Last updated 3 September 2026
corr reads numbers from services you connect and shows you what moves together. This page explains exactly what it reads, where that data goes, and what it is never used for.
Your email address and an encrypted password, used to sign you in. If you subscribe, our payment processor handles your card details — corr never sees or stores them.
When you connect a source, corr reads the measurements needed to build your pages: for example daily commit counts from GitHub, session counts from Google Analytics, or sleep hours from a wearable. corr requests the narrowest read-only permission each service offers, and never requests permission to write.
corr does not read the contents of your work. It does not read your code, your documents, your messages, your emails, or the text of your calendar events. It reads counts, durations and scores.
There is no manual logging in corr, so it holds nothing you typed about yourself. It does not track your location, does not use advertising identifiers, and contains no third-party advertising or analytics SDKs.
corr reads Apple Health through HealthKit on your iPhone. Health samples are processed on the device and the resulting daily figures are stored in your own account. corr's servers never receive raw HealthKit data, and Health data is never shared with any third party, used for advertising, or sold — as Apple's rules require.
If you connect a Google service such as Google Analytics or YouTube, corr requests read-only access and reads only the metrics needed to build your pages and findings.
corr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: Google user data is used only to provide and improve the features you can see in corr. It is not transferred to others except as needed to provide those features, to comply with the law, or as part of a merger or acquisition. It is not used for advertising, and it is not used to develop, improve or train generalised AI or machine-learning models. You can revoke corr's access at any time from your Google account permissions page or from Account in corr.
That is the whole list. Your data is not used to build features for other people, is not aggregated into products we sell, and is not shared with advertisers.
corr's coach uses a third-party large language model to turn your numbers into sentences and to answer your questions. When you use it, the relevant figures from your account are sent to that provider to generate a response for you.
We use that provider under terms that prohibit training on data sent through the API. No connected-service data is used to train any model. Apple Health data is not sent to the model provider except where a figure derived from it appears in something you asked about.
| Service | What it handles |
|---|---|
| Supabase | Database, authentication and server functions |
| Nango | Holds the sign-in tokens for connected services, so corr never stores them itself |
| OpenAI | Generates coaching responses and findings |
| Vercel | Hosts this website |
| Apple | App distribution and subscription billing |
These providers act on our instructions and may not use your data for their own purposes.
Your data is kept while your account exists, so your history remains available to you.
Connection credentials are stored encrypted and are never returned to the app or shown in full again. Every read of your data is scoped to your account by row-level security in the database, so one account cannot reach another's rows. Traffic is encrypted in transit.
You can access, correct, export or delete your data. Most of this is available directly in the app; for anything else, write to us and we will act within 30 days. Depending on where you live you may also have the right to object to processing or to complain to a data protection authority.
corr is not intended for anyone under 16, and we do not knowingly collect data from children.
If this policy changes materially, we will say so in the app before the change takes effect. The date at the top always reflects the current version.
Questions about privacy, or a request about your data: privacy@getcorr.com.