Privacy Policy

Effective: August 26, 2026
The short version: your health data never leaves your device. It moves directly from Oura's servers to your iPhone and into Apple Health — it never passes through us, and we have no way to see it. To keep the app working reliably, we collect anonymous crash diagnostics and subscription records. Those never contain health data. No advertising identifiers, no user accounts, no data sales.

What the App Does With Your Data

OuraSync reads health metrics (resting heart rate, heart rate variability, blood oxygen, body temperature, and VO₂ Max) from your Oura account using Oura's official API, and writes them to Apple Health on your device. All processing happens on your iPhone.

Sign-In and Tokens

You sign in with your Oura account using OAuth. Your Oura password is never seen by the app. To complete sign-in, a minimal token service operated by Steelheart Labs exchanges and refreshes OAuth tokens with Oura. Only authentication tokens transit this service — never health data. The service is stateless: it stores nothing and does not log token contents. Tokens are kept in your device's Keychain.

Diagnostics We Collect

So we can find and fix crashes and sync failures across devices, the app sends anonymous crash and performance diagnostics to Sentry (Functional Software, Inc.), our diagnostics processor. These reports contain stack traces, device model, OS version, and app version — they are engineered to never contain your health values, your Oura tokens, or your identity, and are not linked to you. You can turn crash reporting off anytime in Settings → Privacy.

What We Never Collect

Data Retention and Deletion

What we keep on our servers: nothing. Your health data never reaches Steelheart Labs, so there is no copy of it to retain or delete. The token service that completes your Oura sign-in is stateless — it holds no data between requests and logs no token contents.

What stays on your device: the sync ledger. The app keeps a sync ledger on your iPhone. We want to be specific about it, because it is the one place OuraSync holds a copy of your Oura readings outside Apple Health.

For each metric and day, the ledger records: the value that was written, the timestamp of the write, the status of that write (written, skipped because the value fell outside plausible bounds, failed, or deferred), a reason when a write was skipped or failed, and two internal version numbers that identify how the value was transformed and which revision of the sample it represents.

It holds the value, not just a record that a write happened, for three reasons. The app compares what it previously wrote against what Oura reports now, so it can correct a sample rather than duplicate it. It shows you your own sync history in the app, so a gap or a wrong-looking reading is visible without opening Apple Health. And when a sync fails, the value is what makes the failure diagnosable rather than merely reported.

The ledger lives only on your iPhone. It is excluded from device backups, is never uploaded to Steelheart Labs, never written to iCloud, and never sent to any analytics or crash-reporting service. There is no automatic expiry — entries stay until you remove them. You remove them by using Purge All in Settings, which clears both the ledger and the samples the app wrote to Apple Health, or by deleting the app, which removes all of its local data. Signing out clears your Oura tokens but does not by itself clear the ledger — use Purge All or delete the app if you want the values gone as well. The health samples themselves live in Apple Health, under your control, and remain there until you remove them.

Tokens. Your Oura access and refresh tokens are stored in your device's Keychain and nowhere else. Signing out erases them immediately. You can also revoke OuraSync's access from your Oura account at cloud.ouraring.com at any time, which stops further syncing. If you revoke access and also want the readings the app already recorded removed, run Purge All or delete the app.

Diagnostics and subscription records. Crash reports (Sentry) and subscription status (RevenueCat) contain no health values, no tokens, and no name, email, or other identifier — only an anonymous app-generated identifier. They are kept only as long as needed to diagnose problems and administer your subscription, and are then deleted on our providers' retention schedules.

Removing data yourself, immediately. The purge tool in Settings removes every sample OuraSync wrote to Apple Health, per metric or all at once. Sign Out erases your tokens. Deleting the app removes all local data, including the sync ledger. These take effect at once and do not require contacting us.

Requesting deletion from us. Email support@steelheartlabs.com and ask us to delete your data. Because there are no accounts and we hold no health data, in most cases there is nothing on our side to delete, and we will tell you so. For anything we do hold — support correspondence, a problem report you chose to send us, or diagnostic and subscription records tied to an anonymous identifier you provide — we will delete it within 72 hours of your request. If we cannot match any records to you, we will tell you that within the same 72 hours rather than leave your request open.

When you cancel a subscription. See section 3 of the Terms of Service for how canceling affects data the app has already written to Apple Health.

Purchases

Subscriptions are billed entirely by Apple — we never receive your payment details. We use RevenueCat (RevenueCat, Inc.) to manage subscription status and understand aggregate metrics like trial conversion and renewals. RevenueCat receives an anonymous app-generated identifier and transaction records — never your name, email, or any health data.

Support and Problem Reports

If you choose to contact support, you can attach a problem report generated by the app. It contains your local sync history and device diagnostic logs. It is created and shared only when you explicitly export it, and you can review its contents before sending.

Your Controls

Children

OuraSync is not directed at children under 13, and we do not knowingly collect personal information from anyone — including children.

Changes

If this policy changes, the updated version will be posted here with a new effective date. Any material change to what we collect would be prominently disclosed in the app before taking effect. The health-data commitment is not subject to change: it is how the product is built.

Contact

Questions: support@steelheartlabs.com