Legal
Privacy Policy
1. About this privacy policy
This privacy policy explains what data Tentava collects, what we use it for, who we share it with and what rights you have. We have written it as specifically as we can. Where we state a retention period, we mean it.
Sections 1 to 28 apply to Tentava users in the current Switzerland launch. Section 29 contains information that may become relevant if EU/EEA law applies in the future. Where mandatory law applies differently, that law prevails.
Language versions
This English version is the primary reference version. All other language versions are translations of this text and are provided so that you can read this policy in your own language.
This English text is our primary reference for maintaining consistent translations. Each published language version is intended to provide the same information. Nothing in this clause limits rights that you have under mandatory local law or prevents you from relying on information provided to you in a language required by that law.
Tentava is not a medical application. The app does not replace medical advice, diagnosis or treatment. Details are set out in our medical disclaimer.
2. Who is responsible for your data
| Controller | KITAV Vuong, sole proprietorship |
|---|---|
| Owner | Kim Tai Vuong |
| Address | Allmendstrasse 3b, 6048 Horw, Switzerland |
| Company identification number | CHE-337.875.632 |
| Privacy | privacy@tentava.app |
| Support | support@tentava.app |
| Website | https://tentava.app |
KITAV Vuong is the controller under the Swiss Federal Act on Data Protection and, where the GDPR applies, the controller within the meaning of Art. 4(7) GDPR.
3. Privacy contact
For any privacy matter, contact us at privacy@tentava.app. We respond within the statutory time limits.
Data protection adviser
We have not appointed a data protection adviser. Under Swiss law, appointing a data protection adviser is voluntary for private controllers under Article 10 of the FADP. For any privacy matter you can reach us directly at privacy@tentava.app.
4. Who and what this policy covers
This policy covers the Tentava iOS app, the website tentava.app and all associated features. These include your account and profile, workout planning and logging, progress, statistics and goals, friend, coach and chat features, public workouts, custom exercises, training locations, health and fitness integrations, AI-generated insights, subscriptions, and support and reporting.
It does not cover third-party services you use yourself. If you connect Tentava to Apple Health or Wahoo, the data held in those services is governed by the privacy policies of Apple and Wahoo respectively.
5. Terms used
| Term | What it means in this policy |
|---|---|
| Personal data | Any information that relates to you or makes you identifiable. |
| Health data | Information relating to your physical or mental health. In Tentava this can include body measurements, heart rate, respiratory rate, sleep, injuries and, depending on their content and context, certain workout and fitness data. Health data is a special category of personal data under Article 9 of the GDPR and sensitive personal data under Swiss law. |
| Processing | Anything we do with data: collecting, storing, using, sharing, deleting. |
| Processor | A company that processes data on our behalf and on our instructions — for us, mainly Google and OpenAI. |
| Consent | Your voluntary, informed and explicit agreement, which you can withdraw at any time. |
6. Where your data comes from
| Source | What comes from it |
|---|---|
| From you | Registration, profile details, logged workouts, custom exercises, goals, messages, photos and videos, feedback. |
| From your sign-in provider | If you sign in with Apple or Google: an identifier and basic profile details. We never receive your password. |
| From your device | Device details, app version, language setting, time zone, IP address, push token, and your location when you search for a place. |
| From Apple Health | Only with your permission. See section 10. |
| From Bluetooth sensors | Only if you connect a sensor. See section 12. |
| From Wahoo | Only if you set up the connection. See section 11. |
| From FIT files | Only if you import a file. See section 13. |
| From Apple (App Store) | Subscription status and receipt information. We never receive payment details. |
| From other users | When someone sends you a friend request, messages you, invites you to a workout or reports you. |
7. What data we process
7.1 Account and profile data
| Data | Required or optional |
|---|---|
| Email address | Required |
| Username | Required |
| First and last name | Optional, if this field is available in the app version you use |
| Date of birth or birth year | Required for age eligibility and age-dependent calculations; the app collects only the level of detail shown in the registration flow |
| Gender | Optional, including an option not to state it |
| Height and weight | Optional |
| Profile picture | Optional |
| Bio and linked social media profiles | Optional |
| Training profile, experience level, goals, preferred training days | Optional |
| Injury profile | Optional — health data |
| Identifier, sign-in method, account status | Technically required |
| Consent records with timestamp and text version | Technically required |
7.2 Workout and health data
Planned and completed workouts, exercises, muscle groups, sets, repetitions, weights, intensity and RIR, duration, rest periods, training volume, estimated one-repetition maximum, progress, goals and target values, statistics and your full workout history. In addition, body measurements, heart rate, respiratory rate, calories burned, power, cadence, speed, distance and elevation, where those values come from the sources listed in section 6.
Some of these data can qualify as health data depending on their content and context. Where special-category or sensitive-data rules apply, we process the relevant data only after obtaining the consent required for that processing. Where the GDPR applies and health data is involved, we rely on explicit consent under Art. 9(2)(a) GDPR together with the applicable Art. 6 GDPR basis stated in section 8.
7.3 Social, chat and coach data
Friendships and friend requests, follower relationships, group invitations, blocks, public and joinable workouts and join requests, coach assignments and the individual permissions you grant to a coach, coach notes, activity likes and views, and the content of your chat messages including attachments.
7.4 Content you create
Custom exercises, workout titles, notes, and photos and videos attached to your workouts and exercises.
7.5 Location data
We use your device location only when you search for a training location or attach a location to a workout. It serves to centre the place search on your surroundings. We do not track your location in the background. We use Google Places and Apple MapKit for the place search. We save the locations you mark as favourites.
If you make a planned workout public, the location attached to it becomes visible to other users so that they can find the workout. You can grant or withdraw location access at any time in your iOS settings.
7.6 Device and technical data
Device model, operating system version, app version, language setting, time zone, IP address, log data, security events and a push token for notifications. We use Firebase App Check and Apple App Attest to verify that requests come from genuine instances of our app.
7.7 Subscription and transaction data
Subscription status, plan, renewal information and the receipt information needed to verify your subscription. Payment is handled entirely by Apple. We never receive or store credit card or bank details.
7.8 Support, reports and moderation
Feedback you submit in the app, including category, free-text message, app version, platform, country or region and your account identifier; messages you send to support@tentava.app; and reports you submit about content or users, together with our decision on them. To help our administrators classify and summarise feedback, the feedback message and its category and technical context can be processed through an API provided by OpenAI. This internal classification is separate from the personalised AI features in section 14 and does not use your workout history. Please do not include health data or other sensitive information that is not necessary for your feedback.
7.9 Usage data
With your analytics consent, Firebase Analytics records a limited set of product events together with an app-instance identifier and technical context such as device type, operating system, app version, language and approximate country or region derived from the network connection. Details are in section 18. We do not use this information to track you across third-party apps or websites and we do not show advertising.
8. Purposes, legal bases and retention at a glance
This table assigns each processing activity its purpose, legal basis, recipients and retention period.
| Purpose | Data | Legal basis | Recipients | Retention |
|---|---|---|---|---|
| Provide and operate your account | Account and profile data | Contract, Art. 6(1)(b) GDPR | Life of the account | |
| Plan, log and analyse workouts | Workout and health data | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Life of the account | |
| Read data from Apple Health | HealthKit data | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Not shared | Display only; imported activities for the life of the account |
| Write values back to Apple Health | Body measurements, energy, heart rate, water, workouts | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Apple, on your device | Controlled by you in Health |
| Import Wahoo workouts | Wahoo workouts, access token | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Google, Wahoo | Access token and connection record: until you disconnect; imported workout data: until you delete the workout or your account |
| Process FIT files | Time series and metrics from the file | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | File deleted immediately; metrics for the life of the account | |
| Record heart rate live | Bluetooth measurements | Consent, Art. 6(1)(a) GDPR; explicit consent, Art. 9(2)(a) GDPR where health data is involved | Live processing during the workout; stored heart-rate series and derived values until you delete the workout or your account | |
| Generate AI insights | Minimised structured workout-performance data, high-level training goals and comparison aggregates described in section 14; no sensitive health metrics or user-authored free text | Separate consent; where the GDPR applies, Art. 6(1)(a) GDPR | OpenAI Ireland Ltd., its approved subprocessors and Google | AI result until deletion or account deletion; OpenAI abuse-monitoring logs for up to 30 days under standard API controls |
| Friends, feed and public workouts | Social data | Contract, and consent for public content | Google, other users | Life of the account |
| Chat | Messages and attachments | Contract, Art. 6(1)(b) GDPR | Google, recipient | Life of the chat |
| Coaching | Data released per permission | Explicit consent | The coach you choose | Until you withdraw the permission |
| Send notifications | Push token, event data | Contract and consent | Google, Apple | Until you opt out or after 180 days of inactivity |
| Manage subscriptions | Subscription and transaction data | Contract and legal obligation | Apple, Google | 10 years under Article 958f of the Swiss Code of Obligations |
| Provide support | Feedback, messages | Contract and legitimate interest | 24 months | |
| Handle reports | Report, reported content, decision | Legitimate interest. Where the Digital Services Act applies, there is also a legal obligation under that Act, known as the DSA. | Report and decision for 12 months, or 24 months for repeat cases; copied evidence normally for 180 days unless a case requires longer | |
| Prevent abuse, maintain security | Logs, security events, App Check | Legitimate interest, Art. 6(1)(f) GDPR | Google, Apple | 30 to 90 days |
| Analyse usage | Named events, app-instance identifier, device/app context and approximate country or region | Consent | 14 months | |
| Classify and summarise support feedback | Feedback message, category, app version, platform and country or region | Contract and legitimate interest in improving support and product quality, Art. 6(1)(b) and (f) GDPR | OpenAI Ireland Ltd., its approved subprocessors and Google | Feedback record for 24 months; OpenAI abuse-monitoring logs for up to 30 days under standard API controls |
Legitimate interest means we have a genuine interest of our own in the processing and have assessed that your interests do not override it. You can object to such processing — see section 24.
9. Health and fitness data
Health and fitness information can be among the most sensitive data Tentava processes. We treat data that qualifies as health data as sensitive personal data under Swiss law and, where the GDPR applies, as a special category under Art. 9 GDPR.
Where data qualifies as health data or sensitive personal data, we process it only after obtaining the explicit consent required for the relevant feature. Other workout records that do not qualify as health data are processed only for the purposes described in this policy.
What we do not do with your health data
- We do not sell it and we do not share it for advertising.
- We do not use it for advertising, marketing or data mining.
- We do not pass it to insurers, employers or data brokers.
- We do not store health data in iCloud.
- We use data from Apple Health only for the features you open in the app.
Your consent
Where consent is required for health and fitness processing, we ask for it through a clearly marked action in the app. Consent is not hidden in our terms. You can refuse or withdraw it at any time in Settings. Withdrawal applies to future processing and does not make earlier processing unlawful. Features that require the withdrawn data will stop working; unrelated parts of Tentava remain available.
10. Apple Health (HealthKit)
When you connect Apple Health, iOS asks for your permission. You decide for each data type individually whether we may read or write it. You can change these permissions at any time in the Health app.
10.1 Data we can read
We request permission for the data types below. Whether we actually receive them depends entirely on what you allow.
| Area | Data types |
|---|---|
| Activity | Steps, walking and running distance, cycling distance, flights climbed, exercise minutes, move minutes |
| Energy | Active energy burned, basal energy burned |
| Body | Body mass, body mass index, body fat percentage, waist circumference |
| Heart and circulation | Heart rate, resting heart rate, walking heart rate average, heart rate variability, VO2 max |
| Nutrition | Water intake |
| Running metrics | Running power, running speed, stride length, ground contact time, vertical oscillation |
| Cycling metrics | Cycling power, cycling speed, cadence, functional threshold power |
| Sleep | Sleep analysis |
| Workouts | Workouts recorded by other apps and devices |
| Routes | Route data attached to workouts |
| Important note on route data Route data from Apple Health contains precise location information. We read it solely so that imported workouts can be displayed in full. We do not store route coordinates on our servers. This data never feeds into AI insights. Our software explicitly blocks the transmission of location and route information to AI services. |
|---|
10.2 Data we can write
If you allow it, we write values you have recorded back to Apple Health: body mass, body mass index, body fat percentage, waist circumference, active energy burned, water intake, heart rate and your workouts. We only ever write values that you recorded yourself or that came from a sensor you connected.
10.3 Withdrawing permission
You can withdraw permission at any time in the Health app under Data Access & Devices. Access ends immediately. Workouts already imported remain in Tentava until you delete them or delete your account.
11. Wahoo
When you connect your Wahoo account, we open a sign-in page hosted by Wahoo. We never receive your Wahoo password. After you approve, Wahoo issues us an access token.
We request the following permissions: read power zones, read workouts, read routes, access stored data, and read basic account information.
We use these to import your Wahoo workouts and display them in Tentava as activities. The token and the import are handled by our backend, not by the app. The token is stored encrypted and is never delivered to your device.
You can disconnect at any time in your settings. We then delete the token and the connection record immediately. Workouts already imported remain until you delete them. Disconnecting does not delete any data held in your Wahoo account — for that, contact Wahoo.
12. Bluetooth sensors
You can connect a heart rate sensor over Bluetooth, such as a chest strap. Tentava uses the standard Bluetooth heart rate service for this.
| Question | Answer |
|---|---|
| What values are read? | Only heart rate in beats per minute. When connecting, we also process the device name and identifier. |
| Are the values stored? | Yes. During the workout we display them live. Afterwards we store the average, minimum and maximum, and the series of readings, as part of the workout record. |
| What are they used for? | Live display during the workout, analysis afterwards and statistics. Bluetooth heart-rate values and raw sensor time series are not transmitted to OpenAI for the personalised AI features described in section 14. |
| How do I withdraw? | You can withdraw Bluetooth access at any time in your iOS settings, or disconnect the sensor in the app. |
13. Importing FIT files
You can import workout files in FIT format. The file is transmitted to our backend over an encrypted connection, processed there and deleted immediately afterwards — whether or not the import succeeded.
From the file we read heart rate, speed, power, cadence, elevation and respiratory rate as time series, together with distance, duration and the corresponding average and maximum values.
| We do not store location data from FIT files. FIT files often contain GPS coordinates. Our processing only checks whether route points are present at all, and stores nothing more than the fact that the activity included a route. The coordinates themselves are never stored, processed further or displayed. |
|---|
14. AI features
Tentava offers insights generated with the help of a language model. For this we work with OpenAI. We describe it in full here so that you can decide whether you want to use these features.
14.1 Which features use AI
| Feature | What it does | When it runs |
|---|---|---|
| AI Training Review | Produces a written assessment of load, progress and recommendations after a workout. | Automatically after each completed workout, while your separate AI consent remains active. |
| AI Weekly Summary | Summarises your training week in plain language and puts your goals in context. | Automatically once per calendar week in the background, while your separate AI consent remains active and the feature is enabled. |
The personalised OpenAI-powered user features covered by this consent section are AI Training Review and AI Weekly Summary. AI Training Review runs automatically after each completed workout only while your separate AI consent remains active. AI Weekly Summary runs automatically once per calendar week only while your separate AI consent remains active and the feature is enabled. No other user-facing training or health feature sends personal data to OpenAI unless this policy and the in-app consent notice are updated before that processing begins. The separate internal classification of support feedback is described in sections 7.8 and 22 and does not use your workout history.
14.2 What data is transmitted
Depending on the feature, the request contains only the minimised structured records and aggregates listed below. We do not send your name, username, email address, Firebase user ID, date of birth, free-text bio, private messages, workout notes, photos, videos, payment data, precise location or route coordinates. Training and goal references in the AI payload use technical aliases rather than the real account or training-document identifiers. The remaining payload can still relate to your account, so we treat it as personal data and do not claim that it is anonymous. The personalised AI payload is designed not to include sensitive health data.
- Training dates and types; exercise names; sets, repetitions, weights, duration, intensity, training volume, RIR and progression values relevant to the analysis
- High-level training goal categories and timeframes relevant to the analysis; body measurements, target body weight, injury information and medical or health-related free text are excluded
- Aggregated comparison values from relevant current and previous workouts, muscle-group load indicators and data-quality indicators
- No heart-rate values, respiratory-rate values, sleep data, injury data, body measurements, Apple Health source records, raw sensor time series, contact details, social graph, chat content, user-authored free text, media, location or route data
- The output language and the technical instructions for formatting the response
| AI data minimisation Tentava constructs a defined server-side feature payload and is designed to exclude direct account identifiers, contact details, private communications, user-authored free text, sensitive health metrics, precise location, route data and user-uploaded media. Only the structured data categories described in section 14 may be included. If a future AI feature requires sensitive health data, Tentava will not enable that transfer until the contractual basis, this policy and the in-app consent information have been updated as required. The remaining information can still be personal data, so we do not describe it as anonymous. |
|---|
14.3 What happens to the data at OpenAI
| Question | Answer |
|---|---|
| Who is the recipient? | OpenAI Ireland Ltd., acting as a processor for KITAV Vuong, together with approved affiliates and subprocessors required to provide the API service. |
| Is the data used to train AI models? | No. OpenAI states that API data is not used to train or improve its models unless the customer expressly opts in. KITAV Vuong does not opt in. |
| Is the data stored permanently? | No. Tentava sends Responses API requests with store=false, so Tentava does not ask OpenAI to retain response application state. Under standard API controls, abuse-monitoring logs that may contain inputs and outputs can be retained for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect OpenAI’s services or third parties from harm. |
| Where is the data processed? | OpenAI Ireland Ltd. and approved affiliates or subprocessors may process data in Ireland, the United States, Switzerland, EEA/UK locations and other countries listed in OpenAI’s current subprocessor register. International-transfer safeguards are described in section 23. |
| Does the AI make decisions about me? | No. The output is explanatory guidance. It does not produce legal or similarly significant effects, and it must not be treated as medical advice. |
| Are the results stored? | Yes. Tentava stores the generated review or summary in your account until you delete it or delete your account, subject to the retention exceptions in section 25. |
For customers in Switzerland, OpenAI Ireland Ltd. acts as a processor under the OpenAI Services Agreement and the Data Processing Addendum entered into by KITAV Vuong and OpenAI. Tentava uses the Responses API with store=false, so Tentava does not ask OpenAI to retain response application state. OpenAI states that API data is not used to train or improve its models unless the customer expressly opts in; KITAV Vuong does not opt in. Under standard API controls, abuse-monitoring logs that may include inputs and outputs can be retained for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect OpenAI’s services or third parties from harm. Processing can involve approved OpenAI affiliates and subprocessors. International-transfer safeguards are described in section 23.
14.4 Your choice
AI processing is optional and is not activated merely because you purchase or enable the Peak subscription. Before the first AI transfer under this consent version, the app shows a separate AI consent view describing the two features, the structured data categories, OpenAI processing and your choices. You must actively confirm the consent text and choose to allow the AI features. We store the decision status, consent version, decision time, language, source, app version and a decision identifier in your account and decision history. If you do not consent, the two OpenAI-powered features remain disabled; unrelated Tentava functions remain available. You can withdraw consent at any time under My Profile > AI Features. Withdrawal stops future OpenAI transfers and disables both the automatic post-workout review and the automatic weekly summary. Existing AI results remain in your account until you delete them, use an available deletion control, or delete your account. AI outputs can be incomplete or incorrect and are not medical advice, diagnosis or treatment.
15. Social features and public content
Tentava has social features. What you share there can be seen by others. Below is exactly what is visible to whom.
| Content | Who can see it |
|---|---|
| Username | All signed-in users — it exists so that people can find you. |
| Profile picture | All signed-in users. A profile picture is optional. You can remove it at any time. |
| Bio | According to your setting: only you, your friends, or everyone. Private by default. |
| Activity list | According to your setting: only you, your friends, or everyone. Private by default. |
| Linked social media profiles | According to your setting. Private by default. |
| Goals and goal progress | Not public. Visible only to a coach to whom you have granted the relevant permission. |
| Public workouts | Visible to everyone, including the attached location — that is the purpose of the feature. |
| Chat messages | Only to the people involved. See section 16. |
| Photos and videos attached to workouts | Only you, unless you explicitly make the workout public. |
You can block other users. Blocking prevents contact and mutual visibility.
16. Chat messages
We will say this plainly: chat messages in Tentava are not end-to-end encrypted. They are stored on our servers and are encrypted in transit and at rest. Technically, we are able to access them.
We do so in three situations only: when a message is reported to us and we have to review the report, when we are legally required to, or when it is unavoidable in order to fix a technical fault. Every such access is logged.
We deliberately chose not to use end-to-end encryption, because otherwise we could not review reported content or protect you from harassment. Please do not treat chat messages as a confidential channel for highly sensitive information.
17. Coaches
You can connect with a coach. When you do, you decide for each individual permission what the coach may see or do.
| Permission | What the coach can see or do with it |
|---|---|
| Training overview | Your completed and planned workouts |
| Goals | Your goals and their progress |
| Exercise statistics | Your performance history per exercise |
| Plan workouts | Create workouts for you |
| Log workouts | Record workouts on your behalf |
| Profile details | Your profile information |
Without a granted permission, a coach sees nothing beyond an ordinary profile. Permissions are enforced on our servers, not only in the app. You can withdraw any permission individually at any time, or end the connection entirely — the effect is immediate.
We do not automatically share your injury profile or body measurements with coaches.
18. Usage analytics and diagnostics
We use Firebase Analytics from Google and record a limited number of named events:
- Sign-in — including the method used and whether it was a new registration
- Completion of onboarding
- Opening the subscription screen
- Starting, changing or restoring a subscription
- Requesting account deletion, and its completion
These events help us measure registrations, account deletions, subscription conversion and where people stop in a flow. Google assigns an app-instance identifier and may process device/app context and an approximate country or region derived from the network connection. We do not attach your workout content, health metrics, private messages, name or email address to analytics events.
Website analytics
On tentava.app and dev.tentava.app, Google Analytics for Firebase is loaded only after you actively accept analytics in the website consent interface. Before acceptance, the website does not download Google Analytics code, create analytics cookies or send analytics requests to Google. Refusing analytics does not restrict essential website functions.
The website records an automatic page view and a limited set of named interactions: a successfully completed contact-form submission, an App Store link click, an external-link click using only the destination hostname, and a language change using only the language code. Contact-form contents, names, email addresses, messages and full external URLs are not sent to Analytics. Page URLs are recorded without fragments or arbitrary query parameters; only restricted campaign parameters may be retained.
| Storage | Purpose | Maximum lifetime |
|---|---|---|
tentava_analytics_consent in local storage | Stores only your choice, the policy version and the time of the choice | 6 months |
_ga and _ga_<container> cookies | Distinguish website visits after analytics consent | 6 months |
The “Accept all” button accepts the optional Analytics category. It does not enable advertising storage, advertising user data or ad personalisation; all of those remain disabled.
You can change or withdraw your choice at any time through “Cookie settings” in the website footer. Withdrawal stops future collection and removes accessible Google Analytics cookies where technically possible. The development and production websites use separate Firebase projects and separate Analytics streams.
For Google’s own information, see how Google safeguards Analytics data and Google’s GA4 cookie documentation.
What we explicitly do not do
- We do not track you across other apps or websites. No App Tracking Transparency prompt is therefore required.
- We show no advertising and work with no advertising network.
- We do not sell your data and do not share it for advertising.
- We use no crash reporting or performance monitoring.
- We do not activate website analytics or analytics cookies without your prior consent.
Analytics collection is disabled until you consent where consent is required. You can withdraw consent at any time in Settings; collection then stops for the future. Event-level analytics data is retained for up to 14 months, subject to shorter technical logs and aggregated reports that no longer identify an app instance.
19. Push notifications
If you allow notifications, we receive a push token for your device. We use it for messages, friend requests, workout reminders, achievements and streaks. Each of these categories has its own switch in your settings. You can disable notifications entirely at any time in your iOS settings. A token with no active device is deleted after 180 days at the latest.
20. Subscriptions and Apple
Subscriptions are purchased through the App Store. Apple handles payment. We receive your subscription status and receipt information from Apple, but no payment details.
An active subscription continues after you delete your Tentava account and will continue to be charged.
Cancel it before deleting your account, in your Apple ID settings under Subscriptions.
We cannot cancel your subscription for you — technically, only Apple can.
21. Support, reports and moderation
You can report content and users through the app. We review reports without undue delay, prioritising credible threats to safety, unlawful content and matters involving minors. Where applicable, we provide the notices, reasons and redress information required by the Digital Services Act and other law.
Where legally required, we inform the affected person if we restrict content or an account and explain the principal reasons. We do not generally review all user content before publication. We act when content is reported, detected through proportionate safety measures or otherwise brought to our attention.
We generally keep reports and moderation decisions for 12 months after closure, or up to 24 months for repeat abuse, disputes, legal claims or authority requests. An immutable copy of reported content is normally kept for 180 days so that later edits do not alter the evidence. It may be retained longer where a live case, safety need, legal claim or authority request requires it, and is then deleted or de-identified.
22. Service providers and recipients
| Recipient | Service | Role | Location and place of processing |
|---|---|---|---|
| Google LLC / Google Ireland Limited | Firebase: database, storage, authentication, server functions, notifications, abuse prevention, analytics, hosting | Processor | Configured Google Cloud/Firebase service regions and Google/subprocessor processing locations. Depending on the service, processing may occur in Switzerland, the EEA/UK, the United States and other countries listed in Google’s current subprocessor registers. |
| OpenAI Ireland Ltd.; OpenAI affiliates and approved subprocessors | Language model used for AI Training Review. It is also used for AI Weekly Summary and for the internal classification of support feedback. Section 14 describes the limits applied to personalised AI payloads. | Processor | Ireland, United States, Switzerland, EEA/UK locations and other countries listed in OpenAI’s current subprocessor register |
| Apple Inc. | App Store, subscriptions, Sign in with Apple, push delivery, HealthKit on your device | Independent controller for App Store and account services; device-level platform provider for HealthKit and push delivery | Locations described by Apple for the relevant service |
| Wahoo Fitness LLC | Only where you have set up the connection: providing your workout data | Independent controller for the data in your Wahoo account | USA |
| Google (Places) | Place search when selecting a training location | Provider role depends on the Google Maps Platform service and applicable terms | Google processing locations, which may include the United States |
| Coaches | Only the data you have released | Recipient acting on your instruction | Depends on the coach |
Where a provider processes personal data on our instructions, we use data-processing terms that address confidentiality, security, subprocessors, assistance with rights and deletion. Some recipients, such as Apple for App Store transactions or Wahoo for its own account service, act as independent controllers for their own processing. We otherwise disclose data only where required by law, needed to protect people and the service, or necessary to establish, exercise or defend legal claims.
Our use of the OpenAI API is governed by the OpenAI Services Agreement and a Data Processing Addendum between KITAV Vuong and OpenAI. For KITAV Vuong in Switzerland, OpenAI Ireland Ltd. is the contracting processor. The personalised AI payload is limited to the structured data described in section 14 and is designed not to include sensitive health data or user-authored free text. The separate support-feedback classification described in section 7.8 can process the feedback text that you choose to submit; please do not include unnecessary sensitive information. The API projects are configured not to opt in to model training.
23. International data transfers
Tentava is operated from Switzerland. Some service providers and their subprocessors process data outside Switzerland. For Google/Firebase, the destination state depends on the configured service region and the specific Firebase or Google Cloud service; service maintenance, support and subprocessors can also operate from other countries. Current Google Cloud subprocessor countries are published at https://cloud.google.com/terms/subprocessors. Firebase subprocessor information is published at https://firebase.google.com/terms/subprocessors.
OpenAI processing is contracted through OpenAI Ireland Ltd. OpenAI’s current API subprocessor register includes processing locations in Switzerland, EEA countries, the United Kingdom, the United States and additional countries used by its infrastructure providers. The current list and processing locations are published at https://platform.openai.com/subprocessors. We review these provider lists when they change.
Where personal data is disclosed to a country that does not provide an adequate level of data protection under Swiss law, we rely on a permitted safeguard, including recognised Standard Contractual Clauses with the adaptations required for Switzerland, or another lawful mechanism. Transfers of Swiss and EEA data outside Switzerland or the EEA are covered by the DPA provided by OpenAI. That DPA states that these transfers are protected by Standard Contractual Clauses or an applicable adequacy decision. We also use supplementary measures such as encryption in transit and at rest, access controls, data minimisation and contractual purpose limitations where appropriate.
You may request information about the destination states and the safeguards applicable to a specific processing activity at privacy@tentava.app. KITAV Vuong maintains provider contracts, transfer safeguards and current subprocessor information separately and updates this policy when a material provider, destination or processing configuration changes.
24. Your rights
| Right | What you can ask for |
|---|---|
| Access | A copy of the data we process about you, together with details of purposes, recipients and retention periods. |
| Rectification | Correction of inaccurate details. You can change many of them directly in your profile. |
| Erasure | Deletion of your data. The simplest way is to delete your account in the app. |
| Restriction | That we temporarily only store certain data without using it further. |
| Objection | To object to processing that we base on a legitimate interest. |
| Data portability | Your data in a common, machine-readable format. |
| Withdrawal | To withdraw any consent at any time, with effect for the future. |
| Complaint | To lodge a complaint with a supervisory authority. The relevant bodies are listed in sections 28 and 29. |
Write to us at privacy@tentava.app. We respond within one month. If a request is particularly complex, we may extend that period by two months and will tell you if we do. Where we have doubts about your identity, we may ask for further information — solely to protect your data. Handling requests is free of charge, except for manifestly unfounded or repetitive requests. The relevant supervisory bodies are listed in sections 28 and 29.
You can create a machine-readable ZIP export of your Tentava data directly in the app under My Profile > Settings > My Data. You may also request access or portability by writing to privacy@tentava.app.
25. Deleting your account
You can request account deletion at any time in the app under Profile and Settings. Access to the account is disabled when deletion is confirmed, and deletion from Tentava’s active systems is initiated without undue delay. KITAV Vuong does not create or retain a separate recoverable copy of your account for its own purposes after deletion. The process cannot be undone once completed. Limited statutory records and provider recovery copies are described below.
What is deleted
Your profile, your workouts and planned workouts, your goals and statistics, your custom exercises, imported activities, your photos and videos, your AI insights, your friendships and requests, your coach connections, your settings, your push tokens, your directory entry, your Wahoo connection including the token, and your sign-in credentials are deleted from Tentava’s active systems.
What remains
| Data | Why | For how long |
|---|---|---|
| Your chat messages in the other person’s chat | So that the other person keeps their own conversation history. Your name is replaced with “Deleted user”. | Until the other person deletes the chat |
| Subscription and invoicing data | Swiss law requires this retention under Article 958f of the Code of Obligations. | 10 years |
| Reports and moderation decisions | Evidence for authorities, the reporting person and the affected person; immutable copied evidence is normally retained for 180 days | Decision record 12 or 24 months; copied evidence normally 180 days, longer only where the case requires it |
| A record of the deletion with no personal reference | So that we can demonstrate the deletion took place | 24 months |
| Provider recovery copies | KITAV Vuong does not keep a separate recoverable user backup after account deletion. Technical provider recovery systems cannot always be edited selectively. | Overwritten or removed under the applicable provider backup cycle, normally no later than 180 days unless law or a security incident requires isolation for longer |
Remember to cancel your subscription through your Apple ID first — see section 20.
26. Data security
We protect your data through, among other things: encryption in transit and at rest, access rules enforced on our servers, verification of app authenticity through Firebase App Check and Apple App Attest, rate limiting against abuse, an optional device lock using Face ID, and server-side data-minimisation controls designed to prevent direct account identifiers, user-authored free text, sensitive health metrics and excluded content from reaching the personalised AI features described in section 14.
No system is completely secure. We assess suspected personal-data breaches, contain and document them, and notify affected people and competent authorities when the applicable legal thresholds are met and within the legally required timeframes.
27. Minimum age
Tentava is intended for people aged 16 and over. The registration flow asks for a date of birth or birth year, depending on the app version, to apply the age gate and age-dependent calculations. People under 16 may not create or use an account.
We do not knowingly collect data from children under 16. If we learn that a younger person is using an account, we disable it and delete the data unless retention is legally required. A parent or guardian who believes a child under 16 has an account may contact privacy@tentava.app.
Users under 18 have the same privacy-friendly defaults as everyone else: bio, activity list and linked profiles are private by default, and goals are never published.
28. Additional information for Switzerland
If you live in Switzerland, the Swiss Federal Act on Data Protection applies. Health data is sensitive personal data under Art. 5(c) FADP. We process the health data described in this policy only after obtaining the explicit consent required for the relevant feature. Where we rely on consent for sensitive personal data, that consent is obtained expressly in accordance with Art. 6(7) FADP.
You have the rights set out in Art. 25 to 28 FADP, in particular the right of access and the right to data release or transfer. Complaints may be addressed to the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.
29. Additional information for the EU and EEA
Tentava is not offered in the EU/EEA under this Switzerland launch version. Before Tentava is offered to individuals in the EU/EEA, KITAV Vuong will review and update this policy as required. Where the GDPR applies, the legal bases described in section 8 apply and health data will be processed only where an Art. 9 GDPR condition is satisfied, including explicit consent under Art. 9(2)(a) where relied upon.
If the GDPR applies in the future, you may lodge a complaint with the supervisory authority of your country of residence, your place of work or the place of the alleged infringement. The European Data Protection Board maintains the list of supervisory authorities at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.
Tentava does not take decisions based solely on automated processing that produce legal effects or similarly significantly affect you within the meaning of Art. 22 GDPR. The personalised AI features provide explanatory training guidance only.
30. Changes to this policy
We update this policy when the app, our service providers or the law change. The version in force is always available in the app and at tentava.app. We will notify you in advance of material changes, in the app or by email. Where a change affects processing based on your consent, we will ask for your consent again.
31. Contact
KITAV Vuong, Allmendstrasse 3b, 6048 Horw, Switzerland. Privacy: privacy@tentava.app. Support: support@tentava.app.