Effective July 27, 2026
ricBod is a personal iOS application built and used by one person, Ric Nevarez. It is not offered to the public, has no other users, and collects no information about anyone else. This policy describes how the app handles the data it touches.
The only person whose data ricBod handles is its developer and sole user. There is no user base, no account system, and no sign-up. If you are reading this as part of an API review, that is the entire scope.
ricBod keeps a local database on the iPhone containing:
If Oura access is authorized, ricBod reads daily sleep, readiness, and activity summaries along with resting heart rate and heart-rate variability. These readings feed the app's recovery model, which adjusts training prescriptions.
Oura data is requested directly from Oura's API by the app on the device and written into the same local database as everything else. It is read-only: ricBod never modifies your Oura account and never publishes to it. Access tokens are held in the iOS Keychain.
There is no ricBod server. No data is sent to any infrastructure operated by the developer, because none exists. Three external destinations are possible, all under the user's control:
Apple iCloud (optional, off by default). The app can mirror its database to the user's own private iCloud database so a second device stays in sync. This is disabled unless explicitly turned on in Settings. Apple, not the developer, operates that storage, and the data stays in the user's private CloudKit container.
Apple Health (on device). With permission, ricBod reads workouts and body measurements from HealthKit and writes completed workouts back. This exchange happens entirely on the device and is governed by iOS.
OpenRouter (only when coaching chat is used). The app includes an optional coaching assistant. When — and only when — a message is sent to it, a summary of recent training and recovery context is transmitted to OpenRouter, which routes it to a large language model provider. If Oura is connected, that context can include derived recovery values such as sleep and readiness scores. Nothing is sent unless a chat message is deliberately sent, and the feature can be left unused entirely.
Data is kept for as long as the app remains installed. To remove it:
The local database is protected by iOS file encryption and device passcode. OAuth tokens are stored in the iOS Keychain rather than in application storage. All network requests use HTTPS. Because there is no server and no shared account, there is no remote credential database to breach.
ricBod is not directed at children and is not available to anyone other than its developer.
If the app's data handling changes, this page is updated and the effective date above changes with it.
Questions about this policy: ric@thetrustweb.com