Effective Date: February 2, 2026
Pharo ("we," "our," or "the App") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we process it, with whom we share it, and your rights regarding your data.
By using Pharo, you consent to the practices described in this policy.
With your explicit permission, we access the following from Apple HealthKit:
This data is stored locally on your device. During calibration, this data is transmitted to our servers for processing as described in Section 3.2.
Any labels you create (e.g., "bad day," "good day," or any other text) and the dates you assign them to. These are transmitted during calibration to train your personalized model.
Your email address is used for:
We do not use your email for marketing purposes without your explicit consent. Your email is stored securely in our account database and is never shared with third parties except as required to provide the service.
After calibration, all operations happen entirely on your iPhone:
For these ongoing operations, no data leaves your device.
When you request model calibration (a Pro feature), your health data is transmitted to our servers for processing. Here is exactly what happens:
| Data Type | What's Sent | Purpose |
|---|---|---|
| Heart Rate | Daily values, timestamps | Feature extraction for model training |
| HRV | Daily values, timestamps | Baseline deviation calculation |
| Respiratory Rate | Daily values, timestamps | Pattern correlation analysis |
| Sleep | Duration, efficiency per night | Recovery pattern analysis |
| Activity | Daily step counts, active minutes | Activity pattern analysis |
| Labels | Dates and label text | Training target definition |
We use Anthropic's Claude AI to orchestrate the calibration process. The AI determines which experiments to run and how to optimize your model.
What is sent to Anthropic:
What is NOT sent to Anthropic:
Anthropic's data handling:
See Anthropic's privacy policy: anthropic.com/privacy
Our servers run on Amazon Web Services (AWS). AWS provides the computing infrastructure but does not access or process your data directly. All data is encrypted in transit using TLS 1.3.
We do not sell, rent, or share your data with any other third parties, including:
We employ an ephemeral processing architecture for calibration:
| Data Type | Storage Location | Retention Period |
|---|---|---|
| Health data (during calibration) | Server memory only | Purged immediately upon completion |
| Trained model file | Your device + encrypted backup | Backup deleted after 30 days or upon request |
| Email address | Encrypted database | Until account deletion |
| Account metadata | Encrypted database | Until account deletion |
| Calibration metadata | Encrypted database | Job ID, timestamps, cost (no health data) |
Data stored on your device remains until you delete the App or clear its data. You have complete control over this data through iOS Settings.
Calibration is a discrete, one-time process. We do not continuously upload, sync, or monitor your health data. Each calibration is an independent event. After your model is delivered, we have no ongoing access to your health information.
We implement comprehensive security measures:
You have the following rights regarding your data:
Request a copy of all data we hold about you. Note: Due to our ephemeral processing model, we do not retain your health data after calibration completes.
Request deletion of your account and all associated data, including:
You can revoke HealthKit permissions at any time via iOS Settings → Privacy & Security → Health → Pharo. This immediately stops the App from accessing any health data.
You can export your labels, settings, and model configuration from within the App.
You can use the free tier indefinitely without ever transmitting data to our servers. Server-based calibration is entirely optional.
Your trained model file is stored on your device in a standard format. You own this model and can delete it at any time.
Pharo is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us immediately for deletion.
Our servers are located in the United States. By using Pharo, you consent to the transfer of data to the US for processing. We comply with applicable data protection laws, including:
Our ephemeral processing model minimizes data exposure regardless of jurisdiction.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via the App or email. Your continued use of Pharo after such changes constitutes acceptance of the updated policy.
For privacy questions, data access requests, deletion requests, or concerns:
Email: privacy@pharo.app
We aim to respond to all privacy inquiries within 30 days.
| Question | Answer |
|---|---|
| Is health data transmitted to your servers? | Yes, during calibration only |
| Is health data stored on your servers? | No—processed in memory only, never written to disk |
| How long do you have my health data? | Only during active calibration (minutes), then immediately purged |
| Where does my model run? | Entirely on your device after calibration |
| Do you see my ongoing health data? | No—after calibration, we have no access |
| Is data shared with third parties? | Limited statistics to Anthropic during calibration only |
| Can I use the app without sending data? | Yes, free tier is fully on-device |
| Do you sell my data? | No, never |
| Can I delete everything? | Yes—contact privacy@pharo.app |