Personal Dash

Privacy Policy

Effective October 8, 2026

Personal Dash shows your health in one place: sleep, recovery, food, workouts, labs and records. It is run by Keya LLC ("we"). This policy says what we keep, where it goes, and how to remove it. Questions go to support@keya.dev.

The short version

Ways to use Personal Dash

The iPhone app and your account. When you sign in with Apple or Google, we create an account for you, hosted at my.personaldash.app on Cloudflare. The rest of this policy is mostly about this account.

The web app at personaldash.app. Its data stays in your browser, encrypted with a passphrase only you know. We can't read it. When you connect Oura or Function Health there, the requests pass through our relay because those services don't accept browser requests directly; the relay forwards them and keeps nothing. If you link the web app to your account, it syncs with your account as described below.

Running it on your own computer. The open-source version keeps everything on your machine and sends nothing to us unless you connect it to an account.

What your account keeps

AI answers

When you ask the in-app assistant a question, your message and the dashboard summary for the page you're on are sent through OpenRouter, a service that routes requests to AI models, to Anthropic's Claude to write the answer. If that's unavailable, Cloudflare Workers AI answers instead. Photos you attach are read by Cloudflare Workers AI, and that reading goes with your message. Voice is turned into text, and answers read aloud, by Cloudflare Workers AI. Each provider processes this under its own terms. Nothing is sent to an AI provider unless you ask.

If you connect an AI app such as ChatGPT or Claude to your account, that app can read the data you share and log entries for you while you use it. Its handling of that data is covered by its own privacy policy. You can disconnect it at any time from Connect AI.

Usage analytics and crash reports

To see which features get used and to fix crashes, the iPhone app and the web app send PostHog events such as "screen viewed", "meal logged" or "answer received", along with crash reports and basic device and app version details. These events never include health values, what you ate, what you wrote or asked, your email or your name. In the iPhone app, people who sign in with Google are identified to PostHog by an account id only; everyone else is anonymous. Session recording is off. The version that runs on your own computer sends no analytics.

We also count how many AI tokens each answer uses, to keep track of costs. That count contains no text.

Who processes data for us

We share data with no one else, except when the law requires it.

Keeping and deleting your data

We keep your account data until you delete it. You can delete or correct any entry in the app or through a connected AI assistant. To delete your whole account and everything in it, email support@keya.dev from the address you signed in with; we delete it within 30 days. Data in the web app lives only in your browser: clearing the site's data removes it.

Security

Data travels over encrypted connections. Your account is reached only through your sign-in, and the keys for the AI providers and data sources live on our servers, never in the app. No system is perfectly secure; if we learn of a breach that affects your data, we will tell you.

Children

Personal Dash is not meant for children under 13, and we don't knowingly collect their data.

Changes

If we change this policy, we'll update the date above. For a change that affects what we collect or who receives it, we'll tell you in the app before it takes effect.

Terms of Service · support@keya.dev