One-time price, no subscription, ever. Pre-order now
Stealthy
The Stealthy app

Legal

Privacy Policy

Stealthy: Stealthy Wearables Pty Ltd (ACN 694 833 344)

Last updated: 17 September 2026

This is the authoritative English version.This same policy, word for word, governs inside the Stealthy app. It is also shown there, translated for convenience, in six other languages; if a translation and this English version ever conflict, this version governs.

1. Overview

Stealthy Wearables Pty Ltd ("Stealthy", "we", "us", "our") is bound by the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). This Privacy Policy explains what personal information the Stealthy app and connected Devices (the Watch Clasp and Sports Band) collect, why, how it is stored and shared, and what rights you have over it. It should be read alongside our Terms of Service. The English version of this Policy is the authoritative version; translations are provided for your convenience.

A significant portion of what we collect is health information, which is "sensitive information" under APP 3.3 and requires your explicit consent to collect, separate from your general acceptance of our Terms. That consent is requested specifically at sign-up and again the first time you enable the menstrual cycle feature. See section 8.

2. Information we collect

2.1 Account information

  • Email address and password, or an identifier from Google or Apple Sign-In if you use one of those options
  • First name (optional: auto-filled from Google/Apple where available, or entered manually)

2.2 Profile information (optional, but improves accuracy)

  • Birth year and month, not full date of birth. We store only enough precision for our age-based calculations to be accurate; we do not need or collect the exact day
  • Biological sex, used only because it is a real input to the heart-rate-zone reference formulas and calorie estimation formula we use. It is not treated as a general identity field
  • Height and weight

2.3 Biometric and health data, collected via a connected Device

  • Heart rate and heart rate variability (HRV)
  • Blood oxygen saturation (SpO2)
  • Step count and movement/activity data
  • Sleep duration and sleep stage data
  • Derived metrics we calculate from the above: a stress estimate, Focus Index, Body Battery, and Biological Age estimate

2.4 Menstrual cycle data (only if you enable this feature)

  • Dates you log as period start/end
  • Symptoms you tag against a given day
  • Settings you provide (e.g. whether you use hormonal birth control, whether you are trying to conceive), used only to adjust how the feature interprets your data, never shared outside the purpose you provided it for

2.5 Workout data

  • Sport type, duration, and, for strength training, sets, reps, and weight you log manually
  • GPS route data, but only for workout types that use location (e.g. outdoor running, cycling) and only while a GPS-based workout is actively being recorded
  • Heart rate recorded during the session, and real, timestamped lap/split data if you use that feature

2.6 Calendar data: never stored on Stealthy's servers, however you connect it. There are two ways to bring a calendar into Stealthy. First, by importing one directly , pasting in a private .ics link or its contents , in which case it is parsed and stored entirely on your device, and never transmitted to us or to any third party. Second, by connecting your Google or Microsoft (Outlook / Microsoft 365) calendar: you sign in and grant Stealthy read-only access to your calendar events through Google's or Microsoft's own sign-in screen, the app then fetches your events by communicating directly with Google's or Microsoft's servers using that authorisation, and stores them, and the connected account's email address, on your device only. In neither case does any calendar or meeting data pass through or get stored on Stealthy's own servers. You can connect up to five calendars at once, in any combination, and disconnect any of them at any time, from within the app or directly in your Google or Microsoft account settings. Where a connection uses Google's APIs, Stealthy's use and transfer of information received from them adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2.7 Device and technical information

  • Device connection status, push notification token, general app usage and diagnostic information necessary to operate the Service

3. How we use your information

  • To operate the core features of the Service: displaying your real-time and historical biometric data, computing the derived metrics described in section 2.3, and generating your daily Signal briefing
  • To generate your daily Signal briefing's natural-language text, a real summary of your own recent data (not your raw biometric stream) is sent to OpenAI for processing. See section 5
  • To send you notifications you have opted into, respecting the quiet hours and category preferences you set. We do not send notifications outside the categories you have enabled
  • To maintain the security of your account and the Service
  • To comply with our legal obligations

We do not sell your personal information. We do not use your health data for advertising, and Stealthy's own products do not display third-party advertisements.

5. Who we share information with

We share only what each provider needs to perform its specific function, and no more:

  • Supabase: hosts our database, user authentication, and file storage. Most of the data described in section 2 is stored here.
  • Google: if you use Sign in with Google, Google authenticates your identity. Google Maps is used to render workout routes on-screen; route data is sent to Google only to draw the map you are already viewing. If you connect a Google Calendar, Stealthy is granted read-only access to its events directly between your device and Google, to correlate them with your stress data; this never passes through our servers, and no Google Calendar data is shared with any other provider in this list.
  • Microsoft: if you connect a Microsoft or Outlook calendar, Stealthy is granted read-only access to its events for the same purpose, directly between your device and Microsoft; this never passes through our servers, and no Microsoft Calendar data is shared with any other provider in this list.
  • Apple: if you use Sign in with Apple, Apple authenticates your identity.
  • OpenAI: a real, de-identified summary of your day's data (metrics and their deviation from your own baseline, not your name or raw sensor stream) is sent to OpenAI to generate the natural-language text of your Signal briefing.
  • Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM): receive a device token used only to deliver the push notifications you have opted into.

We do not share your information with data brokers or advertisers. We may disclose information if required by law, or to protect the rights, property, or safety of Stealthy, our users, or the public.

6. International data transfers

Several of the providers listed in section 5 (Supabase, OpenAI, Google, Apple, and the push notification services) may store or process data on servers located outside Australia, including in the United States. For the current, up-to-date position on data hosting regions and applicable safeguards, please refer to//stealthy.band/.

7. Data storage and security

Your data in our database is protected by row-level security policies that restrict every table so a user can only ever read or write their own data. This is enforced at the database level, not only in the app. Data is encrypted in transit between the app and our servers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Sensitive information: special note on menstrual cycle data

Menstrual cycle tracking is entirely optional and is only visible to accounts that identify as female in their profile. It is not presumed or enabled by default. Enabling it for the first time requires a separate, explicit acknowledgment beyond your general Terms acceptance, naming this category of data specifically. You can view, edit, or delete every logged entry from within the feature itself at any time, and disabling the feature does not require you to delete your history unless you choose to.

9. Data retention and deletion

We retain your personal information for as long as your account is active, or as needed to provide the Service. If you delete your account, we will delete your personal information from our active systems, other than information we are required to retain for legal, accounting, or fraud-prevention purposes. For the current, up-to-date position on exact retention periods, please refer to//stealthy.band/.

10. Your rights

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or out-of-date information
  • Request deletion of your account and associated data
  • Make a complaint if you believe we have mishandled your personal information

You can access and correct most of your profile information directly within the app (Profile and Preferences). Account deletion is handled by request: contact us using the details in section 13, and we aim to complete it within 30 days of a verified request.

11. Children's privacy

The Service is not directed at, and we do not knowingly collect personal information from, anyone under 16 years of age. See the Terms of Service, section 2, for our full position on eligibility.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the change takes effect.

13. Contact us and complaints

Stealthy Wearables Pty Ltd

ACN 694 833 344

Level 1, 200 Lygon Street, Carlton, Victoria 3053, Australia

Privacy contact:info@wearstealthy.com

If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.