Privacy Policy
Last updated May 31, 2026 · Effective May 31, 2026
This Privacy Policy explains how Hona (“Hona,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use the Hona iOS app, its Apple Watch companion, the optional Hona Garmin Connect IQ data field, and related services (together, the “Service”).
Hona is operated by Peter Jones Experience Design LLC. For privacy questions or requests, contact peter@pjxdesigns.com.
1. Who this policy covers
Hona supports two types of accounts:
- Athletes, who track their own training, recovery, and nutrition.
- Coaches, who are linked to one or more athletes and can view those athletes’ training and recovery data and exchange messages with them.
This policy applies to both. Where a practice differs by role, we say so.
2. Information we collect
2.1 Account information
When you create an account we collect:
- Your name (display name) and email address.
- Your role (athlete or coach).
- Authentication credentials. If you sign up with email and password, your password is handled by Google Firebase Authentication and is never stored by us in plain text. If you sign in with Apple or Google, we receive a unique account identifier and, where you permit it, your name and email.
2.2 Health, fitness, and biometric data
The core function of Hona is to compute your daily readiness, training load, and recovery trends. To do this we process health and fitness data, which may include:
- Apple Health (HealthKit): heart rate variability, resting heart rate, sleep, workouts, and body metrics that you authorize Hona to read. With your permission, Hona also writes workouts and nutrition you log in-app back to Apple Health.
- Connected wearables and services that you choose to link via their own secure sign-in:
- Oura: sleep, heart-rate variability, heart rate, and readiness data.
- Strava: your activities, including duration, distance, and GPS routes/maps.
- Whoop: recovery, daily cycle, and sleep data.
- Manually entered data: workouts, nutrition and food logs, body weight, training notes, race and goal information.
- Derived metrics that Hona calculates: for example your Hona readiness score, training load (fitness/fatigue/form), and macronutrient targets.
Health and biometric data is sensitive personal information, and we treat it accordingly (see Sections 4–6).
2.3 Device permissions
With your consent, Hona may access:
- Calendar: read-only, to display upcoming training and fueling reminders alongside your day. Calendar events are read on your device only and are never modified or uploaded.
- Camera: to scan nutrition barcodes and read nutrition labels so you can log foods.
- Photo library: to read a saved photo of a nutrition label you want to log.
You can change or revoke these permissions at any time in the iOS Settings app.
2.4 Information we do not collect
Hona does not use third-party advertising networks, and the current build does not include third-party analytics, marketing, or crash-reporting SDKs.
3. How we use your information
We use the information above to:
- Provide the Service: compute your readiness, training load, recovery trends, and nutrition targets, and display your dashboard.
- Maintain your account and authenticate you.
- Enable the coach–athlete relationship: if you link to a coach (or, as a coach, accept an athlete), share the relevant training, recovery, activity, and message data between you.
- Generate AI-assisted insights and coaching suggestions (see Section 5).
- Communicate with you about the Service, including service-related emails such as password resets.
- Maintain the security and integrity of the Service and comply with legal obligations.
We do not sell your personal information, and we do not use your health data for advertising.
4. Where your data is stored and how it is protected
- On your device: Connected-service access tokens (Oura, Strava, Whoop) and your personal encryption key are stored in the iOS Keychain. Some activity data is cached locally for performance.
- In the cloud: Account data and your training/recovery data are stored in Google Firebase / Cloud Firestore. Sensitive health, activity, and message fields are encrypted on your device using AES-256-GCM before they are uploaded, using a key held in your device Keychain. A copy of that key is stored in your account record so that a coach you have explicitly linked to can decrypt the data you share with them.
- Access controls: Firestore Security Rules restrict each athlete’s data so it is readable only by that athlete and their linked coach. Coach workout templates are private to the coach. Messages are readable only by the two participants.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
5. AI-assisted features
Hona uses Anthropic’s Claude models to generate training insights and nutrition suggestions. When you use these features, a set of de-identified training and biometric numbers (for example your readiness score, heart-rate variability, resting heart rate, sleep hours, training load, and your race name and training phase) is sent to Anthropic to produce the insight.
Some of these values (for example, heart-rate variability, resting heart rate, sleep duration, and workout summaries) may originate from Apple HealthKit. When they do, they leave your device only in this de-identified, numeric form — Anthropic does not receive your name, email, account identifier, location, exact birthdate, or raw GPS, route, or sample-level HealthKit data.
Based on the current implementation, this data does not include your name, email address, location, exact birthdate, or raw GPS data.
6. How we share information
We share information only as described here:
- With your linked coach (or athletes): If you are an athlete linked to a coach, your shared training, recovery, activity, and message data is visible to that coach. If you are a coach, your athletes can exchange messages with you. Linking is initiated by you.
- Service providers (sub-processors) that process data on our behalf:
- Google LLC (Firebase Authentication, Cloud Firestore): account, authentication, and encrypted data hosting.
- Anthropic, PBC (Claude API): AI insight generation, as described in Section 5.
- Data sources you authorize: Oura, Strava, and Whoop. When you connect these, you are subject to their own privacy policies, and you can disconnect them at any time in Hona.
- Food databases: when you search for or scan a food, the search term or barcode is sent to the USDA FoodData Central and Open Food Facts services. These requests contain food queries, not your personal or health data.
- Legal and safety: we may disclose information if required by law, or to protect the rights, safety, or property of users or the public.
- Business transfers: if Hona or Peter Jones Experience Design LLC is involved in a merger, acquisition, or asset sale, your information may be transferred, subject to this policy.
We do not sell your personal information and do not share it with advertisers.
7. Apple Health (HealthKit) data
Consistent with Apple’s requirements, data Hona reads from or writes to Apple Health:
- is used only to provide you with the Service’s health, fitness, and recovery features;
- is not used for advertising, marketing, or data-mining;
- is not sold, rented, or disclosed to data brokers; and
- is not shared with any third party except as needed to provide the Service to you (for example, your linked coach), and never for that third party’s own marketing.
8. Data retention and deletion
We retain your data for as long as your account is active. You can:
- Disconnect any wearable or service (Oura, Strava, Whoop) at any time, which deletes the stored tokens for that service.
- Request deletion of your account and associated data by contacting peter@pjxdesigns.com.
When you request account deletion, we remove your live account data from our cloud database (Firebase / Cloud Firestore) within 30 days. Encrypted copies may persist in our cloud provider's automated, rolling backups for up to an additional 90 days before they age out; during that window the data is inaccessible to us in normal operations and is overwritten as backups cycle. We may retain a minimal set of records — for example, abuse-prevention or security logs and any documentation we are required to keep for tax or legal compliance — for the period the law requires, stored separately from live account data and not used to personalize the Service.
Disconnecting a third-party service (Oura, Strava, Whoop) removes its access tokens from your device immediately. Any data we already received from that service before you disconnected remains on your account until you delete it or close your account.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. This includes rights under the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA). To exercise any of these rights, contact peter@pjxdesigns.com. We will not discriminate against you for exercising them.
If you are in the EEA or UK, our legal bases for processing are your consent (for health data and connected services), performance of a contract (to provide the Service), and our legitimate interests (to secure and improve the Service).
10. International data transfers
Hona’s cloud infrastructure (Google Firebase) and AI provider (Anthropic) are based in the United States, so your data may be processed there. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for international transfers.
11. Children's privacy
Hona is not directed to children. You must be at least 16 years old to create an account or use the Service.
In the United States, we comply with the Children's Online Privacy Protection Act (COPPA): we do not knowingly collect, use, or disclose personal information from children under 13. In jurisdictions that set a higher minimum age for digital consent (for example, age 16 under the EU GDPR), we apply that higher threshold. If we discover that we have collected personal information from a child below the applicable age, we will delete that information and close the associated account promptly.
Parents or guardians who believe a child has provided us personal data can contact peter@pjxdesigns.com and we will act on the request without delay.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide notice in the app or by email.
13. Contact us
Hona — Peter Jones Experience Design LLC
Email: peter@pjxdesigns.com