Privacy Policy

Last updated 3 September 2026

corr reads numbers from services you connect and shows you what moves together. This page explains exactly what it reads, where that data goes, and what it is never used for.

The short version

What corr collects

Account information

Your email address and an encrypted password, used to sign you in. If you subscribe, our payment processor handles your card details — corr never sees or stores them.

Data from services you connect

When you connect a source, corr reads the measurements needed to build your pages: for example daily commit counts from GitHub, session counts from Google Analytics, or sleep hours from a wearable. corr requests the narrowest read-only permission each service offers, and never requests permission to write.

corr does not read the contents of your work. It does not read your code, your documents, your messages, your emails, or the text of your calendar events. It reads counts, durations and scores.

What corr does not collect

There is no manual logging in corr, so it holds nothing you typed about yourself. It does not track your location, does not use advertising identifiers, and contains no third-party advertising or analytics SDKs.

Apple Health stays on your device

corr reads Apple Health through HealthKit on your iPhone. Health samples are processed on the device and the resulting daily figures are stored in your own account. corr's servers never receive raw HealthKit data, and Health data is never shared with any third party, used for advertising, or sold — as Apple's rules require.

Google user data

If you connect a Google service such as Google Analytics or YouTube, corr requests read-only access and reads only the metrics needed to build your pages and findings.

corr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: Google user data is used only to provide and improve the features you can see in corr. It is not transferred to others except as needed to provide those features, to comply with the law, or as part of a merger or acquisition. It is not used for advertising, and it is not used to develop, improve or train generalised AI or machine-learning models. You can revoke corr's access at any time from your Google account permissions page or from Account in corr.

How your data is used

That is the whole list. Your data is not used to build features for other people, is not aggregated into products we sell, and is not shared with advertisers.

AI processing

corr's coach uses a third-party large language model to turn your numbers into sentences and to answer your questions. When you use it, the relevant figures from your account are sent to that provider to generate a response for you.

We use that provider under terms that prohibit training on data sent through the API. No connected-service data is used to train any model. Apple Health data is not sent to the model provider except where a figure derived from it appears in something you asked about.

Who processes data on our behalf

ServiceWhat it handles
SupabaseDatabase, authentication and server functions
NangoHolds the sign-in tokens for connected services, so corr never stores them itself
OpenAIGenerates coaching responses and findings
VercelHosts this website
AppleApp distribution and subscription billing

These providers act on our instructions and may not use your data for their own purposes.

Keeping and deleting data

Your data is kept while your account exists, so your history remains available to you.

Security

Connection credentials are stored encrypted and are never returned to the app or shown in full again. Every read of your data is scoped to your account by row-level security in the database, so one account cannot reach another's rows. Traffic is encrypted in transit.

Your rights

You can access, correct, export or delete your data. Most of this is available directly in the app; for anything else, write to us and we will act within 30 days. Depending on where you live you may also have the right to object to processing or to complain to a data protection authority.

Children

corr is not intended for anyone under 16, and we do not knowingly collect data from children.

Changes

If this policy changes materially, we will say so in the app before the change takes effect. The date at the top always reflects the current version.

Contact

Questions about privacy, or a request about your data: privacy@getcorr.com.