Legal
Version 1.0 · Effective 20 September 2026
Every agreement, policy and disclosure that governs your use of Svaya, on one page.
Each has a permanent link you can bookmark or cite. If we change any of them in a way that materially affects you, we will tell you in the app or by email before it takes effect.
- Terms of Service — The agreement between you and Vyoma Technologies Limited.
- Privacy Policy — What we collect, why, and how to export or delete it.
- Privacy Choices — What is always on, what is yours to choose, and what each switch controls.
- Body-Geometry & Biometric Data Consent — What the camera measures, what leaves your phone, and how long it is kept.
- Medical Disclaimer — Svaya is not medical care and does not give medical advice.
- Assumption of Risk & Release of Liability — The risks of training, and what you accept by training with Svaya.
- AI & Automated-Feedback Disclaimer — What the automated counts, scores and forecasts can and cannot do.
- Age Attestation — Svaya is available to adults only.
- Consent to Electronic Records & Signatures — Receiving and signing Svaya's agreements electronically.
- Beta Software Acknowledgment — Svaya is pre-release software.
- Coach Access Disclosure — Exactly what a coach can see when you grant them access.
- Coach Data Access Consent — Granting a coach access to your data, one category at a time.
- Coach Content Licence & Rights Attestation — For coaches publishing content on Svaya.
Terms of Service
01 · The agreement between you and Vyoma Technologies Limited.
Technologies Limited
1. The agreement
These Terms are a contract between you and Vyoma Technologies Limited ("Vyoma", "we", "us"), an Ohio limited liability company with its registered office at 3296 Logsdon Loop, Delaware, Ohio 43015, USA. They govern your use of the Svaya™ mobile application and any related websites and services (together, "Svaya" or "the Service").
By accepting these Terms, you agree to them. If you do not agree, do not use Svaya.
Five other documents form part of this agreement and are presented to you alongside it: the Privacy Policy, the Medical Disclaimer, the Assumption of Risk & Release of Liability, the AI & Automated-Feedback Disclaimer, and the Beta Acknowledgment. Where any of them addresses a subject more specifically than these Terms do, the more specific document governs that subject.
Svaya™ is a trademark of Vyoma Technologies Limited. A US application for SVAYA is pending on the Principal Register — serial 50018265, filed 28 July 2026 under § 1(b) (intent to use), International Class 009. The mark is not registered, so it is used as ™ and never as ®.
2. Who may use Svaya
You must be 18 years of age or older to create an account or use Svaya. Account creation requires an explicit affirmation that you are
directed to children, and we do not knowingly collect any personal data — including camera-derived body-geometry data — from anyone under 18. If we learn that a person under 18 has created an account or that we hold their data, we will close the account and delete the data. To report a suspected under-age account, contact privacy@getsvaya.com.
Whatever the age position, the following also apply:
You must be able to form a binding contract where you live.
You must not be barred from receiving the Service under the export-control or sanctions laws of the United States or your own country.
If you accept these Terms on behalf of an organisation, you confirm you are authorised to bind it.
We may refuse, suspend or terminate service to anyone, at any time, where we reasonably believe it is necessary to comply with law, protect users, or protect the Service.
3. Your account
You are responsible for keeping your credentials secure and for everything that happens under your account. Give us accurate information and keep it current — in a product that prescribes physical exercise based on what you tell it, a false age, weight or health condition is not a harmless inaccuracy.
Tell us promptly at hello@vyomatechnologies.com if you believe your account has been used without your permission.
4. What Svaya is — and what it is not
4.1 What it is
Svaya uses your phone's camera and on-device analysis to observe your movement during exercise, count repetitions, estimate the quality of your form, generate workout plans, and track your progress over time. It can also connect you with a human coach, subject to §6.
4.2 What it is not
Svaya is not a medical device. It is not cleared, approved or registered as one by the U.S. Food and Drug Administration or by any other regulator, and it is not intended to diagnose, treat, cure, mitigate or prevent any disease or condition.
Svaya does not provide medical advice, physical therapy, rehabilitation, diagnosis, or nutritional or dietary advice. It will not tell you what to eat, and any output that appears to make a physiological or medical claim is outside its intended scope and should not be relied upon.
Svaya does not supervise you. Nobody is watching a live feed for your safety. If something goes wrong during a workout, the app will not know, will not call anyone, and cannot help you. This is true even during a live coaching call, where your coach can see you but cannot reach you.
Svaya is not a substitute for a qualified in-person trainer, physician, physiotherapist or dietitian who can assess you in the room.
4.3 Automated exercise prescription — read this
Svaya decides, by software, which exercises to give you, how many sets and repetitions, and how hard to push. Those decisions are produced by algorithms and machine-learning models operating on the information you supplied and on what the camera measured. They are estimates and suggestions, not instructions, and they can be wrong in ways that matter: an exercise unsuitable for your body, a load your joints are not ready for, a rep count that is off, or form feedback that misreads what you are doing.
You remain the decision-maker for your own body. Do not perform a movement that feels wrong simply because Svaya suggested it or counted it. The full statement of what the automated outputs can and cannot do is in the AI & Automated-Feedback Disclaimer, which forms part of this agreement.
5. Your content and your data
You keep ownership of what you create — your workout notes, measurements, photographs you choose to add, videos you record, and any feedback you send us.
You grant us the licence we need to run the Service. For as long as you keep content on Svaya, you grant Vyoma a non-exclusive, worldwide, royalty-free licence to host, store, reproduce, transcode, adapt for display, and transmit your content solely in order to operate and improve the Service for you and, where you have authorised it, for a coach you have connected. This licence ends when you delete the content or your account, except for copies retained in routine backups until they rotate out, and except for anonymous or aggregate statistics that no longer identify you.
We do not have a marketing licence to your content. This licence does not let us use your name, likeness, images, videos or results in advertising, promotion, testimonials or case studies. If we ever want to, we will ask you separately.
How we handle your personal data is governed by the Privacy Policy, not by this section. The Privacy Policy is the specific document and it controls.
Feedback you send us — bug reports, feature ideas, suggestions — may be used freely by us without obligation or compensation. Do not send us anything you consider confidential or want to be paid for.
6. Coaches
Svaya can connect you with an independent human coach.
Coaches are independent, not our employees or agents. They are independent contractors who set their own methods and are responsible for their own advice, qualifications, conduct and compliance with the law where they and you are located. Vyoma does not provide coaching services, does not supervise a coach's programming, and is not responsible for what a coach tells you to do. A coach's plan is theirs.
Verification badges mean something narrow. Where a coach is shown as "verified", it means we checked one or more specific credentials they gave us. It is not an endorsement of their competence, judgment or safety, and it is not a warranty that their advice suits you. Where a coach is shown as self-attested, it means the coach declared their credentials and we did not verify them. Read the badge literally.
What a coach can see is controlled by you. A coach sees only the categories of your data you have specifically granted, each granted separately and revocable at any time. Access to your body-geometry data is a separate grant that is off by default and never bundled with anything else. Every access a coach makes is recorded in an audit log.
Disputes with a coach are between you and the coach. We are not a party to your arrangement with them. We may, but are not obliged to, help resolve a complaint.
Payments. No payment for coaching currently flows through Svaya. Verified: the commerce subsystem is present in the codebase but is a stub, gated off by default, and no code path processes a payment or moves money between users. If and when we enable paid coaching, we will publish separate terms covering fees, merchant of record, taxes, refunds and payouts, and you will accept them before any charge. Do not treat this section as authorising a payment.
7. Subscriptions and payment
Svaya requires a paid subscription. After you create an account and complete onboarding, you receive a 7-day free trial of the full app. When the trial ends you must subscribe to continue using Svaya; there is no free tier and no permanently free level of access. Access is granted while you are in the trial or hold an active paid subscription.
Subscriptions are sold and billed by Apple through your App Store account, under Apple's terms and the price shown to you at purchase.
They renew automatically for the same period unless you cancel at least 24 hours before the current period ends. Your account is charged for renewal within 24 hours before the period ends.
You manage and cancel in your device's App Store subscription settings. Deleting the app does not cancel a subscription.
Free trials, where offered, convert to a paid subscription unless cancelled before the trial ends. Eligibility for an introductory offer is determined by Apple.
Refunds are handled by Apple under Apple's policies. We generally cannot issue them.
Price changes take effect only after we notify you and, where required, obtain your consent; you may cancel before they apply.
8. Acceptable use
You agree not to:
use Svaya for anything unlawful, or in a way that infringes anyone's rights;
upload video or images of any person who has not agreed to appear;
reverse-engineer, decompile or attempt to extract our models, source code or training data, except where that restriction is prohibited by law;
scrape, bulk-download, or use automated means to extract data from the Service;
resell, sublicense, or provide the Service commercially to third parties without our written agreement, or use it to build a competing product;
interfere with the Service's operation, probe or breach its security, or access it by means we did not provide;
misrepresent your identity, credentials, or your relationship to anyone;
submit false, misleading or incentivised reviews or testimonials;
use the Service to provide medical, physiotherapeutic or nutritional services to another person unless you are lawfully qualified to do so where they are.
We may investigate and act on suspected breaches, including by suspending or terminating access.
9. Our intellectual property
Svaya, including its software, models, designs, exercise library, coaching copy, name and logo, belongs to Vyoma or our licensors, and is protected by intellectual-property law. We grant you a personal, limited, revocable, non-exclusive, non-transferable licence to use the app on devices you own or control, for your own non-commercial use, for as long as you comply with these Terms. That is the whole of what you get; nothing else is granted by implication.
10. App store terms
You obtained Svaya from the Apple App Store. As a condition of Apple's rules:
These Terms are between you and Vyoma only. Apple is not a party.
Vyoma, not Apple, is solely responsible for Svaya and its content.
Apple has no obligation to provide any support or maintenance for Svaya.
To the extent permitted by law, Apple has no warranty obligation. Any failure to conform to a warranty is Vyoma's responsibility, and Apple's only obligation is to refund the purchase price, if any.
Vyoma, not Apple, is responsible for any claim that Svaya or your use of it infringes intellectual-property rights, and for product-liability and regulatory claims.
You confirm you are not located in a country subject to a U.S. embargo or designated as terrorist-supporting, and are not on any U.S. prohibited-party list.
Apple and its subsidiaries are third-party beneficiaries of these Terms and may enforce them against you.
11. Availability and changes
We may change, suspend or discontinue any part of Svaya, and we may impose limits on features or storage, at any time. We will give reasonable notice of a material adverse change where we can. Beta features may change or disappear without notice — see the Beta Acknowledgment.
We may update these Terms. For a material change, we will re-present the Terms and require you to accept them before you continue using Svaya. Your acceptance of each version is recorded, against the exact text you were shown.
12. Termination
You may stop using Svaya and delete your account at any time in Settings → Privacy. We may suspend or terminate your access if you materially breach these Terms, if we reasonably believe your use creates legal risk or harm to others, or if we cease providing the Service.
Sections that by their nature should survive — your content licence for already-shared content, disclaimers, limitation of liability, indemnification, dispute resolution, and this sentence — survive termination.
13. Disclaimer of warranties
Svaya is provided "as is" and "as available." To the fullest extent permitted by law, Vyoma disclaims all warranties, express, implied and statutory, including merchantability, fitness for a particular purpose, title, non-infringement, accuracy, and any warranty arising from course of dealing or trade usage.
We do not warrant that Svaya will be uninterrupted, timely, secure or error-free; that rep counts, form scores, plans or projections will be accurate; or that any result will be achieved.
Some jurisdictions do not allow the exclusion of certain warranties, so parts of this section may not apply to you. Nothing here excludes liability that cannot lawfully be excluded — including, in the United Kingdom and European Union, liability for death or personal injury caused by negligence, and statutory consumer rights; and in India, rights under consumer-protection law.
14. Limitation of liability
To the fullest extent permitted by law:
(a) Vyoma and its officers, employees and agents are not liable for indirect, incidental, special, consequential, exemplary or punitive damages, nor for lost profits, lost data, or loss of goodwill, however caused and on any theory of liability, even if we were advised such damages were possible.
(b) Vyoma's total aggregate liability arising out of or relating to Svaya will not exceed the greater of (i) the amount you paid us in the twelve (12) months immediately before the event giving rise to the claim, or (ii) one hundred US dollars (US$100).
(c) These limits apply to all claims, whether in contract, tort (including negligence), strict liability, statute or otherwise.
(d) Nothing in this section limits liability that cannot lawfully be limited, including for fraud, wilful misconduct, or death or personal injury caused by negligence where the applicable law prohibits its exclusion.
15. Indemnification
You will defend, indemnify and hold harmless Vyoma and its officers, employees and agents from any claim, damage, liability, cost and expense (including reasonable legal fees) arising from your breach of these Terms, your misuse of Svaya, content you upload, your infringement of anyone's rights, or — if you are a coach — the coaching services you provide.
16. Disputes
UNFILLED — dispute-resolution clause. Counsel must supply this, or section 16 must be deleted and disputes left to section 17.
17. Governing law
These Terms are governed by the laws of UNFILLED — governing law, without regard to its conflict-of-laws rules. UNFILLED — venue
Nothing in this section deprives a consumer of the protection of mandatory laws of the country where they habitually reside — which, for users in the European Union, the United Kingdom and India, materially limits the effect of a choice of foreign law.
18. Export control and service location
Svaya is controlled and operated from the United States. We make no representation that it is appropriate or available elsewhere. You are responsible for complying with local law where you use it, and you may not use or export it in violation of U.S. export-control or sanctions law.
19. General
Entire agreement. These Terms, together with the five accompanying documents named in §1 and the Privacy Policy, are the entire agreement between you and Vyoma about Svaya.
Severability. If any provision is held unenforceable, it is modified to the minimum extent necessary, or severed, and the rest remains in force.
No waiver. Not enforcing a provision is not a waiver of it.
Assignment. You may not assign these Terms. We may assign them to an affiliate or in connection with a merger, acquisition or sale of assets.
No third-party beneficiaries, except Apple under §10.
Notices to you: to your account email or in the app. To us: to hello@vyomatechnologies.com and 3296 Logsdon Loop, Delaware, Ohio 43015, USA.
Force majeure. Neither party is liable for failure to perform due to causes beyond its reasonable control.
20. Contact
General and legal: hello@vyomatechnologies.com
Privacy and data rights: privacy@getsvaya.com
Postal: 3296 Logsdon Loop, Delaware, Ohio 43015, USA
Privacy Policy
02 · What we collect, why, and how to export or delete it.
privacy@getsvaya.com
1. Who we are
Svaya is operated by Vyoma Technologies Limited (“Vyoma”, “we”, “us”). Svaya™ is our trademark. A US trademark application for SVAYA is pending on the Principal Register — US serial number 50018265, filed 28 July 2026 on an intent-to-use basis under § 1(b), in International Class 009. It is not yet registered, which is why the mark appears as ™ throughout and never as ®.
Registered office: 3296 Logsdon Loop, Delaware, Ohio 43015, USA
Privacy and data-rights contact: privacy@getsvaya.com
General contact: hello@vyomatechnologies.com
India grievance officer: Grievance Officer, Vyoma Technologies Limited — support@getsvaya.com, 3296 Logsdon Loop, Delaware, Ohio 43015, USA — see §11.
For users in the European Economic Area and the United Kingdom, Vyoma is the controller of the personal data described here.
*RESOLVED 2026-09-04. This paragraph previously recorded a conflict: the app and the served page carried the pre-rename @fitcoach.app address while this policy directed data-rights requests elsewhere, and only one could be the address of record. The founder has confirmed the three live mailboxes — privacy@getsvaya.com for privacy and data-rights requests, support@getsvaya.com for support, and hello@vyomatechnologies.com for corporate and legal notices — and every @fitcoach.app route has been removed from the document set, from the served pages and from the app. Verified 2026-09-04: 13 references in the iOS source and 13 in the served pages resolve to privacy@getsvaya.com, and no @fitcoach.app mailbox remains in either. The App Store listing is the one surface not verifiable from the repository and must be checked before launch.*
2. The short version
Raw camera video is processed on your phone and is not uploaded during a workout. Verified: no image, frame, or video column exists on workout_frames; the table stores only numeric geometry.
The body-geometry data computed from that video IS uploaded and stored on our servers, and it is the core of how Svaya works. It is not optional, and it is not anonymous.
That geometry includes points on your face — nose, both eyes, both ears — and, when your device uses the high-resolution capture mode, your jaw, chin, eyelids, eyeballs, and every joint of all ten fingers.
We train our own models on it, but only if you switch that on. Model training is a separate opt-in, default off, and revocable.
We never sell your data, never give it to advertisers or data brokers, and never give it to another company to train their models.
You can export everything and delete your account from inside the app.
Everything below is the detail behind those six lines.
3. What we collect
3.1 Account and identity
| Data Notes | |
|---|---|
| Email address Stored hash is stored for l | encrypted at rest; a separate one-way ookup |
| Display name | |
| Password Stored only form | as a salted hash, never in readable |
| Sign in with Apple I identifier | f you use Apple sign-in |
| Two-factor secret En | crypted, only if you enable 2FA |
| Login and lockout Ti history state | mestamps, failed-attempt counts, account-lock |
Verified: users table columns email, email_hash, password_hash, password_hash_algo, apple_user_id, totp_secret_enc, failed_login_attempts, locked_until, last_login_at.
3.2 What you tell us about your body and your health
| Data Notes | |
|---|---|
| Age, gender, height, weight, body type F | rom onboarding and Settings |
| Fitness level, training experience, training frequency, time since last break | |
| Goals, target state, sessions per week, session length | |
| Equipment you own, and the locations you train in | |
| Body measurements you log over time | |
| Health conditions and injuries you Inc select or type cardiac conditions and pregnancy | ludes categories such as |
Verified: user_profiles (24 columns incl. age, gender, height_cm, weight_kg, body_type, primary_goal), body_measurements, user_health_conditions, user_equipment, user_locations, user_goals.
Health conditions and injuries are sensitive data. They are treated as special-category data under GDPR Article 9, as sensitive personal data under India's DPDP framework, and as consumer health data under Washington's My Health My Data Act.
3.3 Body-geometry ("pose") data — read this section
This is the significant one, and it is the reason this policy exists in this form.
What happens. During a tracked set, your phone runs a pose-estimation model on the live camera feed on the device. The model outputs the coordinates of a set of named body points. Those coordinates — not the picture — are uploaded to us and stored, at roughly fifteen samples per second.
What is in each stored sample:
Named body points, each with a horizontal and vertical coordinate and a confidence value. Some capture modes additionally record a depth coordinate and a three-dimensional world position for each point.
Computed joint angles — currently 21 named values, including both elbows, both shoulders, both hips, both knees, mid-spine, and a family of movement-specific depth metrics.
The rep-counter signal, the detected movement phase, the running rep count, the set number, and a form score.
Camera quality metadata: confidence, tracking quality, pitch and roll angle of the phone, and whether the phone was steady.
Which pose engine produced the sample.
Verified: workout_frames columns landmarks (jsonb), joint_angles (jsonb), depth_metric, depth_metric_key, rep_count, phase, set_number, form_score, form_events, camera_confidence, tracking_quality, camera_pitch_deg, camera_roll_deg, camera_steady, primary_source, counter_source, counter_depth, rep_event, in_position. Per-point keys observed across the corpus: name, x, y, conf, z, wx, wy, wz.
How many points, and which ones. Measured across the 467,865 samples currently stored:
| Skeleton Points | Samples **W | hen collected* | * |
|---|---|---|---|
| Standard (current 23 behaviour) (95.8%) ongoi | 448,203 2026-0 ng | 4-19 → today, | |
| High-resolution ARKit only | 112–113** 8,88 | 6 (1.9%) **202 | 6-08-01 → 2026-08-03 |
| Partial / 8–30 10,776 ( low-confidence | 2.3%) throughou | t |
The standard 23-point skeleton includes five points on your head: nose, leftEye, rightEye, leftEar, rightEar. The remaining eighteen are shoulders, elbows, wrists, hips, knees, ankles, heels, toes, neck and a root point. This is what we collect today, on every tracked set.
During a three-day period in August 2026, a high-resolution capture mode additionally recorded the jaw, the chin, both eyeballs, and the upper and lower lid of each eye — and a complete hand skeleton for both hands: thumb, index, middle, ring and little finger, three to four joints each. That mode is not in use today, but the data it produced is still stored and will remain until it ages out under the 180-day rule in §8. We disclose it rather than describe only the present.
Verified: distinct landmarks[].name values and per-shape date ranges queried directly from workout_frames on 2026-08-16.
This is stated so precisely because it is the fact that decides how this data is regulated. A "stick figure" framing would be inaccurate: a time-series of eye, ear and nose positions is a geometric description of your face, and the August captures add hand geometry — which Illinois' statute names explicitly. See §4.
What is NOT in it. No image data. No video. No audio. There is no pixel, image, thumbnail, or frame column on workout_frames, and none of the stored values reconstruct a picture of you.
Why we store it (legal basis). To count your reps, score your form, drive range-of-motion and tempo feedback, keep your history consistent across devices, and let a coach you have connected review your movement. For users in the EEA/UK this is Article 6(1)(b), performance of the contract you signed up for — the same basis as storing your rep counts. It is not gated behind a toggle, and we do not offer a version of the tracked-workout feature that does not upload it. If you do not want body-geometry data stored, do not run a tracked set; manual logging does not produce it.
Model training is separate and opt-in. See §5.
3.4 Wearables, Apple Health, and motion sensors
If you grant access, Svaya reads the following from Apple HealthKit: heart rate, heart-rate variability, resting heart rate, active energy, VO₂ max, step count, body mass, and sleep analysis. It writes back only your completed workouts and active energy. It never writes your weight.
Verified:; com.apple.developer.healthkit entitlement in iOS/FitCoach/App/FitCoach.entitlements.
What reaches our servers, corrected as of 2026-08-17
wearable reaches our servers, and gave the measurement behind it: zero non-null workout_frames.watch_accel, zero non-null workout_frames.airpods_attitude, zero non-null workout_sessions.avg_heart_rate_bpm, and zero rows in health_metrics and apple_health_workouts, across 467,865 samples and 580 sessions. That measurement was correct on 2026-08-16 and is no longer the current behaviour. Two changes landed on 2026-08-16/17 and this policy states them rather than inheriting the older sentence:
Heart rate is now stored (V90.106). Your watch already ran a real workout session and read heart rate; the app threw every sample away and kept a single overwritten number that was never persisted. It is now stored as a raw timestamped series — one row per reading, roughly one every five seconds — in a dedicated heart_rate_samples table, alongside the app state observed at that moment (which exercise phase was running, and which set number). Those state fields are recorded as contemporaneous facts about the app, not as an attribution of any heartbeat to any set, and heart rate is explicitly barred from grading a set. We store the raw observation and derive the metric later, because heart rate lags the work that caused it and any averaging window chosen before we had data to tune it against would be a guess baked in irreversibly. Verified: migration V111_.
Wrist and head motion can now actually stream (V90.105). The columns had existed since V30 and nothing ever wrote to them, because the watch was told to stop streaming and never told to start — a wiring defect, not a design. That path is now connected, so wrist and head motion can reach our servers. It does so only under the separate opt-in below.
Wrist and head motion (off unless you turn it on)
Only if you turn on Wrist motion in Profile → Data Sharing, we record motion from the devices you are wearing:
| Device What we often | record** **How | |
|---|---|---|
| Apple Watch Accelera rotation rate, and t direction | tion with gravity removed, 50 times a he gravity second | |
| AirPods (models The with motion as a qua support) second | same three, plus head orientation About ternion times a | 25 |
Four things about this that we want to be exact about:
Only while a set is running. Not between sets, not during rest, not while you are setting up, and never outside a workout.
Only if the device is actually there. We check for a paired watch and for AirPods that report motion. If they are absent we record that fact and collect nothing.
Off by default, and nothing breaks without it. Rep counting works from the camera alone and does not use this data. It never has to be there.
Recording it is not the same as training on it. Whether we may use it to improve our shared models is the separate "Help Train Shared Models" choice. If that is off, this data is not used for training.
We do not record sound, and we do not record your location.
This is stored with the rest of that workout under the same pseudonym, which means it is linkable to your account, not anonymous, and it is deleted when you delete your account.
The two corrections, kept on the record
Corrected 2026-08-16 (V90.105). An earlier version of this policy claimed that head motion from AirPods never leaves the device. That is no longer true, and the sentence was removed rather than softened. If you turn on the wrist-and-head motion setting above, head motion IS sent to our servers. It is off unless you turn it on, and it is only recorded while a set is actually running.
Corrected 2026-08-16 (V90.105). An earlier version of this policy said the watch streamed "raw accelerometer motion" during every workout. That was never true. The database columns built to hold it (workout_frames.watch_accel, workout_frames.airpods_attitude) were non-null on 0 of 470,599 rows — the columns existed and nothing ever wrote to them. The claim was wrong on the day it was written, and V90.105 — which starts collecting this data for the first time, under an explicit opt-in — must not be mistaken for having made the old sentence retroactively correct.
OPEN: a full-rate sensor-upload lane (sensor_sessions) exists in code and ships disabled. It carries a raw user_id, has no training_eligible column, and therefore missed the V34 pseudonymisation sweep, which means consent revocation cannot reach it. It must not be enabled before those two gaps close, and this policy must be re-versioned if it is.
Camera-derived heart-rate estimation
A face-based heart-rate estimation feature (from the camera, not from a wearable) exists in the session pipeline. It is disclosed here for completeness. We use what it produces for your workout summaries and analytics, never for advertising. (Carried forward from Version 2, audit finding #23.)
3.5 Usage and diagnostic telemetry
We record which screens you open, what you tap, how you navigate, errors you hit, and workout events. This is always on; there is no decorative off switch, because we use it to keep the coaching features working and we would rather say so than offer a toggle that does nothing.
It is first-party only — it goes to our own servers under a per-device identifier. It does not go to an advertising network or a third-party analytics product. Verified: analytics_events and crash_reports are our own tables; there is no third-party analytics or advertising SDK in the app.
Because it is keyed to your device rather than your account, the 90-day retention bound in §8 is also what limits it after you delete your account.
3.6 Consent records
Every acceptance, decline and revocation is written to an append-only, hash-chained ledger, together with the SHA-256 fingerprint of the exact text you were shown, the app version, and the time you actually consented.
We keep this even after you delete your account, because it is the record that proves what you were shown and what you agreed to. It contains no personal data beyond your account identifier. Verified: consent_ledger, migration V67. A prior version of this policy also claimed we record the IP address and browser/app identifier observed at consent time; that claim is withdrawn as of 2026-08-19 — the ledger schema has those columns (V96) but the server does not populate them. If capture is ever wired and verified, this section may say so again — not before.
3.7 Video — the cases where it does leave your device
Nothing in (a) to (c) happens during an ordinary tracked workout. Each is something you start deliberately.
(a) Live coaching calls. Your camera and microphone stream in real time to the other participant, via LiveKit (§7). Calls are not recorded — the product has no recording capability and issues no permission that would allow one. Verified: V75_; no media-egress grant path exists.
(b) Coach demonstration clips. If you are a coach, videos you record and upload are stored as files on our server, with a pointer row in the database. Access is only ever through short-lived signed links; there is no public address. Verified:,, V82_.
(c) Group-session recordings a coach uploads.
⚠️ Faces in group-session video are not blurred. Automatic face redaction is designed but not shipped. Today the only protection is the coach's attestation that every person visible agreed to appear and that the coach holds the rights to their likeness. If you appear in a group session, ask your coach what they are uploading.
We state this in the policy rather than only in the coach's upload screen, because the people most affected are the participants — who are not the ones reading that screen. Verified: face redaction exists only in an internal research harness and is not referenced anywhere in the shipping app; the in-app copy at says so directly.
(d) Development builds only — engineering diagnostics. Development builds contain a frame-dump / screen-recording capability used for engineering diagnostics. It is not part of the shipping consumer flow and does not upload media. It will be compiled out of release builds before launch. (Carried forward from Version 2, audit findings #16 and #22.)
3.8 Coaches you connect
If you connect a human coach, they can — only with your explicit per-scope consent — view selected parts of your data, such as your workout history or your body-geometry form replay. Each scope is granted
revoked. Every staff or coach access to your data is written to an audit table (§12). The per-scope consent text is
Version 2 §10, audit finding #21, and expanded to describe the per-scope grant that has since shipped.)*
4. Biometric data — our position, stated plainly
Several U.S. laws regulate "biometric identifiers" specifically, and they do not all define the term the same way.
What we believe the honest characterisation is. The body-geometry data in §3.3 is a repeated geometric measurement of your body, including your face, and in the high-resolution mode your hands. Illinois' Biometric Information Privacy Act names "a scan of hand or face geometry" as a biometric identifier. Texas' CUBI uses similar language. Washington's My Health My Data Act reaches "biometric data" and consumer health data broadly, and covers bodily functions and measurements. We therefore treat this data as biometric, and give you the protections those statutes require, rather than arguing about whether a joint map is technically a "scan".
Accordingly:
(a) We tell you before we collect it. This policy, and the separate body-geometry consent screen
any tracked set can run.
(b) We tell you why, and for how long. Purpose: rep counting, form scoring, progress tracking, and — only with the separate opt-in in §5 — improving our own models. Retention: body-geometry samples are automatically and permanently deleted 180 days after collection. This is not a promise about a future job; it is a database-level retention policy that runs daily. Verified: TimescaleDB retention policy on the workout_frames hypertable, drop_after = 180 days, job 1001, scheduled daily; plus a compression policy at 7 days. Fifty-one retention_sweep events recorded in privacy_events.
(c) We get your written consent. Acceptance is captured electronically with a prior E-SIGN/UETA consent step, recorded in the hash-chained ledger against the fingerprint of the exact text.
(d) We do not sell, lease, trade or otherwise profit from it. Not to anyone, under any arrangement, ever.
(e) We publish our retention and destruction schedule. It is the table in §8.
(f) We protect it. In transit with TLS; at rest on encrypted volumes; stored under a pseudonym identifier rather than directly under your name.
On the pseudonym, honestly. Body-geometry samples are stored against a pseudonym_id rather than your user id. This is a single stable pseudonym per account, not a rotating one, and the samples remain linkable back to you through session identifiers. It reduces casual exposure; it is not de-identification, and we do not describe this data as anonymous. The pseudonym link is severed immediately when you request deletion. Verified: workout_frames.pseudonym_id, ml_pseudonyms table.
5. Training our models
We use body-geometry data, and the "was that rep count right?" corrections you confirm, to train and improve our own rep-counting and form-scoring models.
The Help Train Shared Models setting controls this. It is off by default.
Each uploaded sample carries a training_eligible flag set from your setting at the moment of upload. Our training pipeline selects only flagged samples.
Turning it off stops future samples from being flagged. Samples collected while you were opted in keep their flag; email privacy@getsvaya.com and we will clear them.
We do not send this data to OpenAI, Anthropic, Google, or any other company for their model training.
If you delete your account, the "was that rep count right?" corrections you gave us are kept in de-identified form and remain usable for this purpose. They are stripped of every identifier first, and the link back to you is destroyed rather than hidden. §8 describes exactly what is kept and what is not.
Being precise about what the toggle does and does not do. It does not control whether body-geometry data is uploaded — that happens either way, as §3.3 says. It controls only the eligibility flag. We say this plainly because one of our own settings screens currently describes it as though it governed sharing, and that screen is wrong. Verified: the flag is read at and written into the upload payload; the upload itself is unconditional, per the comment at and the runtime log at :1353 ("storage is unconditional"). The setting defaults to false at. Revocation de-flags rather than deletes:, :379-385.
6. Automated decisions and AI
Svaya algorithmically generates your workout plans and prescribes exercises, sets and repetitions. It also produces automated form feedback and projections about how your body may change over time.
These are software estimates, not professional advice, and they can be wrong. The full statement is in the AI & Automated-Feedback Disclaimer.
They are not medical advice, not a diagnosis, and not nutritional advice.
No decision with a legal or similarly significant effect on you is made by automated processing. If you are in the EEA/UK and believe otherwise, you may contact us to request human review.
To generate plans we send a structured fitness profile to an external AI provider. See §7.
7. Who else processes your data
| Processor **What t | hey do** **What they rece | ive** |
|---|---|---|
| Microsoft (Azure) Appl database and file §3 storage — one Linux virtual machine that runs our own PostgreSQL/TimescaleDB and holds uploaded fil on its disk. Microsoft supplies the infrastructure; it doe not operate the databa or the application. | ication hosting, Everythi | ng described in |
| Fly.io Legacy — no traffic. Held all §3 three of the above unt 2026-08-19. The deployment is suspende and its database credential was rotated but a frozen copy of t production database remains there pending destruction. | live A copy of everythin as it stood on il 2026-08-19 | g in |
| Anthropic (Claude Work API) profile — see t below | out-plan generation A str he note | uctured fitness |
| LiveKit Live video coa sessions video, only w are in a call | ching Real-time audio and hile you | |
| Apple App distribution sign-in, subscription billing, HealthKit | , Per Apple's own terms | |
| GitHub Encrypted off-s database backups — not currently running, see below | ite Nothing since 2026-08 | -19 |
| Google ML Kit / Pose e MediaPipe, Apple scori ARKit / Vision, throug CoreML, ONNX Runtime i Google's ML Kit does, by its own declaration collect a device identifier and diagnostic data for it own analytics — see below | stimation, form Your bo ng, coach voice leaves th h these — all nference is local. | dy data never e device |
| Cloudflare R2 Media st coded but not implemented | orage Nothing today - | – |
Where this runs. The application, the database and every uploaded file sit on Microsoft Azure infrastructure in Microsoft's Central US region, in the United States. Until 2026-08-19 all three ran on Fly.io; that deployment is suspended and holds only a frozen copy of the database, which is scheduled for destruction.
Live video does not pass through our servers. When you join a coaching call, your device connects directly to LiveKit's infrastructure over WebRTC. Our backend only issues the signed token that lets you into the room; it never carries the audio or video. Verified:,.
Google ML Kit's own data collection. The pose-detection library we bundle ships a privacy manifest in which Google declares that it collects a device identifier and diagnostic/performance data for its own analytics and app functionality, not linked to your identity and not used for tracking. We do not send it anything and we receive nothing from it, but it is a third-party data flow inside our app and you should know about it. Verified: iOS/Pods/MLKitCommon/Frameworks/MLKitCommon.framework/PrivacyInfo.xcprivacy.
Live video is not recorded. No recording capability exists in the product: the platform issues no media-egress permission for a live session. Verified: live_video_grants / live_video_sessions schema and the absence of any egress grant path.
8. How long we keep things
| Data Retention | Enforced by | |
|---|---|---|
| Body-geometry samples (workout_frames) perman production | *180 days**, then Databas ently dropped daily — * | e retention policy, runs verified in |
| Usage and diagnostic 90 telemetry | days Scheduled retention | job |
| Account, workout Until history, plans, account measurements | you delete your | |
| Heart-rate samples and wearable motion account | Until you delete your Del belong to | eted with the workout they |
| Deleted account Body-ge unlinked from you (Priv immediately and hours irreversibly; the on account itself permanently erased afte a 30-day grace period | ometry samples Applicatio acySweepScheduler), every , logged to privacy_event every run — verified | n sweep 6 s |
| De-identified movement measurements and to you reported counts, after you delete (retained_re | Kept, no longer linked Co and not linkable into a back identifier of any ki p_labels) | pied at the moment of unlinking table that holds no nd |
| Off-site backups **None | at present** — | |
| Consent ledger Kept ind deliberately, as a regulatory record | efinitely, Append-only ta | ble |
On deletion, precisely. Deletion happens in two steps, and the first one is immediate.
Step 1, at the moment you ask (irreversible). We do not merely delete the lookup table that connects your body-geometry samples to you — we rewrite the keys themselves. Every pseudonym and every session identifier on your pose frames, sensor streams, heart-rate samples and session metrics is replaced with a freshly generated value that exists nowhere else, and the old-to-new mapping is never written down anywhere. We do the same wherever your account identifier had leaked into diagnostics: usage telemetry, crash reports and the access-audit log. From that moment the samples are anonymous, and signing back in does not and cannot re-attach them to you.
Step 2, after the 30-day grace period. Your account, workout history, plans and everything that hangs off them are permanently deleted. Signing in within those 30 days keeps the account (step 1 still stands).
Until 2026-08-19 this paragraph continued: "Because backups rotate on a ~7-day cycle, deleted data leaves every copy we hold within about a week of the erasure executing." That is withdrawn rather than quietly deleted, because it was a representation about where your data ends up. No off-site backup has been taken since the Azure cutover, so today there is no backup copy for an erasure to have to reach. When backups resume, the rotation window has to be restated here — and it has to be a window that erasure actually propagates through.
What we keep, and why we say so here rather than in a footnote. On deletion we irreversibly de-identify your workout data and retain de-identified movement measurements and your reported counts to improve rep counting. Concretely: for each set, the number of reps you told us you actually did, how many our counter thought you did, the weight you entered, and the one-tap observation you gave us about the set. They are copied out at the moment of step 1, keyed only by the freshly generated identifier that replaced your session identifier, into a table that holds no account id, no pseudonym, no email, no device id and no foreign key to anything. Nothing you typed in free text is copied, because free text can name a person. The result is not "your data with the name removed" — the link was destroyed in step 1 and was never written down, so there is nothing left to reverse. It is a measurement of a movement that is no longer attached to anyone.
We keep it for one reason: those corrections are the only record of when our rep counter was wrong, and without them the counter cannot be made better for the people still using it. Verified: retained_rep_labels holds no identity column and no foreign key; AccountErasureCoverageTest fails if one is ever added, and AccountErasurePostgresIntegrationTest asserts both halves after a simulated deletion — the measurements are still there, and no join path from them reaches an account.
Verified: — the sweep enumerates every table holding an identity column, with a test (AccountErasureCoverageTest) that fails when a new one is added outside it; AccountErasurePostgresIntegrationTest performs a simulated deletion against a real database and then searches every column of every table for the erased identifiers. PrivacySweepScheduler runs step 2 and writes a privacy_events row on every sweep, including sweeps that find nothing, so a stopped job is distinguishable from an idle one.
What this replaces, stated plainly because a previous version of this document said otherwise: until 2026-08-19 deletion removed only the pseudonym record. A second link survived — each frame kept its session identifier and each session kept its owner — so 99.0% of stored body-geometry samples (477,547 of 482,151) remained one join away from the account, and no scheduled job ever deleted them. The wording here now describes the mechanism that exists.
[The FOLLOW-ON recorded here — erasure destroying the reps a deleted user had counted by hand to correct us — was closed on 2026-08-19: those corrections are now copied out de-identified before the rows go, and the paragraph above describes it. Recorded rather than deleted so the sequence stays on the record: the text was written first and the code made to match it, not the reverse.]
9. Your rights
In Settings → Privacy you can, today:
Export your data as a JSON file.
Delete your account. Your body-geometry samples are unlinked from you immediately and irreversibly; the account itself is permanently erased after 30 days. Signing back in within 30 days keeps the account — it does not re-attach the unlinked samples. We retain de-identified movement measurements and your reported counts to improve rep counting; they carry no identifier and cannot be linked back to you. §8 says exactly what is kept.
Withdraw model-training consent at any time.
Your privacy event log. Every export, every deletion request, every consent change and every retention sweep is recorded in an immutable privacy_events log. An in-app viewer is planned; until then, request your log via privacy@getsvaya.com. (Carried forward from Version 2 §6.)
By writing to privacy@getsvaya.com you can also request access, correction, portability, restriction, objection, and a copy of your consent history. We do not discriminate against you for exercising any of these rights.
Depending on where you live you may also complain to a supervisory authority: your national data-protection authority in the EEA, the ICO in the UK, the Data Protection Board in India, or your state Attorney General in the United States.
10. Children
three options and their consequences are preserved in
of adults-only, with a family/kids mode held as a designed v2 built on on-device processing — see the 2026-03 kids-UX validation.)
Svaya is not directed to children, and we do not knowingly collect any personal data — including camera-derived body-geometry data — from anyone under 18. You must be 18 or older to create an account, and account creation requires an explicit age affirmation (recorded in the
18 has been collected, we will delete it and close the account. To report a suspected under-age account, contact privacy@getsvaya.com.
The statements below describe the mechanics as built, and are consistent with the decision above:
Svaya is built for adults 18 and older only, with the parent/guardian path deliberately removed (founder decision, 2026-07-05).
Age is collected as a self-reported number during onboarding and self-reported ages under 18 are refused. We require an 18+ affirmation before the app can be used. This is an affirmation, not a verified date-of-birth gate.
Svaya is not directed to children and we do not knowingly collect data from anyone under 18. If you believe we hold data from someone under 18, email privacy@getsvaya.com and we will delete it.
11. India
India's Digital Personal Data Protection Act applies to us now — it has no turnover or user-count threshold, and we already process personal data of people in India, including at least one coach and their clients.
Notice. This policy, presented in English before collection, is the notice.
Consent. Free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and capable of being withdrawn as easily as it was given.
Your rights as a data principal. Access, correction, completion, updating, erasure, grievance redressal, and nomination of another person to exercise your rights if you die or become incapacitated.
Grievance officer. Grievance Officer, Vyoma Technologies Limited — support@getsvaya.com, 3296 Logsdon Loop, Delaware, Ohio 43015, USA. You may raise a grievance with the Grievance Officer before approaching the Data Protection Board. We aim to respond within one month of receiving it.
Cross-border transfer. Your data is processed and stored in the United States on infrastructure operated by our hosting provider, and by the processors listed in §7.
12. Security
TLS in transit. Encrypted volumes at rest. Passwords stored only as salted hashes. Email and the 2FA secret encrypted at the field level. Signing keys and database credentials in managed secret storage, never in source control. Role-based access control on staff and coach access, with every access written to an audit table (1,375 entries to date).
No system is perfectly secure, and we do not claim otherwise.
13. Changes
We version this policy. When we change it materially we re-prompt you, and you accept the new version before continuing — which generates a new, independently verifiable ledger entry against the new text.
14. Contact
Privacy, data rights, and deletion requests: privacy@getsvaya.com
Everything else: hello@vyomatechnologies.com
Postal: 3296 Logsdon Loop, Delaware, Ohio 43015, USA
Verified against source
| Claim Source | |
|---|---|
| Consent ledger is append-only, backe hash-chained, bound to the exact shown text | nd/src/main/resources/db/migrations/V67_ |
| Ledger schema HAS request-metadata b columns (V96) but the server does §4 NOT populate them — the policy claimed capture until 2026-08-19, when the claim was withdrawn to match measured reality | ackend/src/main/resources/db/migrations/V96_; |
| 30-day deletion grace period backend (pending_deletion_at). execute_pendi disarmed by V116 — it deleted which reaches none of the nine table reported success for a job it only p | /src/main/resources/db/migrations/V35_ ng_deletions from the same migration was the account row and trusted ON DELETE CASCADE, s that carry no foreign key to users, so it artly did |
| user_consents schema and its same mi improve_app opt-in intent | gration |
| Heart rate is stored as a raw backen timestamped series, with phase/set 2 recorded as contemporaneous app state and barred from grading a set | d/src/main/resources/db/migrations/V111_ (V90.106, 026-08-17) |
| Watch motion streaming was V90.105 ( unreachable until it was wired phone | 2026-08-17) — startStreaming was called only from message handlers the had stopped sending; watch_accel non-null on 0 of 470,599 rows before the fix |
| Full-rate sensor_sessions upload V90 lane ships DISABLED | .105 — fullRateUploadEnabled = false, guarded at the enqueue |
| Prose is placeholder pending header counsel | |
| Trainer video stored as bytes on, the host's own disk with a V82_, Postgres pointer row; no backup workflow for that store. Corrected 2026-09-03: this row said "a Fly volume" and cited backend/fly.toml. Since the 2026-08-19 Azure cutover the bytes live on the Azure VM at /data/app/trainer_videos_store. The host moved; the unbacked-up finding did not. | tools/azure/deploy_api.sh:125 |
| media-egress grant exists | |
| The erasure sweep genuinely com.fi executes advisory-locked so replic privacy_events on every run includin /api/v1/admin/privacy/erasure-sweep /api/v1/admin/privacy/erasure-sweep/ machines could not host an in-proces opened a proxy to the database we ha called performed a partial erasure. overwritten.* | tcoach.privacy.PrivacySweepScheduler — in-process, every 6 hours, as do not double-run, writing a retention_sweep row to g no-op runs; POST triggers it and GET status reports when it last ran. *This replaces., which was correct on Fly (auto-stopped s timer) and became wrong at the Azure cutover: it d migrated away from, and the SQL function it Both facts are recorded rather than quietly |
| Body-geometry upload is (rationale), unconditional; consent flags, (r not gates | :1189 / :1351 (flag read), :1353 untime log "storage is unconditional") |
| Model-training setting defaults off | |
| Revocation de-flags rather than, :37 deletes | 9-385 |
| Telemetry consent is vestigial; — uploader has no consent check is | (no gate anywhere in file). This why §3.5 describes telemetry as always-on rather than offering a toggle |
| No pixels leave the device on the, D workout path | TO at :349-541 |
| Pose inference is entirely iOS/FitCo on-device inference code in backend/ | ach/PosePipeline/ — MediaPipe, ML Kit, Vision, ARKit estimators; no src/main/kotlin |
| HealthKit read/write type lists | |
| Face redaction is not active in Fa production in-app copy | ceRedactor exists only in iOS/EquipTest/, referenced nowhere in the app target; |
| Group-participant consent is not (an | alytics event only); |
| ML Kit self-declares device-ID + iOS diagnostic collection | /Pods/MLKitCommon/Frameworks/MLKitCommon.framework/PrivacyInfo.xcprivacy |
| Live media bypasses our backend; | |
| No payment processing exists today, off) | 91-102; (COMMERCE_MODE defaults |
| Legal artifacts are generated from, this file, and drift fails the push | make lint-legal-drift |
**Carried forward from the 2026-07-17 compliance audit
Training-eligibility filter missing on the backend export route (§1 item 9); LiveKit undisclosed and no DPA with Anthropic or LiveKit (§1 item 11); India DPDP compliance at zero (§1 item 10); DSAR export omits ~14 tables (§2 item 3); trainer video files survive account deletion (§2 item 2); health conditions, measurements and date of birth stored in plaintext (§2 item 11); ML-consent revocation not reaching the backend (§2 item 1).
Carried forward from the 2026-06-12 audit and the V82.8 implementation pass
Version 2 of this policy was the honesty revision produced from plus the V82.8 pass that made its promises real: legal pages served at /legal/*, the 30-day hard-deletion job scheduled, 90-day analytics retention enforced, the training-corpus training_eligible filter implemented, consent-revoke de-flagging rather than over-broad deletion, privacy_events logging on export / delete / consent, the export email decrypted, and the in-app consent UI made truthful. Known remaining items from that pass, still open: the in-app privacy-event viewer, a birth-date age gate, export table-coverage expansion, and the backup-identifier-stripping decision (audit #7 — whether to strip direct identifiers from the nightly dump).
Claims from the prior policies that this draft REMOVED as unsupported
"33 body keypoints." The stored data is 23 points in 95.8% of samples and 112–113 in the high-resolution mode. 33 appears nowhere in the distribution.
"A stick-figure skeleton… never pixels, never video" — the second half is true and is kept; the "stick figure" framing is dropped because it implies no facial or hand geometry, and both are stored.
"During a workout the watch streams heart rate, active energy, and raw accelerometer motion to your phone and on to our backend." Zero such values existed in production when that sentence was published, which is why it was removed. It has NOT been restored. §3.4 instead states the narrower and currently-true position: heart rate is stored as of V90.106; wrist and head motion can reach us only under an explicit opt-in that is off by default, wired as of V90.105.
"Head motion from AirPods never leaves the device." Removed rather than softened — see the correction blocks in §3.4. It is transmitted when the wrist-and-head motion setting is on.
Privacy Choices
03 · What is always on, what is yours to choose, and what each switch controls.
Privacy (PrivacyConsentView), shown during onboarding
THE SCREEN TEXT
Your data, plainly
Always on — this is how the app works
Workout and body-position recording. When you run a tracked set, your phone measures where your body is, many times a second, and sends those measurements to us. That is how reps get counted and form gets scored — there is no version of tracked workouts without it. The camera picture itself never leaves your phone. These measurements are automatically deleted after 180 days. If you would rather not have them stored at all, log your workouts manually instead.
Usage and diagnostics. We record which screens you open, what you tap, and what errors you hit, so we can find and fix problems. It goes only to our own servers, never to an advertising network or an outside analytics company, and it is deleted after 90 days. We do not offer a switch for this, because a switch that did nothing would be worse than none.
Your choice — off unless you turn it on
Help train shared models. Lets us use your body-position measurements, and the rep-count corrections you confirm, to train and improve Svaya's own rep-counting and form-scoring models.
This switch does not control whether your measurements are collected or stored — that happens either way, as above. It controls only whether they may be used for training. You can turn it off at any time; future measurements stop being marked immediately. To also clear the marking from measurements already taken, email privacy@getsvaya.com.
What we never do, with any of it
We never sell your data. We never share it with advertisers or data brokers. We never give it to another company to train their models. We do not track you across other apps or websites, and we embed no advertising or third-party analytics tools.
Your controls
Export everything · Delete your account · Withdraw training consent · Ask us anything at privacy@getsvaya.com
Body-Geometry & Biometric Data Consent
04 · What the camera measures, what leaves your phone, and how long it is kept.
Sharing (DataSharingConsentView), and presented before the first tracked set
Why this document exists separately
Illinois' Biometric Information Privacy Act requires that, before collecting a biometric identifier, a private entity informs the subject in writing that it is being collected, states in writing the specific purpose and the length of time it will be kept, and obtains a written release. Texas' CUBI imposes a notice-and-consent duty and a destruction deadline. Washington's My Health My Data Act requires separate, specific consent for collecting consumer health data and a distinct authorisation before any sale.
Those are not satisfied by a paragraph inside a general Terms of Service. This is the separate written notice and release.
BIPA carries a private right of action and statutory damages per violation. That is the reason this document is drafted conservatively even though the question of whether our data is covered is genuinely arguable — see §7.
THE NOTICE
1. What we collect
When you run a tracked set, Svaya's camera measures where your body is, many times a second, and records the result as numbers.
Right now, each measurement records the position of 23 named points on your body. Five of them are on your head: your nose, both eyes, and both ears. The other eighteen are your neck, shoulders, elbows, wrists, hips, knees, ankles, heels, toes, and a central reference point. Each point is recorded with its horizontal and vertical position and a confidence score. Some capture modes also record a depth value and a three-dimensional position.
We also compute and store, from those points: 21 joint angles, the movement signal that drove your rep count, the phase of the movement, your rep count, your form score, and quality information about the camera.
A note about August 2026. For three days (1–3 August 2026) a higher-resolution capture mode was in use on some devices. It recorded 112–113 points instead of 23, adding your jaw, chin, eyeballs, and both eyelids of each eye, and a complete skeleton of both hands — thumb, index, middle, ring and little finger, three to four joints each. That mode is not currently in use. The measurements it produced are still stored, and will be permanently deleted 180 days after they were taken, in line with §3.
2. What we do NOT collect
No pictures. No video. No audio. The camera image is processed on your phone, in the moment, and thrown away frame by frame. It is never uploaded, and nothing we store can be turned back into a picture of you or of your room.
This is verifiable rather than promised: there is no image, video, or binary media column in the table that holds this data.
3. How long we keep it, and when we destroy it
Body-geometry measurements are permanently deleted 180 days after they are collected. This is enforced automatically by the database itself on a daily schedule, not by anyone remembering to run it.
If you delete your account, the record linking these measurements to you is destroyed immediately, and the measurements themselves age out within the same 180 days.
We publish this schedule here so that it is a stated, checkable commitment rather than an internal practice.
4. Why we collect it
To count your repetitions and score your form.
To measure your range of motion, tempo and consistency over time.
To show you your history and progress.
To let a coach review your movement — only if you have separately granted that coach access to this specific category of data. It is off by default and never included in any other permission.
If, and only if, you switch it on: to train our own rep-counting and form-scoring models. See §5.
5. Model training is a separate choice, and it is off unless you turn it on
The Help Train Shared Models setting controls whether your measurements may be used to train and improve Svaya's own models. It is off by default.
Be clear about what this setting does and does not do:
| It does whet control training | her your measurements are marked as usable for our models |
| It does not control — that because it is ho | whether measurements are collected and stored at all happens for every tracked set either way, w the app counts your reps |
We spell this out because one of our own settings screens has described it loosely, in a way that could be read as an upload switch. It is not one. If you do not want body-geometry measurements stored, do not use tracked sets; log your workouts manually instead.
You can turn training off at any time. Future measurements stop being marked immediately. Measurements taken while it was on keep their marking — email privacy@getsvaya.com and we will clear them.
6. What we will never do with it
We will never sell, lease, trade, or otherwise profit from your body-geometry data. Not to advertisers, not to data brokers, not to insurers, not to anyone, under any arrangement.
We will never give it to another company to train their models.
We will never use it to identify you to anyone, or to match you against any other database.
We will never disclose it except: to you; to a coach you have specifically authorised; to a service provider hosting it under contract on our behalf; or where a court order or law compels us, in which case we will tell you unless legally forbidden.
7. Our position on whether this is "biometric" data
We think the honest answer is that it should be treated as biometric data, and we have written this notice on that basis.
The measurements include the geometry of your face, and — in the August 2026 captures — of your hands, which Illinois' statute names explicitly. We could argue that a 23-point joint map is too coarse to identify anyone and is not a "scan" in the statutory sense. That argument may well be correct. We have chosen not to rely on it, because the protections the statutes require are ones we are willing to give regardless: tell you first, in writing; say why and for how long; get your written consent; publish a destruction schedule; never sell it.
8. How we protect it
Encrypted in transit and at rest.
Stored under a pseudonym rather than under your name. Honestly: this is a single stable pseudonym, not a rotating one, and the measurements remain linkable to you through session identifiers. It reduces casual exposure; it is not anonymisation, and we do not call this data anonymous.
Access by our staff and by coaches is role-restricted and written to an audit log.
9. Your rights
You may, at any time:
withdraw this consent (below, or in Settings);
turn off model training;
export your data;
delete your account, which destroys the link between you and these measurements immediately;
ask us at privacy@getsvaya.com to clear the training marking from measurements already collected.
Withdrawing consent will stop tracked sets from working, because the measurement is the tracking. It does not affect manual logging, your history, or anything else in the app.
THE RELEASE
By tapping I agree, I confirm that:
I have read the notice above and understand what Svaya measures, > why, how long it is kept, and when it is destroyed.
I understand that these measurements include points on my face, and > that they may be treated as biometric data under the laws of > Illinois, Texas, Washington and elsewhere.
I consent to and authorise Vyoma Technologies Limited, and the > service providers it names in its Privacy Policy, to collect, > store, use and destroy this data as described above.
I understand this consent is voluntary, that I may withdraw it at > any time, and that withdrawing it stops camera-tracked workouts > but nothing else.
Medical Disclaimer
05 · Svaya is not medical care and does not give medical advice.
MEDICAL DISCLAIMER
1. Svaya is not a medical device and is not medical care
Svaya is a general fitness application. It is not a medical device, is not cleared, approved or registered as one by the U.S. Food and Drug Administration or any other regulator, and is not intended to diagnose, treat, cure, mitigate or prevent any disease, injury or condition.
Everything Svaya shows you — workout plans, exercise selections, repetition counts, form scores, coaching cues, range-of-motion and tempo measurements, progress charts and projections — is general fitness information, not medical advice, diagnosis, treatment, physical therapy, rehabilitation, or nutritional or dietary advice.
Svaya makes no claim about what any exercise will do to your body. It does not tell you that a movement will strengthen a particular structure, correct a posture, relieve a pain, rehabilitate an injury, or produce any physiological effect. If something in the app reads that way, it is outside the app's intended scope and you should not rely on it.
2. Talk to a doctor first
Consult a qualified physician or other licensed healthcare professional before starting any exercise programme, and especially before using Svaya, if any of the following apply to you:
you have, or have had, a heart condition, chest pain, high or low blood pressure, an irregular heartbeat, or a stroke;
you are pregnant, may be pregnant, or have recently given birth;
you have diabetes, a metabolic, respiratory or neurological condition, or any chronic illness;
you have a current or recent injury, surgery, joint problem, or back or neck pain;
you have osteoporosis, a bone or joint condition, or have been told to avoid particular movements;
you have a seizure disorder, a balance or vision problem, or take medication that affects your heart rate, balance or alertness;
you have been physically inactive for a long period;
you are unsure, for any reason, whether exercise is safe for you.
If a healthcare professional has advised you against exercise, or against a particular movement, follow their advice and not the app's. Your clinician knows things about you that Svaya cannot.
3. No doctor–patient relationship
Using Svaya does not create a doctor–patient, therapist–patient or any other clinical relationship between you and Vyoma Technologies Limited or anyone associated with it. Coaches you connect with through Svaya are fitness coaches, not clinicians, and must not provide medical, physiotherapeutic or nutritional services unless they are separately and lawfully qualified to do so where you are located.
4. Stop and get help
Stop exercising immediately and seek medical attention if you experience:
chest pain, pressure or tightness, or pain radiating into the arm, neck or jaw;
severe or unusual shortness of breath;
dizziness, light-headedness, faintness or confusion;
an irregular, racing or pounding heartbeat;
sudden or severe pain, a popping sensation, or loss of function in a joint or muscle;
nausea, cold sweat, or unusual fatigue;
any symptom that worries you.
Do not wait for the app to notice. Svaya does not monitor you for medical problems, has no way to detect one, and will not summon help. Call your local emergency number.
5. Do not delay medical care because of anything in this app
Never disregard professional medical advice, or delay seeking it, because of something Svaya showed you or something a coach said through it. If you think you may have a medical emergency, contact emergency services immediately.
6. You decide whether you are fit to exercise
You are solely responsible for judging your own fitness to exercise, for choosing whether to perform any movement Svaya suggests, and for stopping when your body tells you to. Your own judgment and physical sensations always take priority over anything the app says or fails to say.
Assumption of Risk & Release of Liability
06 · The risks of training, and what you accept by training with Svaya.
PLEASE READ. THIS AFFECTS YOUR LEGAL RIGHTS.
1. Exercise is inherently risky
Physical exercise carries risks that no app can remove. They include muscle strains and tears, sprains, joint and back injuries, dislocations, fractures, overuse injuries, fainting, heat illness, dehydration, aggravation of an existing condition, cardiac events including heart attack, stroke, and — rarely — serious permanent injury or death.
These risks exist whether or not you use Svaya. Some of them are increased by exercising alone, without a qualified person present.
2. Risks specific to using Svaya
You should understand these before you accept:
Nobody is supervising you. Svaya does not watch for your safety. If you are injured, lose consciousness, or need help, the app will not notice, will not summon anyone, and cannot assist. This is true even during a live coaching call: a coach can see you but cannot reach you.
Svaya decides what exercises to give you, by software. Those decisions are automated estimates based on what you told it and what the camera measured. They may be unsuitable for your body, your injuries, your experience or your equipment.
The rep count, the form score and the coaching cues can be wrong. They may miss repetitions, count ones you did not do, misread your form, or tell you your form is acceptable when it is not. An absent warning is not a confirmation that you are moving safely.
Using a phone camera changes how you train. You may position yourself for the camera rather than for good mechanics, be distracted by the screen, trip over the phone or its stand, or continue a set you should have stopped in order to complete a count.
Your environment is your responsibility. Floor surface, obstructions, ceiling height, equipment condition and stability, and other people or animals in the space are outside our knowledge and control.
3. You confirm you are fit to exercise
By accepting, you confirm that:
you are voluntarily choosing to exercise, and are physically able to do so;
you have had the opportunity to consult a physician, and have done so if you have any reason to;
you have accurately told Svaya about your injuries and health conditions, and you will update that information if it changes;
you are not exercising against medical advice.
4. You assume the risks
Knowing what is written above, you knowingly and voluntarily assume all risks of injury, loss or damage arising from your use of Svaya — including risks arising from your own physical condition, your environment, your equipment, and from Svaya's automated suggestions, feedback, rep counts and form scores being incomplete or wrong.
5. Release
To the fullest extent permitted by the law that applies to you, you release and discharge Vyoma Technologies Limited, and its officers, directors, employees, contractors and agents, from all claims, demands, damages and causes of action for injury, loss or damage arising out of or relating to your use of Svaya — including claims based on ordinary negligence — and you agree not to bring such a claim.
What this release does NOT cover, and cannot:
gross negligence, recklessness, wilful or wanton misconduct, or fraud;
any liability that the law where you live does not permit to be released, including — in many places — liability for death or personal injury caused by negligence;
the acts or omissions of an independent coach, who is not covered by this release and is responsible for their own advice;
your statutory consumer rights.
6. On behalf of others
You accept this on your own behalf and, to the extent the law allows, on behalf of your heirs, family, personal representatives and anyone claiming through you.
7. If part of this fails
If any part of this release is held unenforceable, the rest remains in force to the fullest extent the law allows, and the unenforceable part is limited rather than struck in its entirety where that is permitted.
8. Stop if something is wrong
Stop exercising immediately and seek medical attention if you experience chest pain or pressure, pain radiating into the arm or jaw, severe shortness of breath, dizziness, faintness, an irregular heartbeat, sudden severe pain, or any symptom that concerns you. Do not wait for the app to tell you. The app will not tell you.
The affirmation
AI & Automated-Feedback Disclaimer
07 · What the automated counts, scores and forecasts can and cannot do.
AI, AUTOMATED-FEEDBACK & FORECAST DISCLAIMER
1. What is automated
Svaya uses computer vision and machine-learning models to do the following without a human reviewing the result:
decide what you should do — which exercises, how many sets and repetitions, what progression, and when to make it harder;
estimate where your body is during a movement;
count your repetitions;
score your form and generate coaching cues;
project how your body may change over time — estimated timelines, weekly pace, progress percentages, "on track / behind / ahead" status, and estimated dates to reach a goal such as fat loss, muscle gain, strength, endurance or recomposition.
The exercise prescription is the important one on that list. Svaya is not merely logging what you chose to do; it is choosing for you. That is the difference between this app and a workout diary, and it is why this document exists.
2. These outputs can be wrong
They are software estimates. They can and do fail. Specifically:
Rep counts can miss repetitions, count repetitions you did not perform, or stop counting mid-set.
Form scores can misread what you are doing. A good score is not a certification that your technique is safe, and the absence of a warning is not a confirmation that you are moving well. The app can only assess the things it was built to look for.
Coaching cues may not fit your body proportions, mobility, equipment, lighting, clothing, camera angle or the space you are training in.
Generated plans may include an exercise that is unsuitable for you, or a volume or intensity your body is not ready for.
Camera conditions matter. Poor lighting, an unusual angle, loose clothing, a partially out-of-frame body, or another person or a pet in shot can degrade every one of the above.
3. Forecasts are estimates, and nothing is guaranteed
Any projection of future results — a transformation timeline, a weekly rate of change, a progress percentage, an "on track" status, or an estimated date to reach a goal — is a statistical estimate from limited data. It is not a promise, a target, or a commitment.
Svaya does not guarantee any outcome. It does not guarantee that you will lose any amount of weight or fat, gain any amount of muscle, strength or endurance, reach any goal, or reach it by any date.
Individual results vary, substantially. What actually happens to your body depends on genetics, nutrition, sleep, stress, consistency, medication, health conditions, your starting point, and many other factors the app knows nothing about. Two people following the identical plan can get very different results.
4. Not professional, medical or nutritional advice
Automated feedback, generated plans and forecasts are general fitness information. They are not a substitute for a qualified personal trainer, physiotherapist, physician or dietitian who can assess you in person.
Do not make a medical, nutritional or weight-management decision based on an estimate from this app. Svaya gives no dietary or nutritional advice at all, and makes no claim about the physiological effect of any exercise.
5. Use your own judgment
Do not perform a movement that feels unsafe because Svaya suggested it.
Do not keep going because the app is still counting.
Do not treat a forecast as a target you must hit.
If the app's feedback conflicts with what your body is telling you, your body is right.
6. How your data is used to improve the models
With your separate consent, your body-geometry measurements and the rep-count corrections you confirm may be used to train and improve Svaya's own models. That consent is off by default and revocable. Your data is never given to another company to train their models. The details are in the Privacy Policy and the Body-Geometry & Biometric Data Consent.
7. A note about the AI service that builds your plan
To generate a workout plan, Svaya sends a structured description of your fitness profile to an external artificial-intelligence provider, which returns a suggested plan. [OPEN: the precise field list must be confirmed and stated — the published policy has described this as including injuries and free-text goals, while an internal audit found the client sends structured fields only, with no identifiers and no free text. One authoritative answer is needed before this sentence ships.] That provider is a processor acting for us; it does not use your data for its own purposes and does not train on it.
The acknowledgment
Age Attestation
08 · Svaya is available to adults only.
scope_or_value on the ledger row (currently "18_or_older")
Option A — Adults only, 18+ (the current build)
The affirmation: the user confirms they are 18 or older; under-18s are refused.
Simplest compliance posture. No COPPA obligations, no parental-consent plumbing, no verifiable-parental-consent mechanism.
Forecloses the kids/family market entirely.
The honesty problem: children will use it anyway, on a parent's account. That is the classic COPPA "actual knowledge" trap — if the company ever markets to families, or has actual knowledge that a child is using an account, the 18+ clause is not a defence and the absence of any parental-consent machinery becomes the violation.
The current gate is weaker than the clause. The date-of-birth check is client-side and can be skipped if the picker is left untouched, and telemetry is collected before the age check runs. An 18+ representation should be backed by a server-authoritative gate.
Option B — 13+ with verifiable parental consent below 18
The affirmation: users 18+ affirm for themselves; users 13–17 require a parent or guardian to accept on their behalf.
Keeps the teen market. Common in fitness apps.
Requires a real guardian-acceptance flow, guardian identity capture, and a guardian-facing copy of every document.
Does not solve the under-13 case, which is where the validated use case actually sits.
Option C — Under-13 supported, full COPPA compliance
The affirmation: a child account exists only under a parent account, created by the parent.
The only option that legitimately serves the validated market.
Requires verifiable parental consent by an approved method — not a checkbox. Requires direct notice to the parent, parental access, review and deletion rights, strict data minimisation, no behavioural advertising, and a retention limit tied to the purpose.
The hard part is not the paperwork. COPPA requires collecting no more personal information than is reasonably necessary. Svaya's core function is measuring the geometry of a body, including the face, and storing it on a server for 180 days. For a child, that is a substantially harder case to make, and it interacts directly with the biometric statutes in. It may require a materially different data posture for child accounts — for example on-device-only processing with no upload — which is a product and architecture decision, not a legal one.
The affirmation (Option A, as shipped)
I confirm I am 18 years of age or older. Svaya is available to adults only.
"age_attestation", scope_or_value = "18_or_older". This is a self-attestation, not a verified date-of-birth gate; onboarding additionally collects a self-reported age and refuses values under 18.
Consent to Electronic Records & Signatures
09 · Receiving and signing Svaya's agreements electronically.
step 1 — presented and accepted before any other document, because consenting to transact electronically must precede the electronic acceptance of the agreements themselves.
CONSENT TO ELECTRONIC RECORDS AND SIGNATURES
Before you accept Svaya's agreements on your phone, United States federal law (the Electronic Signatures in Global and National Commerce Act, "E-SIGN") and state law (the Uniform Electronic Transactions Act, "UETA") require that you first consent to doing business with us electronically. Please read this and consent to continue.
1. What this covers
You agree that every agreement, disclosure, notice, policy and record between you and Vyoma Technologies Limited may be provided to you electronically, and accepted by you electronically. That includes the Terms of Service, the Privacy Policy, the Medical Disclaimer, the Assumption of Risk & Release of Liability, the AI & Automated-Feedback Disclaimer, the Beta Acknowledgment, the age affirmation, the body-geometry consent, and any future version of any of them.
This consent is ongoing and applies for as long as you use Svaya, unless you withdraw it.
2. Your electronic signature has legal effect
When you tap to accept a document, that action is your signature. It has the same legal effect as signing on paper. We record each acceptance, including the exact text you were shown, the version, the time, and the app you used.
3. You can get a paper copy, free
You may request a free paper copy of any record we provide electronically. Email hello@vyomatechnologies.com from your account address, naming the document and version, with a postal address. There is no charge.
4. You can withdraw this consent
You may withdraw this consent at any time, free of charge, by emailing hello@vyomatechnologies.com.
Be aware of the consequence. Svaya provides and accepts its agreements only electronically. If you withdraw this consent, we cannot continue to provide the Service to you, and your account will be closed. Withdrawal takes effect when we process it and does not undo anything you already agreed to or anything that already happened.
5. What you need in order to receive these records
To access and keep these records you need:
a current iPhone running a supported version of iOS;
the Svaya app, or a current web browser;
an internet connection;
an active email address on your account;
enough storage, or a printer, to save or print a copy.
If our hardware or software requirements change in a way that creates a material risk that you cannot access or keep your records, we will tell you and give you the chance to withdraw this consent without charge.
6. Keep your contact details current
You are responsible for giving us a working email address and keeping it current. Update it in Settings → Profile, or email hello@vyomatechnologies.com. If notices sent to your address on file bounce or go unread, they are still effective.
7. Scope of your consent
Your consent applies to your whole relationship with Svaya, not just this session. You may also request a paper copy of any individual record without withdrawing this consent for everything else.
The affirmation
Beta Software Acknowledgment
10 · Svaya is pre-release software.
BETA SOFTWARE ACKNOWLEDGMENT
1. This is pre-release software
Svaya is currently in beta. It is provided for testing and early use, not as a finished product.
2. Expect it to break
Beta software contains defects, incomplete features and untested paths. Svaya may behave unexpectedly, produce wrong results, crash, freeze, or be unavailable. Features may be added, changed or removed at any time, without notice, including features you have come to rely on.
3. Your data may be lost
Do not use Svaya as the only record of anything you care about. During the beta period your workouts, history, plans, measurements and other data may be lost, corrupted, reset or made inaccessible — including by our own mistakes while developing the product. Keep your own record of anything important.
4. Accuracy is not warranted during beta
Rep counts, form scores, plans and forecasts are under active development and are being changed frequently. Their accuracy during the beta is lower and less predictable than it will be at release. This does not reduce the risk of exercise, and it increases the importance of your own judgment — see the Medical Disclaimer, the Assumption of Risk & Release of Liability, and the AI & Automated-Feedback Disclaimer.
5. No warranty
Beta features are provided "as is", without warranty of any kind, to the fullest extent permitted by law.
6. We collect diagnostics
To find and fix problems, we record how the app is used and what errors occur. This is described in the Privacy Policy, is first-party only, and is not shared with advertisers or data brokers.
7. Being in the beta gives you no entitlement
Participating in the beta does not entitle you to the final product, to any particular feature, to a free or discounted subscription, or to continued access. We may end the beta, change who can use it, or discontinue Svaya entirely.
8. Please tell us what breaks
Reporting problems is genuinely useful and is the point of a beta. Email hello@vyomatechnologies.com. Feedback you send may be used freely by us, as set out in the Terms of Service.
The acknowledgment
Coach Access Disclosure
11 · Exactly what a coach can see when you grant them access.
consent. Nothing here is accepted or declined. The consents it describes are recorded separately (trainer_scope, and the team grant/revocation
and linked from the team picker before a team is chosen.
What this document is
Svaya can put a human coach in your account. This page says exactly what that coach can see, how they got the ability to see it, how long it lasts, and how you end it.
Every statement below is checked against the code that runs. Where the code grants more than you would expect from the screen you tapped, this page says so instead of smoothing it over. The list of those gaps is at the end, and it is part of the document, not an appendix to it.
1. There are two ways a coach gets access, and they are not the same
Every read a coach makes goes through one gate in the server. That gate looks up the one active grant on your account and branches two ways.
A. You chose a coaching team
You picked a team on the team picker screen. That single tap is the grant.
It gives the team two things, as a fixed pair: your workout history, and the skeleton replay of your recorded sets.
val TEAM_SERVICE_SCOPES: Set<String> = setOf("workout_history", "form_review")
There are no per-item choices on this path. You cannot take the skeleton replay off and keep the history. The set is a constant in the server.
The grant is to the team, not to a person. Anyone listed as a member of that team can read. The names you are shown — the lead and the "core" members — are a subset of the people who can actually read. The database says so in as many words: the wider pool "keeps is_core = false and is never presented to the client".
What the picker screen currently tells you is narrower than what it does. The whole disclosure on that screen today is:
"Your team answers your questions and reviews your sets. Choosing a team gives them access to your training history — that's what lets them coach you." —
It does not mention the skeleton replay, and it does not say how many people are in the team. That is a gap in the app, listed in §11. Until it is closed, this page is the fuller statement, and it is the one that is true.
Where this stands in production, 2026-09-03: one team, one team member, and one active team assignment — every currently active assignment on the platform is a team assignment.
B. You connected a named individual coach
You connected to one specific coach by code or by accepting their invitation. Before that connection completes you are shown six switches, and you can change them afterwards from Manage Permissions.
| Switch **What it lets that coach d | o** |
|---|---|
| Workout History — always on, Se cannot be turned off sets and form sc | e your sessions, exercises, ores |
| Rep Detail See per-rep range of motion tempo and stability | , |
| Health Metrics See your heart rate and | calories |
| Session Notes Read the notes you write sets | after |
| Plan Assignment Assign you workout pla your plan library | ns from |
| Form review (skeleton replay) Replay a movement | stick-figure of your |
Workout History is locked on in the app and the server refuses to save a set of permissions without it. If you do not want a coach to see your workouts, the answer is to not have that coach, not to narrow the switches.
Health Metrics needs three things to be true before a number reaches your coach: an active connection, the switch on, and your standing health-sharing consent. A team never gets it at all.
2. What a coach can see
Read this table with §1 in hand: the middle column is a team, the right column is a named coach with everything switched on.
| Your data A A named coach coaching team | ||
|---|---|---|
| Session list — activity, start and end time, status, number of sets, average form score | Yes Yes | |
| Full session detail — every Yes Yes exercise, every set | ||
| Per-rep detail (range of motion, **No tempo, stability) | ** Only wit | h Rep Detail on |
| Heart rate and calories No Only w and your health-sharing consent | ith Health | Metrics on |
| Skeleton replay of a recorded set Yes | Only with | Form review on |
| Your whole chat thread with the team or coach, and your display name | Yes Yes | |
| Notes you wrote after sets No Onl | y with Sess | ion Notes on |
| Assigning you a plan No Only with on | Plan Assig | nment |
| Your profile context — training **N days, activity level, fitness level, goals | o** Yes | |
| A body-composition band derived from BMI (e.g. "OVERWEIGHT") — see §11 | No Only | with Body Metrics on |
| Live video call with you No Only live-call flow | through the | separate |
Session detail is delivered whole and then stripped: heart rate, calories and per-rep events are removed when the grant does not cover them, and everything else in the stored session passes through unchanged. So "what a coach sees in a session" is best read as everything Svaya recorded about that session, minus those three things.
3. What a coach cannot see
Your camera. Ever. No video, no photo, no audio from a tracked set is sent to a coach, because none of it is sent anywhere. What leaves your phone from a workout is numbers.
Your email address, phone number or date of birth. The client list a coach is given carries an id, the permissions you granted and a date — no name, no contact detail. Your display name reaches them only through your chat thread.
Your body measurements, weight or body-fat entries. No coach route reads the measurements table.
Your password, your login history or your device.
Other coaches' notes about you, if you have switched. Ending one grant ends every read that rode on it.
A team cannot see anything in the "No" column of §2 — including your notes, your heart rate, your per-rep detail and your profile.
4. The skeleton replay, precisely
This is the most detailed thing a coach can look at, so it gets its own section.
A replay is a stick figure. It is built from 23 named points on your body, played back over time:
nose, neck, root, left eye, right eye, left ear, right ear, left and right shoulder, elbow, wrist, hip, knee, ankle, heel, toe
Five of those points are on your head — your nose, both eyes and both ears. They are coordinates, not a picture of your face, and no image is stored or sent. But it is not accurate to say the replay excludes your head, so we do not say it.
Playback runs at up to 15 frames per second, and one set is capped at 900 frames. Longer sets lose smoothness, not duration.
The coordinates are sent as whole numbers scaled by 10,000. That is a transport format, and the code calls it "lossless at 4 decimal places". It is not a privacy measure and we will not describe it as one.
Every replay a coach opens is recorded (form_replay_view). 57 such records exist on the platform as of 2026-09-03.
5. A video you send for review
You can attach a video clip to a form-review request. This is the one place where video from your phone reaches our servers, and it only happens when you choose to send it.
The app blurs faces before the file is written, and redaction is the default. The server records a face_redacted flag that the app supplies and the server does not verify. So the honest claim is: the app redacts by default, and the flag records what the app reported — not that the server checked.
A coach never gets the file. They get a link that stops working after 120 seconds, and a new one is only issued while the grant is live.
You can un-share a clip at any time — one door, per clip. Deleting it makes every link to it fail immediately.
One honest limit: a link already handed to a coach cannot be recalled mid-flight, because it is validated by its signature rather than by a session. The window is bounded by the link's own lifetime — at most 120 seconds as issued, and never more than 300 by configuration.
Deletion timing. The file is deleted 7 days after your coach finishes or dismisses the review, and in any case within 30 days of being sent. That is not the same as "deleted the moment the review is done", so we do not claim that.
As of 2026-09-03 there are zero live review clips on the platform.
6. Live video calls
A live call is only possible with a named coach, never with a team, and only through the call flow you accept each time. Two separate things are involved:
live_video — the call itself. Withdraw it and a call in progress is ended: the room is destroyed server-side, which is what actually stops a camera feed.
pose_data — sharing your live skeleton during that call. Withdrawing it cancels the grant on the server, clears the flag and revokes any open grant. It does not stop landmark data mid-call today. The shipped iOS publishing loop does not read the flag, and the code says so explicitly and instructs that the scope must not be described as blocking landmark data. Until the app reads the flag, the accurate sentence is: withdrawing it ends the authorisation and is recorded — it does not cut the stream in the middle of a call. Ending the call does.
7. How long access lasts
Until you end it. There is no time limit.
The grant record has a column for when it ended and no column for when it expires. Nothing ages out. A coach you connected a year ago and never spoke to again can still read your workouts today.
Sending a form-review request does not create a separate, shorter grant. It is served under the standing grant you already gave.
8. How you cut it off
If you have a named coach
Three controls, all in the app, all immediate:
Narrow it. Turn switches off in Manage Permissions. Turning off live_video ends a call in progress; turning off Form review deletes every clip you had shared with that coach.
Pause it. A paused connection grants nothing at all, and any live call is torn down.
End it. One tap. The server finishes the work before it answers you: the connection is revoked, live sessions are cancelled, the video rooms are destroyed, and every clip you shared with that coach is deleted.
This is not a setting that takes effect later. Your permissions are re-read from the database on every single request a coach makes, with no cache. The next thing they tap fails.
If you have a coaching team
You can move the grant to a different team. There is no button that leaves you with no team at all.
The only two team controls the app offers are "list the teams" and "choose a team". A team grant is ended in exactly one place in the server: inside the transaction that creates its replacement. So the switch is a real revocation — the moment you pick a new team, the old team fails the gate on every route, and the switch screen says so before you tap:
"Your current team will lose access to your workouts and chat. Your conversation history moves with you." — (and, before any tap, at :96)
But it is a transfer, not a stop. Switching also hands your entire past conversation to the incoming team: the thread is re-keyed to the new grant in the same transaction. The screen mentions that your history moves; this page says plainly who it moves to.
If you want to end team access altogether today, contact us at privacy@getsvaya.com, or delete your account (§9). Closing this gap is listed in §11.
9. What happens to data a coach has already seen
Reading is not copying, and we cannot un-see anything. What we can tell you is what remains and what goes:
Notes and annotations a coach wrote about you stay on your account after the grant ends. They are yours as much as theirs. They are removed when your account is deleted, by database cascade.
Your chat thread stays. Each thread is stamped with a 730-day retention ceiling when it is created, but no job reads that column today, so nothing currently deletes chat on that schedule. The true statement is: your chat is kept until you delete your account, at which point it is removed by cascade.
Review requests and any clip rows are removed with your account.
The audit record of what a coach looked at is deliberately kept. It is the proof of what happened, and it is the one thing that would let you or a regulator reconstruct an access after the fact.
Anything a coach wrote down outside Svaya is outside our reach. That is true of every platform, and §10 explains what we do about it.
10. Every access is recorded — and what you can currently see of it
Every read a coach makes writes a row. So does every refusal, including attempts to reach a client they have no grant for. Replays (form_replay_view) and video links (shared_clip_url_minted) are recorded individually.
What you can see of that record today is narrower than the record itself:
The in-app coach-activity feed shows seven kinds of event: history reviewed, session reviewed, notes read, plan assigned, note left, note edited, note removed.
It does not show skeleton-replay views or video-link issues — the two most sensitive reads on the list.
It is only reachable if you have a named coach. A team-coached client gets "relationship not found" from the activity feed and applicable = false from the reviews view.
So the accurate promise is: every coach access to your data is recorded, and we will give you the record on request at privacy@getsvaya.com. It is not yet true that you can see all of it in the app.
11. Our commitments, and where the app does not yet keep them
Svaya holds itself to four standing rules about coaches
truth about it.
Anything that affects your rights gets its own screen. Partly kept. A named coach's permissions get a real screen with real switches, and your choice is written to an append-only consent record. A team grant does not. It is one tap on a screen that describes only half of what it gives away.
Coaches should not be able to copy your data off their screen. Downgraded, honestly. We tried to make coach screens invisible to screenshots and it made them invisible to the coach as well. What ships instead: a coach's screen goes black while it is being recorded, mirrored or AirPlayed, and a screenshot is detected and logged against their account. That runs on their device and a determined person can defeat it. It is a deterrent and a trail, not a wall. No technology stops someone photographing a screen with a second phone.
Sharing your live movement skeleton is a separate choice we never assume. Two failures, both stated. It has no switch in the shipped permissions screen — so if you ever granted it, saving that screen quietly re-grants it, and the only way to withdraw it is to end the whole connection. And withdrawing it does not stop data mid-call (§6). One of the three active connections on the platform today carries this permission.
Video access ends with the review. Not as written. Read access ends when the connection or the team grant ends. The file is deleted 7 days after the review closes, and within 30 days regardless (§5).
Open gaps, listed plainly
The team picker does not mention the skeleton replay, and gives no per-item choice. Fix: disclose it on that screen, or move form_review out of the automatic team grant.
There is no way to leave a team without joining another one. Fix: a leave-team route.
You cannot see how many people are on your team, or who they all are.
pose_data and body_metrics are real permissions with no switch. Fix: give them switches, or stop accepting them.
Withdrawing pose_data does not stop landmark data mid-call.
Your access record is incomplete in the app and unavailable to team clients.
Chat is stamped with a 730-day limit that nothing enforces.
The face_redacted flag on a shared clip is trusted, not verified.
Until each of these is closed in the code, this page is the accurate description and the app is the thing that needs to change.
12. Questions, or a copy of your record
privacy@getsvaya.com
You can ask for the full record of every coach access to your data, and we will provide it.
Coach Data Access Consent
12 · Granting a coach access to your data, one category at a time.
screen (MyTrainerView) Recorded as: the granted scope name in scope_or_value
THE SCREEN TEXT
What you are sharing with [coach name]
You choose what your coach can see. Each item below is a separate decision. You can change any of them at any time, and changes take effect immediately.
Nothing is shared until you turn it on.
| What **What you | r coach sees if you turn it on** |
|---|---|
| Workout Which wor history exercises | kouts you completed, when, and the in them |
| Set detail Your | sets, reps, weights and rest times |
| Notes The notes | you write on a workout or set |
| Plan changes Pe workout plans | rmission for your coach to create and change your |
| Body Height, weig measurements | ht and the measurements you log |
| Health The injuri information | es and health conditions you have entered |
| Form review You the app detected | r form scores and the specific movement faults |
| Body-position A m replay during a s | oving figure showing exactly how your body moved et |
| Live Your rep cou monitoring | nt and form score, live, while you train |
| Live video Your c call | amera and microphone during a scheduled call |
Read this before turning on body-position replay
Body-position replay is the most revealing thing on this list. It lets your coach watch a reconstruction of how your body actually moved — not a summary, a replay. It is off by default, and it is never included in any other permission here. Turning on "workout history" or "form review" does not turn this on.
Read this before turning on health information
Injuries and health conditions are sensitive. Share them with a coach only if you want that coach to plan around them, and only with a coach you trust.
What we do to protect you
Every time your coach opens your data, we record it. You can ask us for that log at any time.
Your coach cannot download or keep your data. Video access is granted only for a specific review, through short-lived links, and is withdrawn automatically when the review is finished.
Coaches are told not to copy or record your data. We enforce this technically where we can. Honestly: we cannot make screen-recording impossible. Someone determined to capture what is on their screen can. The real protection is that we show a coach as little as your choices allow — which is why these switches are separate and default to off.
Live calls are not recorded. The product has no recording capability at all.
Turning it off
Switch any item off, or end the coaching relationship entirely, at any time. Access stops immediately. It does not delete what your coach already saw or noted, and it does not affect their own records — ask your coach directly about those.
Coach Content Licence & Rights Attestation
13 · For coaches publishing content on Svaya.
record / first upload (ContentLicenseSheet), and the group-session upload gate (GroupParticipantConsentSheet) Audience: coaches, not clients
What this document is for
The per-upload rights grant. It implements constraint FC1's "no bytes without attestation" rule: the backend refuses to accept video unless the coach has attested to the rights, and it records which licence version they accepted.
It is narrower than the Coach Agreement, which governs the whole relationship. Where the two overlap, this is the operative per-upload grant and the Agreement describes it.
THE SCREEN TEXT
Before you upload
You are about to put video on Svaya. Please confirm two things.
1. You have the rights
You confirm that:
you made this recording, or you have written permission from whoever did;
everyone visible or audible in it has agreed to appear on Svaya, and to the uses described below;
you own or have licensed everything else in it — music, logos, branded clothing, artwork, footage or text belonging to someone else;
nothing in it infringes anyone's rights, including rights of privacy and publicity;
no one in it is a minor, unless you have their parent or guardian's written permission.
If you are not certain about any of these, do not upload. Music playing in the background of a gym recording is the single most common way this goes wrong.
2. The licence you are granting
For as long as your content is on Svaya, you grant Vyoma Technologies Limited a non-exclusive, worldwide, royalty-free licence to host, store, copy, transcode, watermark, excerpt for a preview, and stream your content to the people you have chosen to make it available to, and to do the technical things needed to deliver it.
What this licence does not include:
We do not get to use your content to advertise Svaya, or in any marketing, unless you agree separately.
We do not own your content. It remains yours, and you can license it elsewhere.
We do not get to keep distributing it after you remove it. When you delete it, or your account, we stop serving it. Copies may persist in routine backups until they rotate out.
We do not use your content to train models without asking you separately.
3. How your video is protected
No public address. Every view goes through a short-lived signed link.
Where a client is given access for a form review, that access is limited to the review and withdrawn automatically when it finishes.
Views are watermarked with an identifier that ties the view back to the audit record of who opened it.
4. If you upload a group session
⚠️ Faces are not blurred. Automatic face redaction is designed but not shipped. Right now, your attestation is the only protection the people in your footage have. Everyone in frame will be visible to whoever you share it with.
Only upload group footage where every single person visible has actually agreed — not assumed, not implied by their being in your class. If you cannot say that with confidence about every person, do not upload it.
5. What happens if the attestation is wrong
If a rights claim is made about your content, we may remove it immediately and without notice while we look into it. Repeated or serious problems can end your ability to publish on Svaya. As set out in the Coach Agreement, you are responsible for claims arising from content you uploaded without the rights to it.
The attestation
I confirm I hold all necessary rights to this content, that everyone appearing in it has agreed to appear, and that I grant Svaya the licence described above. I understand Svaya relies on this confirmation and does not independently verify it.