Eravyr is operated by TKOLABS INC, a Florida corporation. Eravyr is a small operation, not a large company with a dedicated privacy department — which is precisely why this document tries to be specific rather than reassuring.
Questions about your data, or to exercise any right described here, contact privacy@eravyr.com.
Eravyr is a general-wellness tool. It turns signals you share into six gauges and a trend over time, measured against your own normal for the chapter of life you're in.
Eravyr reflects; it doesn't diagnose. It is not a medical device, and nothing it shows you is a diagnosis, a treatment, or medical advice. It is not intended to detect, prevent, or manage any disease. If something concerns you, talk to a clinician. Eravyr is not a HIPAA-covered entity, and using it does not create a clinical relationship of any kind.
| Data | Why | Required? |
|---|---|---|
| Email address | Sign-in (we use emailed links, not passwords) and, if you opt in, the weekly recap | Yes |
| Display name | To address you in the app and in emails | Optional |
| Weekly check-in ratings | Feeds Clarity, Connection and Spark, which no sensor can measure | Optional |
| Events you log (workout, walk, family time, and your own custom events) | Moves the matching gauges | Optional |
| Age band and sex | A last-resort estimated starting band, fully replaced once your own baseline exists | Optional |
| Lab results and medications, if you upload them | Gives the engine clinical context and chapter boundaries | Optional |
Only if you choose to connect a device or upload an export. Depending on your device this can include daily step counts, sleep duration and stages, heart-rate variability, resting heart rate, weight, and workout sessions.
What that does not mean. We are precise about this because vague security language is how products mislead people. Specific sensitive fields are encrypted — the database as a whole is not, and this is not end-to-end or zero-knowledge encryption. Eravyr's hosted service is a server we operate: your data is decrypted there in order to compute your gauges, and staff with server access can technically reach it. We do not claim otherwise, and we will never tell you your data "never leaves your phone" when it does. See What we encrypt (and don't) for the field-level list.
No system is perfectly secure, and we cannot guarantee absolute security.
We do not sell your personal information. We have never sold it, we do not share it for advertising or cross-context behavioral advertising, and we do not use data brokers.
Two service providers are necessarily involved in running Eravyr:
| Provider | What it receives | Why |
|---|---|---|
| Resend (email delivery) | Your email address and the contents of emails we send you — sign-in links and, if you opt in, your weekly recap, which includes your gauge numbers | We cannot email you without an email provider |
| DigitalOcean (hosting) | Hosts the server your data sits on | The service has to run somewhere |
Both act as our processors, not independent controllers, and neither is permitted to use your data for their own purposes. If you opt into an outside connector in future, we will say so plainly at the point you choose it.
We may also disclose data if legally compelled, or to protect someone's safety or our legal rights. If we are ever acquired or merged, your data could transfer as part of that transaction; we would tell you before it became subject to a materially different policy.
Eravyr has an operator console used to run the service. Through it, an administrator can see your email address, display name, account ID, sign-up and last-active dates, whether you've opted into the recap, and counts of your events plus your database size. The console does not display your health readings themselves.
Being straight with you, though: administrators have access to the server, and could technically read the underlying data. Access is limited to those running the service, every administrative action is written to the security log, and we don't look at individual health data except when you ask us for support or we must investigate a fault.
What deletion does not reach. After you delete, entries in the security log and the pseudonymous analytics store remain, holding only your former random account ID, timestamps, actions and IP addresses. Because deletion destroys the record linking that ID to you, what remains can no longer be tied back to you by us. Deleted data may also persist in encrypted backups until those rotate, as described in section 7. Export, deletion, encryption and the warming-up behaviour are never placed behind a paywall.
You may have rights to access, correct, delete, or obtain a portable copy of your data, to withdraw consent, and not to be discriminated against for exercising those rights. Residents of some U.S. states — including Washington, whose My Health My Data Act covers consumer health data specifically — and users in the UK/EEA may have additional rights, including the right to lodge a complaint with a supervisory authority. Write to privacy@eravyr.com and we will honour any request the law gives you. Most of these are already self-serve above.
Eravyr is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
Eravyr's servers are in the United States. If you use Eravyr from outside the U.S., your data is transferred to and processed there.
We will update this page as Eravyr grows and will flag material changes rather than quietly editing them in. The "last updated" date at the top always reflects the current version.