Privacy Policy

Teko · Last updated: 17 August 2026

Português

Teko is a local-first training application: user data is kept on the device, encrypted, and the application operates without transmitting it. This policy describes which data is processed, which data leaves the device, and how to exercise the rights provided by law.

Controller

Data is processed by Gabriel Velasco, an individual, acting as data controller under Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018). Contact for matters relating to this policy, including the exercise of rights: tekoappsuporte@gmail.com.

Where data is stored

All data recorded in Teko is written only to the user's device. Workouts, runs, check-ins, profile, measurements and health data are held in a database encrypted with AES-256, whose key is randomly generated on first launch and kept in the operating system's key store. Neither the controller nor any third party has access to that database.

The same applies to conversations with Teko Intelligence and to answers flagged by the user: they are held in the encrypted database and removed together with the application's data.

Exception: the home screen widget. The widget is drawn by the operating system outside the application, in a process that has no access to the database encryption key. For that reason, while the widget is added to the home screen, a summary of the day (readiness, hydration, the day's workout, steps and the week's total) is written to the widget's own data area without encryption. This summary corresponds only to what is displayed on screen, does not include the user's history and is not sent by Teko to any server. The application disables both Android's automatic cloud backup and the copying of this data area during a device-to-device transfer. If the widget is not added, none of this data is written.

Teko keeps no copy of user data on any server. Should this change, this policy will be updated beforehand, and any upload will be optional, encrypted on the device and subject to activation by the user.

Data processed

Sensitive data and consent

Reports of pain, injuries, menstrual cycle, body measurements and other health data constitute sensitive personal data (LGPD art. 5, II). Processing is based on the data subject's specific, highlighted consent (art. 11, I): none of this information is mandatory, every module is optional, and deletion may be carried out at any time. Cycle tracking remains disabled by default and requires express activation.

Data that leaves the device

The following list is exhaustive:

The following is never transmitted: training history, pain and injury reports, cycle records, body measurements, GPS routes and the application database.

Advertising, analytics and tracking

Teko does not display advertising, does not use analytics or profiling tools, does not send automatic crash reports and does not sell data. There is no advertising identifier and there are no tracking cookies.

The subscription data described above is sent to the provider that administers purchase validity solely to keep a subscriber's access working — never for advertising, profiling or any marketing purpose.

Health Connect

Subject to the user's authorisation, Teko reads steps, distance, calories, exercise, heart rate, sleep, weight and height from Health Connect, in order not to request again information already recorded on the device. Reading occurs locally, the data is incorporated into Teko's encrypted database and is not transmitted. The authorisation is optional and may be revoked at any time in Settings › Data and privacy › Privacy and your data, or from Health Connect itself.

Data held by Health Connect does not belong to Teko and is not erased by it. The application only reads from Health Connect and never writes; Android allows an application to delete only the records it has written itself. When Teko's data is erased, the application revokes the authorisations granted — which stops the reading, but does not remove what Health Connect stores, as Android's own documentation states: when you remove data permissions, you don't remove the stored data. Erasing those records is done by the user in the Health Connect app, under Permissions and data › Delete data.

Location

Location is used solely during a GPS run started by the user, in order to measure distance and pace and to draw the route. While a run is active, a foreground service with a visible notification is maintained, so that tracking continues with the screen off. Teko does not track location in the background outside a run, and the route is not used in analytics, in Teko Intelligence or in diagnostic records.

To display the map, the application retrieves map tiles from OpenStreetMap (tile.openstreetmap.org), a project maintained by a non-profit foundation. The request occurs only when a map is opened, and the OpenStreetMap Foundation receives the coordinates of the tiles displayed and the user's IP address, which corresponds to the region of the route. The route itself, point by point, is not transmitted: it is drawn on the device, over the map.

Diagnostics and technical records

Teko writes no log file to the device. Recent technical events are held in memory only, pass through an automatic redaction layer that removes personal and health data, and are discarded when the application closes. The report may be reviewed in full in Settings › About › Diagnostic report, and it is for the user to decide whether to copy it when requesting support. Nothing is sent automatically.

Sharing with third parties

There is no sharing of data, except with the providers strictly necessary for the functionality described in this policy:

Retention period

Data does not expire automatically: the history remains on the device for as long as the user wishes to keep it. Once deletion is requested, it is immediate and permanent; there is no cloud copy to restore from and no means of recovery available to the controller. Uninstalling the application also removes the database.

Data subject rights

The LGPD (art. 18) grants the data subject confirmation of processing, access, correction, anonymisation, portability, erasure, information on sharing and withdrawal of consent. In Teko these rights are exercised directly in the application, with no need for a request:

Any right may also be exercised in writing at tekoappsuporte@gmail.com, with a response within 15 days.

Security measures

Database encrypted with AES-256, key held in the operating system's secure store, traffic exclusively over HTTPS, declarative blocking of unencrypted traffic, and blocking of the application on devices compromised by root. Details in Security.

Minimum age

Teko is intended for adults aged 18 or over and is not directed at children or adolescents. There is no intentional collection of minors' data; should it occur, deletion will be carried out upon notice to the contact indicated in this policy.

Changes to this policy

Material changes, in particular any transmission of data to a server, will be communicated in the application before taking effect, and the date shown at the top of this page will be updated.