Privacy Policy
Effective October 10, 2026
Personal Dash shows your health in one place: sleep, recovery, food, workouts, labs and records. It is run by Keya LLC ("we"). This policy says what we keep, where it goes, and how to remove it. Questions go to support@personaldash.app.
The short version
- We don't sell your data, show ads, or use your health data to market anything.
- Your health data is used to show you your dashboard and to answer the questions you ask.
- Usage analytics, when turned on, record that something happened (a screen opened, a meal logged), never what was in it.
- You can delete what you log at any time, and ask us to delete your account.
Ways to use Personal Dash
The iPhone and Android apps, the web app and your account. When you sign in with Apple, Google, an emailed code or a passkey, on your phone or at personaldash.app, you use your account, hosted at my.personaldash.app on Cloudflare. The web app shows what your account holds and keeps nothing in your browser except your sign-in. The rest of this policy is mostly about this account.
A browser set up with a passphrase at personaldash.pages.dev keeps its own encrypted copy there, which we can't read. When it connects Oura or Function Health, the requests pass through our relay because those services don't accept browser requests directly; the relay forwards them and keeps nothing.
Running it on your own computer. The open-source version keeps everything on your machine and sends nothing to us unless you connect it to an account.
What your account keeps
- Who you are: the email address and account id that Apple or Google gives us at sign-in, or the email address you sign in with by code. Google and email sign-in go through Clerk, our sign-in provider.
- What you log: meals, workouts, sleep, measurements, habits and their check-offs, supplements, vaccines, records and notes, whether you add them in the app or through a connected AI assistant.
- Apple Health, if you allow it: daily totals (such as steps, sleep, heart rate variability and resting heart rate) and workouts. The app writes the meals and workouts you log back to Apple Health. Apple Health data is used only to show you your dashboard and grades and to answer your questions. It is never used for advertising and never shared with anyone except as described in "AI answers" below.
- Sources you connect: data from Oura, Function Health or a health calendar you link. Your account keeps the login or token for each so it can read new data for you; these are never shown back to you or anyone else. From a calendar we keep only health events (workouts, therapy, medical, mindfulness and recovery) and drop everything else before saving it.
- The dashboard you share: if you also run Personal Dash on your own computer, it sends your account the dashboard sections you choose to share, charts included, so the web app and your phone can show them. Profile, genetics, MRI and vaccines are off until you turn them on.
- Your plan: whether you are on Free or Plus. If you subscribe to Plus, Apple tells us which plan you bought, when it renews or ends, and a transaction id, and we keep that with your account to turn Plus on and off. Apple handles the payment; we never see your card or billing details.
- AI answers: each answer's messages are kept for 24 hours so the app can show it after you come back, then deleted. Photos you send are read and not stored. If you report an answer, that answer, the reason you chose and your account's id and email are kept and sent to us so a person can look at it.
AI answers
When you ask the in-app assistant a question, your message and the dashboard summary for the page you're on are sent through OpenRouter, a service that routes requests to AI models, to Anthropic's Claude to write the answer. If that's unavailable, Cloudflare Workers AI answers instead. Photos you attach are read by Cloudflare Workers AI, and that reading goes with your message. Voice is turned into text, and answers read aloud, by Cloudflare Workers AI. Each provider processes this under its own terms. Nothing is sent to an AI provider unless you ask.
If you connect an AI app such as ChatGPT or Claude to your account, that app can read the data you share and log entries for you while you use it. Its handling of that data is covered by its own privacy policy. You can disconnect it at any time from Connect AI.
Usage analytics and crash reports
To see which features get used and to fix crashes, the iPhone and Android apps, the web app and this website send PostHog events such as "screen viewed", "page viewed", "meal logged" or "answer received", along with crash reports and basic device and app version details. These events never include health values, what you ate, what you wrote or asked, your email or your name. In the phone apps, people who sign in with Google or an email code are identified to PostHog by an account id only; everyone else is anonymous. Session recording is off. The version that runs on your own computer sends no analytics.
We also count how many AI tokens each answer uses and what it cost, and keep a running total for each account, to keep track of costs and to apply the limits of your plan. Those counts contain no text.
Reminders
If you turn on reminders, the app schedules them on your phone, at the times you choose. They are not sent from our servers, and turning them on gives us nothing new about you. You can turn them off in the app or in your phone's settings.
Who processes data for us
- Cloudflare: hosting, storage, the relay, voice and one of the AI models.
- Clerk: Google and email sign-in.
- Apple: Sign in with Apple, Apple Health on your phone, and payment for Plus.
- OpenRouter and Anthropic: AI answers you ask for.
- PostHog: usage analytics and crash reports.
- Oura, Function Health and your calendar provider: only when you connect them, to read your data from them.
We share data with no one else, except when the law requires it.
Keeping and deleting your data
We keep your account data until you delete it. You can delete or correct any entry in the app or through a connected AI assistant. To delete your whole account and everything in it, use Settings → Delete account in the app, or email support@personaldash.app from the address you signed in with (see Delete your account). You're signed out at once; the account is kept for 30 days, so signing in again within that time keeps it, and then it is deleted for good. A reported answer is kept with its report. Canceling Plus does not delete anything: your data stays in your account, on Free. A browser set up with a passphrase keeps its data only in that browser, and clearing the site's data removes it.
Security
Data travels over encrypted connections. Your account is reached only through your sign-in, and the keys for the AI providers and data sources live on our servers, never in the app. No system is perfectly secure; if we learn of a breach that affects your data, we will tell you.
Children
Personal Dash is not meant for children under 13, and we don't knowingly collect their data.
Changes
If we change this policy, we'll update the date above. For a change that affects what we collect or who receives it, we'll tell you in the app before it takes effect.