Telos
TürkçePrivacy Policy
Last updated: 21 August 2026
Telos exists to give you time back, and we handle your data with the same care. This page explains, in plain language, what we collect and why, where we keep it, and how much say you have over it. Continuity, not guilt. Transparency, not pressure.
What we collect
Almost everything Telos holds is content you entered yourself. The categories are:
- Account details: your email address, your password (stored encrypted by Supabase Auth; we cannot see it), your display name, the archetype and starting preferences you chose, and your notification preferences.
- Your module data: your habits and daily marks; your goals and the reflections you write on them; your daily intentions; your finance data (categories, transactions, assets, statement records); your plans and tasks; your fitness data (programs, sessions, logs); your diet data (meals, drinks, targets); your reading and film/series/game lists; your journal entries; your day states and factors; your focus/detox sessions; your community shares.
- Notification data:your device's push notification key (token), so reminders can reach you. This key is deleted when you sign out.
- Ask Telos (the operator): The messages you write in the in app chat are sent to the AI provider (Google Gemini) so an answer can be produced. So the answer fits your setup, the NAMES of your existing habits, groups and goals are sent too, along with your archetype, whether macro tracking is on, and how many training days your weekly program holds. Your journal text, habit and meal notes, finance transaction notes and health data are NEVER used by this feature. The conversation is not stored on our servers; it stays on your device and is deleted when you sign out. The operator never saves anything on its own: nothing changes in your account until you approve its plan.
- Guide (artificial intelligence): the Guide looks at the module data you entered (habits, spending, diet, fitness, journal entries and day state) and produces a monthly summary report. For this report, a derived summary of your data and, if you turned journal content on, the text of your journal entries are sent to the AI provider (Google Gemini). This setting is off by default: your journal text is never sent unless you explicitly choose to include it, either the first time you use the Guide or under Settings › Privacy and Data. While it is off the Guide looks only at statistics (how many days were written, mood distribution) and your journal text is not sent. Health data (steps/sleep) never enters this flow. A usage counter is also kept, to limit excessive use.
- Usage events: we count which screens are opened and whether a few core actions happened (checking off a habit, creating a reminder, starting a bond). The point is to see where the product gets stuck. These records carry no content: your habit names, journal entries, meal descriptions and note text cannot enter them; only the event name, a normalised screen path (for example "/habits/[id]") and a number are stored. This data stays on our own server, is never sent to a third party, is deleted automatically after 180 days, and goes with your account if you delete it.
- Together / pairing:if you invite someone into "Together", only the limited data you choose to share becomes visible to them. Sensitive content such as your journal entries and dopamine records is not shared through pairing.
What we do not collect
Telos has no advertising identifier, no location tracking and no third-party analytics or trackers. The usage counters we keep to improve the product (described above) stay on our own server and carry no content. We do not sell your data, rent it out, or use it for advertising.
The steps, active energy and sleep figures in the Health module are read from your device's health service (Health Connect on Android, Apple Health on iOS) on your device only; they are not sent to our servers and we do not store them. We request readaccess only; Telos never writes anything back to your health service. Health data is never used for advertising, never shared with or sold to third parties, and never sent to the AI features. You can revoke the permission at any time in your device's Health Connect (Android) or Health (iOS) settings; once revoked the module simply appears empty, and there is no copy on our side to delete.
Where and how we store your data
- Your data is hosted in a PostgreSQL database on Supabase, in the European Union region (Frankfurt).
- Two flows leave the European Union: content you send to an AI-assisted feature is processed by Google, and your notification key is processed by Expo. These transfers take place under the data processing terms of those providers.
- Row-level security (RLS) means every record is open only to its owner: no other user can reach your data, except the limited items you explicitly choose to share (see "Together / pairing" above).
- All connections between the app and the server are encrypted with HTTPS.
- Your journal photos, progress photos and the statement images you upload are kept in private storage and are viewable only through short-lived, signed links. Your profile photo, if you set one, is stored at a public address: it is not listed anywhere and the address is not guessable, but anyone who has the link can open it.
What we use your data for
We use your data only to make the app work: to show your records, calculate your progress, send reminders and provide the features you ask for. We do not process it for any other purpose.
Third parties (data processors)
We use a small number of providers to deliver the service. In some features, the content needed to run that feature is passed to the relevant provider:
- Supabase: database, authentication and file hosting (European Union, Frankfurt).
- Expo push notification service: to deliver reminders to your device (your notification key only).
- RevenueCat: to manage subscription status and verify purchases. Your payment/card details are handled by the App Store or Google Play; neither Telos nor RevenueCat sees or stores your card details.
- Google (Gemini AI): when you use certain AI-assisted features, the content you give that feature is sent to Google and processed there: your meal photo or description for diet (calorie/macro estimate), the credit card statement image/PDF you upload for Spending (transaction breakdown), the recipe text you paste (recipe parsing), your inputs for a fitness program suggestion, and, for the monthly Guide report, a derived summary of your data along with the text of your journal entries, if you turned journal content on (it is off by default). This content is sent only to produce the result in question. (The Turkish translations of the exercise descriptions in the fitness library were generated with Gemini ahead of time, over a public data set; they contain none of your personal data.)
- Content search services: when you search a list, only your search term or the barcode you scanned is sent to the relevant service (not your personal data): TMDB, IGDB and OMDb for films/series/games; Open Library and Google Books for books; FatSecret and Open Food Facts for food and barcodes. These services return only cover art, ratings or nutrition information.
Apart from these processors, we do not share, sell or rent your data to anyone.
Your rights
All of the rights below (access, export, deletion and correction) can be exercised from inside the app, under Settings › Privacy and Data:
- Access: you can reach your data at any time in the app and view your records.
- Export:"Download your data" exports all of your data as a JSON file, which you can then share or save wherever you like (to a destination you choose).
- Deletion:with "Delete account", after a two-step confirmation (typing to confirm), your account and all of your personal data are deleted immediately and permanently and you are signed out. This cannot be undone; there is no waiting period and no grace period. Full removal from backups may take up to 30 days.
- Correction: you can edit most of your data freely in the app, or delete entries one by one.
- Complaint: if you have a concern about how your data is processed, you have the right to lodge a complaint with the competent data protection authority: in Türkiye the Personal Data Protection Authority (KVKK), and in the European Union the relevant supervisory authority.
How long we keep your data
We keep your data until you delete it or close your account. When you delete your account, your data is deleted right away and for good; there is no holding period and no grace period. Full removal from backups may take up to 30 days. Anonymous content no longer tied to your identity may be retained after deletion, but it can no longer be associated with you.
Children's privacy
Telos is not designed for people under 13, and we do not knowingly collect data from that age group.
Changes to this policy
We may update this policy from time to time. Changes are published on this page and the "last updated" date above is refreshed.
Contact
For any privacy questions you can reach us at support@telos.onl.
See also: Terms of Use