Privacy Policy
Effective: 2 September 2026 · Version: 2026-09-02
Octane is a training-nutrition app: you log what you eat, connect the devices you already wear, and it works out what to fuel with. This policy explains what we collect, why, and who else ever sees it.
Health data is the sensitive part, so there is a separate Consumer Health Data Privacy Policy covering it in the detail Washington's My Health My Data Act requires. That policy governs where the two overlap.
1. Who we are
Octane is operated by CareyOS. Contact: privacy@careyos.com.
2. What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Your email address, or the Apple account identifier if you sign in with Apple, and your name if you give one | To have an account at all, and to sign you back in |
| What you log | Food and drink, portions, meal times, water, notes, saved meals and recipes | It is the product |
| Photos of food | Images you choose to photograph for macro estimation | To estimate what is in the meal |
| Body and training | Weight, body composition, sex, age and height if you enter them; training days, planned and completed sessions | To calculate your targets and judge how a session went |
| Connected devices | Workouts, sleep, heart rate, heart-rate variability, resting heart rate and breathing rate, from Apple Health, Garmin or an Oura ring — only the sources you connect | Recovery and fuelling recommendations |
| Workout readings (detailed run analysis, optional) | If you turn on detailed run analysis, the per-second heart-rate, distance and cadence readings of a finished run are sent once so summary figures (drift, splits, recovery) can be computed; only those summary figures are kept and the readings are discarded | The post-run read |
| Protocol records | Supplements, medications and doses, if you choose to record them | Covered by the consumer health data policy; collected only after separate consent |
| Subscription | Whether you have an active subscription and which tier | To unlock what you paid for |
| Training location (optional) | Where you usually train, if you choose to share it — rounded to a tenth of a degree (about 11 km, a town rather than an address) before it is stored. You can share your phone's location or type a city or postal code instead. While you allow location access, the phone app re-checks when you open it and updates the stored town if you have moved; only the latest town is kept — never a history, never a track. A town name may be stored alongside for display. Remove it, or revoke location access in iOS Settings, and the re-checking stops | To look up the weather at the hour you run and tell you what to expect from it |
| Operational logs | Error codes, timing, and which features were used — never the contents of a meal, a dose or a health reading | To keep the service working |
Activity files and routes. When you connect a fitness account such as Garmin, the activity file your watch recorded is kept as part of your workout record. That file can contain the GPS trace of the run. Octane does not map, display or analyse where you ran, and never derives a location from it — with one exception you control: if you turn on route outlines on share cards (off by default, in Settings), a card you choose to share can carry the run's outline. The outline is built on request from that file with the first and last 300 metres removed, and contains no coordinates, scale or compass reference — only the shape. Nothing about a route is stored beyond the card you published, and you can take a card down at any time.
We do not collect precise location beyond the activity file described above, location history, contacts, or your device's advertising identifier. The optional training location above is a single coarse point you set yourself; you can remove it at any time in Settings. Weather is fetched from Open-Meteo using that coarse point only — no account identifier or other data goes with the request. Octane contains no third-party analytics or advertising SDK.
The website. If you arrive at octanefuel.app from a link that carries a referral or campaign code, the site stores that code in one first-party cookie for 30 days so the person or campaign who sent you is credited when you join. It holds nothing about you, and an ordinary visit sets no cookie at all. The website's own page views and clicks are counted by Octane itself, with a per-day hash that cannot identify you across days; no third-party analytics runs on the site either.
3. Where it comes from
- You, when you enter or photograph it.
- Apple Health, for the categories you authorise on your device. You choose each one, and you can withdraw any of them in the Health app at any time.
- A fitness account you connect, such as Garmin or Oura. You approve the connection on that provider's own page; we never see your password for it. Disconnecting stops further imports immediately.
- A training plan you connect — Intervals.icu (a connection you approve on their page) or Runna (a private calendar link you paste inside Octane; the link never leaves the app and is stored encrypted). We read your planned workouts so the day's call can see your plan. Disconnecting stops further reads immediately.
We do not buy data about you, and we do not infer health information from your behaviour elsewhere.
4. How we use it
- To show you your own records and calculate your targets.
- To produce the recommendations, trends and written briefs in the app.
- To send the emails you have switched on, and no others.
- To bill your subscription.
- To find and fix faults.
We do not sell your data. We do not use it for advertising, and we do not share it with advertisers, ad networks or data brokers.
5. Artificial intelligence
Some features send your data to an AI provider to be turned into text: photo and dictated meal estimates, meal plans, coaching emails and the daily brief.
- The providers are Anthropic and Google, acting as processors under contract. They do not use your data to train their models.
- Numbers in AI-written text are computed by Octane and passed to the model to narrate. The model is not permitted to invent figures, and output containing numbers we did not supply is rejected.
- AI estimates are estimates. Macros from a photo or a description are approximations you can edit, and they are not a substitute for weighing food.
- Protocol data reaches an AI provider only if you separately opt in to that, and withdrawing that consent stops it on the next request.
6. Who else sees it
Only service providers that operate the product for us, under contract, and only for that purpose:
| Recipient | What reaches them | When |
|---|---|---|
| Anthropic, Google | The context needed for the feature you used | When you use an AI feature |
| DigitalOcean | All stored data, at rest on our infrastructure | Always — it is where the product runs |
| Cloudflare | Encrypted traffic in transit | Always |
| Our email provider | The address and content of emails you enabled | Only if you enable them |
| Apple | Subscription status and purchase records — no health or food data | For billing |
| Stridee | The identifier for the fitness account you connected, so your workouts can be fetched | Only if you connect a device |
| Oura | Nothing. We read from Oura; we send them no data about you | Only if you connect a ring |
| Intervals.icu | Nothing beyond the connection itself. We read your planned workouts; we send them no data about you | Only if you connect it |
| Runna | Nothing beyond fetching the private calendar link you pasted. We read your plan; we send them no data about you | Only if you paste a link |
| Sentry | Technical error and crash diagnostics — app version, device model, stack traces. Never health or food values | Always, to keep the product working |
We may also disclose data if the law requires it, or to protect someone's safety, and will tell you unless legally prevented.
7. How long we keep it
- Your logs and history stay until you delete them or close your account.
- Photos are kept while the estimate they belong to exists.
- Snapshots of a connected training-plan feed (and raw workout files from a connected device) are retained for a bounded period so imports can be re-checked, then pruned automatically. Disconnecting or closing your account deletes them.
- Operational logs are kept for a short period and contain no health values.
- Closing your account deletes your data. Records of consent given and withdrawn are retained as evidence of what was agreed; they contain no health values.
8. Your rights
In the app, taking effect immediately:
- See it — everything is displayed back to you.
- Export it — Settings → Protocol & health data.
- Delete it — delete individual records, delete imported health data, or close your account entirely.
- Withdraw consent — for AI processing of protocol data, or by disconnecting a device.
Depending on where you live you may also have rights to correct data, object to processing, or complain to a regulator. Write to privacy@careyos.com and we will respond within 45 days, telling you if we need longer.
9. How we protect it
- Encrypted in transit (TLS) and access-controlled at rest.
- Access tokens for connected accounts are encrypted with AES-256-GCM.
- Health values never appear in application logs or error reports — codes and counts only.
- Staff do not browse health data for support. An administrator viewing another household member's profile cannot see protocol data at all, and cannot write anything on their behalf.
10. Children
Octane is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us data, write to privacy@careyos.com and we will delete it.
11. Where data is held
Data is stored in the United States. If you use Octane from elsewhere, you are sending your data to the United States, which may not offer the same protection as your own country's law.
12. Changes
If we change what we collect, why, or who receives it, we will publish an updated version and — where the change concerns health data — ask for your consent again rather than carrying an old consent forward.