Overview
Areta is a personal operating system for your health, fitness, nutrition, and weekly planning. This policy explains what information Areta collects, why, how it's used, who it's shared with, and the choices you have. It applies to the Areta mobile app and the areta-ai.com web app.
Most of what Areta collects is information you choose to connect or enter yourself — we don't sell your data, and we don't use it for advertising.
Information we collect
Account information. Email address, name, and password (handled by our authentication provider, Supabase — we never see your raw password) when you create an account.
Profile and goals. Information you enter during onboarding and in Settings — your mission, goals, current phases, coaching preferences, time zone, wake/bed times, and recurring days you set for weekly review, grocery shopping, and meal prep.
Health and fitness data (opt-in). If you connect Apple Health, Areta reads categories including body weight, body composition, steps, heart rate (including resting and variability), VO2 max, active/basal energy, distance, flights climbed, walking metrics, blood oxygen, respiratory rate, sleep, and workout sessions. This is read-only — Areta never writes to Apple Health. Data older than a rolling 3-year window is not imported. You can disconnect Apple Health at any time in Settings, which stops future syncing (previously imported data is handled per the retention and deletion terms below).
Nutrition data. Meals and food items you log, including quantities, units, macros, and notes. If you use the barcode scanner, the scanned barcode is sent to the free, third-party Open Food Facts database to look up product nutrition information — no other personal data is sent with that lookup.
Calendar data (opt-in, read-only). If you connect Google Calendar, Microsoft Outlook, or Apple Calendar, Areta reads your event titles and times so they can appear alongside your meals and workouts in your daily schedule. Areta requests read-only access and cannot create, edit, or delete events in your calendar. OAuth tokens for Google and Microsoft are encrypted at rest; Apple Calendar uses an app-specific password you provide, which is also encrypted at rest. You can disconnect any calendar at any time in Settings.
Usage and device information. Standard technical information such as app version, device type, and basic request logs, used for debugging and reliability.
How we use your information
- To generate and adjust your personalized nutrition and workout plans
- To build your daily schedule, combining calendar events with meals and workouts
- To generate your weekly review brief and other AI-assisted summaries
- To track progress toward the goals you set
- To operate, maintain, and secure the app
AI-assisted features
Some features — such as your weekly review brief and parts of onboarding — use a third-party AI provider (Anthropic) to turn your account information into structured, personalized content. This can include information like your goals, a summary of your recent metrics (for example, derived from health or nutrition data you've logged or synced), and your own notes. The AI provider processes this information solely to generate the requested content for you, under its own data-processing and confidentiality terms with us; it is not used to train third-party models.
Who we share information with
We share information only as needed to run Areta:
- Service providers: Supabase (database, authentication, file storage) and Vercel (app hosting) — both process data on our behalf under their own security commitments.
- Calendar and health platforms:Google, Microsoft, and Apple, solely to read the calendar data you've authorized; Apple Health, solely on your device, through Apple's HealthKit framework.
- Open Food Facts, for barcode-to-nutrition lookups (barcode only, no account data).
- Anthropic, for the AI-assisted features described above.
- Your trainer,if you've connected with one through Areta — trainers can see the client data needed to build and adjust your programs. You can end that relationship at any time in Settings.
We do not sell your personal information, and we do not share it for advertising.
Data retention
We keep your data for as long as your account is active. Imported Apple Health data is kept on a rolling 3-year window — older records are not retained. If you delete your account, we delete your personal data within a reasonable period, except where we're required to retain it (for example, financial records) or where it's been aggregated so it no longer identifies you.
Your choices
- Disconnect Apple Health, or any calendar connection, at any time in Settings
- Edit or delete the goals, notes, and logged data you've entered
- Request a copy of your data or deletion of your account by contacting us below
Security
Data is encrypted in transit (HTTPS) and calendar OAuth tokens/credentials are encrypted at rest. Access to your data is restricted by row-level security policies scoped to your account. No method of storage or transmission is 100% secure, but we work to protect your information using industry-standard practices.
Children's privacy
Areta is not directed to children under 13, and we do not knowingly collect information from them.
International users
Areta is operated from the United States, and your information is processed there.
Changes to this policy
If we make material changes to this policy, we'll update the effective date above and, where appropriate, notify you in the app.
Contact us
Questions about this policy or your data? Email dgrayze249@gmail.com.