Privacy Policy

Last updated: August 15, 2026

Overview

Yudemon is designed with privacy at its core. We believe your health and practice data belongs to you, and we've built our products to respect that principle.

The Yudemon mobile app (Yudemon HRV) keeps your health and practice data entirely on your device unless you create an account and enable cloud sync. ApexFlow, our racing analytics platform, requires cloud storage to function but gives you full control over your data.


Yudemon HRV Mobile App

Local-Only Usage (No Account)

When using Yudemon HRV without an account:

  • Your health and practice data (sessions, heart-rate recordings, settings, progress) stays entirely on your device – it is never uploaded, and we cannot access, view, or recover it
  • The app sends usage analytics (see Usage Analytics below) and communicates with the app stores and our subscription provider for subscription processing
  • No personal information such as your name or email address is collected

Usage Analytics (Mobile App)

The mobile app uses Firebase Analytics (Google) to collect usage events – for example which screens and features are used, sessions completed, and announcements seen. These events are tied to a random, device-scoped identifier, not to your name, email, or account, and they never include your heart-rate data or session recordings. We use them solely to understand which features matter and to improve the app.

Account-Based Usage (Optional)

Required Information:

  • Email address only – used for account authentication, recovery, and occasional product updates (you can unsubscribe anytime)

Optional Data (Only if you enable cloud sync):

  • Practice statistics (session counts, duration, streaks)
  • App preferences (breathing rates, session settings, audio levels)
  • Heart rate variability data and session averages
  • Journey mode progress and personal resonance frequency discoveries

Cloud sync is entirely optional. You control exactly what data gets backed up through individual category toggles in your account settings.


ApexFlow Racing Analytics

ApexFlow combines heart rate data with racing telemetry to help drivers understand their physiological state during racing sessions. Unlike the main Yudemon HRV app, ApexFlow requires cloud storage to function – there is no local-only mode.

Data We Collect

From the Desktop App:

  • Heart rate data: Beat-by-beat RR intervals from your Bluetooth heart rate sensor (e.g., Polar H10)
  • Racing telemetry: Data from your iRacing sessions including speed, throttle, brake, steering, lap times, and track position

Processed and Stored:

  • Session metadata: Track name, car name, session type (practice/qualifying/race), duration
  • Physiological metrics: Heart rate, heart rate variability (RMSSD), and breathing rate estimates
  • Performance data: Lap times, incidents, position changes
  • GPS coordinates: Virtual track positions from the racing simulation
  • User-provided tags: Custom labels you add to sessions

What We Don't Collect

  • Your iRacing username or account information
  • Your real-world location or IP address (beyond standard web traffic)
  • Any data from outside your racing sessions

Data Storage and Retention

  • Raw files (telemetry and heart rate recordings): Retained indefinitely until you delete the session or your account
  • Processed session data: Retained indefinitely until you delete the session or your account
  • Session summaries: Cached for fast loading, updated when sessions change

ApexFlow-Specific Processing

Your data is processed by automated systems to:

  • Parse racing telemetry files and extract relevant variables
  • Detect and correct artifacts in heart rate data
  • Compute heart rate variability metrics
  • Align physiological data with telemetry timestamps
  • Identify laps, incidents, and position changes
  • Generate per-lap and session-level statistics

This processing happens automatically when you upload a session. No human reviews your individual data.


How We Use Your Information

Email Addresses

  • Account authentication and password recovery
  • Occasional product updates and feature announcements (unsubscribe available)
  • Never shared with third parties other than the providers that send our email for us

Health and Practice Data

  • Stored securely in your personal, private cloud storage
  • Used primarily for cross-device data synchronization and to provide insights and analytics to you
  • When you use our web dashboard, summary metrics derived from your sessions (for example session duration, average heart rate, heart rate variability, and breathing rate) – but never your raw beat-by-beat recordings – may be processed at an individual, identified level by our analytics provider (PostHog) to help us understand how features are used and improve our products
  • We never sell your data, and we never share it with third parties other than the service providers that operate the product on our behalf under contractual data-protection obligations
  • You can export or delete all data at any time

Sharing With a Coach (Optional)

  • You can choose to share your session analytics with a coach or practitioner by entering their email address in your account settings – this is entirely optional and off by default
  • Sharing gives that person read-only access to your session analytics on the web dashboard (sessions, trends, insights, and per-session detail including heart-rate data); they cannot change or delete anything, and they never see your account settings
  • The moment you share is recorded as your consent, and you can revoke access at any time from the same settings page – access ends immediately
  • Sharing relationships are included in your data export and are permanently removed when either account is deleted

Third-Party Services

Firebase (Google)

  • Manages secure account authentication and cloud data storage, and provides the mobile app's usage analytics (Firebase Analytics – see Usage Analytics above)
  • Your data is stored in your individual, private database
  • GDPR-compliant infrastructure
  • Google does not access your personal health data

Google BigQuery

  • Stores processed session data for analytics queries
  • Same privacy protections as Firebase
  • Data partitioned and isolated by user

Google Cloud Storage (ApexFlow Only)

  • Stores your raw telemetry and heart rate files
  • Retained until you delete the session or your account, so sessions can be reprocessed when our analysis improves
  • Access restricted to your account only

RevenueCat

  • Handles subscription management across platforms
  • Only receives subscription status, not personal or health data
  • Enables sharing Yudemon Pro across iOS, Android, and web platforms

PostHog (Web Dashboard Analytics)

  • Provides product analytics and session replay for our web dashboard (app.yudemon.com), so we can understand how the dashboard is used and improve it
  • Receives usage events tied to your account identifier – including which features you use, page performance/loading times, and summary session metrics (such as average heart rate, heart rate variability, and breathing rate). It never receives your email address or your raw beat-by-beat recordings
  • Session replay records your interactions with the dashboard with all text and input fields masked, so the actual values and content you view are not captured
  • Processes this data solely on our behalf under a data-processing agreement, and does not sell it
  • Used only on the web platform – the mobile app does not use PostHog

Apple App Store / Google Play Store

  • Processes subscription payments
  • Shares only necessary transaction information with RevenueCat
  • We do not receive your payment information

Your Data Rights

Access and Control

  • View all your data anytime in the app or web dashboard
  • Export all your data in standard formats
  • Choose exactly what data to sync to the cloud (HRV app)
  • Disable cloud sync at any time (HRV app)

Data Deletion

  • Delete your account and all cloud data from within the app or web dashboard – deletion starts immediately, and a small tail of very recently processed analytics data clears automatically within about two hours
  • Delete individual ApexFlow sessions at any time
  • Local data remains on your device unless you manually delete the app
  • After an account deletion we keep a minimal deletion record (account identifier, email, and request metadata such as IP address) for up to seven years, as evidence that the deletion was requested and carried out

Data Portability

  • Export your complete practice history, settings, and progress
  • Export ApexFlow sessions with full telemetry and physiological data
  • Data provided in machine-readable formats for use with other applications

Data Security

Local Storage (Mobile App)

  • All data encrypted using iOS/Android system-level security
  • Protected by your device's security (passcode, biometrics)

Cloud Storage

  • Secure encryption during transmission (TLS) and at rest
  • Hosted on Google Cloud with enterprise-grade security
  • Access controls keep your data private to your account and to anyone you explicitly share it with
  • Security managed by Google's infrastructure and monitoring

Geographic Considerations

International Users

  • Data may be stored in Google Cloud facilities worldwide
  • All storage locations comply with applicable privacy laws
  • EU users' data handled in compliance with GDPR

California Residents (CCPA)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale (we never sell data)
  • Right to non-discrimination for exercising these rights

Children's Privacy

  • Yudemon is not intended for children under 13
  • We do not knowingly collect information from children under 13
  • If we learn we have collected such information, we will delete it immediately

Health Data Considerations

  • Heart rate variability data is considered sensitive health information
  • We treat all practice and health data with the highest level of protection
  • Never sold and never used for advertising
  • We may analyse de-identified data in aggregate to improve our products and to study how breathing practice works, and we may publish those aggregate findings – see Research and Publication below
  • We will never share your individual records with external researchers or any other third parties (beyond the service providers that operate Yudemon on our behalf) without your explicit consent
  • You maintain complete ownership and control of your health data

Research and Publication

Yudemon is a small, research-driven product. Understanding how breathing practice actually works – across many people rather than one – is how we make it better. Occasionally that work turns up something of broader scientific interest, and we publish it.

What this means in practice:

  • We analyse de-identified session data in aggregate to study questions such as how the body's response changes over the course of a session, or how optimal breathing rates vary across a population
  • Where results are of scientific interest we may publish them – on our blog, as a preprint, or in a peer-reviewed journal – and in doing so we may work with academic collaborators or submit the work for independent ethical review
  • Only aggregate statistics are ever published. No individual record, session, or recording is published, and nothing we publish can be traced back to you
  • We do not share individual-level data for research. Not with collaborators, not with journals, not with anyone – doing so would need your explicit, separate consent first. (This is about research specifically. Running Yudemon at all means your data is stored and processed by the service providers listed above, under contract and on our behalf.)
  • Personal identifiers are removed before analysis
  • If we ever want to go beyond this, we will ask you first

If you would rather your data were not included even in aggregate analysis, turn off Include my data in research in your account settings – or email privacy@yudemon.com and we will do it for you. This has no effect on your use of the app.


Changes to This Policy

  • We will notify users of significant changes via email or in-app notification
  • Continued use after changes constitutes acceptance
  • Previous versions available upon request

Data Retention Summary

Data TypeRetention Period
Account dataUntil you delete your account
Local app dataUnder your complete control on your device
Cloud-synced HRV dataUntil you delete your account or disable sync
ApexFlow raw filesUntil you delete the session or your account
ApexFlow sessionsUntil you delete the session or your account
Anonymized statisticsMay be retained indefinitely for product improvement and research – cannot be linked back to you
Web dashboard analytics (PostHog)Retained per our analytics retention settings; deletable on request
Deletion recordsUp to seven years – proof that an account deletion was requested and completed

Contact Information

For privacy questions or to exercise your data rights:


Legal Basis for Processing (GDPR)

  • Account creation: Contract performance
  • Cloud sync: Your explicit consent (you can withdraw anytime)
  • App functionality: Legitimate interest in providing the service
  • Communication: Your consent (easily withdrawn)
  • Web dashboard analytics & session replay: Your consent (covered by the same consent that enables cloud data and the web dashboard; you can withdraw at any time)
  • Mobile usage analytics: Legitimate interest in understanding and improving the app (device-scoped, no health data)
  • Deletion records: Legal obligation and legitimate interest in evidencing that erasure requests were honored
  • Research and product improvement: Legitimate interest in understanding and improving the product. Data is de-identified before analysis, and anything we publish is aggregate statistics that can no longer be linked to an individual. You can opt out at any time by emailing privacy@yudemon.com

Key Principles

Yudemon HRV keeps your health data entirely on your device by default. All cloud features are optional enhancements that you explicitly choose to enable; the only thing the app sends on its own is device-scoped usage analytics that never include your health data.

ApexFlow requires cloud storage to function, but you maintain full control: data uploads require manual approval, you can delete any session, and you can export or delete all your data at any time.

Your privacy and data ownership are never compromised.