← HERDA support
HERDA · Privacy policy

HERDA privacy policy

The new HERDA beta stores workouts and profile measurements on your device. It has no advertising, tracking SDK or AI processing of workout data.

For the October 2026 beta · Last updated 3 October 2026

Who is responsible

HERDA is provided by Ola Oldernes Hårstad. Contact oohaarstad@gmail.com for privacy questions.

Profile, workouts and permissions

HERDA saves the exercise definitions, plans, profile information and weight entries you supply, together with workout dates, reps, loads, notes, pauses and measurements. With your permission and compatible hardware, workouts can include heart rate from Apple Health or connected sensors, location and routes, motion, steps and distances.

These records and active-workout recovery checkpoints stay in the app’s local storage. HERDA excludes its health-data storage from iCloud Backup and does not upload new health records through CloudKit. Apple’s own Health and device services operate separately under your Apple settings. You can change Health, location, and motion permissions in system settings. Some measurements will be unavailable when access is denied.

Paired Watch transfers

Completed Watch-owned recordings transfer between your Watch and paired iPhone through Apple’s WatchConnectivity service. A recording includes its measurements, routes if enabled, timing and source-device name. Pending copies remain on the Watch until the iPhone acknowledges a saved import. Apple provides the device transport; the developer does not receive these workout files.

Optional activity presence

Share activity presence is off by default. If you enable it in Settings, HERDA sends a random installation identifier, app version, platform, last-seen time and whether the app is open or recording to Apple CloudKit’s public database. This counts recently active installations. The persistent identifier connects these status updates to the same installation; CloudKit also supplies technical record metadata. It is not anonymous aggregate data.

No workout contents, profile measurements, heart-rate samples or routes are included. Public presence records can be read through the app’s CloudKit database by permitted app clients and the developer. Optional sharing uses your consent. Turning it off stops future updates and attempts to delete your presence record. If the request cannot reach CloudKit, the old record may remain; it stops contributing to the active count after five minutes but is not automatically erased by that time limit. Contact us if you need help with deletion.

Older versions and future storage

Earlier HERDA builds used the private iCloud database for profile and workout synchronization and Watch uploads. Updating does not automatically delete historical CloudKit copies, and old Watch uploads may be read into local history and removed after a saved import. Previously uploaded data remains subject to your Apple account and iCloud settings until separately migrated or deleted.

Supabase storage contracts are being prepared, but this beta has no Supabase connection, sign-in or workout upload. We will update the policy and provide the required choices before connecting that service.

Keeping and deleting data

Saved records remain locally until you delete them or remove the app. Pending recordings and recovery checkpoints can remain until they are successfully saved or discarded. Deleting a local record does not erase a historical iCloud copy created by an older version. There is currently no user-facing export/restore feature or app-operated backup; the developer cannot recover or edit device-only history. Do not uninstall HERDA as a troubleshooting step if you need to retain it.

Support, providers and your rights

If you contact support, we process your email and the information you choose to send to respond, retaining it as needed to resolve the request and meet applicable obligations. Support correspondence is handled through Gmail. Apple provides Health, device permissions, Watch transport, TestFlight and CloudKit under Apple’s privacy information; provider-managed diagnostics and operational logs follow their settings and retention practices.

This support website is hosted on Vercel and may process connection metadata for delivery and security. The website privacy information explains support processing, international transfers and applicable rights. Contact us to request access, correction, deletion or withdrawal of consent for information we process, or complain to Norway’s Datatilsynet. We cannot access records stored only on your device.