TENPACE

Tenpace Health Privacy Notice

Effective August 19, 2026 · Beta version 2026-08-19

This notice supplements the general Tenpace Privacy Policy for Tenpace Health (“Health”). Health handles information that may reveal details about your health, body, diet, and activity. We designed the beta around explicit consent, member-controlled Circle sharing, export, and deletion.

Information Health processes

  • Account details from Tenpace, including your user ID, email, display name, profile image, and timezone.
  • Goals, schedule, available equipment, dietary preferences, limitations, and coaching preferences.
  • Workouts, exercises, loads, repetitions, nutrition entries, recipes, body measurements, notes, and files you upload.
  • Agent conversations and the context needed to answer or carry out your request when you opt into AI processing, including transcripts created from voice notes you choose to send.
  • An optional good or bad rating you give a completed Bel conversation, its revision and timestamp, and the private conversation link needed to review a bad rating.
  • Security and reliability data such as a hashed IP address, browser information, consent history, timestamps, and model usage totals.
  • For the native app, limited crash diagnostics such as app and build version, device model and Android version, exception type, message and stack, and the operating system’s process-exit reason. Credential and email patterns are redacted on the device before an authenticated upload on the next launch.
  • If you connect Android Health Connect, the body-measurement records you authorize, their timestamps, source-app name and package, and source record identifiers used to prevent duplicate imports.
  • If you create a Pantry, its name, foods, optional private address label, optional recognition coordinates and range, active-Pantry selection, and optional Circle association. If you enable nearby suggestions, your device also sends its current coordinates and reported accuracy when it checks for a match.
  • If you use activity profiles, your section-by-section audience choices, public-profile setting and link identifier, support preference, and the aggregate activity used to assemble the profile.

How we use it

We use this information only to authenticate you, operate and improve the features you request, maintain your history and plan, provide optional AI assistance, prevent abuse, secure the service, respond to support requests, and comply with law. We do not sell Health data, use it for targeted advertising, or permit data brokers to use it.

Pantry location recognition

Pantry location is optional and nearby suggestions begin off. An address is a private label and does not itself grant location permission. You choose whether to capture a recognition point from a device and whether Health may check the device’s location. Health compares a location on the server, suggests a matching Pantry, and waits for you to switch; it does not switch automatically. You can turn suggestions off, clear a Pantry’s recognition point, remove its address label, or delete the Pantry.

A Pantry shared with a Circle exposes its name, owner, food assignments, and whether recognition is available to active members. Its address label and exact stored coordinates are not returned to visiting members. A visitor’s current coordinates are used to find a visible match and are not added to their Health history. Removing or leaving the Circle ends future access under the same membership checks as other Circle data.

Android Health Connect

Health Connect is optional and read-only in Tenpace. With your Android permission, the native app can read weight, height, body-fat percentage, lean body mass, body-water mass, bone mass, and basal metabolic rate. It derives BMI from height and weight and may derive body-water percentage from body-water mass and weight. Tenpace does not write or delete records in Health Connect.

With the separate exercise permission, Tenpace can also read completed exercise sessions: activity type, start and end time, duration, and the app that recorded the session. Tenpace does not request Health Connect’s exercise-route permission and does not import GPS tracks, route points, or live location.

Authorized records are sent to your private Health account so they appear in your body-measurement history across devices. Tenpace stores source and time metadata to update an imported record and avoid duplicate copies, including when the same scale reading arrives through both a scale app such as RENPHO Health and Google Fit. Older-history and background access are separate Android permissions; without older-history access, Tenpace reads only the recent period allowed by Health Connect.

Exercise sessions are reconciled with matching manual workouts and copies of the same session from other connected apps so one activity does not inflate your history. Imported sessions count in your private weekly recap and self-relative rhythm. They begin private in every Circle. In Circle Settings, you can separately allow each recording app to share only a summary of its activities; changing one Circle does not change another.

You can change individual permissions in Android or disconnect in Health Settings. Disconnecting or signing out revokes the app’s Health Connect permissions and stops future imports. It does not delete measurements already copied into Tenpace; you can export them or delete your Tenpace Health account through its account controls. Health Connect data is not sold, used for advertising, or shared with data brokers.

AI processing

AI-assisted guidance is part of the initial Health setup and requires a separate acknowledgement before setup can be completed. Relevant messages, attachments, profile context, and recent Health records may be sent through Tenpace’s server-side account to its contracted AI provider to answer your request. We do not ask you to provide a personal API key or third-party login. After setup, you can withdraw AI processing in Settings; manual tracking remains available when it is off.

When you send an Agent voice note, its audio is sent through Tenpace to the contracted AI provider for transcription. Tenpace processes the raw recording in memory and does not add it to your Health records, Agent attachments, or private media storage. The native app deletes its temporary recording file immediately after reading it for upload. The resulting transcript becomes the user message in your Agent conversation and is retained, exported, and deleted under the same rules as other Agent messages.

You can optionally rate a completed Bel conversation as good or bad and change that rating later. A current bad rating queues a private quality review. An authorized Tenpace automation may inspect that conversation locally, decide that no change is justified, or make and deploy a narrow, tested product improvement. The review notification does not include your identity, transcript, attachments, or Health records. Health sends the central Tenpace feedback system only the rating, selected date, opaque feedback reference, and revision; the transcript remains in Health.

Circles, automatic support, and deliberate sharing

A Health Circle is a private collaboration space for adults you invite. When you join, your recipes, saved ingredients, and meal entries are fully visible to active Circle members by default. Workouts begin private. You can change each category to private, summary, or full visibility. You can also override the setting for one item. Body measurements, general health profile details, limitations, and Agent conversations are never shared through these item-sharing controls. The separate activity-profile controls described below govern only the aggregate profile sections you deliberately choose.

Circle Highlights are built from completed workouts currently visible to that Circle and completed support open loops. They do not include meal or nutrition logs, measurements, missed days, skipped plans, or cancelled plans. Highlights appear only when qualifying activity exists, with older highlights available on demand. A member can leave or remove one Cheer on another member’s shared workout; the Cheer count and Circle member identity are visible inside that Circle. Health can notify the workout owner about a Cheer under the separate Cheer notification preference.

When you save a Weekly Split, Health automatically creates or updates a private support relationship between you and each active member of every Circle you belong to. Each member sees only their own pairwise support relationship with you. Health may notify those members that you updated your split and surface dated active-day open loops when a check-in can help. Joining a Circle is the consent boundary for this automation; leaving or being removed ends future support in that Circle.

Automatic support stores the relevant Weekly Split schedule, local time and timezone, the owner and Circle member, and generated dated open loops. Changing a future split day to Rest cancels generated future loops for that day; moving one loop changes only that occurrence. Completing a matching workout can close its linked open loop automatically. The owner may mark a dated loop starting, moved, skipped, completed, or in need of help. A Circle member may check in or add a note but cannot change the owner’s health record. Prior events remain in the support history.

The current-week Circle recap is calculated automatically from active members’ current Weekly Splits and matching meaningful completed workouts. A manually completed support loop may also confirm completion. Pairwise support rows are not counted as separate planned sessions. The recap shows collective planned, completed, and remaining totals and may identify members who completed their planned week. A separate “Your rhythm” result is visible only to you and compares your week-to-date meaningful-workout count with the same elapsed days in your four prior weeks. Neither feature creates a leaderboard, health score, or public challenge.

You can invite your Circle to an upcoming activity already in your Weekly Split. A shared session stores the Circle, activity title and category, scheduled date and optional time, leader, members who join or leave, and matching workout completion references. It does not collect a route, live location, chat, or participant ranking. Only active Circle members can see or join it; the leader can cancel it, and each other participant can leave independently. Removing or leaving the Circle ends access.

Active Circle members can see only items that are currently visible. Full sharing lets a member copy an item into their own log. The copy keeps the source owner’s name. Later edits do not change that copy. Removing or leaving a Circle stops future access immediately.

Activity profiles and public sharing

Activity-profile sections are visible to active members who share a Circle with you by default. You can hide any section from your Circle or make it public from Profile sharing settings. Sections can include a 365-day activity map, this week’s planned-versus-completed Weekly Split summary, 90-day activity mix, recent activity and personal-record highlights, support preferences and an aggregate “support helped” count, and Circle information. A Circle viewer sees only Circle names you both share. A public Circle section shows only a count and never member or supporter names.

The public profile itself is off until you enable it. When enabled, its stable link can expose your Tenpace display name, profile image, and only sections set to Public to anyone with the link and potentially to search engines. Turning the public profile off makes that link unavailable; changing a section to a narrower audience removes it from later public responses. Public profiles do not include email, meals, food names, macros, weight, measurements, limitations, detailed workout notes, skipped commitments, or supporter identities.

Agent access to visible household items is enabled by default. You can turn it off for all your visible items or block one item. The Agent receives an item only when that item is visible to the member. A separate setting, enabled by default and available to turn off at any time, allows Bel on another active member’s account to add nutrition entries to your log when that member explicitly requests it. Those entries identify their creator. Membership, invitation, sharing changes, item changes, Agent-created entries, and reuse create a bounded Circle audit record that does not store the item’s contents.

Reminders and notifications

Health can show in-app or device notifications for Circle encouragement, Cheers, legacy reactions, unfinished workouts, and reminders you enable. Circle encouragement, Cheers, and workout reminders begin enabled and can be turned off separately. Macro reminders are off by default and require you to opt in. You can also turn off all Health reminders, choose quiet hours, revoke Android notification permission, or change a device’s operating-system settings. Notification text is intentionally brief and does not include measurements, limitations, Agent conversations, or a detailed meal record.

Storage, access, and security

Health data is separated by account in the application database. Uploaded files are held in private object storage and are served only after an ownership check. We use encrypted transport, access controls, expiring sessions, dependency and deployment checks, and encrypted backups. No security program can guarantee zero risk.

Service providers and disclosures

We disclose data only to providers needed to host, secure, back up, and operate Health; to the AI provider when you enable AI; when you direct us to; or when law or safety requires it. Providers receive only the data needed for their role and are expected to protect it. We do not share Health data with employers, insurers, advertisers, or social networks unless you explicitly direct us to.

Retention and deletion

We retain Health data while your Health account is active. You can download a machine-readable export and permanently delete the Health account in the product. Deletion removes live account data and private media promptly. Encrypted backup copies expire on the backup schedule and are purged within 30 days. We retain a minimal, non-reversible deletion audit containing a hashed Tenpace identifier and purge deadline so we can verify the request was honored.

If you own a Circle when deleting your account, ownership transfers to the longest-standing remaining active member; a Circle with no other active member is deleted. Source snapshots attached to another member’s reused item are purged and marked as deleted, while the independent item that member intentionally added to their own log remains theirs.

Health sends the central Tenpace billing service your Tenpace user ID and an account-deletion lifecycle event so dependent access can be revoked and an owner’s next Health renewal can be canceled. This event contains no measurements, meals, workouts, profile details, or Agent content. Central subscription, invoice, credit, tax, refund, and dispute records follow the retention described in the general Tenpace Privacy Policy.

Your choices

  • Review and correct profile or tracking information.
  • Export your Health data.
  • Withdraw or later re-enable AI processing after setup.
  • Rate a Bel conversation and change that rating later.
  • Control Circle membership and visibility, activity-profile audiences, public-profile availability, and reminder preferences.
  • Manage Pantry addresses and recognition points, disable nearby suggestions, or deny device location permission.
  • Choose, review, or revoke Android Health Connect permissions.
  • Delete the Health account without deleting your Tenpace account.
  • Contact us about access, correction, or privacy questions.

Health and legal status

Health is a consumer wellness product, not a healthcare provider, medical record system, or emergency service. Depending on where you live, consumer-health privacy or breach-notification laws may apply even when medical privacy laws designed for healthcare providers do not. We will provide notices and honor rights required by applicable law.

Age limit

The beta is for adults 18 and older. We do not knowingly collect Health data from children.

Changes and contact

Material changes will be shown in the product and may require renewed consent. Questions or requests can be sent to [email protected].

← Back to Tenpace Health