Privacy Policy
Effective October 8, 2026
Personal Dash shows your health in one place: sleep, recovery, food, workouts, labs and records. It is run by Keya LLC ("we"). This policy says what we keep, where it goes, and how to remove it. Questions go to support@keya.dev.
The short version
- We don't sell your data, show ads, or use your health data to market anything.
- Your health data is used to show you your dashboard and to answer the questions you ask.
- Usage analytics, when turned on, record that something happened (a screen opened, a meal logged), never what was in it.
- You can delete what you log at any time, and ask us to delete your account.
Ways to use Personal Dash
The iPhone app and your account. When you sign in with Apple or Google, we create an account for you, hosted at my.personaldash.app on Cloudflare. The rest of this policy is mostly about this account.
The web app at personaldash.app. Its data stays in your browser, encrypted with a passphrase only you know. We can't read it. When you connect Oura or Function Health there, the requests pass through our relay because those services don't accept browser requests directly; the relay forwards them and keeps nothing. If you link the web app to your account, it syncs with your account as described below.
Running it on your own computer. The open-source version keeps everything on your machine and sends nothing to us unless you connect it to an account.
What your account keeps
- Who you are: the email address and account id that Apple or Google gives us at sign-in. Google sign-in goes through Clerk, our sign-in provider.
- What you log: meals, workouts, sleep, measurements, supplements, vaccines, records and notes, whether you add them in the app or through a connected AI assistant.
- Apple Health, if you allow it: daily totals (such as steps, sleep, heart rate variability and resting heart rate) and workouts. The app writes the meals and workouts you log back to Apple Health. Apple Health data is used only to show you your dashboard and grades and to answer your questions. It is never used for advertising and never shared with anyone except as described in "AI answers" below.
- Sources you connect: data from Oura, Function Health or a health calendar you link. Your account keeps the login or token for each so it can read new data for you; these are never shown back to you or anyone else. From a calendar we keep only health events (workouts, therapy, medical, mindfulness and recovery) and drop everything else before saving it.
- The summary you share: if you also use the dashboard on your own computer, it can send your account the summary sections you choose to share. Profile, genetics, MRI and vaccines are off until you turn them on.
- AI answers: each answer's messages are kept for 24 hours so the app can show it after you come back, then deleted. Photos you send are read and not stored.
AI answers
When you ask the in-app assistant a question, your message and the dashboard summary for the page you're on are sent through OpenRouter, a service that routes requests to AI models, to Anthropic's Claude to write the answer. If that's unavailable, Cloudflare Workers AI answers instead. Photos you attach are read by Cloudflare Workers AI, and that reading goes with your message. Voice is turned into text, and answers read aloud, by Cloudflare Workers AI. Each provider processes this under its own terms. Nothing is sent to an AI provider unless you ask.
If you connect an AI app such as ChatGPT or Claude to your account, that app can read the data you share and log entries for you while you use it. Its handling of that data is covered by its own privacy policy. You can disconnect it at any time from Connect AI.
Usage analytics and crash reports
To see which features get used and to fix crashes, the iPhone app and the web app send PostHog events such as "screen viewed", "meal logged" or "answer received", along with crash reports and basic device and app version details. These events never include health values, what you ate, what you wrote or asked, your email or your name. In the iPhone app, people who sign in with Google are identified to PostHog by an account id only; everyone else is anonymous. Session recording is off. The version that runs on your own computer sends no analytics.
We also count how many AI tokens each answer uses, to keep track of costs. That count contains no text.
Who processes data for us
- Cloudflare: hosting, storage, the relay, voice and one of the AI models.
- Clerk: Google sign-in.
- Apple: Sign in with Apple, and Apple Health on your phone.
- OpenRouter and Anthropic: AI answers you ask for.
- PostHog: usage analytics and crash reports.
- Oura, Function Health and your calendar provider: only when you connect them, to read your data from them.
We share data with no one else, except when the law requires it.
Keeping and deleting your data
We keep your account data until you delete it. You can delete or correct any entry in the app or through a connected AI assistant. To delete your whole account and everything in it, email support@keya.dev from the address you signed in with; we delete it within 30 days. Data in the web app lives only in your browser: clearing the site's data removes it.
Security
Data travels over encrypted connections. Your account is reached only through your sign-in, and the keys for the AI providers and data sources live on our servers, never in the app. No system is perfectly secure; if we learn of a breach that affects your data, we will tell you.
Children
Personal Dash is not meant for children under 13, and we don't knowingly collect their data.
Changes
If we change this policy, we'll update the date above. For a change that affects what we collect or who receives it, we'll tell you in the app before it takes effect.