Cirrus Privacy Policy
Last updated: 13 August 2026
The short version
- Your health data never leaves your iPhone. Cirrus reads it from Apple Health, computes your recovery score on the device, and stores the result on the device. We never receive it, and we could not access it if we wanted to.
- You don't need an account. The app works fully without one. Signing in is optional and stores nothing on our servers.
- We run no analytics and no advertising. There is no tracking SDK, no crash reporter, and no advertising identifier in the app.
- We never sell your data. There is nothing to sell — we don't hold it.
- One thing does reach us: when the app downloads Playbook articles, that request reveals your IP address to our content host, the same way visiting any website does. Details in “What leaves your device”.
1. Who is responsible for your data
The data controller for Cirrus is ⚠️ TO FILL IN — controller name, based in Paris, France.
For anything in this policy — questions, requests, complaints — write to ⚠️ TO FILL IN — privacy email. We aim to reply within 30 days, which is the deadline the GDPR sets.
2. Health data
Cirrus reads the following from Apple Health, with your explicit permission, which you grant through Apple's own permission screen and can withdraw at any time in iOS Settings → Health → Data Access & Devices → Cirrus:
- Resting heart rate
- Walking heart rate average
- Heart rate variability (SDNN)
- Respiratory rate
- Blood oxygen saturation
- Active energy burned
- Sleep analysis (time in bed, awake, core, deep and REM stages)
- Workouts (type, start time, duration, energy burned, average heart rate)
Cirrus only reads from Apple Health. It never writes anything back.
All of it is processed on your device, by code running on your iPhone, to produce a daily recovery score between 0 and 100 and a breakdown of the factors behind it. None of this data is transmitted to us or to anyone else. There is no server that receives it. We have no copy of it, no backup of it, and no ability to retrieve it.
Because this processing happens entirely on your own device, under your control, and we can never access the results, French data protection guidance (CNIL, Deliberation n° 2025-024) treats an app of this shape as software you operate rather than a service we run. We describe it here in full regardless, because you are entitled to know what the app does with your data whether or not we are legally the controller of that particular step.
3. What Cirrus stores on your device
| What | Where | Kept for |
|---|---|---|
| Your daily recovery score, the factor breakdown behind it, and the underlying values (e.g. resting heart rate in bpm, HRV in ms, sleep duration) together with your personal baselines | App storage on your device | Until you delete the app |
| Intra-day score snapshots, used to draw the timeline | App storage on your device | 30 days, then deleted automatically |
| If you sign in: your display name, an account identifier from Apple or Google, and which of the two you used | Your device's Keychain, marked so it is excluded from iCloud Keychain and from encrypted device backups | Until you sign out or delete the app |
| A cached copy of the Playbook articles, so the tab works offline | App storage on your device | Refreshed periodically; cleared when you delete the app |
If you have an Apple Watch paired, your current score and its top factors are sent to your own Watch so it can display them. That transfer is directly between your two devices, over Apple's device-to-device connection. It does not pass through us.
4. Signing in (optional)
Cirrus works completely without an account — every feature, including your recovery score, history and the Playbook. If you choose to sign in, you can use Sign in with Apple or Sign in with Google.
We do not operate a user account system. Nothing about you is created or stored on our servers when you sign in. The name and identifier we receive are written to your device's Keychain and stay there.
Signing in does mean interacting with Apple or Google, who each handle that under their own privacy policies and as their own data controllers:
- Sign in with Google. Google's SDK is embedded in the app. Google's own published disclosure states that it may collect name, email address, phone number, coarse location, user ID, device ID and usage data, some of it for analytics purposes, linked to you. That collection is Google's, under Google's privacy policy, and it only happens if you tap the Google button. If you would rather not, use Sign in with Apple, or don't sign in at all.
- Sign in with Apple. Handled by Apple under Apple's privacy policy. Apple offers to hide your email address if you prefer.
5. What leaves your device
We want to be precise here rather than claim more than is true.
Your health data and your account identifier never leave your device. That is a property of how the app is built, not a promise about how we behave.
One thing does reach a server we control. The Playbook tab downloads its articles from our content host (Supabase, on servers in the European Union). That request is anonymous — it carries no account identifier, no device identifier and no health data — but like any request to any website, it necessarily reveals your IP address and basic technical information (such as the time of the request) to that host, and those appear in its access logs.
We use this only to serve you the content and to keep the service working and secure. We do not use it to build a profile of you, and we do not combine it with anything else — we have nothing else to combine it with.
6. What we never do
- We do not sell your personal data, and we never will.
- We run no advertising, and the app contains no advertising identifier and no ad SDK.
- We run no analytics and no crash-reporting service. Cirrus contains none.
- We do not track you across other apps or websites. The app asks for no tracking permission because it does nothing that would need one.
- We do not use your health data for marketing, or share it with data brokers, insurers or employers.
- We do not access your location. The app contains no location code.
7. Legal bases
| What | Legal basis |
|---|---|
| Reading Apple Health data and computing your score, on your device | Your explicit permission, given through Apple's Health permission screen and revocable there at any time. Because the results never reach us, we do not process this data as a controller. |
| Serving Playbook content (and the IP address in the resulting server logs) | Our legitimate interest in delivering the content you requested and keeping the service operating securely (GDPR Article 6(1)(f)) |
| Keeping you signed in, if you chose to sign in | Performance of the service you asked for (GDPR Article 6(1)(b)) |
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have it corrected if it is wrong;
- have it erased;
- restrict or object to our processing of it;
- receive it in a portable format;
- withdraw consent at any time, without affecting anything done before you withdrew it.
In practice, the honest answer for most of these is that we hold almost nothing about you. Your health data and your recovery history are on your device, not with us — so:
- To see or export your data: it is in the app, on your device. We cannot show you a copy because we do not have one.
- To erase your health data: delete the app. That removes the recovery history and the stored sign-in record from your device. You can separately revoke Cirrus's access to Apple Health in iOS Settings → Health → Data Access & Devices at any time, which stops any further reading immediately.
- To sign out: Settings → Account → Sign out, inside the app. Your recovery data stays on your device.
- For the server access logs described in section 5: write to us at the address in section 1. Please note we can only identify log entries as yours if you can tell us the IP address and approximate time — otherwise there is nothing that links those records to you, which is itself a privacy protection rather than an evasion.
9. How long we keep things
We keep no personal data about you on our systems beyond the server access logs described in section 5, which our content host retains for a limited period as part of normal service operation and security. Everything else lives on your device for as long as you keep the app, as set out in section 3.
10. Where data is processed
Our content host processes requests on servers located in the European Union. Because the only data involved is the technical request information described in section 5, no health data is transferred anywhere, inside or outside the EU.
11. Children
Cirrus is not intended for children. The app is rated for users aged 16 and over, and we do not knowingly collect data from anyone under 16. If you believe a child has used the app in a way that concerns you, contact us at the address in section 1.
12. Changes to this policy
If we change how Cirrus handles data, we will update this policy and change the date at the top. If a change is significant — in particular, if Cirrus ever begins transmitting health data off your device, which it does not do today — we will make that clear in the app itself rather than relying on you to re-read this page.
13. Complaints
If you think we have handled your data improperly, please contact us first — we would rather fix it. You also have the right to lodge a complaint with the French data protection authority:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy — TSA 80715, 75334 Paris Cedex 07, France
www.cnil.fr/en/plaintes
If you live outside France, you may instead complain to your own country's data protection authority.