← back

privacy at whylo

last updated: may 6, 2026

whylo is built around a simple privacy posture: we read what your phone already knows, we send the smallest possible derived signals to an AI to generate the language you see, and we don't keep records of you on our servers. this page explains exactly what that means.

what we collect

health data (via apple healthkit)

  • sleep duration, step count, active energy, mindful minutes
  • read-only, with your explicit permission via apple's standard healthkit prompt
  • never stored on whylo's servers
  • stored locally on your device using ios's swiftdata framework
  • you can revoke access anytime: ios settings → health → data access & devices → whylo

calendar density (via apple eventkit)

  • the COUNT of events on your calendar each day
  • never the titles, locations, attendees, or notes — only how many events
  • read-only, with your explicit permission via apple's standard calendar prompt
  • never stored on whylo's servers
  • you can revoke access anytime: ios settings → privacy & security → calendar → whylo

onboarding answers

  • your responses to the three onboarding questions
  • stored locally on your device only
  • never transmitted

email address (optional, only if you join the waitlist on getwhylo.com)

  • used solely to notify you when whylo launches on the app store
  • not used for marketing automation, behavioral targeting, or sold to anyone
  • delete anytime by emailing support@getwhylo.com

what we do not collect

  • location
  • contacts
  • photos or camera
  • microphone
  • usage analytics or behavior tracking
  • advertising identifiers
  • third-party cookies
  • crash logs that identify you

we use no analytics services. no firebase. no mixpanel. no amplitude. no facebook sdk. no google analytics.

how data flows

once a day, when whylo generates the phrase you see below the orb (and once a week for the sunday insight card), the app sends a small derived signal payload to a server we operate on cloudflare workers. the payload looks like this:

{ "state": "neutral", "steps": 3325, "meetings": 3, "sleepHours": 7.2 }

no name. no apple id. no email. no device identifier. just the derived signals needed to generate one phrase.

cloudflare workers forwards this payload to anthropic's claude api, which returns the phrase. we display the phrase, cache it on your device, and the cycle ends. the payload is not retained by whylo.

anthropic may retain api requests according to their stated policy (currently 30 days for standard requests). their privacy policy: anthropic.com/legal/privacy. cloudflare may log standard request metadata (ip address, timestamp). their privacy policy: cloudflare.com/privacypolicy

data we send to third parties

two services, both for the single purpose of generating language:

  • anthropic — receives anonymized signal payloads, returns generated phrases
  • cloudflare workers — proxies requests between the app and anthropic

we do not share data with advertisers, data brokers, marketing platforms, or any other third party. we do not sell data. we have nothing to sell.

retention

  • health and calendar data: never stored on our servers; lives on your device only
  • signal payloads to anthropic: not retained by whylo; subject to anthropic's stated retention
  • email addresses on waitlist: kept until launch + a brief window for the launch announcement, then deleted unless you've opted into ongoing communication

your rights

you can:

  • revoke healthkit or calendar access via ios settings at any time
  • delete all whylo data by uninstalling the app
  • request removal from the launch waitlist by emailing support@getwhylo.com
  • ask us anything about how your data is handled by emailing support@getwhylo.com

children

whylo is not directed at children under 13. we do not knowingly collect data from users under 13. if a parent believes their child has used whylo, please email support@getwhylo.com and we will assist.

changes to this policy

if we change how data flows through whylo, we'll update this page and update the "last updated" date at the top. material changes will be communicated in-app where possible.

contact

for any privacy question, write to: support@getwhylo.com

operator: destone evans
jurisdiction: united states

made with attention.