Privacy Policy

Last updated: July 2026

Data We Collect

Navara reads workout data from Apple HealthKit (activity type, duration, distance, calories, heart rate, route GPS coordinates) to display your fitness history. If you use Strava import, we parse your exported activities.csv and GPX files.

If you enable cloud sync, this data is uploaded to and stored on our servers (Supabase). This explicitly includes data derived from Apple HealthKit — your workouts, precise GPS route coordinates, heart rate, and power — alongside your training plans and social data. This data is linked to your account. Cloud sync is off by default; if you never enable it, none of this data leaves your device.

If you use AI coaching, an anonymized training summary (no name, no exact GPS coordinates) is sent to Anthropic's Claude API.

If you use route discovery, the start location you pick (often your current location) is sent to the mapping and routing providers listed below so they can build routes near you. If weather display is enabled, approximate activity coordinates and dates are sent to a weather provider. These requests carry no account identifiers.

We also collect anonymous usage analytics — which screens are viewed and general app usage events — to understand how Navara is used and improve it. These events are not linked to your account or identity, and never include your health data, workouts, or GPS coordinates.

Local-First Storage

By default, all your data is stored locally on your device using SwiftData. Cloud sync is optional and must be explicitly enabled. You can use Navara fully offline with no server dependency.

Third Parties

  • Supabase — Cloud database and authentication (only if you enable sync). Hosts your synced workouts, including HealthKit-derived health and precise location data, on its cloud infrastructure.
  • Anthropic (Claude) — AI coaching analysis. Receives anonymized training summaries only. No personal identifiers are sent.
  • Apple HealthKit — Read-only access to your workout data. Navara never writes to HealthKit.
  • OpenStreetMap (Overpass API) — Route discovery. Receives the coordinates of the area you're generating routes in, to find trails, paths, and green space. No account identifiers are sent.
  • OpenRouteService — Route discovery. Receives your chosen start location to generate round-trip route suggestions. No account identifiers are sent.
  • Mapbox — Route discovery. Receives route-leg coordinates to compute realistic walking and running paths. No account identifiers are sent.
  • Open-Meteo — Weather display on activities. Receives approximate activity coordinates and dates to look up historical conditions. No account identifiers are sent.
  • PostHog — Product analytics for the app and this website. Receives anonymous usage events (screen views, app lifecycle, page views) that are not linked to your account. Never receives health, workout, or location data.
  • Vercel — Hosts this website.

No Ads, No Data Selling

Navara contains no advertisements and does not track you across other apps or websites. We do not sell or share your data with advertisers or data brokers. The only analytics we run are the anonymous, first-party usage analytics described above — used solely to improve Navara.

Data Retention & Deletion

Local data is retained on your device until you delete the app. Cloud data is retained as long as your account is active. You can delete your account at any time from the app settings, which permanently removes all server-side data.

Contact

Questions about this policy? Reach us at hello@navara.fit.