Privacy Policy

Ground App · Effective Date: March 8, 2026 · Last Updated: April 14, 2026

1. Introduction

Ground App ("we," "our," or "the App") is a mobile application designed to guide users through personalized breathing exercises for nervous system regulation. This Privacy Policy describes how we collect, use, store, and protect your information, including health and biometric data obtained from wearable devices and health platforms.

By using the App, you consent to the practices described in this policy. If you do not agree, please discontinue use of the App.

2. Information We Collect

2.1 Information You Provide Directly

2.2 Health and Biometric Data

With your explicit consent, we access the following data from connected devices and platforms:

Apple Health (HealthKit):

Oura Ring (via Oura Cloud API):

Whoop (via Whoop API):

Garmin (via Garmin Health API / HealthKit):

2.3 Automatically Collected Information

Oura Usage Data Disclosure: When you connect your Oura Ring to Ground App, Oura may collect certain Usage Data related to your use of the Oura API and platform. Oura may use this Usage Data for its own business purposes as described in Oura's Privacy Policy.

2.4 Information We Do NOT Collect

3. How We Use Your Information

We use your data exclusively to provide and improve the App's core functionality:

PurposeData Used
Personalized breathwork recommendationsHRV, resting heart rate, sleep data, readiness scores, stress levels, recovery scores
Nervous system state assessmentAggregated biometric data from connected devices
Proactive wellness notificationsBiometric trends and anomaly detection
Session history and progress trackingSession records, mood ratings, technique usage
Voice-guided sessionsInstructor preference, audio settings
App improvementAnonymized, aggregated usage patterns

We do not use your health data for advertising, marketing to third parties, or any purpose unrelated to providing you personalized breathwork guidance.

4. How We Store and Protect Your Data

4.1 On-Device Storage

4.2 Cloud Storage (Optional)

If you create an account and enable cloud sync:

4.3 Third-Party Services

ServicePurposeData Shared
Apple HealthKitRead/write health metricsAccessed on-device only; never transmitted to our servers without consent
Oura Cloud APIRetrieve readiness, sleep, and stress dataOAuth token stored in Keychain; data fetched directly to your device
Whoop APIRetrieve recovery, sleep, and strain dataOAuth token stored in Keychain; data fetched directly to your device
Garmin Health APIRetrieve stress, Body Battery, and respiration dataOAuth token stored in Keychain; data fetched directly to your device
Anthropic (Claude API)Generate personalized session recommendationsAnonymized nervous system state summary (no raw biometric values); no personally identifiable information
Mistral (Voxtral)Text-to-speech for voice-guided sessionsSession narration text only; no personally identifiable information
SupabaseAccount authentication and optional cloud syncAccount info, session history (if sync enabled)

Important: Raw biometric data (heart rate values, HRV readings, sleep staging) is never sent to Anthropic, Mistral, or any AI service. Only computed, anonymized summaries (e.g., "nervous system state: mildly stressed") are used for generating recommendations.

5. Apple HealthKit Compliance

In accordance with Apple's HealthKit guidelines:

6. Oura Data Usage Compliance

In accordance with the Oura API Agreement:

7. Whoop Data Usage Compliance

In accordance with the Whoop API Terms of Use:

8. Garmin Data Usage Compliance

In accordance with Garmin's Health API Terms:

9. Your Rights and Controls

You have full control over your data:

ActionHow
Disconnect a deviceSettings > Connected Devices > Toggle off
Revoke HealthKit accessiOS Settings > Privacy & Security > Health > Ground App
Revoke Oura accessApp Settings or cloud.ouraring.com > Connected Apps
Revoke Whoop accessApp Settings or app.whoop.com > Profile > Connected Apps
Revoke Garmin accessApp Settings or Garmin Connect > Account > Connected Apps
Delete session historySettings > Delete Account / Reset Data
Delete all dataSettings > Delete Account (removes all cloud-stored data)
Export your dataSettings > Export My Data (downloads all your data as CSV and JSON)
Access your dataSettings > Export My Data, or contact privacy@groundapp.live

Upon account deletion, all associated data is permanently removed from our servers within 30 days. On-device data is removed immediately. All cached wearable data (Oura, Whoop, Garmin) is deleted immediately upon disconnection or account deletion.

10. Data Retention

11. Data Security and Breach Notification

11.1 Security Measures

We employ commercially reasonable administrative, technical, and physical security measures to protect your data, consistent with GDPR Article 32 standards. These include:

11.2 Breach Notification

In the event of a security breach affecting your personal or health data:

12. Children's Privacy

The App is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.

13. State-Specific Privacy Rights

13.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:

To exercise these rights, contact us at privacy@groundapp.live. We will respond within 45 days.

13.2 Washington Residents (My Health My Data Act)

If you are a Washington state resident, the following applies under the Washington My Health My Data Act (RCW 19.373):

13.3 Other U.S. States

We comply with applicable state privacy laws, including but not limited to the Colorado Privacy Act, Connecticut Data Privacy Act, Virginia Consumer Data Protection Act, and other state laws that provide consumer privacy rights. If you are a resident of a state with applicable privacy legislation, you may exercise your rights by contacting privacy@groundapp.live.

14. International Users and GDPR

14.1 Legal Basis for Processing (EEA/UK Users)

For users in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:

14.2 Your GDPR Rights

14.3 Data Transfers

Your data is processed in the United States. For transfers from the EEA/UK, we rely on Standard Contractual Clauses and your explicit consent for health data.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the App and updating the "Last Updated" date. For material changes affecting health data practices, we will provide prominent notice and, where required by law, obtain fresh consent. Continued use of the App after changes constitutes acceptance of the revised policy.

16. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

Privacy Inquiries: privacy@groundapp.live

Legal Inquiries: legal@groundapp.live

End User Support: info@groundapp.live

Website: https://groundapp.live/privacy

This Privacy Policy was last reviewed and updated on April 14, 2026.