Woah Recovery App

Privacy Policy

Last updated: September 26, 2026

This policy describes how Woah ("the app") handles your data. The app is developed by Petter Höglander, an individual developer based in Sweden.

1. Data we access

Woah reads the following from Apple Health — read-only, never written back:

This data is processed entirely on your device to compute your daily recovery score, Lifestyle score, Fitness age and Longevity estimate. It is never sold, used for advertising, or shared with any analytics providers.

Some things are not in Apple Health, so Woah asks you instead: your daily habit logs (alcohol, nicotine, caffeine, food, and how you felt), manual stress ratings, and your answers to the Longevity intake. You choose whether to give them, they are stored as described in section 4, and they are never included in analytics.

The Longevity intake asks about smoking, drinking, diet, how you would rate your own health, how long people in your family have lived and what runs in it, conditions you have been diagnosed with (including depression or anxiety), how socially connected you feel, whether you live alone, whether you have a sense of purpose, and — only when Apple Health holds no VO₂max for you — how fit you feel compared to others your age. Every question is optional and skippable, and the app only ever asks about things no sensor can measure. Several of these answers are what the GDPR calls special category data concerning health. Woah processes them on the basis of your explicit consent, given by answering; you can withdraw it at any time by clearing your data (section 9), and the answers are used for one purpose only — computing the estimate shown to you on your own device.

2. AI-generated content

Woah generates personalized daily messages and insights using Anthropic's Claude AI. To do this, health summaries are transmitted to Anthropic's servers — for example: "Recovery score 72, sleep 7.5h, mild stress signal." The illness radar's summary line — its 1–10 score and which overnight signals deviate from your own baselines, including the wrist-temperature deviation where measured — is part of the same daily summary.

What is included: your first name, in the notifications Woah writes for you, so a message can address you by name. If you are paired with someone, their first name is included the same way in the notifications about them, and the values they chose to share with you are included in the text Woah writes about them — their score, their sleep and activity, and their longevity estimate and fitness age when they share those. Your age, sex and a band word derived from your weight and height are included; the measurements themselves are not. Because the requests carry the number of days you have lived, your date of birth can be derived from them.

What is never included: your surname, email or any account identifier — Woah has no logins, so no such identifier exists. No answer you give the Longevity intake is ever sent to the AI — not your smoking or drinking, not your diet, not your family history, diagnoses or mental health, not how connected you feel or whether you live alone. That is stated as a category and not as a list, so it stays true when the questions change. Requests pass through a small relay Woah runs on Cloudflare before they reach Anthropic. The relay reads a random app identifier (the same one RevenueCat uses) to check that your subscription is active, and it can see your IP address, as any server you connect to can. It forwards the request without that identifier, and it never stores or logs what a request or its answer contains: only the time, the model, whether it succeeded, and a shortened one-way hash of the identifier so that a daily usage limit can be kept. Anthropic therefore sees the relay's address, not yours, and receives no identifier linking one day's request to another.

Anthropic processes these summaries to generate text and does not retain them for training. See Anthropic's Privacy Policy for their data practices.

Woah Coach. When you write to the coach, your message and a summary of your recent health data are sent to Anthropic so it can answer. Conversations stay on your device — they are never synced, backed up, or shared with a partner. Once a day Woah may distil a short block of plain facts from a conversation, such as a goal you set or that you train on Tuesdays, so the coach still knows them tomorrow. That block is stored in your own private iCloud; the conversation itself is not. When you ask the coach about a workout, or it looks one up for you, a one-line summary of the session is sent as well: its kind, start time, length, distance, average and maximum heart rate, minutes in each heart-rate zone, calories, the source that recorded it, and the recovery score the next morning. Since version 3.6 the same summary also says what the session was walked into: that morning's recovery score, HRV and resting heart rate, the training in the two days before, and your habit-log entries for the evening before and the session's day (alcohol, nicotine, caffeine, mood, fluids, stress rating, sickness and symptoms, and any note you wrote), which are the same entries the coach's daily summary already includes. The GPS route of a session is read from Apple Health to draw a map on your phone and is never sent anywhere.

3. Partner sharing

Pairing with a partner is free, and always your choice. When you pair, Woah publishes a snapshot of the metrics you have chosen to share — via your sharing settings — to Apple's CloudKit, as a separate record for each person you share with. Revoking someone deletes their copy.

Woah keeps the record of who may read your data on the server, not only in your phone's own list. That way a reinstalled or restored device cannot go on sharing with someone the app can no longer name for you. You can see every reader, and revoke any of them, under Partner → Who can see your data.

Connections made before Woah recorded them this way are also served by a single shared snapshot, kept for backwards compatibility, which can be read by anyone already paired with you. The same screen offers Stop sharing with unknown readers, which removes that shared snapshot so revocation becomes absolute.

Your Longevity and Fitness age are shared with a paired partner as the resulting number only. The intake answers behind them never leave your own storage.

4. Data stored on your device

The app stores the following locally using Apple's UserDefaults (encrypted by iOS data protection):

So that your history survives a new phone, Woah mirrors the entries you have made yourself — habits, stress ratings, locked daily scores, profile, goals, and the coach's distilled memory — to your personal iCloud (the CloudKit private database). Only you can read it: it is not sent to us, and not shared with a partner. Raw Apple Health data is never mirrored.

Your current score and today's answers are also written to a storage area shared with the Woah widgets and the Apple Watch app, so they can show a number without recomputing anything.

5. Product analytics & purchase attribution

Woah uses PostHog for product analytics, hosted on servers in the European Union. We collect anonymous usage events — for example which screens are viewed and which features are used — to understand how the app is used and improve it.

Woah also uses GoMarketMe to understand which marketing partner referred a subscription purchase, so that partner can be credited. When you make or restore a purchase, a device identifier and purchase information (such as the product and transaction) are shared with GoMarketMe for this purpose.

Woah also uses Singular to understand which ad campaign a new install came from, so we can measure whether our advertising works. When you first install the app, and when you make or restore a purchase, a device identifier and campaign or purchase information are shared with Singular for this purpose.

Our website at woah-recovery.app counts visits using the same EU-hosted PostHog service, so we can tell whether the people we reach actually arrive. This is deliberately the lightest form of measurement we could use:

The pages hosting this policy and our terms are not measured at all.

6. Feedback you send us

The app includes an optional feedback form. When you use it, the app opens your own email client with a message addressed to the developer — you choose what to write, can optionally attach a screenshot, and send it from your own email account. The app itself never reads or transmits this content; you send it directly, and we receive only what you choose to send. Any feedback is used solely to respond to you and improve the app.

7. What we do not do

8. Children

Woah is not intended for users under 13 years of age. We do not knowingly collect data from children.

9. Your rights (GDPR)

If you are located in the European Economic Area, you have the right to access, correct, and delete your personal data. Since most data lives on your device:

10. Data retention

11. Third-party services

12. Changes to this policy

We may update this policy as the app evolves. The date at the top of this page reflects the most recent revision. Continued use of the app after changes constitutes acceptance.


Questions? Contact us at petter@woah-recovery.app