Zetra AI — Privacy Policy

Last updated: March 12, 2026


Welcome

Zetra AI ("Zetra," "Company," "we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, retain, and protect your personal information when you use the Zetra AI running coach application (the "App," "Service"), including its Apple Watch companion application and related websites.

This Privacy Policy applies to all users of the Service. By downloading, installing, accessing, or using the App, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, do not use the App.

This Privacy Policy should be read together with our Terms of Use.


1. Information We Collect

We collect the minimum information necessary to provide a personalized AI coaching experience. We collect information in three ways: information you provide, information generated through your use of the Service, and information from third-party sources.

1.1 Information You Provide

Account Information. We use Sign in with Apple for authentication. When you sign in, we receive only the information you choose to share:

  • Apple User ID (an opaque, app-specific identifier — not your actual Apple ID)
  • Email address (if you choose to share it; Apple may provide a private relay address that forwards to your real email)
  • Name (if you choose to share it; provided by Apple only on first sign-in)

We do not collect passwords. Authentication is handled entirely by Apple's Sign in with Apple service. We generate an internal user ID (UUID) to identify your account within our systems.

Profile Information. Information you provide during onboarding and profile setup:

  • Age (date of birth or age value)
  • Biological sex
  • Height
  • Weight
  • Running goals (e.g., build a habit, weight loss, 5K, half marathon, marathon)
  • Running experience level (weekly volume, longest run duration, comfort with hard runs)
  • Limiting factors (e.g., time, motivation, injury history, endurance)

Health Affirmation. During onboarding, you confirm your current health status through a self-assessment questionnaire, as described in our Terms of Use §9.2. We store your affirmation status to establish that you have represented your fitness to participate in physical activity.

Support Information. Information you provide when contacting us for help, including your email, description of the issue, and any attachments.

1.2 Information Generated Through Use of the Service

Workout & Activity Data. Data recorded during your runs and workouts, either directly through the App or via the Apple Watch companion app:

  • Date, time, and duration of workouts
  • Distance, pace, and speed
  • Geolocation data (GPS route coordinates, altitude, course/heading, and GPS accuracy)
  • Cadence (steps per minute) and stride length
  • Workout type and completion status
  • Per-kilometer split data (pace, heart rate, cadence, elevation change per split)

Advanced Running Metrics. On supported Apple Watch models (Series 6+, Ultra), we may also collect:

  • Ground contact time (milliseconds)
  • Running power (watts)
  • Vertical oscillation (centimeters)

Motion & Activity Data. We use Apple's CoreMotion framework to collect real-time sensor data during workouts:

  • Step count and cadence (via pedometer)
  • Relative altitude and vertical speed (via barometric altimeter)
  • Activity type classification (stationary, walking, running — via motion activity manager)

Weather Data. When you start a workout, we use Apple WeatherKit to fetch current weather conditions at your location. The following weather data is stored with your workout record:

  • Temperature and "feels like" temperature (Celsius)
  • Humidity (%)
  • Wind speed (km/h)
  • Weather condition (clear, cloudy, rain, snow, etc.)

Health & Biometric Data. If you grant permission to access Apple HealthKit, we may read:

  • Heart rate (resting, active, and workout heart rate)
  • Heart rate variability (HRV)
  • VO2 Max (estimated maximal oxygen consumption)
  • Resting heart rate
  • Calories burned (active and total)
  • Step count
  • Sleep data (duration, stages — if available)
  • Biological sex, height, weight, and date of birth (from HealthKit profile)
  • Menstrual cycle data (flow, phase — opt-in only, for female athletes who choose to enable cycle-aware training adjustments)

Important: Health and biometric data from Apple HealthKit is processed locally on your device and on our secure servers solely for the purpose of AI coaching. It is never sold, shared with advertisers, or used for marketing purposes. See §4 (Apple HealthKit Data) for complete details.

AI Coaching Data. Information related to your interactions with the AI coach:

  • Training plans generated for you
  • AI coaching messages and recommendations
  • Your readiness assessments
  • Conversational coaching context (used to improve coaching accuracy during your session)
  • Feedback you provide on coaching quality

Device & Technical Information. Information collected automatically:

  • Device type, model, and operating system version
  • App version
  • IP address (used for approximate geolocation and security)
  • Language and locale settings
  • Time zone
  • Crash reports and diagnostic data

Usage Data. Information about how you use the App:

  • Features accessed and frequency of use
  • Onboarding completion and step progression
  • Session duration
  • In-app actions (e.g., starting a workout, viewing a training plan)
  • Permission grant/denial events (HealthKit, Location, Motion)

Performance Metrics. We generate derived metrics from your data to provide coaching insights:

  • Estimated fitness level and classification (beginner, intermediate, advanced)
  • Training load and recovery assessments
  • Pace zones, heart rate zones, and cadence zones
  • Progress trends over time
  • Bio-markers: Decoupling index (aerobic efficiency drift), cardiac cost (heart beats per kilometer), and heart rate recovery (1-minute and 2-minute post-workout heart rate drop)
  • Risk flags: Client-side safety assessments generated from workout data (e.g., abnormal heart rate patterns, overtraining indicators)
  • AI coach feedback: Post-run coaching summaries generated by the AI coach and stored with your workout record

1.3 Information From Third-Party Sources

Apple HealthKit. If you authorize HealthKit integration, we read health data as described in §1.2. We may also write workout data back to HealthKit with your permission.

Sign in with Apple. We use Sign in with Apple as our sole authentication method. Apple provides us with an opaque user identifier, and optionally your name and email address (which may be a private relay address). We do not receive your Apple ID password.

Apple App Store / StoreKit. We receive subscription and purchase status data from Apple's StoreKit framework to manage your subscription. Apple handles all payment processing — we never see or store your credit card or payment method details. We store:

  • Subscription active status and product identifier
  • Subscription expiration date
  • Trial start date (if applicable)
  • Feature usage counts (plan imports, plan generations)

2. How We Use Your Information

We use your information for the following purposes:

2.1 To Provide and Personalize the Service

  • Create and maintain your account
  • Generate personalized AI training plans based on your fitness profile, goals, and historical data
  • Provide real-time AI coaching during workouts (pace guidance, form cues, encouragement)
  • Analyze your performance and track your progress over time
  • Calculate heart rate zones, pace zones, and training load
  • Assess your readiness and recovery status
  • Sync workout data between your iPhone and Apple Watch

2.2 To Process AI Coaching

  • Transmit relevant portions of your profile and workout data to our AI backend to generate coaching recommendations
  • Use your historical workout patterns to improve the relevance and safety of AI-generated advice
  • Process your conversational coaching inputs to provide contextual responses

AI Processing Note: We send limited, relevant data to OpenAI's API to generate coaching responses. This includes your fitness profile, recent workout data, and coaching conversation context. OpenAI processes this data under a Data Processing Agreement (DPA) and does not use your data to train their general AI models. See §5 (Third-Party Data Processors) for details.

2.3 To Manage Your Subscription

  • Process and manage subscription status through Apple's StoreKit 2 framework
  • Determine whether you are in a free trial, active subscription, or expired state
  • Verify entitlements across your iPhone and Apple Watch
  • Sync subscription status to Firebase Firestore for cross-device consistency
  • Track feature usage limits (plan imports, plan generations) to enforce entitlement boundaries

2.4 To Improve and Develop the Service

  • Analyze aggregated, de-identified usage patterns to improve features and performance
  • Identify and fix bugs, crashes, and technical issues
  • Develop new features and improve existing ones
  • Conduct internal research on training methodologies and AI coaching effectiveness

2.5 To Communicate With You

  • Send you transactional communications (account confirmation, subscription changes, security alerts)
  • Notify you of material changes to these Terms, our Terms of Use, or the Service
  • Respond to your support requests
  • We do not send marketing emails. If we introduce this in the future, you will be given explicit opt-in consent.

2.6 To Ensure Security and Compliance

  • Detect, prevent, and respond to fraud, abuse, security threats, and technical issues
  • Monitor for violations of our Terms of Use
  • Comply with applicable laws, regulations, and legal obligations
  • Respond to valid legal requests from law enforcement or government authorities

3. How We Share Your Information

We do not sell your personal information. We do not share your personal information for third-party advertising purposes. We share your information only in the following limited circumstances:

3.1 Service Providers (Sub-Processors)

We share the minimum necessary data with trusted third-party service providers who process data on our behalf:

Sub-ProcessorPurposeData ProcessedLocationDPA
OpenAIAI coaching content generationFitness profile (age, sex, goals, experience level), recent workout summaries, coaching conversation contextUnited States✅ Signed
Firebase / Google CloudAuthentication, cloud database, cloud functions, crash reportingAccount data, workout data, app usage analyticsUnited States (Google Cloud)✅ Incorporated in Google Cloud ToS
AppleHealthKit integration, subscription management, push notificationsHealth data (on-device sync), subscription status, device tokensUnited States✅ Apple Developer Agreement
SentryError tracking and crash reportingCrash logs, device info, error context (no health data)United States✅ Sentry DPA

All sub-processors are contractually bound to:

  • Process data only on our instructions
  • Maintain appropriate security measures
  • Not use your data for their own independent purposes
  • Delete or return data upon termination of the service relationship

3.2 What We Do NOT Share With Sub-Processors

  • OpenAI does NOT receive: Raw HealthKit data, GPS coordinates, heart rate readings, sleep data, or any data that directly identifies you (no email, no name). We send anonymized fitness profiles and contextual coaching data only.
  • Firebase Analytics does NOT receive: HealthKit health data (heart rate, HRV, VO2 Max, sleep). Analytics events contain only behavioral data (workout started, onboarding completed, etc.).
  • Sentry does NOT receive: Any health or biometric data. Only technical error context is transmitted.

3.3 Legal Requirements

We may disclose your information if required to do so by law or in good faith belief that such action is necessary to:

  • Comply with a legal obligation, valid subpoena, court order, or government request
  • Protect and defend the rights, property, or safety of Zetra, our users, or the public
  • Detect, prevent, or address fraud, security issues, or technical problems
  • Enforce our Terms of Use

If we receive a request for your personal data from a law enforcement authority, we will:

  • Scrutinize the request for legal validity
  • Notify you of the request unless prohibited by law
  • Provide only the minimum data required

3.4 Business Transfers

If Zetra is involved in a merger, acquisition, bankruptcy, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you (via the App or email) before your personal information is transferred and becomes subject to a different privacy policy.

3.5 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.

3.6 Aggregated and De-Identified Data

We may share aggregated, de-identified data that cannot reasonably be used to identify you. For example, we may publish aggregate statistics about training patterns or app usage trends.


4. Apple HealthKit Data

We treat Apple HealthKit data with the highest level of protection, in full compliance with Apple's App Store Review Guidelines.

4.1 HealthKit Data We Access

With your explicit permission, we read the following data from Apple HealthKit:

  • Heart rate, resting heart rate, and heart rate variability
  • VO2 Max
  • Active and total calories burned
  • Step count
  • Workout data (duration, distance, type)
  • Date of birth, biological sex, height, and weight
  • Sleep analysis data (duration, stages)
  • Menstrual cycle data (flow and phase — opt-in only)
  • Advanced running metrics: ground contact time, running power, vertical oscillation (on supported Apple Watch models)

4.2 How We Use HealthKit Data

HealthKit data is used exclusively for the following purposes:

  • To calculate your heart rate zones, pace zones, and training recommendations
  • To assess your readiness and recovery status before workouts
  • To provide personalized AI coaching based on your physiological data
  • To track your fitness progress over time
  • To populate your profile if you choose to sync from HealthKit instead of entering data manually

4.3 HealthKit Data Protections

In compliance with Apple's requirements and our commitment to your privacy:

  • Never sold. HealthKit data is never sold to any third party, under any circumstances.
  • Never used for advertising. HealthKit data is never used for advertising, marketing, or to serve you ads.
  • Never shared with advertisers or data brokers. HealthKit data is never disclosed to advertisers, data brokers, or any third party for marketing purposes.
  • Raw HealthKit data is never stored in iCloud. We do not write raw HealthKit readings (individual heart rate samples, HRV values, VO2 Max readings, sleep records) to iCloud containers. However, workout summaries — which include aggregated metrics such as average heart rate, cadence, and per-kilometer splits derived during your workout session — are stored in your personal iCloud Documents for cross-device access (see §5.5 below).
  • Never logged to analytics. Raw HealthKit readings (heart rate, HRV, VO2 Max, sleep data) are never sent to Firebase Analytics, Google Analytics, or any third-party analytics service.
  • Used solely for coaching. HealthKit data is processed locally on your device and on our secure servers for the sole purpose of providing and improving your AI coaching experience.
  • Deleted upon account deletion. When you delete your account, all stored health-related data is permanently deleted from our servers.

4.4 Writing Data to HealthKit

With your permission, we may write workout summaries back to Apple HealthKit, including:

  • Workout type, duration, and distance
  • Calories burned during the workout
  • Heart rate data recorded during the workout

You can revoke HealthKit read/write permissions at any time through Settings > Privacy & Security > Health on your iOS device.


5. Third-Party Data Processors

5.1 OpenAI (AI Coaching)

We use OpenAI's API to generate AI coaching content. When you interact with the AI coach:

  • What we send: A curated subset of your data, including your fitness profile (age, sex, goals, experience level, recent workout summaries), coaching conversation context, and current training plan parameters. We do not send your name, email, GPS coordinates, or raw HealthKit readings.
  • Processing: OpenAI processes this data to generate coaching text responses. Under our Data Processing Agreement, OpenAI does not use your data to train their general-purpose AI models.
  • Retention by OpenAI: Under our DPA, OpenAI retains API input/output data for up to 30 days for abuse monitoring purposes, then deletes it. Zero-retention is available and may be enabled.
  • Legal basis: Contract performance (necessary to provide you with AI coaching services).

5.2 Firebase / Google Cloud

We use Firebase for database (Cloud Firestore), cloud functions, and analytics:

  • Database (Cloud Firestore): We store the following in Firestore:
    • User document: Profile information (account creation date, email if shared, name if shared), subscription entitlements (active status, expiration date, product ID, feature usage counts), and linked identity references (Apple User ID mapping)
    • Identity links: Mapping between your Sign in with Apple identifier and your internal Zetra user ID
  • Cloud Functions: Server-side processing for AI coaching, plan generation, and entitlement validation
  • Analytics: Behavioral events only (feature usage, onboarding progress, workout start/complete/cancel, permission status, app errors). User properties include age, height, and weight for aggregate analysis. No raw health data (heart rate, HRV, VO2 Max, sleep) is included in analytics events.
  • Crash reporting: Technical crash data, device info, and stack traces (no health data)

5.3 Apple Services

  • HealthKit: On-device health data sync (see §4)
  • StoreKit 2: Subscription management (Apple handles all payment processing; we never see your credit card information). We receive transaction verification data including product ID, purchase date, and expiration date.
  • APNs: Push notification delivery (we send notification content; Apple delivers it)
  • Sign in with Apple: Our sole authentication method. We receive an opaque user identifier and, optionally, your name and email address (which may be a private relay address).
  • WeatherKit: We request current weather conditions at your location when you start a workout. Apple processes your location to return weather data; we store a weather snapshot (temperature, humidity, wind speed, conditions) with your workout record. Apple's WeatherKit is governed by Apple's privacy policy.
  • CoreMotion: On-device motion sensor framework. All CoreMotion data (pedometer, altimeter, activity recognition) is processed locally on your device. No raw sensor data is transmitted to external servers.
  • iCloud: See §5.5 below.

5.4 Sentry

We use Sentry for real-time error tracking, crash reporting, and application performance monitoring. Sentry receives:

  • Error messages, stack traces, and crash logs
  • Device type, OS version, app version, and build number
  • User ID (opaque UUID, for correlating issues to user sessions)
  • Session ID (for grouping errors within a single app launch)
  • App performance data: network request timing, file I/O tracing, and app hang detection
  • Contextual tags (used for filtering and debugging): training level (e.g., beginner/advanced), main goal (e.g., improve 5K), age (if available), biological sex (if available), whether benchmark data exists (VO2 Max, 5K/10K times — boolean flags only, not the actual values)
  • During active workouts: Run ID, workout type, simulation flag, segment count, and elapsed time

Privacy protections in Sentry:

  • Email and username are scrubbed from all Sentry events before transmission
  • GPS coordinates (latitude/longitude) are scrubbed from all breadcrumbs before transmission
  • No health, fitness, or workout performance data (heart rate, pace, distance, calories) is sent to Sentry
  • Sentry data is retained for 90 days, consistent with our crash report retention policy (see §6)

5.5 Apple iCloud

We use Apple iCloud to store and sync your data across your devices. iCloud storage is governed by Apple's privacy policy and your personal iCloud account settings.

iCloud Documents (Run Storage): After each workout, a detailed run record is saved to your personal iCloud Documents. This record includes:

  • Workout metadata (date, duration, distance, pace)
  • Heart rate, cadence, and elevation sample timelines
  • GPS route coordinates
  • Per-kilometer splits
  • Bio-markers (decoupling index, cardiac cost, heart rate recovery)
  • Weather snapshot at workout start
  • AI coach feedback for the run
  • App version and run source (iPhone or Watch)

iCloud Key-Value Store: We sync lightweight data across your devices using Apple's iCloud Key-Value Store:

  • Onboarding completion status
  • Runner profile data (age, sex, height, weight, goals, experience level)
  • Weekly training plan

Important: All iCloud data is stored in your personal iCloud account, not on Zetra servers. Zetra does not have access to your iCloud account. You can manage iCloud storage through your device's Settings > [Your Name] > iCloud.


6. Data Retention

We retain your personal information only for as long as necessary to provide the Service, comply with our legal obligations, and resolve disputes.

6.1 Retention Periods

Data CategoryRetention PeriodJustification
Account InformationUntil you delete your accountNecessary to provide the Service
Profile InformationUntil you delete your accountNecessary for personalized coaching
Workout & Activity DataUntil you delete your accountNecessary for progress tracking and coaching
Health & Biometric DataUntil you delete your accountNecessary for coaching; deleted immediately upon account deletion
AI Coaching ConversationsActive session + 90 daysNecessary for coaching continuity; automatically purged
Device & Technical Data12 monthsNecessary for debugging and service improvement
Crash Reports90 daysNecessary for bug fixing
Usage Analytics24 months (aggregated/de-identified)Necessary for service improvement
Support Correspondence3 yearsLegal and quality assurance purposes
Subscription Records7 years after expiryTax and legal compliance

6.2 Account Deletion

You may request deletion of your account and all associated personal data at any time by:

  • Using the Settings > Account > Delete Account feature in the App
  • Emailing us at team@zetra.run

Upon receiving a deletion request:

  1. Your account will be deactivated immediately
  2. All personal data, workout data, health data, and coaching history will be permanently deleted from our servers within 30 days
  3. All data held by sub-processors will be deleted in accordance with their data processing agreements
  4. Anonymized, aggregated data that cannot be linked back to you may be retained for analytical purposes
  5. Data required to be retained by law (e.g., subscription transaction records for tax purposes) will be retained for the minimum legally required period, then deleted

Note: Deletion is irreversible. Once completed, your data — including workout history, training plans, and progress — cannot be recovered.

6.3 Data Portability

You have the right to export your data in a machine-readable format. You can request a data export by contacting us at team@zetra.run. We will provide your data in JSON or CSV format within 30 days.


7. Data Security

We implement industry-standard administrative, technical, and physical safeguards to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

7.1 Technical Safeguards

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher
  • Encryption at rest: Personal data stored on our servers is encrypted at rest using AES-256 encryption
  • Authentication: Secure authentication via Firebase Authentication with support for Sign in with Apple
  • Access controls: Strict role-based access controls limit employee access to personal data on a need-to-know basis
  • Infrastructure: Our backend runs on Google Cloud / Firebase infrastructure, which maintains SOC 2, ISO 27001, and other security certifications

7.2 Organizational Safeguards

  • Employee access to personal data is limited to those who require it for their job function
  • Employees are trained on data protection obligations
  • We conduct regular security reviews of our systems and practices
  • Sub-processors are vetted for security practices and bound by DPAs

7.3 Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR
  • If the breach is likely to result in a high risk to your rights, we will notify you directly without undue delay, via email and/or in-app notification
  • Our notification will include: the nature of the breach, the categories of data affected, the likely consequences, and the measures we have taken or propose to take to address the breach

8. Your Privacy Rights

Depending on where you live, you may have specific rights regarding your personal information. We honor these rights regardless of your location, to the extent technically feasible.

8.1 Rights Available to All Users

All users of the Service may:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete personal data
  • Deletion: Request deletion of your personal data (see §6.2)
  • Portability: Request your data in a portable, machine-readable format (see §6.3)
  • Withdraw consent: Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

To exercise any right, contact us at team@zetra.run. We will verify your identity before processing your request and respond within 30 days.

8.2 Additional Rights for EEA, UK, and Swiss Users (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have the following additional rights under the General Data Protection Regulation (GDPR) and equivalent local laws:

  • Right to restriction: Request that we restrict processing of your personal data in certain circumstances
  • Right to object: Object to processing of your personal data based on our legitimate interests
  • Right to object to automated decision-making: You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal effects concerning you. Our AI coaching does not make decisions with legal or similarly significant effects — it provides recommendations only.
  • Right to lodge a complaint: You may lodge a complaint with your local Data Protection Authority (DPA). Since Zetra is based in Israel, you may also contact the Israeli Privacy Protection Authority (PPA).

Data Controller: Zetra AI is the data controller for all personal data processed under this Privacy Policy.

Contact for GDPR inquiries: team@zetra.run

Legal Bases for Processing:

PurposeLegal Basis
Providing the Service (account, coaching, workouts)Contract — necessary to perform our contract with you (Terms of Use)
Processing HealthKit dataConsent — explicit consent granted through iOS permission prompts
Processing health data for AI coachingConsent — you affirmatively agree during onboarding
Subscription managementContract — necessary to manage your subscription
Usage analytics (aggregated)Legitimate interest — improving our services, balanced against minimal privacy impact
Security and fraud preventionLegitimate interest — protecting you and the Service
Legal complianceLegal obligation — complying with applicable laws
Crash reportingLegitimate interest — maintaining service reliability

International Data Transfers: Your data may be transferred to and processed in the United States (where our sub-processors are located) and Israel (where Zetra is based). When transferring personal data outside the EEA/UK, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all sub-processors
  • Israel's adequacy decision by the European Commission (Israel is recognized as providing an adequate level of data protection)

8.3 Additional Rights for California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

Right to Know. You have the right to know:

  • The categories of personal information we collect
  • The purposes for which we use each category
  • The categories of third parties with whom we share personal information
  • The specific pieces of personal information we have collected about you

Right to Delete. You have the right to request deletion of your personal information, subject to certain exceptions allowed by law.

Right to Correct. You have the right to request correction of inaccurate personal information.

Right to Non-Discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights.

Do Not Sell or Share.

  • We do not sell your personal information. Zetra has never sold personal information and has no plans to do so.
  • We do not share your personal information for cross-context behavioral advertising.
  • We do not use or disclose sensitive personal information for purposes other than providing the Service.

Categories of Personal Information Collected (for CCPA disclosure):

CCPA CategoryExamplesSold?Shared for Advertising?
IdentifiersName, email, user ID❌ No❌ No
Personal Information (Cal. Civ. Code §1798.80)Age, sex, height, weight❌ No❌ No
Internet ActivityApp usage, feature interactions❌ No❌ No
GeolocationGPS route data❌ No❌ No
Sensory DataHeart rate, HRV (from HealthKit/Apple Watch)❌ No❌ No
Health InformationFitness metrics, workout data, sleep data❌ No❌ No
InferencesFitness level, training load, zone calculations❌ No❌ No

To exercise your California privacy rights, contact us at team@zetra.run or use the in-app account management features. We will verify your identity and respond within 45 days, with the possibility of a 45-day extension if reasonably necessary.

Authorized Agents. You may designate an authorized agent to make requests on your behalf. We may require you to verify your identity directly and confirm the agent's authorization.

8.4 Additional Rights for Other US State Residents

If you reside in Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia (or other states with enacted consumer privacy laws), you may have similar rights to California residents, including:

  • Right to access, correct, and delete your personal data
  • Right to opt out of targeted advertising (we do not engage in targeted advertising)
  • Right to opt out of sales (we do not sell your data)
  • Right to non-discrimination
  • Right to appeal our decision regarding a privacy request

Contact us at team@zetra.run to exercise these rights.

8.5 Additional Rights for Brazilian Users (LGPD)

If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including confirmation of processing, access, correction, anonymization/blocking/deletion of unnecessary data, data portability, information about sharing, and the right to withdraw consent.


9. Children's Privacy

The App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are under 13, do not use the App and do not provide us with any personal information.

If you are between 13 and 17 years of age, you may use the App only with the consent of a parent or legal guardian. By allowing your child to use the App, the parent or guardian agrees to be bound by our Terms of Use and this Privacy Policy, and assumes responsibility for all activity on the child's account.

If we learn that we have collected personal information from a child under 13, we will take steps to delete such information from our systems as soon as possible. If you believe we may have inadvertently collected information from a child under 13, please contact us immediately at team@zetra.run.


10. Cookies and Tracking Technologies

10.1 In the App

The Zetra AI App is a native iOS application. We do not use browser cookies within the App. However, we use the following technologies:

  • Firebase Analytics SDK: Collects anonymized usage events (feature interactions, session data). No health data is logged. You can opt out of analytics by contacting us at team@zetra.run.
  • Sentry SDK: Collects crash reports, error diagnostics, and application performance metrics (network timing, app hangs). No health data is logged. See §5.4 for full details.
  • Apple Frameworks: Standard iOS frameworks including HealthKit (health data), CoreLocation (GPS), CoreMotion (motion sensors, pedometer, altimeter, activity recognition), WeatherKit (weather data), and StoreKit 2 (subscriptions). These operate under Apple's privacy controls and your device permissions.

10.2 On Our Website

If you visit our website (zetra.run), we may use:

  • Essential cookies: Required for website functionality (session management, form submission)
  • Analytics cookies: Used to understand website traffic and usage patterns (e.g., Google Analytics). These are anonymized and not linked to your App account.

We do not use advertising cookies, retargeting pixels, or social media tracking pixels on our website.


11. Geolocation Data & Route Privacy

11.1 How We Use GPS Data

When you record a run with GPS tracking enabled, we collect precise geolocation data (latitude, longitude coordinates over time) to:

  • Record your running route
  • Calculate distance, pace, and elevation
  • Provide location-aware AI coaching (e.g., segment-based guidance)

11.2 Route Privacy

  • Your routes are private by default. The App does not have social sharing features; your route data is visible only to you.
  • Route data is stored securely on our servers and is not shared with any third parties except as described in §3.
  • You can delete individual run records, including their GPS data, at any time through the App.

11.3 Safety Notice

Please be aware that GPS tracking inherently records where you run, including start and end locations that may reveal your home or workplace address. You are responsible for your own safety when recording route data. Zetra does not evaluate the safety of any running route.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.

12.1 Notification of Changes

  • Material changes: We will notify you of material changes via in-app notification and/or email at least 30 days before the changes take effect.
  • Non-material changes: Minor clarifications or formatting changes may be made without advance notice but will be reflected in the "Last updated" date at the top of this Policy.

12.2 Continued Use

Your continued use of the App after any changes to this Privacy Policy constitutes your acceptance of the updated Policy. If you do not agree with the changes, you must stop using the App and delete your account.


13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Zetra AI Email: team@zetra.run Website: zetra.run

For GDPR-specific inquiries (EEA, UK, and Swiss users): Email: team@zetra.run Subject line: "GDPR Data Request"

For CCPA/CPRA requests (California residents): Email: team@zetra.run Subject line: "CCPA Privacy Request"

We will acknowledge receipt of your request within 5 business days and respond substantively within:

  • 30 days for GDPR requests (extendable by 60 days for complex requests)
  • 45 days for CCPA/CPRA requests (extendable by 45 days if reasonably necessary)

14. Governing Law

This Privacy Policy is governed by the laws of the State of Israel, without regard to its conflict of laws provisions. Any disputes arising from this Privacy Policy shall be resolved in the courts of Tel Aviv, Israel, except where mandatory local data protection laws require otherwise (e.g., GDPR may allow you to bring claims in your country of residence).


15. Summary of Key Points

QuestionAnswer
Do we sell your data?Never.
Do we share data with advertisers?Never.
Do we use HealthKit data for ads?Never. Apple prohibits this, and so do we.
Who processes your AI coaching data?OpenAI (under DPA — they don't train on your data).
Where is your data stored?Google Cloud (US) and Israel.
Can you delete your data?Yes. Settings > Account > Delete Account, or email team@zetra.run.
Can you export your data?Yes. Contact team@zetra.run for a JSON/CSV export.
Is your data encrypted?Yes. TLS in transit, AES-256 at rest.
Are GPS routes shared publicly?No. Routes are private by default. No social features.
Minimum age to use the App?13 years. Parental consent required for ages 13-17.

This Privacy Policy is effective as of March 12, 2026.

© 2026 Zetra AI. All rights reserved.