Privacy Policy
Last updated 31 August 2026
TechTwin (“TechTwin”, “we”, “us”) builds a personalised physiological model from the health, training, and genetic information you choose to provide. That is sensitive data, and this policy is written to tell you exactly what happens to it — what we collect, who it reaches, how long we keep it, and what you can make us do about it. It applies to our website and application (the “Service”).
1. Who we are
TechTwin is the data controller for the information described here. You can reach us about anything in this policy at team.techtwin@gmail.com. We have not appointed a Data Protection Officer, as we are not required to.
We are based in the UK and the Service is available to people in the EEA, so both the UK GDPR and the EU GDPR can apply to you depending on where you live.
2. Information we collect
We collect what you enter, what you connect, and what the Service derives from those:
- Account & profile — name, email, and the profile details you enter: date of birth or age, sex, height, weight, body composition, fitness level, goal, sport, training availability, race times, time zone, and your units and display preferences.
- Health & biometric data — training and workout logs, heart-rate variability, resting and workout heart rate, sleep (including naps and sleep stages), VO₂max, blood oxygen, respiratory rate, overnight wrist or skin temperature, steps and distance, weight and body fat, blood-biomarker results you upload, and menstrual-cycle data if you use it.
- Nutrition & lifestyle — meals and their descriptions, food photos you submit, calories and macros, hydration, caffeine, supplements, allergies and dietary exclusions, and any injury, illness or health notes you write.
- Substance use — alcohol, smoking, vaping and nicotine-pouch intake, and how long you have used them, where you choose to log these.
- Genetic data — trait values derived from a DNA file you upload (e.g. 23andMe/AncestryDNA). See the highlighted section below, which explains precisely what is and is not stored.
- Your conversations — the messages you send to the AI coach and protocol builder, and the replies, are stored against your account so you can return to them.
- Connected sources — data imported from services you link, such as Apple Health, Strava, Oura, Fitbit, WHOOP, or a device export file (for example Garmin). This can be two-way: with your permission, water and meals you log in TechTwin can be written back into Apple Health.
- Derived and inferred data — readiness scores and bands, training load, a detected fitness level, physiological parameters fitted to your own history, and forecasts. See “Automated profiling” below.
- Device & technical data — a push-notification token if you enable notifications, your time zone, sync timestamps, and server logs needed to operate, secure and debug the Service.
- Product analytics — pages viewed and coarse device information, collected only while you are signed in. See “Cookies, analytics and on-device storage”.
- Waiting-list contact details — if you register interest before an account exists, we hold the name and email you gave us so we can tell you when the Service opens.
How your DNA is handled
Your raw genetic file is parsed entirely in your browser and is never uploaded to or stored on our servers. The file is read on your device, a small set of trait values is computed from it, and the raw genotype data is discarded when you leave the page. We never receive it, and there is no way for us to ask for it.
What we do save to your account is a set of derived trait values — for example an aerobic-response score, a caffeine-clearance category, or an iron-overload risk category — together with a list of which marker IDs your file did not cover. We want to be precise about two things people often assume:
- This derived data is not anonymous. It is stored against your account and is personal data about you, in the special category covering health and genetics.
- Some of these values can be worked backwards. Several traits are computed from a single named marker, so someone who knows our method and sees the stored number could infer your genotype at that specific marker — for example your ACTN3 power variant, your CYP1A2 caffeine variant, or your HFE iron variant. We cannot rebuild your genome, and the great majority of it never reaches us at all, but we will not claim these scores are unlinkable to the genetics they came from.
You can delete your derived genetic data without closing your account by contacting us, and we will stop using genetic information in your model from that point.
3. How we use your information
- To build and continuously calibrate your digital twin, and to generate forecasts, insights, readiness scores and protocol recommendations.
- To power AI features — both those you invoke directly (such as estimating a meal's nutrition or writing a report) and scheduled background processing described below.
- To send you notifications you have enabled, which can include your own health figures.
- To operate, secure, maintain, debug and improve the Service, and to measure our own AI processing costs.
- To communicate with you about your account and respond to your requests.
We do not use your data for advertising, we do not profile you for marketing, and we do not sell it.
4. Automated profiling and forecasts
The Service is built on automated processing, and you should know what that means in practice. From your health data we automatically compute and store characteristics about you — a daily readiness score and band, an inferred fitness level, physiological parameters fitted to your own history, and forward-looking forecasts. Some of this runs on a schedule, without you opening the app, and the results shape what the Service then recommends to you.
These are modelled estimates, not medical findings, and they produce no legal or similarly significant effect: nothing is decided about you, no access is granted or refused, and you remain free to ignore any recommendation. You can ask us to explain how a figure was derived, contest it, or object to this processing using the contact details below.
5. Legal bases
Under the UK and EU GDPR we rely on:
- Your explicit consent (Article 9(2)(a)) for processing special-category data — health, genetic and, where you log it, substance-use information. This is the basis for the core of the Service.
- Performance of our contract with you (Article 6(1)(b)) to create and run your account and deliver the Service you asked for.
- Our legitimate interests (Article 6(1)(f)) in operating, securing, debugging and improving the Service, including product analytics. You can object to processing on this basis at any time.
- Consent (Article 6(1)(a)) for optional extras such as push notifications and waiting-list contact.
You can withdraw consent at any time, and withdrawing it is as easy as giving it. Withdrawing consent for health and genetic processing means we can no longer provide the Service, so in practice it means closing your account — see “Your rights”.
6. AI processing
Several features send your information to Anthropic, our AI provider, which returns the result. So that you can judge this properly, the inputs can include: your profile and training history, your biometric and sleep data, blood-biomarker results including text extracted from a blood-test PDF you upload, traits derived from your genetic data (referred to by gene name), menstrual-cycle information, lifestyle and substance-use history, allergies and any health notes you have written, meal descriptions, food photos, and what you type into the coach.
These inputs are processed under contractual confidentiality, are used only to generate your output, and are not used to train the provider's models. Food photos are used only to produce the nutrition estimate and are not stored by us afterwards. Some of this processing is triggered by you; some runs on a schedule to prepare insights and notifications.
Separately, when you ask the coach a research-backed question, it may search a public scientific literature database (PubMed, operated by the US National Library of Medicine) using search terms derived from your question. No account identifier is sent with that search.
7. Cookies, analytics and on-device storage
Cookies. We use a small number of strictly necessary cookies to keep you signed in, set by our authentication provider. We use no advertising or cross-site tracking cookies, so we do not show a cookie banner.
Analytics. We use Vercel Web Analytics to understand which features are used. It records page views and coarse technical details and, according to its provider, does not set cookies or store identifiers on your device; it does not receive your name, email or health data. We enable it only when you are signed in — visitors who are not signed in are not measured. You can switch it off under Settings → Privacy, and the change takes effect the next time the app loads.
On your own device.To keep the app fast and usable offline, it stores things in your browser or app storage: a cached copy of your dashboard, your current day's plan, your most recent insight report, sync timestamps, notification tokens, and the access keys for any wearable service you have connected. None of this is used for advertising or shared with third parties. It is cleared when you sign out, clear the app's storage, or uninstall the app.
8. Who we share your information with
We do not sell your personal data and we do not share it for advertising. We share it with the following providers, who act on our instructions under data-protection agreements, and only so far as they need it:
- Supabase — database and authentication; holds your account and health data.
- Railway — hosting for our application server, which processes your data and holds operational logs.
- Vercel — hosting for our website and app, and the product analytics described above.
- Anthropic — AI processing, as described in section 6.
- Apple — delivery of push notifications, where you enable them. Notification text can include your own health figures, which means it passes through Apple's servers and appears on your lock screen.
- Our email provider — sending account emails such as sign-in confirmation and password resets.
- Services you connect yourself — Apple Health, Strava, Oura, Fitbit and similar, which exchange data with us because you authorised them to.
We may also disclose information where the law requires it, or to establish or defend legal claims.
9. International transfers
Some of our providers process data outside the UK and EEA, including in the United States — this is the case for our AI processing. Where personal data is transferred internationally we rely on appropriate safeguards, such as the UK International Data Transfer Addendum and the European Commission's standard contractual clauses. You can ask us for details of the safeguards that apply.
10. How long we keep it
We keep your health and account data for as long as your account exists — we do not delete it on a schedule, because the value of the model depends on your history. Two things do expire automatically: our internal record of AI processing volume is deleted after 90 days, and device push tokens are removed once they stop working.
When you delete your account we permanently erase your login record, and that cascades to every table holding your profile, training, sleep, biometric, blood, cycle, genetic-trait, meal, plan and conversation data. Two things are not covered automatically and we will remove them on request: a waiting-list entry submitted before you had an account, and operational logs held by our hosting providers. We may retain limited records where the law requires it.
11. Security
Data is encrypted in transit. Access to your records is restricted to your own authenticated account: in the app this is enforced by database row-level security, and on our own server — which necessarily holds broader credentials in order to run the model — by application controls that scope every request to the signed-in user. We limit internal access.
Some information is held on your own device, as described in section 7, including the access keys for wearable services you have connected. Anyone with access to your unlocked device may be able to reach it. No system is perfectly secure, but we work to protect your information using industry-standard measures, and we will tell you and the relevant regulator about a breach where the law requires it.
12. Your rights
You have the right to access your data, correct it, receive a copy in a portable form, have it erased, restrict or object to how we process it, and withdraw consent. Where we can, we have built these into the product:
- Correct it — edit your profile in Settings, and edit or delete individual entries in the Log.
- Export it — Settings → Privacy gives you a JSON copy of your profile, daily logs, meals, blood panels, cycle logs, protocols and genetic traits. Some records, including your coach conversations, are not yet in that file — email us and we will send you everything we hold.
- Delete it — Settings → Privacy permanently deletes your account and the data described in section 10. If you cannot sign in, or you want the full picture of what deletion does and does not cover, see Delete your account. Access you granted to Strava, Oura or Fitbit is controlled by those services, so revoke TechTwin there too if you want the connection fully closed.
- Everything else — email team.techtwin@gmail.com.
We respond within one month, which can be extended by two further months for complex requests; we will tell you if that happens. We may ask you to confirm your identity first.
You also have the right to complain to a data protection supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk, 0303 123 1113). In the EEA it is the authority where you live or work.
13. Children
The Service is not intended for anyone under 18 and you must confirm you are 18 or over to use it. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy as the Service evolves. We will revise the “Last updated” date and, for material changes, take reasonable steps to notify you before they take effect.
15. Contact
Questions or requests about your privacy? Email team.techtwin@gmail.com.