← I/O
Privacy Policy
Last updated August 21, 2026
The short version
I/O is on-device by default. Your logs, mined patterns, and
experiments are stored in a local database on your phone. The core
app needs no account, collects no analytics, and sends no telemetry.
An optional I/O Cloud subscription adds cloud connectors and AI
features, and is the only feature set that talks to our servers.
Account-free core
No analytics
No telemetry
On-device by default
What stays on your device
- Event history — everything you log or sync, in a local SQLite database.
- Mined patterns and experiments — statistics computed in a background isolate, stored locally.
- Voice utterances — parsed on-device; audio never leaves the microphone pipeline.
- Connected-account credentials — tokens live in the platform keystore, never in the database.
What leaves your device, and only when you ask
- Connector syncs — when you connect Oura, Cronometer, or similar, your phone talks to those services directly to pull your data.
- Weather & air quality — coordinates are sent to Open-Meteo/OpenAQ to fetch conditions for your location.
- Cloud LLM parsing — off by default. If enabled, an utterance you choose to re-parse is sent to the I/O Cloud LLM endpoint. Raw health data is never attached.
- I/O Cloud (optional, subscription) — if you sign in, your account email and subscription status live on our Supabase backend. Cloud connectors (Whoop, Strava, Dexcom and similar) broker OAuth through it, and AI narration sends mined-pattern summaries — only the data each feature needs, only while you use it.
Permissions I/O requests
- Location (coarse, one-time) — to resolve coordinates for weather and air quality. Not tracked, not stored server-side.
- Microphone — voice logging, only while the capture sheet is open.
- Notifications — experiment nudges and mood check-in reminders you configure.
- Health data (read-only) — Apple Health / Health Connect, for the types you approve.
Export and deletion
Settings → Data exports your full history as CSV + Parquet files,
stored on your device. Settings → Delete all data removes everything
stored locally, immediately. If you created an I/O Cloud account,
Settings → Delete account permanently erases the account and all
server-side data associated with it.
Children and sensitive data
I/O is intended for adults self-tracking their own health. Do not use
it to track another person without their consent.
Not medical advice
I/O is not a medical device. Mined patterns are statistical
hypotheses, not diagnoses. Always consult a qualified healthcare
professional about medical decisions.
Contact
Questions: contact@iolog.app