arii/hrm

Privacy Policy

Last Updated: December 9, 2025

arii/hrm ("the Project," "we") is an open-source web application. This Privacy Policy explains how we handle your data, specifically regarding our planned integrations with Strava and active integrations with Spotify.

1. Introduction

arii/hrm is designed to prioritize your privacy. We process your health data locally on your device in real-time. We do not store your personal health information on our servers.

Our Core Privacy Promise: Your health data stays on your device. We believe in data minimization and only process data necessary for the functionality of the app.

2. Data Collection & Usage

Health Data

We read real-time Heart Rate (HR) data from your connected Bluetooth Low Energy (BLE) devices. This data includes:

Important: All heart rate data is streamed via Bluetooth for real-time visualization. This data is processed in your browser's memory and is not stored on our servers. When you close the application or end your session, this data is immediately discarded.

Workout Session Data

If you choose to save workout summaries (duration, average heart rate, zones), this data is stored locally on your device only. We never transmit or store this information on external servers.

3. Third-Party Services & Attribution

Our service integrates with the following platforms. Your use of these integrations is subject to their respective privacy policies:

Strava Integration (In Development)

Note: This feature is currently in development. When active:

When you connect your Strava account, we request access to:

Strava Data Usage Commitment:

We do not use Strava data for any purpose other than providing the arii/hrm functionality to you. We comply fully with Strava's API Agreement and Brand Guidelines. Strava activity data is only used to display your workout metrics during active sessions and is never stored, analyzed for other purposes, sold, or shared with third parties.

We do not manipulate, store, or redistribute this content. Use of Strava features is subject to the Strava Terms of Service.

Strava Attribution: Some activity data displayed in this application may originate from Garmin devices. We acknowledge that this data is sourced from Garmin via Strava. Garmin is a trademark of Garmin Ltd or its subsidiaries.

Spotify Integration

When you authorize Spotify, we access:

Our Spotify integration uses the Spotify Platform. By using our Spotify integration, you agree to be bound by the Spotify Developer Agreement and Spotify Privacy Policy.

Key Terms:

Garmin Data

We use the Strava API to sync and display activity data. In compliance with Strava API Brand Guidelines:

4. Data Retention and Deletion

We do not store your health data.

All heart rate and workout data is processed in real-time on your device or our application when you close the application or end the session. This data is discarded immediately after your workout session ends unless you explicitly choose to upload it to a connected third-party service.

Account Disconnection

You may disconnect your Strava or Spotify accounts at any time via the "Settings" menu in the app. Upon disconnection, all authentication tokens are immediately permanently deleted from our system. You may also revoke access directly via the Strava Apps Settings pages or Spotify Apps Settings pages.

5. Data Security

We implement appropriate technical measures to protect your information:

6. Your Rights and Control

You maintain full control of your data:

7. Children's Privacy

Our service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.

8. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date at the top of this policy. Continued use of the service after changes constitutes acceptance of the modified terms.

9. Third-Party Links

Our application may contain links to third-party websites and services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.

10. International Users

This application processes data locally on your device. If you use our service from outside the United States, please be aware that any information processed will be in accordance with this Privacy Policy.

11. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or request data deletion, please contact us at:

Email: anders.ariel@gmail.com

© 2025 arii/hrm. All rights reserved.