Privacy Policy
Effective Date: September 1, 2026 · Last Updated: September 1, 2026
TL;DR: We collect only what's needed to make tesr work. tesr is local-first: your health records live on your device first. Your data belongs to you. We don't sell your data. We don't show ads. We don't track you across apps.
1. Who We Are
tesr ("we," "us," "our") is a personalized fitness and nutrition application, your AI-powered buddy, under development for iOS and Android. tesr is an initiative of TESR Technologies Private Limited, a company incorporated in India (CIN: U62011TS2026PTC220820), with its registered office in Hyderabad, Telangana, India. We can be reached at:
Website: https://tesr.health
Contact: support@tesr.health
2. Information We Collect
2.1 Waitlist information
When you join our early-access waitlist on this website, we collect your email address and the date you signed up. We use it solely to contact you about early access and product updates. You can ask us to remove you from the waitlist at any time by emailing support@tesr.health.
2.2 Account information
When the app launches and you create an account, we expect to collect:
- Email address
- Date of birth (for an age gate and to personalize your plans and guidance)
- Authentication identifiers: managed by our authentication providers. We never store your password directly.
If you sign in with Google or Apple, we receive your name and email from those providers. We do not receive or store your Google/Apple password.
2.3 Health & fitness data
Data you enter while using the app, expected to include:
- Workouts: exercises, sets, reps, weight, duration, dates and notes
- Training plans: AI-generated and manually built plans, and your progress through them
- Nutrition: meals, foods, quantities, and macro/calorie targets
- Body metrics: body weight, measurements, and wearable-derived signals (sleep, heart rate, steps) where you connect a device
- Cycle data: where you choose to use cycle tracking, this is treated as the strictest class of data in the app (see §4)
Local-first by design: this data is written first to a database on your device. It is synchronized to our cloud only so your data survives device loss and follows you across devices, and you are always in control of that sync.
2.4 Device & technical data
We collect minimal technical data needed to operate and improve the service: device type, operating system version, app version, and crash reports. We do not collect: location data, contacts, call logs, SMS, browsing history, advertising IDs, or any data from other apps on your device. Our telemetry deliberately excludes health values and personal identifiers.
3. How We Use Your Data
- Provide the service: generate and adapt your training and nutrition plans, and sync your records across your devices
- Calculate insights: progress analytics, readiness (Charge) scoring, habit and trend tracking
- Authenticate you: sign-in and account management
- Improve the app: fix bugs and understand usage patterns (aggregated, not individual)
- Communicate with you: service updates and, only with your consent, product news
We do not use your data for behavioral advertising, and we do not sell it. Ever.
4. How We Store Your Data
- On your device: your health and fitness records live first in an encrypted local database on your device (local-first architecture)
- In our cloud: an encrypted copy is synchronized through our backend (Supabase/Postgres with PowerSync) hosted with cloud providers, with data residency in India (ap-south-1) for our production services
- On this website: waitlist email addresses are stored in Google Cloud Firestore
Data is encrypted in transit (TLS/SSL) and at rest in our cloud storage. Cycle tracking data, where the feature is used, receives the strictest handling available in the app, including an independently invocable deletion path.
5. Data Sharing
We do not sell, rent, or trade your personal data to anyone. Period.
We share data only in these limited circumstances:
- Infrastructure providers: as our data processors (cloud hosting, authentication, error monitoring), bound by their own privacy and security obligations
- Social features: content you explicitly share within app communities (e.g., group challenges) is visible to members of that group
- Legal requirements: if required by law, court order, or government request
We do not use third-party advertising or cross-app tracking SDKs.
6. Your Rights
You have the right to:
- Access your data: all your data is visible within the app
- Edit your data: modify your records at any time
- Delete your data: delete individual entries, or everything, from within the app
- Export your data: request a full export of your data from within the app or by contacting us
- Delete your account: request complete account deletion at support@tesr.health. We will delete all associated data within 30 days.
- Withdraw consent: where processing is based on consent, you may withdraw it at any time
- Grievance redressal: under India's Digital Personal Data Protection Act, 2023 (DPDP Act), you may escalate concerns to our grievance officer at support@tesr.health, who will respond within the timelines prescribed by the Act
If you are in the European Union (GDPR), California (CCPA), or Australia (Privacy Act 1988), you have additional rights under local law. Contact us to exercise these rights.
7. Data Retention
- Waitlist entries: retained until you ask us to remove you or we retire the waitlist
- Active accounts: data is retained as long as your account exists
- Deleted data: when you delete a record, it is removed from our servers
- Account deletion: all data is permanently deleted within 30 days of request
8. Children's Privacy
tesr is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction, including the age of consent under the DPDP Act for Indian users). We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us at support@tesr.health and we will delete it. Where the app permits use by minors (e.g., teens aged 13–17 with parental consent per our Terms), verifiable parental consent is processed in accordance with the DPDP Act.
9. Security
- All data transmitted between the app and our servers is encrypted using TLS/SSL
- Authentication and credential security are handled by established providers; we do not store passwords
- Database security rules ensure users can only access their own data
- Local-first design means your most sensitive records live on your device, not in a central honeypot
- We do not store passwords; authentication is handled by third-party providers (Google, Apple) where you choose those sign-in methods
No system is 100% secure. If you discover a security vulnerability, please report it to support@tesr.health.
10. Third-Party Services
- Supabase / cloud hosting (database, auth, storage): Privacy Policy
- Google Firebase (website waitlist storage): Privacy Policy
- Google Sign-In: Privacy Policy
- Apple Sign-In: Privacy Policy
- Sentry (crash reporting, no health values or PII): Privacy Policy
- PostHog (product analytics, aggregate events): Privacy Policy
- RevenueCat (subscription management, when payments launch): Privacy Policy
We do not use advertising networks, social media trackers, or analytics platforms that track individual users across apps.
11. Changes to This Policy
- The "Last Updated" date at the top will change
- For significant changes, we will notify users through the app or by email
- Continued use of tesr after changes constitutes acceptance
12. Contact Us
If you have any questions about this Privacy Policy or your data:
Email: support@tesr.health
Website: https://tesr.health
Post: TESR Technologies Private Limited, Hyderabad, Telangana 500089, India
← Back to tesr