Privacy Policy

Effective Date: July 21, 2026

Diorama Health helps you plan, track, and understand your training and recovery. This Privacy Policy explains what information Diorama accesses, what stays on your device, what may leave your device when you use connected features, how that information is used, and the choices available to you.

Diorama does not require an email address, password, or traditional user account. Core health and training records are local-first. Cloud AI, product analytics, feedback, and subscription services use limited off-device data as described below. For a shorter overview, see the health app with no login.

1. Privacy Principles

  • Core health and training records stay on your device
  • You can control Apple Health access, AI features, and product analytics
  • Your health and training data is never sold or used for advertising
  • Diorama does not track you across other companies' apps or websites

2. Information We Access or Collect

a. Health and Fitness Data

With your permission, Diorama may read selected data from Apple Health, including:

  • Workouts, activity, steps, energy expenditure, and fitness metrics
  • Heart rate, heart rate variability, and related recovery signals
  • Sleep data
  • Mobility, body measurements, biological sex, and date of birth
  • Vitals such as respiratory rate, blood oxygen, wrist temperature, and blood pressure
  • Optional health categories you enable, such as medications, lab values, conditions, or health records

Diorama uses this information to display your history, support planning and coaching, and generate recovery and performance insights. Optional clinical categories are separate from the core training experience and require their own permission. Diorama writes to Apple Health only for features you explicitly enable.

b. Information You Enter

  • Training sessions and plans
  • Habits and check-ins
  • Pain, soreness, mood, and recovery inputs
  • Notes, journal entries, and conversations with Ray
  • Feedback messages and an optional contact email when you choose to submit feedback

c. App, Device, and Analytics Information

When analytics is enabled, Diorama may collect product-interaction events together with app version, build number, platform, locale, premium status, and pseudonymous app and device identifiers. The app user identifier can persist across reinstalls and your Apple devices through Apple's iCloud key-value storage. It is not an email address or Apple Account identifier, but it can become linked to your email if you include one in a feedback submission.

d. Subscription and Purchase Information

To activate and maintain premium access, Diorama processes App Store transaction information such as product ID, original transaction ID, subscription status, renewal, expiration, refund, and revocation events. Diorama retains entitlement history so access can be restored and support issues can be resolved.

3. Local Storage and iCloud

  • Core health, training, habit, check-in, and journal records are stored locally in Diorama's protected app storage
  • Diorama does not sync those health or training records through CloudKit
  • Limited non-health preferences, attribution data, and a pseudonymous app identifier may use Apple's iCloud key-value storage
  • Removing Diorama deletes its local records from that device, subject to Apple's normal device backup behavior

4. Ray and AI Processing

Ray uses cloud AI to provide coaching, answer questions, and support training decisions. AI features are enabled by default after the onboarding disclosure and can be turned off at any time in Diorama Settings. When AI is off, Diorama stops sending AI requests from the app.

What is sent

When you use Ray, Diorama sends your message and relevant app context to Diorama-operated server infrastructure and Google Vertex AI. Depending on your question and permissions, that context may include recent workouts, check-ins, plans, and enabled health categories.

What is retained

  • Diorama does not persist readable AI prompt or response content after serving the request
  • Diorama may retain technical metadata such as timing, token counts, tool names, completion status, and error class
  • Google may temporarily retain a prompt for up to 90 days if automated safety systems flag it for suspected abuse
  • Google does not use Diorama's data to train or fine-tune models unless Diorama gives permission; Diorama has not given that permission

No background AI collection

Diorama does not continuously send health data to AI services. AI context is sent when an AI feature performs a request, such as when you ask Ray a question or request an AI-generated briefing.

5. Product Analytics

Product analytics are enabled by default and can be disabled in Diorama Settings. Diorama uses PostHog to understand feature usage and improve reliability and usability.

  • Routine analytics may include product interactions and the app, device, and identifier context described above
  • Routine analytics does not include health values, medication names, pain details, journal or note text, or raw AI prompts and responses
  • Analytics is not used for advertising or tracking across other companies' apps or websites
  • Turning analytics off stops remote analytics events and remote feature-flag lookups

6. Feedback and Support

Feedback & Ideas is an intentional exception to the routine analytics limits above. When you press Send feedback, the message you wrote, your optional email, pseudonymous app and device identifiers, premium status, app version, build number, and submission time are delivered to Diorama through PostHog. Diorama uses this information to read your feedback, improve the product, and contact you when you ask for or may benefit from a reply.

Please do not include sensitive medical details in free-form feedback. Feedback and contact information are retained only as long as reasonably necessary to review the submission, follow up, improve Diorama, and meet legal or security obligations. You may request deletion by contacting Diorama.

7. Service Providers and Data Sharing

Diorama does not sell personal data, share health data with advertisers, or use personal data for cross-app tracking. Information is shared only as needed with:

  • Apple, for HealthKit permissions and data access, limited iCloud key-value storage, and App Store purchases
  • Google Vertex AI, to generate Ray's responses and enforce service safety
  • Google Cloud, for Diorama's server infrastructure, subscription entitlements, usage controls, and technical records
  • PostHog, for product analytics and the feedback submissions described above
  • Authorities or other parties when required by law, needed to protect safety or rights, or involved in a business transfer

8. Your Choices

  • Grant or revoke Apple Health permissions in the Health app
  • Turn AI features off in Diorama Settings
  • Turn product analytics off in Diorama Settings
  • Choose whether to submit feedback and whether to include an email
  • Delete local data in Diorama or by removing the app
  • Contact Diorama to request access to or deletion of feedback, entitlement, or other server-side records associated with you

9. Data Retention

  • Local records remain until you delete them or remove the app
  • Diorama does not retain readable AI prompt or response content after serving the request
  • AI technical metadata, analytics events, and support records are retained only as long as reasonably necessary for their stated purposes and legal or security obligations
  • Subscription entitlement history may be retained to provide and restore access, handle refunds or revocations, prevent fraud, and resolve support or accounting issues
  • Google's suspected-abuse retention for AI prompts may last up to 90 days as described above

10. Security

Diorama uses Apple device encryption, iOS file protection, Keychain storage for premium access tokens, and encrypted network connections. No security measure is perfect, but Diorama limits off-device data and access according to the purposes described in this policy.

11. Children's Privacy

Diorama Health is not intended for children under 13 and does not knowingly collect personal information from children.

12. Changes to This Policy

Diorama may update this Privacy Policy as the product or its data practices change. Updates will be posted at this URL with a revised effective date.

13. Contact

For privacy questions or data requests, contact privacy@diorama.fit. For product support, contact support@diorama.fit.