Privacy Policy
Last updated: 5 September 2026 ·
Provider: YUHA HEALTH LLC (DBA Yuha) ·
Registered: New Jersey, USA
YUHA is a personal health-coaching app operated by YUHA HEALTH LLC,
a New Jersey limited liability company based in Jersey City, NJ ("YUHA,"
"we," "us," or "our"). It consolidates your fitness data from connected
services and provides AI-driven insights. This policy explains what we
collect, how we use it, and the choices you have. We try to keep this
short and plain-English.
Short version: we only collect what we need to coach you.
We don't sell your data. You can disconnect any source or delete your
account at any time. AI requests are sent to our model provider
(Anthropic Claude or Google Gemini) but are not used to train their
models.
1. Who we are
YUHA is operated by YUHA HEALTH LLC, doing business as Yuha,
a limited liability company organized under the laws of the State of
New Jersey, with a principal place of business in Jersey City, New
Jersey, USA ("YUHA," "we," "us," or "our"). You can reach us at
hello@yuha.app for any privacy
question, data export request, or deletion request.
2. Information we collect
2.1 Information you give us
- Account info: name, email, hashed password (PBKDF2-SHA256, never stored in plaintext).
- Profile preferences: distance units, age, weight, training days, personal records.
- Photos you choose: a profile picture, and any image you attach in chat. You pick each one yourself, from your camera or your photo library. YUHA receives only the image you select and never reads the rest of your library.
- Health data you log manually: workouts, meals, mood, goals, custom notes.
- Chat messages: what you write to the YUHA assistant, so we can keep context across the conversation.
2.2 Information from connected services
-
Strava (when you authorize the connection). Your activity history (distance, duration, pace, heart rate, route GPS, elevation, and the kudos and comment counts on your own activities; never who gave kudos or what anyone wrote), your athlete name and id, and basic account information per the OAuth scopes you grant
(
activity:read_all, profile:read_all).
-
Garmin Connect (when you provide credentials): activities, sleep, body battery, stress, VO2max, training load, daily steps, resting heart rate.
-
Google Health (Fitbit & Pixel) (when you authorize the connection): activities, sleep, daily steps, heart rate, and related wellness metrics per the scopes you grant.
-
Apple Health (iOS app only, when you grant Health access): workouts, steps, sleep, heart rate, resting heart rate, heart-rate variability, VO2max, active energy, walking/running distance, and body measurements you choose to share. When you also allow Workout Routes, we read the workout routes your Apple Watch recorded (the GPS positions along an outdoor workout) together with that workout's heart rate, cadence and power over time, so its map, splits and charts can be drawn. A route is stored rounded to about 110 meters, a route shorter than 1 km is never shown, the raw points are not kept once the summary is made, and all of it is deleted with your account. This data is read on your iPhone via Apple's HealthKit framework and securely uploaded to your YUHA account. We use Apple Health data only to provide YUHA's features to you. Your dashboard, readiness score, insights, and coaching. We never use HealthKit data for advertising or marketing, never sell it, never share it with third parties or data brokers, and never store it in iCloud. You can revoke access at any time in iOS Settings → Privacy & Security → Health, or disconnect Apple Health in the app's Sources screen.
-
Health Connect (Android app only, when you grant Health Connect access): workouts, steps, sleep, heart rate, resting heart rate, heart-rate variability, VO2max, active energy, walking/running distance, blood oxygen, respiratory rate, and body measurements you choose to share. Health Connect is Android's on-device health store; apps such as Fitbit, Samsung Health, Wear OS and Pixel write into it, and YUHA reads only the categories you approve on the Android permission screen. This data is read on your Android phone and securely uploaded to your YUHA account. YUHA only reads from Health Connect and never writes to it. We use Health Connect data only to provide YUHA's features to you: your dashboard, readiness score, insights, and coaching. We never use it for advertising or marketing, never sell it, and never share it with third parties or data brokers. You can revoke access at any time in Android Settings → Security & privacy → Privacy → Health Connect (or in the Health Connect app on older Android versions), or disconnect Health Connect in the app's Sources screen.
- We do not receive credit card numbers, contact lists, or location data outside the GPS tracks attached to your activities.
2.3 Technical information
- Session cookie: a single HttpOnly cookie named
yuha_session, expires after 30 days. Used solely to keep you logged in.
- Analytics (website only): on the YUHA website we use Google Analytics (GA4) to understand aggregate, anonymized usage (such as page views and which features are used) so we can improve YUHA. GA4 sets its own cookies (for example
_ga) and processes this data under Google's terms; IP addresses are anonymized, Google signals and ad personalization are disabled, and we do not enable cross-site advertising profiles. The YUHA iOS and Android apps load no analytics at all. The apps contain no advertising or analytics SDK, never access your device's advertising identifier, and do not track you across other companies' apps or websites. We use no other third-party tracking SDKs anywhere.
- Server logs: standard request logs (IP, timestamp, endpoint) retained for up to 30 days for security and debugging.
3. How we use your information
- To provide the core service: show your dashboard, generate insights, answer your questions, build training plans, send weekly digests if you opt in.
- To send you transactional emails (password resets, weekly digests if subscribed, security notices). We do not send marketing emails.
- To improve YUHA: diagnose bugs, identify patterns at an aggregated level. We do not build advertising profiles.
4. AI processing
When you chat with YUHA, your message and a summary of relevant context
(recent activities, goals, memory facts) is sent to our model provider —
either Anthropic (Claude) or Google (Gemini), depending on configuration —
so the model can produce a reply. These providers process the request
under their commercial API terms and do not use API content to
train their models. Your data is not shared with any other AI
vendor.
5. Strava-specific terms
Powered by Strava. YUHA reads your Strava data through the Strava API only to power the features you use inside YUHA, under Strava's API Agreement and API Policy.
- What we read: your activities (distance, duration, pace, heart rate, route, elevation, and the kudos and comment counts on them) and your athlete name and id, per the scopes you grant. New activities arrive automatically through Strava's webhooks. We never read who gave you kudos or what anyone wrote, and we never store other athletes' data.
- Only you see it: your Strava data is shown only to you, inside your YUHA account. It is never shown to other YUHA users, and it is never sold or shared. The service providers in section 8 process it on our behalf and for nothing else.
- We never write to Strava: YUHA does not modify, post, or delete anything on your Strava account.
- Withdrawing consent: tap Disconnect on the Sources page in YUHA, or remove YUHA at strava.com/settings/apps. Either way YUHA stops reading your Strava data at once.
- Deletion: when you disconnect, remove YUHA at Strava, or delete your YUHA account, we delete the Strava data tied to your account (activities, splits and heart-rate summaries, athlete stats, the summaries the coach wrote from them, and the access tokens) and email you a confirmation. You can also ask for deletion at support@yuha.app. An activity you delete or make private on Strava is removed from YUHA within 48 hours.
- Strava's own policies: your use of Strava stays governed by Strava's Privacy Policy, which controls over this section for Strava data if the two ever conflict. Strava may collect usage data about YUHA's use of its API, such as request volumes, under its own policies.
6. How we store and protect your data
- Storage: MongoDB Atlas, encrypted at rest. Hosted in regions disclosed by Atlas.
- Transit: all API traffic uses TLS (HTTPS).
- Multi-tenant isolation, every record carries your
user_id; queries always filter by it. Other users cannot see your data.
- Passwords: hashed with PBKDF2-SHA256. We cannot recover your password; resets generate a new one.
- Tokens: Strava OAuth tokens and Garmin session blobs are stored encrypted in our database, scoped to your user.
7. How long we keep your data
- While your account is active, for as long as you use YUHA.
- Server logs, up to 30 days.
- Strava data, right away when you disconnect Strava, remove YUHA at Strava, or delete your account (section 5); an activity you delete or make private on Strava is removed within 48 hours.
- After account deletion, health data is removed within 30 days; backups are purged within 90 days.
8. Sharing
We share data only with the service providers required to run YUHA:
- MongoDB Atlas, database hosting.
- Anthropic or Google. AI model inference (per section 4).
- Resend: transactional email.
- Google Analytics: aggregate, anonymized usage analytics on the website only, never in the mobile apps (per section 2.3).
- Open-Meteo, Photon, Nominatim, OpenRouteService, OSRM: public APIs queried for weather, geocoding and routing. We send only the place names or coordinates needed for the request, never your account identity.
- Microsoft Azure, application hosting.
We do not sell your data and do not share it for advertising.
9. Your rights and choices
- Access & export, email hello@yuha.app and we'll send your data within 30 days.
- Correction: edit your profile in-app, or email us.
- Deletion: delete your account from the profile screen, or email us. Connected-service tokens and cached data are removed with the account.
- Disconnect a source. Go to Sources in YUHA and click Disconnect. We immediately revoke the token and stop syncing.
- Withdraw consent, by disconnecting or deleting your account.
10. Children
YUHA is not intended for children under 13 (or under 16 in regions where applicable law sets a higher age). We do not knowingly collect data from children.
11. International transfers
YUHA is hosted on infrastructure that may process data outside your country of residence. Where applicable, we rely on standard contractual clauses to safeguard transfers.
12. Changes to this policy
If we change this policy materially, we'll post the updated version at this URL and, where appropriate, notify you by email. The "Last updated" date above always reflects the current version.
13. Contact
YUHA HEALTH LLC
Jersey City, New Jersey, USA
Email: hello@yuha.app
Questions, requests, or complaints? Email hello@yuha.app.