collect

RIKOOP does not collect, process, or store:

  • Your name
  • Your email address
  • Your phone number
  • Your location
  • Your Apple ID or any account credentials
  • Your payment information (handled entirely by Apple)
  • Your IP address
  • Device identifiers for tracking purposes
  • Usage analytics or behavioral tracking data
  • Advertising identifiers (IDFA)
  • Any data for advertising purposes

4. Data Sharing

We do not sell your data. We do not share your data. Period. RIKOOP has no backend infrastructure that receives your health data. We cannot share what we do not have.

4.1 Apple

RIKOOP operates within the Apple ecosystem. Apple processes your App Store purchases and manages subscription billing. Data written to or read from HealthKit is governed by Apple HealthKit policies in addition to this Privacy Policy. Apple's privacy policy: apple.com/privacy.

4.2 No Third-Party Analytics

RIKOOP does not integrate any third-party analytics SDKs, advertising networks, crash reporting services that transmit personal data, or any other service that would receive your health or usage data.

4.3 Legal Requirements

We may disclose information if required by law or valid legal process. To our knowledge this would be limited to app metadata — we have no health data to disclose.

5. Notifications

RIKOOP Premium sends push notifications generated entirely on your device from local data. They are not sent from any server, are scheduled locally using iOS notification APIs, and are never transmitted to or generated by external servers. Manage notification permissions in iPhone Settings → Notifications → RIKOOP.

6. Purchases and Payments

All purchases are processed by Apple through the App Store. RIKOOP does not receive, store, or process your payment information. For purchase-related privacy matters refer to Apple's privacy policy.

7. Children's Privacy

RIKOOP is not intended for use by individuals under the age of 18. We do not knowingly collect data from children under 18. If you believe a child under 18 has used RIKOOP contact us at hello@rikoop.com and we will take appropriate steps.

8. Your Rights and Controls

8.1 HealthKit Permissions

Modify permissions at any time: iPhone Settings → Privacy & Security → Health → RIKOOP, or via the Health app → your profile → Apps → RIKOOP. Revoking permissions reduces App functionality but does not affect data already stored in Apple Health.

8.2 iCloud Sync Controls

Enable or disable iCloud Sync at any time in RIKOOP → Profile → iCloud Sync. Disabling sync stops future writes to iCloud; existing iCloud data is not deleted. To delete iCloud data: iPhone Settings → Apple ID → iCloud → Manage Account Storage → RIKOOP. If iCloud is unavailable, RIKOOP automatically falls back to local device storage with no loss of functionality.

8.3 Deleting Your Data

Delete the RIKOOP app to permanently delete all locally stored computed scores, journal entries, settings, and app data. If you had iCloud Sync enabled, your journal entries and preferences remain in iCloud until you delete them via iPhone Settings → Apple ID → iCloud → Manage Account Storage → RIKOOP. RIKOOP has no server-side data to delete. Your underlying biometric data in Apple Health is unaffected and must be managed through the Health app directly.

8.4 Data Portability

Your raw biometric data lives in Apple Health and can be exported at any time through the Health app. RIKOOP computed scores can be exported from within the RIKOOP app in the Profile section.

9. Security

Because RIKOOP does not transmit your health data to external servers, the primary security of your data is governed by your iPhone's built-in security — hardware encryption, Face ID/Touch ID, and iOS security architecture. Locally stored RIKOOP data is protected by iOS data protection, app sandbox isolation, and has zero network transmission risk. Keep your iPhone updated to the latest iOS version for the strongest protection.

10. iCloud and Device Backups

10.1 iCloud Sync (Opt-In, On by Default)

RIKOOP includes an optional iCloud Sync feature that stores your journal entries and app preferences in your personal iCloud account. This sync is on by default and can be disabled in Profile → iCloud Sync. iCloud Sync never stores health data, biometric data, recovery scores, or any data sourced from Apple HealthKit.

10.2 iCloud Backup

If you use iCloud Backup, RIKOOP's locally stored data (computed scores, settings) may be included in your iPhone's encrypted iCloud backup governed by Apple's iCloud terms. If you restore an iPhone from backup, RIKOOP's local data will be restored along with other app data.

11. International Users

RIKOOP is developed in Canada and is intended for users globally. Because we do not collect or transmit your data to servers, cross-border data transfer concerns related to health data do not apply to RIKOOP's core operation.

11.1 European Users (GDPR)

RIKOOP does not act as a data controller for your health data because we never receive it. All health data processing occurs locally under your direct control. Your legal basis for local processing is your explicit consent via HealthKit permission grants. You may withdraw consent at any time by revoking HealthKit permissions. You have the right to erasure — delete the app to delete all RIKOOP data.

11.2 California Users (CCPA)

RIKOOP does not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising. We do not collect personal information as defined under CCPA beyond what is described in this policy. We do not discriminate against users who exercise their privacy rights.

11.3 Canadian Users (PIPEDA)

RIKOOP is developed in Canada and complies with the Personal Information Protection and Electronic Documents Act (PIPEDA). We collect only the minimum information necessary, with your consent, for the purposes described in this policy.

12. Sensitive Health Data

RIKOOP accesses sensitive health data categories including cardiovascular data, sleep data, reproductive health data (menstrual cycle — female users), and mental and physical wellness indicators. None of this data is shared, sold, or transmitted. The menstrual cycle data accessed by RIKOOP is used solely to adjust anomaly detection thresholds for natural hormonal variation — it is processed on-device and never leaves your iPhone.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in the App or applicable law. We will update the "Last updated" date when changes are made and provide notice within the App for material changes. Continued use after the updated date constitutes acceptance. The current Privacy Policy is always available at rikoop.com/privacy.

14. Contact Us

For privacy questions, concerns, or requests: hello@rikoop.com — rikoop.com

Summary

Data collected by RIKOOP serversNone
Health data transmitted externallyNever
iCloud SyncOptional — journal entries and preferences only. On by default, can be disabled.
Account requiredNo
Data sold to third partiesNever
AdvertisingNone
Analytics SDKsNone
Health data storedLocally on your device only
Journal and preferences storedLocally + optionally in your personal iCloud account
Delete your dataDelete the app (and optionally clear iCloud storage)
PermissionsFully controllable in iPhone Settings
Age requirement18+

This Privacy Policy applies to the RIKOOP iOS application. It does not apply to rikoop.com or any other services we may offer, which have their own privacy terms. Apple, Apple Watch, Apple Health, HealthKit, iCloud, and App Store are trademarks of Apple Inc. RIKOOP is independent of and not affiliated with Apple Inc.