RCVRY

RCVRY Privacy Policy

Last updated: 13 September 2026 Effective date: [SET AT LAUNCH]

RCVRY ("we", "us") is an iOS app for logging recovery and contrast-therapy sessions. This policy explains what we collect, why, where it goes, and what you can do about it.

We do not sell your personal information. We do not share it with data brokers. We do not use it for advertising. We do not track you across other companies' apps or websites.


1. Who we are

RCVRY is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS].

For any privacy question, or to exercise the rights in section 8, contact [PRIVACY CONTACT EMAIL].

2. What we collect

2.1 Account information

When you create an account we process, through our authentication provider:

DataWhySource
Email addressTo identify your account, sign you in, and send password resetsYou
Display nameTo personalise the appYou, during onboarding
Account identifierTo associate your sessions with your accountGenerated
PasswordTo secure your account — stored only as a salted hash, never in plain textYou

If you sign in with Apple or Google, we receive an account identifier and the email address that provider releases to us. Apple's Hide My Email is supported; if you use it we only ever see the relay address.

2.2 Recovery sessions

When you log a session we store, and sync to your account:

cryotherapy, hydrotherapy, or a routine)

This is the data that follows you between your iPhone and any other device you sign in on.

2.3 Apple Health data — stays on your device

If you grant permission, RCVRY reads the following from Apple Health: heart rate, heart rate variability, resting and walking heart rate, sleep analysis, respiratory rate, heart rate recovery, blood oxygen, VO2 max, blood pressure, wrist temperature, water temperature, workouts, and your date of birth.

None of this leaves your device. It is read by the app, analysed locally to produce your recovery score and trend views, and stored in the app's own protected container. It is never transmitted to our servers, and we never see it.

RCVRY only ever *reads* from Apple Health. It does not write anything back.

You can revoke this access at any time in Settings → Privacy & Security → Health → RCVRY. We will never use Apple Health data for advertising or marketing, and we will never disclose it to third parties — as Apple's own HealthKit rules require.

2.4 Session selfies — stay on your device

If you take an optional selfie at the end of a cold plunge or sauna session, it is stored in the app's protected container on your device only. It is not uploaded. It is deleted when you delete the session, and when you delete your account.

2.5 Routines, goals, and your schedule

These are stored on your device only. They are not currently synced, which means they do not follow you to another device.

2.6 What we do not collect

No advertising identifiers. No location. No contacts. No analytics or crash-reporting SDK. No third-party trackers of any kind. RCVRY contains no advertising, analytics, or attribution software — the only network destination the app contacts is our own backend.

3. Why we process it, and on what basis

PurposeDataLegal basis (GDPR/UK GDPR)
Create and secure your accountAccount informationContract (Art. 6(1)(b))
Store and sync your sessionsSession recordsContract (Art. 6(1)(b))
Show trends and your recovery scoreApple Health data (on-device)Explicit consent (Art. 9(2)(a))
Keep the service secure and prevent abuseAccount info, request logsLegitimate interests (Art. 6(1)(f))
Meet legal obligationsAs requiredLegal obligation (Art. 6(1)(c))

Health data is a special category under GDPR Art. 9. We rely on your explicit consent, given through the iOS Health permission prompt, and we process it only on your device. You may withdraw that consent at any time — see 2.3 — without affecting anything else in the app.

4. Who we share it with

We share your data with no one for their own purposes. We use one infrastructure provider:

session records, acting as our processor under a data processing agreement.

We will disclose data if compelled by valid legal process, and we will tell you unless legally barred from doing so. If the business is ever sold or merged, your data may transfer as part of it; you will be notified before any such transfer changes how your data is handled.

5. Security

(completeFileProtectionUntilFirstUserAuthentication), so it is encrypted at rest by the operating system and tied to your device passcode.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant supervisory authority within the deadlines the law sets (72 hours under GDPR).

6. How long we keep it

Deleting your account removes your account and cloud data, and wipes this device's local sessions, routines, and selfies.

7. Children

RCVRY is not intended for anyone under 18. Cold water immersion, sauna, cryotherapy, and the other therapies this app tracks carry real physical risks and are not appropriate for children. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact [PRIVACY CONTACT EMAIL] and we will delete it.

8. Your rights

Wherever you live, you can:

machine-readable export, on demand, without contacting us.

account, your cloud data, and this device's local data.

If you are in the EEA, UK, or Switzerland you also have the right to restrict or object to processing, to data portability, and to lodge a complaint with your supervisory authority.

If you are a California resident, you have the rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for any purpose other than providing the app. We will not discriminate against you for exercising any right.

To exercise anything not available in the app, email [PRIVACY CONTACT EMAIL]. We respond within 30 days (45 for CCPA requests, extendable where the law allows).

9. Changes

If we change this policy materially we will tell you in the app before the change takes effect, and update the date at the top.

10. Contact

[LEGAL ENTITY NAME] [REGISTERED ADDRESS] [PRIVACY CONTACT EMAIL]