Tharpa Health Privacy
The Portuguese version is the legally binding one. This English translation is provided for information only; if the two differ, the Portuguese version prevails.
This app processes health data, which the LGPD classifies as sensitive personal data. Below are the full Privacy Policy and your rights — the same text the app shows in English.
App: com.tharpa.health · Updated on October 7, 2026 ·
Versão em português (a que vale)
Privacy Policy
Tharpa Health keeps the health data you enter so it can show your progress and generate analyses. We do not sell your data, we do not ask for your CPF (Brazilian taxpayer number), and you can export or delete everything in the app.
1. What data we collect
We collect only what you provide or authorize. We do not ask for your CPF or any identity documents.
Account:
- Email and password. The password is never stored as text, only as a code derived from it.
- The name you want to be called.
- Date of birth. It is used to calculate your age and to know whether the account needs a guardian's authorization.
- A public ID in the format TH-XXXX-XXXX. It identifies your account without showing your email, but it remains linked to the account: it is not anonymous.
- Access plan (free, full or trial period), invite codes used, and the confirmation of your email.
- App preferences, such as the measurements shown on screen and the interval of the water reminder.
Health profile:
- Weight, goal weight, height, goal, physical activity level and sun exposure.
- Biological sex, used only to calculate your targets (calories, protein, water).
- Gender identity, optional, used only so that the app and the AI address you the right way. Without it, the language is neutral.
- Whether you are on medication treatment, and the dose.
- If your account confirmed its date of birth after saving a height or weight that is unusual for adults, we keep on the account the height and weight from that moment, only so we do not ask again (section 10).
Entries you make:
- Meals: food, calories, protein, carbohydrates, fat and time.
- Water and other drinks, including any supplement taken with them (such as whey or creatine) and the amount.
- Weigh-ins.
- Tape measurements: waist, abdomen, hips, neck, chest, arms and thighs (each side) and calf.
- Vital signs you type in, such as blood pressure, glucose, oxygen saturation, body fat and basal metabolic rate.
- Symptoms, with intensity and notes.
- Daily check-in: mood, energy, hunger and notes.
- Medication treatment: injections (date, dose, site, next dose, notes) and vial stock.
- Body progress photos (pose, date and weight that day) and the analyses made of them.
- Meal photos, sent for nutritional analysis.
- What you write in the chat with the AI and in suggestion or bug report messages.
Menstrual cycle (optional):
- It only exists if you turn on the menstrual cycle module, in Your account, in the Privacy and your data section. Anyone can turn it on, and turning it on is your consent for this module (section 3).
- The days you mark as menstruation, with the flow: light, medium or heavy.
- Whatever you want to record on each day, all optional: cramps from 0 to 10, mood, energy, hours of sleep, libido, discharge, skin and hair signs (acne, oiliness, hair loss, increased body hair), PMS and a free-text note that only you can see.
- For people over 18, and only with a separate authorization requested the first time: whether you had sexual intercourse that day, with or without protection. This is data about sex life, which the law treats as sensitive. It never appears to a guardian, a companion or the AI, and you can stop recording it whenever you want.
- The estimates the app calculates from these entries: your next period, the fertile window and the cycle phase. They are calculated on our server, using only your own history.
Pregnancy (optional):
- It only exists if you mark that you are pregnant in the cycle log and accept the pregnancy tracking. Accepting is your consent for this module (section 3).
- The information that you are pregnant, the date of the first day of your last period and, if you provide it, the due date given by your doctor. With these, the app calculates the week of pregnancy and the due date.
- If you provide it, the baby's sex (girl, boy, or that you prefer to be surprised) and the color you choose for the pregnancy screen (pink or blue). The app only asks about the sex from week 16 onward, and you can change or delete it whenever you want.
- If you are on medication: whether your doctor has cleared the dose reminder again, which stays paused during pregnancy until you say yes.
- If you provide it, your pre-pregnancy weight, to calculate the recommended weight-gain range. The pregnancy screen also shows the weight and blood pressure you already record in the app.
- If your weight drops below your pre-pregnancy weight and you tap "I've checked with my doctor": your weight at that moment and the date, so the app doesn't repeat the notice unless your weight drops again. Only you can see it. If you tap "I've sought care" on the bleeding notice on the pregnancy screen: the last day of bleeding marked, so the app doesn't repeat the notice until there is new bleeding. Only you can see it.
- While the pregnancy is being tracked, the "Today's period" card leaves the home screen. If cycle tracking is on and there are period days marked after the start of the pregnancy, the pregnancy screen reminds you that, during pregnancy, bleeding is a sign to seek care.
- While the pregnancy is being tracked, the week of pregnancy and your pre-pregnancy weight also adjust your daily goals (calories with no deficit and pregnancy protein) and replace the weight-loss cards with pregnancy weight gain. The goal you saved in your profile does not change and applies again when the pregnancy ends.
- If you take bump photos on the Body screen: the photos, with the date. The week of each photo is calculated from the pregnancy dates and is not stored in the photo. They follow the same rules as body photos (the top of the photo, where the head is, is cropped on your device; only you can see them) and stay saved after you end the tracking, until you delete the photo, the pregnancy data or the account. If you measure your bump with the tape, the measurement is kept with your other measurements.
- If you provide it, whether the pregnancy is of one baby, twins, or three or more, to remove the weight-gain range, which in that case the prenatal care team advises on, and to show the week's notes.
- The appointments and exams you record: the date, the type, the professional, your notes and the result. If you want, also photos of the reports, which are stored on our server so you can see them on any device, until you delete the entry, the pregnancy data or the account.
- If you end the tracking, how the pregnancy ended: the baby was born, there was a loss, or you prefer not to say.
- If you turn on the daily pregnancy tip: that it is on and the time you chose. Each day's text is fixed, the same for every pregnant person in the same week, and does not use AI.
- If you name a partner: which Tharpa Health account is theirs, when you invited them, when they accepted, when you confirmed and when the link ended; what you allowed them to see, since when and when you turned it off (and, for the bump photos, whether you included the ones you had already taken); and, if you allow the warning signs, each sign you log to notify them. The invite code is stored only as a cryptographic hash and is valid for 48 hours.
- From the pregnancy, the AI receives only what is in section 4 (the week, the trimester and the number of babies, when analyzing a meal photo and the growth of your bump, if you turn on "AI comments during pregnancy"). Nothing about the pregnancy appears to a guardian or companion. If you are over 18 and name a partner, they see the week of pregnancy, the expected month of birth and the week's content, and only what you allow, item by item (section 6). While the pregnancy is being tracked, the period prediction is suspended, including in what the guardian sees.
- Workouts: while the pregnancy is being tracked, Workouts shows the pregnancy video categories. For this, the app only checks whether there is a pregnancy being tracked; no new data is stored, and the app does not send any of your data to YouTube. The video opens on YouTube, and what you watch there is subject to YouTube's rules.
- Partner in the pregnancy: if you accept a pregnant person's invite and she confirms, we keep the link (whose partner you are, since when and when it ended). You see, in the Pregnancy tab, her week of pregnancy, the expected month of birth, the week's content and the "How to support during pregnancy" video category, and only what she decides to allow.
Tharpa Walks: walking, running, cycling and hiking (optional):
- It only exists if you turn on Walks, using the Walks button, and authorize the use of your location. Authorizing is your consent for this module (section 3).
- Your phone's location (latitude and longitude, with the accuracy the device reports). It is read while the Walks screen is open, to show where you are before you start, and it is only STORED while you are recording an activity, from Start to Finish. In the Android app, recording continues with the screen off or with another app open: the phone shows a persistent notification while recording, and the route is sent to the server every 30 seconds, with a key that is valid only for that recording. Outside a recording, the app does not use your location with the screen off. With Walks turned off, the app does not use your location. Outside a recording, the location is read only once, when you tap "Update my area" in People nearby. In that case we keep only the approximate area, never the point.
- For each activity: the type, start and end, moving time, distance, pace, calories estimated from your weight, the title you give it, the route on the map, and the stretches where the GPS lost signal. For activities recorded by the watch, also the average and maximum heart rate. The activity is also added to your exercise log, without the location.
- Until the recording ends, the route is kept on your phone and, every minute, also on our server, so it is not lost if the app is closed or the phone's data is cleared midway. This copy is removed from the phone and from the server when the activity is saved or discarded.
- The medals you earn (for total kilometers and for consecutive weeks with activity), the privacy zone you choose and, if a watch also sends the same activity through Health Connect, which of the two records counts in your log.
- Segments (optional): if you mark a segment on one of your activities, we keep its name, the shape of the marked piece and, for each activity you save afterwards that goes through it, the time and the day of the pass. Only you see your segments and your times; no one else, not even in a ranking.
- Watch (optional): if you turn on the watch in the "Watch (Wear OS)" card on the Walks screen, activities recorded by the watch use the watch's own GPS. When you finish, the watch passes the activity to your phone, which sends it to our server; it is stored and shown like the activities recorded by the phone, under the same rules. The watch also measures heart rate during the activity. When you finish, the average and the maximum heart rate of that activity go with it to your phone and to our server; if you turn on "Store heart rate from watch activities" on the watch card (a separate consent, off by default), they are stored with the activity; when off, they are not stored. Only you see them: in the activity details and in your exercise diary. They do not appear in posts, groups, clubs, the wall, Status, rankings or to followers, and they are not sent to the artificial intelligence. They are deleted when you delete the activity, the Walks data or the account; turning the option off stops storing from then on, without deleting what is already stored. Activities recorded by the phone have no heart rate. For people under 18, the activity's heart rate is not stored. So that the watch can send activities, we store only a scrambled version (hash) of its key; the key stops working when you turn off the watch, turn off Walks, delete the Walks data or delete the account. People under 18 use the watch only with the guardian's authorization for Walks, as on the phone.
- Privacy zone: on by default, at 300 meters (you can set it from 200 to 500). We keep the full route, which only you can see, and a second version without the points near the start and the end. Only a cut version can reach another person: the primary guardian and the companion of a person under 18 (section 10) and, if you turn on "Post my activities with the route", the people who see your posts and, in the groups where you share the activity, their members — in that case the cut is at least 200 meters from the start and the end, even with the zone turned off.
- Nothing about the route goes to the AI. If you are under 18, the primary guardian who authorized Walks, and the companion they approved, see each of your activities: the date, the type, the distance, the time and the route without the start and the end (section 10). A guardian who has the Activity category enabled sees, as before, the day's minutes and calories.
- Share: the workout image is put together on your phone, with the route already without the privacy zone, without the time and without the file's location. Nothing is sent to our server. What you post on another network is subject to that network's rules.
- Walks photos (optional, paid plan): up to 3 per activity and 300 per account, with the caption you write (up to 140 characters). The photo is redrawn on your phone before it is sent, without the file data (EXIF), where the camera stores the location. The server rejects any photo that arrives with that data.
- Walks posts (optional): if you turn on "Post my activities with the route", every activity you save from then on becomes a post on your profile, with the cut route map (without at least 200 meters from the start and the end, or your privacy zone, if larger), the type, the title, the distance, the pace (or the speed), the duration, the day and the hour you started, and the photos you add to it. For each post we keep the already-cut route, whether the route or the post is hidden, its moderation status and when it was posted. An activity saved before you turn it on only becomes a post if you choose to post it, one by one, with "Post with the route"; each choice is recorded in the tamper-evident consent history. If you delete an activity's post, it is not posted again.
- Walks profile: your first name, the Walks profile photo (optional), the bio (optional, up to 150 characters), whether the profile is visible or private (private is the default), your Walks invite code, whether you turned on "Show up for people nearby" (off is the default), and the settings "Show up in name search" (on is the default), "Only I can see my followers and who I follow" (off is the default), who sees your stories ("All" or "Followers only") and whether people you follow who also follow you can tag you (on is the default).
- People nearby (optional): if you turn on "Show up for people nearby", we store an approximate area, the center of a square of about 2 km. It is NOT the point where you are. Your phone uses the GPS once, when you tap "Update my area", and calculates the square before sending it. The area does not change on its own and does not use the GPS from your workouts. We also store when you set it and how many searches and updates you made that day (the limit against anyone trying to sweep the search), and, for one day, which people were suggested to you at each distance (so the suggestions do not change every time you open Walks). Turning it off deletes the area and these suggestions immediately. If you turned on "Show up for people nearby", your approximate area also goes, together with other members', into the approximate distance of a public group, to suggest groups to people looking for one. Nobody sees your area or the group's: only a range ("within 10 km"), and only when the group has at least three members with the option on.
- Walks followers: who you follow, who follows you, follow requests (the ones you sent and the ones you received) and when each one was made and accepted. When you and another person follow each other, either of you can tag the other in photos.
- Walks likes and views: the photos and stories you liked and when, and the stories you viewed and when. Of your photos, you see how many likes they received and who liked them; of your stories, who viewed and who liked them — each person's first name and Walks profile photo. In the same way, whoever posted a photo or a story sees that you liked it, and whoever posted a story sees that you viewed it.
- Walks comments: the comments you write on photos and posts (the text, when, on which photo or post and who you replied to), each one's moderation status, and the photos and posts of yours where you turned comments off. Anyone who can see the photo or the post sees your comment along with your first name and Walks profile photo — even if your profile is private. On your photos and posts, you see the comments of the people who can see them and you can delete any of them.
- Walks stories (optional, paid plan): the photo you post as a story, without the file data (EXIF), with the date. Each story stays up for 24 hours and is then deleted from the server. If you turned on "Post my activities with the route" and check "Status" when saving an activity, a story with the post's cut map and the numbers also goes up, and each photo goes with the cut route line and the numbers on top. These stories follow who sees your stories and come down right away if you hide the route, hide or delete the post or turn the option off.
- Walks tags: in which photos you tagged which people (only people you follow who also follow you), and in which photos you were tagged, whether you approved it and when.
- Walks Chat (optional): the messages you exchange with people you follow who follow you back — the text, the photos you send (paid plan; redrawn on your phone before they are sent, without the file data, including the location) and the activities you share (only the type, the day and the activity's photo, if the person can see it; never the route, the time of day, the distance or the duration), with the date and when each one disappears; when you read each conversation; and when we sent the last new-message notice. Only you and the other person in the conversation see the messages. The messages are temporary (section 8).
- Walks training plans (optional): the name of the plan, the goals for each week (activity type, distance or time, and the day, if you choose one), how many weeks it lasts and when it started; and, in a plan with other people, who is in it, who invited whom and when each person joined. The week's progress is not stored: the app calculates it each time from the activities you recorded.
- Walks Groups (optional): the groups and clubs you create or join (name, photo, description, activity type, the city or region you write, whether it's public or closed, the group's goal and deadline, your role and when you joined or asked to join); how the group ended (goal reached or not, the result and the date) and the medal, if it reached the goal with you in it; the activities you choose to share in a group or club; the comments you write on wall activities (the text, when, on which activity and who you replied to) and each one's moderation status, and your wall activities where you turned comments off; the group chat messages (temporary); the challenges you take part in (when you joined and when you completed them); and the reports you make. Goal and challenge progress and the rankings aren't stored: the app works them out each time from the activities you recorded.
- Wall announcements. A group's admins — and, in clubs, whoever manages the club — can pin a short announcement (up to 500 characters, no links or photos) at the top of the wall. Members get a "New announcement in {group}" notification, without the text, at most once a day per group. Only group members see the announcement. An admin's announcement shows their first name; the Tharpa team's and the official club account's show as "Equipe Tharpa" (the Tharpa team). An announcement stays until it is replaced or removed, and is deleted with the group, 30 days after the group ends, or when its author leaves the group, deletes their Walks data or their account. Announcements you wrote are included in "Export my data".
- Comments turned off. A group's admins and the Tharpa team can turn off comments for the whole group. While off, nobody can comment and existing comments are hidden — not deleted — until they are turned back on. If the Tharpa team turned them off, only the team can turn them back on.
- Moderation. For moderation and safety, the Tharpa team may view the content of Walks groups and clubs, including the group chat, at any time. Every access is logged. The log (who accessed, when, which group and what was opened) is kept for 2 years and only the team sees it.
- Banning, muting and penalties. A group's admins can accept or decline join requests, ban a member (they cannot come back to that group until unbanned) and mute them in the group for 1 hour, 24 hours, 7 days or indefinitely. The Tharpa team can mute a person across the whole app and apply penalties — no joining groups and clubs and/or no commenting — for a set time or indefinitely. A muted or penalized person sees what they can't do and until when, never who reported them. These records are not removed by "Delete my Walks data"; they end when they expire or are lifted, or when the account is deleted.
- Report evidence. When someone reports content on Walks, we keep a copy of what was reported (the text and, if it is a photo, the photo) and minimal context — who posted it, when and where. The copy is kept even if the author deletes the content or the account, for 6 months after the report is decided, or longer while there is an open case or a request from an authority, until it ends. Only the Tharpa team can access it, every access is logged, and the copy may be handed to a competent authority. Legal basis: the regular exercise of rights and compliance with a legal obligation or an order from an authority (LGPD, art. 7, II and VI, and art. 16, I), and the Brazilian Internet Civil Framework (Law 12,965/2014) regarding court orders. The report is also sent to the Tharpa team's e-mail, with the username and registered e-mail of both the person who reported and the person reported, so the team can act and, if needed, respond to an authority.
- Who you blocked, the reports you made (what was reported, the reason and any detail you write) and reports about your photos, your posts, your comments or your profile (without telling you who reported), and reports of Chat conversations and messages, with the reported content (section 8).
- Who sees what: the full route of each activity, only you. The distance, duration and time of day are also yours only — follower or not —, except on posted activities, if you turn on "Post my activities with the route" (below), and in what you choose to show in a Walks group or challenge (below); and, if you are under 18, your primary guardian and the companion, as in section 10. The "Your progress" chart (distance and pace per week) is also yours only. In a training plan with other people, those in the plan who follow you and whom you follow see, only while you follow each other and are in the same plan, whether each goal of the week was met and the week's total distance in the plan's activity types — never the route, the map, the time of day, the place or the day of each activity. In a Walks group, members see your first name, your profile photo and, in the rankings, the total distance of the week in the group's activity type and how much you added to the group's goal; they see the activities you choose to share in the group, even with a private profile — the photo (once approved, when there is moderation), the type, the title, the distance, the pace and the duration and, if you turned on "Post my activities with the route", the same cut map as the post — and the messages you send in the group chat. Comments you write on a group or club wall show up to its members, with your first name and Walks profile photo, even if your profile is private; the person who shared the activity and the group admins can delete them, and the person who shared can turn comments off for that activity. In a challenge, other participants see your first name, profile photo, total distance and progress in the period. In groups and challenges, never the full route, the place, the day or the time of day of each activity. Any Walks adult sees the name, photo, description, city, goal, deadline, progress and member count of an active group — not who is in it —, and the keepsake of a group that reached its goal (the goal, the result and the date). Walks clubs (like the official Tharpa Health club) are communities with no goal or deadline, created and run by the Tharpa team: any adult on Walks sees a club's name, photo, description and how many people it has — not who is in it —; the members, wall, weekly ranking and club challenges are for club members only, under the same rules as groups. The official Tharpa Health club's challenges are the exception: any adult on Walks sees them and can join without joining the club; whoever joins appears in the challenge ranking to the other participants, as in the app's challenges. The medals of groups that reached their goal with you and the badges of challenges you completed appear on your profile to whoever can see your profile, under the same rule as photos. Whoever blocked you, or was blocked by you, sees nothing of yours in the group. In the Chat, only the two people in the conversation see the messages; if you stop following each other, the conversation becomes read-only, and if one blocks the other, it disappears for both. Who sees your photos is decided by your profile, not per activity. Private profile (the default): only the followers you approved see your photos, your stories, your bio and your lists. Visible profile (requires the public photos authorization): any adult on Walks can follow you without asking, and your followers and other adults on Walks see the photos, stories and bio. All of this may go through Tharpa Health's moderation before it appears; when there is prior moderation, people you follow back see it right away, and other followers and other adults on Walks see it after moderation approves it. Anyone can report, and three reports hide the content until it is reviewed; Tharpa Health may reject or remove whatever breaks the rules. Anyone who can see a photo or a post can comment on it, and comments follow the same rule: they appear to whoever sees the photo or the post, with the commenter's first name and Walks profile photo; the owner can delete any comment and turn comments off for each photo or post. With a visible profile, you can make your stories followers only. Along with the photo go the caption, your first name, your Walks profile photo, the activity type and the day. If you turn on "Post my activities with the route", every activity saved from then on, and each earlier activity you choose to post, becomes a post, which follows the same rule as photos (private profile: only the followers you approved; visible profile: Walks adults, with moderation when there is any; blocking and three reports hide it): it shows the cut map, the type, the title, the distance, the pace, the duration, the day and the hour, your first name, your Walks profile photo and the activity's photos. The post goes into the feed of people who follow you and into the Posts tab of your profile and, if you check "Status" when saving, into your status for 24 hours, under the stories rule. You can hide an activity's route (without a photo, the post disappears), hide or delete the post, and turn the option off, which removes all posts from others' view right away. The photo appears in the feed of those who follow you; with a visible profile, any adult on Walks can see it on your profile and, from time to time, as a suggestion in their feed. You can hide a photo (it is still yours, and only you see it) or delete it at any time. Any adult on Walks can find your profile through search, by your name (if you leave on the "Show up in name search" option, which starts on) or by your code (RUN-XXXX-XXXX), whether your profile is visible or private; people who do not follow a private profile see only the first name and the Walks profile photo (when there is prior moderation, after it is approved) and can ask to follow. If you turn on "Show up for people nearby", people who also turned it on may see you in the "People nearby" suggestions on the Walks home screen, without searching for your name, and people who use the "Near me" filter additionally see only a distance range, among the options from 5 to 2,000 km (5, 10, 20, 50, 100, 250, 500, 1,000 or 2,000 km), never the exact distance or your area (in the suggestions, the same range, your first name and your approved Walks profile photo; people you blocked or who blocked you do not see it, and people you already follow do not appear as suggestions). Who follows you and who you follow appear to those who can see your profile (with a private profile, only to your followers), unless you turn on "Only I can see my followers and who I follow". When someone you follow who also follows you tags you in a photo, your first name only appears on it for others after you approve, and you can remove the tag at any time.
- Photos you posted before October 2, 2026 on activities marked "only me" were hidden: they are still yours and only you see them, and you can unhide them whenever you want. Photos that were set to "friends" or "public" now follow your profile's rule.
Data from your device (optional):
- If you install the Tharpa app on Android and authorize it in Health Connect, it reads data from your phone such as steps, distance, calories, exercise, heart rate, sleep, VO2 max, body composition, skin temperature and sleep apnea or irregular rhythm alerts (whatever your watch or Samsung Health provides).
- Each phone reads only the data of the person using it. To connect, the app generates a single-use pairing code, valid for 15 minutes. We store the device name.
Notifications and usage:
- Your browser's or phone's notification subscription (a technical address and encryption keys), if you turn on notifications.
- The notices in your in-app notifications inbox.
- How many times each AI feature was used by the account and the estimated cost. The content of the questions is not included in this record.
- The history of acceptances, refusals, authorizations, declarations and age confirmations (see sections 8 and 9).
- Reports that an account may belong to a minor, with the note written by the person who reported it and the team's decision (section 10).
2. What we use it for
- Showing your history, calculating targets and tracking your progress.
- Generating analyses and suggestions with artificial intelligence (section 4).
- Sending reminders and notices you turned on, such as the water reminder and the birthday greeting.
- Sending service emails: confirmation code, password reset and requests for a guardian's authorization.
- Allowing another person to follow your daily summary, when you authorize it (section 6).
- Handling guardian authorization for people under 18 (section 10).
- Answering your suggestions and bug reports.
- Showing your menstrual cycle — the history, the charts and the estimates — if you turn on that module.
- Drawing the route of the activities you record in Walks (with the phone or the watch), counting time, distance and pace, showing you the heart rate measured by the watch, awarding medals and showing you your weekly progress; automatically checking off the goals of your training plan with the activities you record; and, in a plan with other people, showing those in it who follow each other with you the week's progress (goals met and total distance) and notifying the people you invite, if you turn on that module.
- Showing the photos you post on Walks to your followers or, with a visible profile and your authorization, to other adults on Walks; allowing you to follow, accept requests, find people by name or by code and, among those who turned on "Show up for people nearby", by proximity and through suggestions of people nearby; liking and commenting on photos and posts and notifying the owner of a new comment (without the comment's text); showing your bio, your lists of followers and of who you follow, and your stories to those who can see them; allowing you to tag in photos people you follow who also follow you, with the approval of the person tagged; deleting stories after 24 hours; moderating what goes to people who do not follow you and the profile photos that appear in search; receiving and handling reports; applying the blocks you make; if you turn on "Post my activities with the route", posting every saved activity on your profile, with the cut map, the numbers, the day and the hour, to the people who can see your profile; organizing the groups and challenges you take part in; working out the group goal, your challenge progress and the rankings on its own from the activities you record; closing the group at the deadline, turning it into a keepsake and giving out the medal when the goal is reached; showing in the group the activities you choose to share and, if you ask, putting the photo on your status; suggesting public groups near you (if People nearby is on); delivering group chat messages and letting you know a new one arrived; and moderating what is reported.
- Delivering Walks Chat messages between the two people in the conversation, notifying you of new messages and deleting messages when they expire.
- Showing the partner you name in the pregnancy the week of pregnancy, the expected month of birth, the week's content and what you allow; notifying them when you log a warning sign, if you allow it; and showing them and you the pregnancy video categories, if you ask for it.
- Proving, if necessary, that consent was given, and complying with the law.
The cycle estimates (next period, fertile window and phase) come from what you yourself recorded and may vary, especially when the cycle is irregular. They are not a contraceptive or family planning method, and the module does not diagnose anything: only a health professional can do that.
We do not sell your data and we do not use your health data for ads.
3. Legal bases
Health data is sensitive personal data under the Brazilian General Data Protection Law (LGPD). We process it with your consent, given in a specific and highlighted way on the acceptance screen. Without this acceptance, the app cannot be used.
Account data (email, password, plan) is processed to provide the service you requested. The consent history is kept to comply with the law and to defend rights if anything is challenged.
The free trial marker (section 8) is kept on the basis of legitimate interest, to prevent the same person from using the trial more than once. It does not store the email, only a code made from it.
For people under 18, consent is given by a parent or by the legal guardian (section 10).
The menstrual cycle module has its OWN consent, separate from the acceptance of this Policy. It is optional: until you turn the module on, no cycle data is stored. To turn it on, you read the module's text and mark that you authorize it; this acceptance is kept in the same tamper-evident history (section 9), with its own document and version. Turning the module off withdraws this consent. The legal basis is the same as for the other health data — specific and highlighted consent for sensitive personal data —, requested separately because this data is more intimate and the module is optional.
The sexual intercourse entry has an additional consent, separate even from the cycle module's consent: it exists only for people over 18, it is requested the first time you use the field, it is kept in the same tamper-evident history, and withdrawing this authorization makes the field disappear without affecting the rest of the module. What you have already recorded remains stored until you delete the cycle data.
Pregnancy tracking also has its OWN consent, requested when you mark that you are pregnant. It is kept in the same tamper-evident history (section 9). To withdraw this consent, use Delete my pregnancy data, on the Pregnancy screen: the data is removed immediately, and the request is recorded in that history.
Naming a partner in the pregnancy has its OWN consent (document gestacao_parceiro), separate from the pregnancy consent: it is the sharing of sensitive personal data with another person, and for that reason it is requested in a specific and highlighted way for each invite. It is kept in the same tamper-evident history (section 9). Undoing the link withdraws this consent, and this is recorded. Only people over 18 can name a partner. On the partner's side, the acceptance of the invite is also recorded in that history, and so is your confirmation. Each item you allow the partner to see (exact due date, the baby's sex, scheduled appointments and exams, bump photos, weight gain, blood pressure and warning signs) has its own consent (document gestacao_parceiro_itens), asked when you turn it on, with the item's name. Turning it on and off is kept in the tamper-evident history (section 9).
Walks also has its OWN consent for the use of location, requested the first time you open it. It is kept in the same tamper-evident history (section 9). Turning Walks off withdraws this consent: the app stops using your location, and what you have already recorded remains stored until you use Delete my Walks data, on the Walks screen.
For people under 18, Walks requires TWO authorizations: the primary guardian's (walks_menor_responsavel), which they give in Your account, and then the minor's own, in a text written for minors. Both are kept in the tamper-evident history (section 9). The guardian withdraws it in Your account › Minors in your care › Manage › Tharpa Walks: recording stops immediately, and what has already been recorded remains stored until it is deleted.
Walks visible profile: your own consent (run_fotos_publicas), recorded in the tamper-evident history. To withdraw it, turn it off in Walks › Profile › ☰ Settings and activity › Profile privacy, and the profile becomes private immediately. With a private profile, the photos that only your approved followers see are covered by the Walks consent (localizacao_run); you can remove anyone from your followers whenever you want (remove follower or block).
Walks posts with the route: your own consent (walks_trajeto_publico), optional, recorded in the tamper-evident history. To withdraw it, turn off "Post my activities with the route" in Walks › Profile › ☰ Settings and activity › Profile privacy: the posts leave others' view right away, and nothing is deleted.
Heart rate from watch activities: your own consent (walks_batimento_relogio), optional and off by default, recorded in the tamper-evident history. To withdraw it, turn off "Store heart rate from watch activities" on the "Watch (Wear OS)" card on the Walks screen: the app stops storing the heart rate of your next activities, and what was already stored is not deleted.
Walks People nearby: your own consent (walks_perto_de_mim), recorded in the tamper-evident history. To withdraw it, turn off "Show up for people nearby" in Walks › Profile › ☰ Settings and activity: your area is deleted immediately and you leave the "Near me" filter and the people nearby suggestions. If the "Show up in name search" option is on, you can still be found by name, without distance.
Name search on Walks: the legitimate interest of allowing adults who use Walks to find each other, with the limits in section 1 (only the first name and the profile photo of people with a private profile — when there is prior moderation, already approved —, 30 searches per day, never a minor), blocking, which removes you from the other person's search, and the "Show up in name search" option: turning it off in Walks › Profile › ☰ Settings and activity › Profile privacy removes you from name search immediately (your code still finds you).
Walks tags: your approval of each tag. Without it, the photo does not appear among your tagged photos and your name does not appear on the photo for others. You can remove the tag at any time.
Walks Chat: the performance of the service you request when you send a message (LGPD, art. 7, V). Keeping reported content until the decision: the legitimate interest of keeping Walks safe and of responding to the report (art. 7, IX). Walks training plans: the performance of the service you requested when you created or joined a plan; your week's progress is shown to other people only if you join a plan with them (accepting the invite or inviting), and you can leave the plan whenever you want.
Walks Groups: performing the service you asked for when creating or joining a group or challenge, and when sharing an activity in a group (art. 7, V). Suggesting nearby groups relies on your "Show up for people nearby" consent (art. 7, I), which you withdraw by turning the option off. Keeping reported content until the decision, and keeping a group hidden after a report for up to 30 days for review: the legitimate interest of keeping a safe space and complying with the law (art. 7, IX and II).
Moderation, reports and blocks: the legitimate interest of keeping the app safe for its users, and compliance with app store rules for user-generated content.
4. Artificial intelligence
The analyses of meal photos, body photos and measurements, the chat, the tips about symptoms, the estimate of food you type in and the reading of the check-in are done by artificial intelligence, on Google Gemini.
We use Google Gemini at two tiers. We try the free tier first: on it, Google may use what we send (the photo or the text of the request and the profile data below) to improve its products, and Google staff may review this content. Only when the free tier does not respond does the same request go to the paid tier, on which Google does not use the content to improve its products. Accounts of people under 18 always use the paid tier. During pregnancy, whatever carries pregnancy data to the AI (the week, the trimester and the number of babies, and the bump photos) also always goes to the paid tier.
We send the AI what is needed for each answer: the photo or the text of the request and profile data that tailor the answer, such as age, biological sex, height and weight, activity level, gender identity and, for adults who are not pregnant, the goal and whether they are on the medication recorded in Treatment.
- Body photo: the top of the photo, where the head is, is cropped on your own device before it is sent. You check and adjust the crop. The head does not leave the phone and is not stored. Even so, the photo is still personal data: tattoos, scars and body shape can identify someone.
- Plate photo: if the AI answers right away, the image is not stored on the server. If the AI is busy, the photo waits in a queue on the server and the image is deleted as soon as the analysis is ready or, if the AI cannot analyze it, when the app gives up trying. The result of the analysis (the foods recognized and the numbers) stays for 24 hours in the list of recent analyses, so you can check, correct or redo it. After that it is deleted, and what you saved remains in your log.
- Chat: conversations are not stored on the server.
- Menstrual cycle: nothing you record in the cycle module goes to the AI. The estimates are calendar calculations done on our server, from your own history.
- Pregnancy: if you turn on "AI comments during pregnancy" (a separate consent you can turn off whenever you want), when analyzing a meal photo or redoing its comment, the AI receives only that you are pregnant, the week, the trimester and the number of babies, so the comment suits the pregnancy (no weight-loss diet and no mention of medicines). If you ask for the comment on your bump's growth, the AI receives the bump photo and the previous one, cropped at the top like body photos, and only that you are pregnant, the week and the number of babies; it comments only on the growth between the photos, with no diagnosis, no body fat % and no estimate about the baby. Nothing else from the pregnancy goes to the AI: not the dates of your period or due date, appointments, exams, reports, symptoms, your pre-pregnancy weight or your name. While the pregnancy is being tracked, the AI also stops receiving your profile goal and whether you are on medication, and the chat answers as a general nutrition and wellbeing assistant (with no weight-loss goals). What carries pregnancy data to the AI always goes to Gemini's paid tier; other requests follow the same rule as for all adults. The week and the due date are still calendar calculations done on our server.
- Walks: no location or route goes to the AI. Distance, time, pace and calories are calculations done on our server.
- The AI's answers are estimates and suggestions. They do not replace a doctor, a nutritionist or another health professional.
5. Who we share it with
Only with the service providers needed for the app to work. Each one receives only what it needs for its part:
- Hosting and network: the service that hosts the app and the server, and through which all connections pass.
- Database: where the account, the entries and the body photos are stored.
- Storage of Walks photos: Cloudflare (R2 service), which stores the images (also the Chat photos). They are delivered only to those who can see them, through our server.
- Partner in the pregnancy: only the person you name, who accepts the invite and whom you confirm: the week of pregnancy, the expected month of birth and only the items you allow (section 6).
- Other people on Walks: only what you post, under the conditions in section 1. Any adult on Walks who searches for your name (if you do not turn off "Show up in name search") or your code sees your first name and your Walks profile photo (when there is prior moderation, after it is approved). If you turn on "Show up for people nearby", people who also turned it on also see, in the "Near me" filter and in the people nearby suggestions, the distance range. Those who can see your profile also see your bio, your stories and, if you do not turn on "Only I can see", who follows you and who you follow. People you tag in a photo see that photo. Whoever posted a photo you liked, or a story you liked or viewed, sees your first name and your Walks profile photo in the list of who liked or who viewed it. In the Chat, the person you are talking to receives the messages you send them, and only them. In a training plan, the people in the plan who follow you and whom you follow see whether each goal of the week was met and the week's total distance.
- Other Walks people: in the group, in challenges and on your profile (medals and badges), what is in section 1 ("Who sees what"). Challenge sponsors: some app challenges or official Tharpa Health club challenges may have a sponsor, identified on screen ("Sponsored by…"). The sponsor receives no data of yours — not your name, not whether you take part, not your progress. The sponsor's link opens outside the app, and what happens on their site follows their policy.
- Artificial intelligence: Google Gemini, which generates the AI analyses and answers. On the free tier, which we try first, Google may use the content sent to improve its products (section 4).
- Email: the service that sends the app's emails. For suggestion or bug report messages, it carries your email and your public ID to our inbox.
- Your browser's or phone's notification service (for example Google, Mozilla, Apple or Samsung): it delivers the notifications. The text is encrypted, and this service cannot read it.
The app also fetches the news posted on the Tharpa Group website for the notifications inbox. This fetch does not send any of your data.
Data from Samsung Health and Health Connect comes from your phone to us. We do not send your data to Samsung or Google through this path.
We may have to hand over data to authorities when required by law or by a court order.
6. Sharing you decide on
In Your account, in the Other people section, you can generate a tracking code. It is valid for 15 minutes and can be used only once. Whoever enters the code starts seeing your daily summary: steps and activity, water, calories and protein, and weight.
Besides the summary, you can enable two more things for each person who follows you. Both start off, and you turn them on or off whenever you want, in Other people, in the Who sees your summary block:
- Today's meals (list): name, calories and time of each meal, without photos. The person can see previous days, up to 90 days back.
- Sleep: hours slept last night, bedtime and wake-up time, and the 7-night average. It comes from the watch or the phone, through Health Connect.
People who follow you by code never see photos, symptoms, check-ins, vital signs, menstrual cycle or conversations with the AI. Accounts of people under 18 do not enable meals or sleep by code: sharing by a minor, when the guardian allows it, is only the daily summary.
Shared vial: if you share your tirzepatide vial with another Tharpa Health account, by code or through your connection, and the other person accepts, each of you sees the date and dose of the other's injections from that vial, and the stock starts counting both people's injections. Nothing else about anyone's health is shared because of this. Either of you can end the sharing whenever you want, and the acceptance is kept in the consent history.
Partner in the pregnancy: if you are over 18 and your pregnancy is being tracked, you can invite another adult Tharpa Health account, on the Pregnancy screen, under Partner. The invite is a single-use code valid for 48 hours. When the person accepts, you see who it is and confirm or decline; only after your confirmation do they get the Pregnancy tab, with your week of pregnancy, the expected month of birth and the week's content, and the videos on how to support during pregnancy in Workouts. In Pregnancy › Partner › What {name} sees, you can allow, one by one, and all start turned off: the exact due date; the baby's sex (only girl or boy); scheduled appointments and exams (date and type, never notes, results or reports); the bump photos (only new ones, or also the ones you already took); weight gain during pregnancy and the range (never your weight); blood pressure; and the warning signs you log, with a notification to them. Once turned off, they stop seeing it right away. They never see the date of your last period, the cycle, the symptoms, the reports, the notes, the AI comments or any other data of yours. You see who the partner is and since when. There is one partner per pregnancy. You can undo the link whenever you want; the partner can also leave (and you are notified). The link ends on its own if you end or turn off the tracking, delete the pregnancy data or the account, or if the partner deletes their account. A link cannot be created between accounts that have blocked each other on Walks, and a block after the acceptance ends the link. Your consent, the partner's acceptance, your confirmation and each end of the link are kept in the tamper-evident history (section 9).
- The two accounts see each other's chosen name in the app and email, in the list of connections.
- You can also share back with the person you follow. This is a separate authorization.
- You can disconnect or stop sharing whenever you want, with no extra step.
- Each authorization and each disconnection is recorded in the tamper-evident history (section 9).
- Each category enabled and each category turned off is recorded in the tamper-evident history (section 9).
7. Where the data is kept
The database is on servers in the United States. The app and the server run on a network that serves from several countries. The AI and email services may also process data outside Brazil. You can request the list with the name of each provider at [email protected].
That is why there is an international transfer of data. It happens only to provide the service, with the providers listed in section 5.
Walks photos are kept in Cloudflare storage (R2), which may also store data outside Brazil.
8. How long we keep it
In general, for as long as your account exists. There are specific rules:
- Body photos: the 60 most recent are kept. Older ones are deleted automatically. The written analyses remain.
- Plate photo: it is not stored on the server after the analysis (section 4). The result of the analysis stays for 24 hours in the list of recent analyses and is then deleted.
- Chat with the AI: it is not stored.
- Analysis that combines photo and measurements: only the most recent one is kept.
- Notices: they appear in the inbox for 24 hours. After that, or if you close a notice, it disappears from the screen, but it remains stored so the same notice does not arrive again. It is deleted with the account.
- Temporary codes: email confirmation, device pairing and tracking codes are valid for 15 minutes. The new password link is valid for 1 hour.
- App session: up to 30 days without needing to sign in again.
- Consent and sharing history: it is kept with no time limit, even after the account is deleted, because it is the proof that each authorization was given. It keeps only internal codes, the document version, the action and the date. It does not keep your email or your health data.
- The adolescent's agreements and the categories enabled for sharing: they are kept in the consent history, with no time limit, like the other authorizations. The history keeps only internal codes, the category, the version of the text, the action and the date.
- Reports that an account may belong to a minor: kept while the reported account exists. If the person who reported deletes their own account, the report loses its link to that account.
- Menstrual cycle: the marked days and the daily entries are kept while the account exists. Turning the module off does not delete anything — it only leaves the screens and stops accepting entries, and you can turn it on again later.
- Deleting the cycle data: in Privacy and your data, the Delete my cycle data button deletes all days and all entries immediately, permanently, even with the module turned off. The consent history keeps only the line proving that the request was carried out, with the number of days and entries deleted — never a date, a symptom or a note.
- Walks photos: until you delete the photo, the activity, the Walks data or the account. If the paid plan ends, the photos remain; you just cannot post new ones. If rejected by moderation, the photo remains yours (only you see it) until you delete it.
- Walks posts: until you delete the post, the activity, the Walks data or the account. Turning the option off only removes them from others' view.
- Reports: while the reported account exists. The ones you made remain after you delete your account, without any link to you, because they are the moderation history about another person.
- Blocks: until you unblock, or until one of the accounts is deleted.
- The People nearby area: while the option is on. Turning it off, deleting the Walks data or deleting the account deletes it immediately. The day's search count and the day's suggestions are deleted the next day.
- Walks followers, requests and likes: until you unfollow, remove the follower, decline the request, unlike, block, delete the Walks data or the account. A deleted photo takes its likes with it. A story's likes and views disappear along with it, after 24 hours or when it is deleted.
- Walks comments: until you delete the comment, the owner of the photo or post deletes it, the photo or post is deleted, or until you delete the Walks data or the account (then the ones you wrote and the ones on your photos and posts go). A block deletes one person's comments on the other's photos and posts, except a comment with an open report, which is kept — hidden from everyone — until moderation decides. A comment removed by moderation is kept, visible only to whoever wrote it, until it is deleted in one of these ways.
- Walks stories: 24 hours. After that, the story leaves the screen immediately and is deleted from the server and from storage in the next cleanup (twice a day). You can delete it earlier. Reports about a story are removed along with it.
- Walks bio: until you change it, delete it, delete the Walks data or the account.
- Walks tags: until you (or the person who posted) remove the tag, as long as the photo exists and neither account blocks the other or deletes its Walks data.
- Walks Chat messages: temporary. Text and shared activities disappear 30 days after they are sent; photos, after 7 days. After that, the message leaves the screen immediately and is deleted from the server and from storage in the next cleanup (twice a day). You can delete a message of yours earlier: it disappears for both people and shows "Message deleted". A conversation with no messages for 30 days is deleted.
- Content reported in the Chat: the reported message (or the last 20 messages, when the conversation is reported), with its photos, is kept until moderation decides — even if it has already expired or been deleted. Once the report is decided, the content is deleted and only the record remains (the reason, the dates and the decision), like other reports.
- Walks training plans: while you are in the plan. Leaving the plan, deleting the Walks data or the account removes you from it immediately; an invite you decline or that is withdrawn is removed immediately. If you created the plan and leave, it continues for the people in it (with the name and goals you wrote) and passes to whoever joined first; with no one else, the plan is deleted. A block removes you from the plan created by the other person (and them from yours).
- Walks Groups: while you're in the group or challenge. Leaving removes you right away (and the activities you shared on that group's wall). Wall comments stay while the activity is on the wall: they go when it goes (you remove it, delete the activity or leave the group), when you delete the comment, and with the wall, 30 days after the group ends. A reported comment is kept until the team decides; after that only the record of the report remains. Clubs don't end: what you share on a club wall stays until you remove it or leave the club. When the group ends — goal reached or deadline passed —, it stays as a keepsake (the goal, the result, the date and, if reached, the medal) for its members, and the chat and the wall are deleted 30 days later (there's time to save the photos; you're notified). Chat messages already disappear on their own before that: text in 30 days and photos in 7 days. A group hidden after an upheld report is kept for up to 30 days for review and then deleted. A reported message is kept until the team decides and then its content is deleted (only the report record stays: reason, date and decision). The date you completed a challenge (the badge) and a group's medal stay while you're in the challenge or the group. If you created a group and leave, it carries on for its members and passes to someone else; with no one left, the group is deleted.
- The time of each pass through a Walks segment is kept for 90 days; after that, only your best time on each segment, for as long as the segment exists.
- Partner in the pregnancy: the link remains while the pregnancy is being tracked and both accounts exist. After it ends, the record of who the partner was and the dates remains until you delete the pregnancy data or the account. The record of what you allowed and turned off stays with the link's record. Logged warning signs are removed when you delete them, turn off the warning signs or the link ends. The invite code is valid for 48 hours and can be used once.
- Free trial: the start and end dates are kept while the account exists. So that the trial is once per person, we keep a marker of the email in coded form (a hash, without "+alias" and, for Gmail, without dots). When you delete the account, it loses its link to the account and is deleted 2 years after the trial ended.
- Code for the app's change of address: 2 minutes, single use. Only the code's hash is kept on the server.
When you delete your account, the app immediately and permanently deletes your registration and your entries: meals, water, weight, measurements and vital signs, symptoms, check-ins, steps and exercise, the menstrual cycle days and entries, treatment and stock, body photos and analyses, photos that were still waiting for analysis, the analysis that combines photo and measurements, paired devices, notification subscriptions, notices, codes, sharing connections, and the Walks photos, profile and blocks, followers and who you follow, requests, likes, comments (the ones you wrote and the ones on your photos and posts), bio, stories, tags, posts and training plans, your participation in groups and challenges (your activities leave the walls and the medals go; the groups you led pass to someone else or, with no one left, are deleted), the messages you sent in the Chat and in the Walks group chats (on the other side it shows "Message deleted") and their photos, and the pregnancy partner link (if you were the partner, the link ends, what was allowed is turned off and the warning signs are removed; the pregnant person still sees only that there was a partner and the dates). The AI usage count continues to exist only as a statistic, with no link to you. If you were a minor's guardian, the authorization ends and your email is removed from its record.
9. Security
- All connections use HTTPS.
- Passwords stored only as a hash: PBKDF2-SHA256, with salt and 100,000 iterations (very old accounts may keep the previous format, bcrypt, until the password is changed). Device tokens and pairing and tracking codes are also stored only as a hash.
- The face is removed from body photos before they are sent (section 4).
- Notifications encrypted end to end up to your device.
- Sensitive actions, such as requesting or giving a guardian's authorization, require a confirmed email.
- The administration area is restricted. The server checks who can do each thing. It shows registration data and usage counts, not the content of your health entries. In the age check, it shows only which criterion triggered the confirmation (height or weight), without the values.
- The consent history only receives new records; it is never edited. Each record carries a code (hash) linked to the previous one, so any change to the past is detectable.
No system is infallible. If there is a security incident that may bring you relevant risk or harm, we will notify you and the ANPD (Brazilian National Data Protection Authority), as the law requires.
10. People under 18
There is no minimum age. People under 18 can only use Tharpa Health with the authorization of a parent or legal guardian. Consent to process the minor's health data is given by that guardian. The age is calculated from the date of birth entered at sign-up.
How the authorization works:
- The minor confirms their own email and enters the guardian's email. Until there is an authorization, the account stays paused.
- The guardian receives an email and an in-app notice. They must have a Tharpa Health account, with a confirmed email, and be over 18.
- In Your account, in the Minors in your care section, the guardian approves or declines. To approve, they check the declaration: “I declare that I am the legal guardian of this person and I authorize the use of Tharpa Health and the processing of their health data.”
- When approving, the guardian confirms or corrects the minor's date of birth, and the guardian's date becomes the valid one. They also set the biological sex used for the targets and, if they wish, the minor's gender identity.
- If the date entered by the guardian is 18 or older, there is nothing to approve: the request is closed, both sides are notified, and the person continues as an adult, accepting this Policy on their own.
- With the account paused, the minor can still request the authorization again, see the profile, export the data, send a suggestion and delete the account. Nothing is deleted while waiting.
- Each request, approval, refusal, change and closure is kept in the tamper-evident history.
What the guardian sees and does:
- They see only the categories they choose. These start on: Activity, Hydration, Food (totals) and Weight. These start off: Today's meals (list, without images), Sleep, Symptoms, Daily check-in, Vital signs and Menstrual cycle.
- They never see body photos, body analyses, conversations with the AI or medication entries.
- They can only read. They do not edit or delete the minor's entries.
- They can change the categories, allow or not allow the minor to share data with other people, and withdraw the authorization. If they withdraw it, the minor's account becomes paused again, without deleting anything.
- The minor sees who follows the account and what that person sees at that moment, the requests waiting for an answer and what they agreed to share. Both sides identify each other by the name chosen to be called in the app, by email and by public ID. Only the guardian can undo the link.
What Sleep, Symptoms, Daily check-in, Vital signs and Menstrual cycle show:
- Sleep: hours slept last night, bedtime and wake-up time, and the 7-night average.
- Symptoms: the symptoms recorded that day, with the time and the intensity (when entered). It does not show notes. A handwritten symptom appears only as “Other symptom”.
- Daily check-in: the day's mood, energy and hunger, on the app's scale. It does not show notes.
- Vital signs: the day's latest reading of blood pressure, heart rate, oxygen saturation, glucose and skin temperature. It does not show body composition (fat, muscle mass, body water).
- Menstrual cycle: three things, and nothing else — whether they are menstruating today, the prediction of the next period and that day's cramps. Never libido, discharge, mood, energy, sleep, skin and hair, PMS or the free-text note: the note belongs only to the person who wrote it, and it does not appear to the guardian or the companion at any age.
Symptoms, check-ins, vital signs and menstrual cycle follow the minor's age, calculated from the date of birth confirmed by the guardian:
- Up to age 11, the primary guardian can turn these categories on.
- From 12 to 17, turning one of them on is a request. It only appears if the adolescent agrees in the app, in Your account. They read the text and tap I agree or I don't agree. They can undo it whenever they want, without explaining. If they decline or undo it, the category is turned off, the guardian is notified, and to see it again the guardian must ask again.
- When the child turns 12, these categories are suspended until they agree. The guardian and the adolescent are notified.
- Each request, agreement, refusal, undoing and suspension is kept in the tamper-evident history, with the version of the agreement text.
How age is checked:
- At sign-up, the date of birth is requested without saying what it changes. The explanation about the authorization appears after the account is created.
- If an account with an adult's date saves a height below 1.40 m or a weight below 30 kg, the app asks only for a confirmation of the date. Nothing is blocked or paused, and the same question is not repeated for the same measurements. Through this path, the date can only be corrected to a younger age. The answer is kept in the history, without the measurements, and the team can check which accounts confirmed.
- An adult with a confirmed email can report, in Minors in your care, that the account with a given public ID belongs to their son or daughter, with an optional note. The report does not pause the account: the team reviews it. If confirmed, the team corrects the date (the account then needs authorization, and the request goes to the email of the person who reported); if not, it is discarded. The answer to the person who reported is always the same and reveals nothing about the other account. Each decision is recorded.
- To use tirzepatide tracking, the person declares: “I declare that I am 18 or older and that I use tirzepatide with a prescription from a health professional.” The declaration has a version and is kept in the history. People who were already recording the treatment still see their own data and declare once before recording anything new.
Second guardian (companion):
- Another adult, with a confirmed email, can ask to follow the minor in Your account, with the Follow a minor by ID option, using the minor's public ID.
- The request goes to the primary guardian, who approves or declines. There is at most one companion per minor.
- The companion sees the same as what the primary guardian chose, read-only, including the age rule: what is waiting for the adolescent's agreement does not appear to them either.
- The primary guardian can remove the companion, and the companion can leave at any time. If the primary authorization ends, the companion's access ends with it.
Specific rules for minors:
- Tirzepatide treatment is not available. The treatment screens disappear and the profile does not allow marking its use.
- There are no body photos or body analysis. Photos sent before the rule do not appear on screen, but remain in the export and can be deleted.
- The AI adapts its suggestions to age: weight is assessed by BMI-for-age and sex (WHO curves), a change in diet is only suggested if this criterion indicates overweight or obesity, and always with a recommendation to see a professional.
- Sharing data with other people only if the guardian allows it.
- The minor cannot change their date of birth in the app. After approval, only the primary guardian corrects the date, stating the reason, and the minor is notified. If there is a mistake, the minor can ask the guardian or use Suggestion or bug? Tell me.
- Minors do not purchase the paid plan in the app: the subscriber is the primary guardian, from their own account. When there are ads, minors will not see personalized ads, and people under 13 will not see any ads.
- Pregnancy: a pregnant person under 18 sees the pregnancy video categories in Workouts, but does not name a partner, and a person under 18 cannot be anyone's pregnancy partner.
- Tharpa Walks: the minor asks the guardian on the Walks screen, and the primary guardian authorizes or declines in Your account, reading and checking the authorization text. Only then does the minor turn on Walks, with their own acceptance. The minor uses only recording (recording with the phone or the watch, history, medals and progress). The primary guardian and the companion see each activity (date, type, distance, time and the route without the start and the end, because of the privacy zone); only the primary guardian authorizes or withdraws. If the guardian withdraws the authorization, recording stops immediately and what has already been recorded stays stored until the minor deletes it (in Delete my Walks data) or the account is deleted. At 18 the authorization ends together with the link, and the person accepts Walks on their own. Segments are not available to anyone under 18.
- Photos, stories, posts, feed, Walks profile, bio, followers, follower lists, search, tags, follow requests, likes, comments, reports, blocks, the Chat and training plans with other people are not available to people under 18. The app does not show other people's photos or profiles to minors, no one finds a minor through search (by name, by code or in Near me) or sees them in the people nearby suggestions, no one chats with a minor on Walks, no one tags a minor in a photo, and the server rejects the request.
- People under 18 don't use Walks Groups or clubs: they don't create or join groups or clubs, don't take part in challenges or group chats, don't share activities in groups, don't comment on or see wall comments, don't earn medals and don't appear to anyone in them. They also don't see sponsored challenges or any sponsor content.
At 18, the link ends on its own and the guardians are notified. The person starts deciding on their own and must accept this Policy again. If the guardian's account is deleted, the authorization ends and the minor must request a new one.
11. Notifications and notices
- Notifications on your phone or in your browser, only if you allow them: water reminder, birthday greeting (with the name you chose and your age, never the date of birth), notices about guardian authorization, new message in the Walks Chat (with the conversation closed, "New message from" and the first name, without the content, at most one every 5 minutes per conversation) and, if you turn it on on the Pregnancy screen, one tip a day about your week of pregnancy, at the time you choose. This notification shows only "Your tip of the day is here", without the word pregnancy, because it may appear on the lock screen; the tip itself stays in the app.
- On Walks and in your plan: a group chat sends a "New message in {group name}" notice, without the content, at most once every few minutes; a new comment on a photo or post of yours sends "New comment from" and the first name, without the text, at most one per photo or post every 5 minutes. The inbox (and the notification, if you allow it) also lets you know when a group's deadline is extended, when the group reaches its goal or ends without it (and that the chat and the wall will be deleted in 30 days), when a report is decided and, in the free trial, when less than 2 days remain and when it ends.
- In-app notifications inbox: analysis ready, the AI's reading of the check-in, messages from the app team, health news published on the Tharpa Group website and the pregnancy tip of the day.
- Partner in the pregnancy: if the pregnant person allows the warning signs and logs one, the partner gets a notification: "{name} logged a warning sign: seek care together with her". It may appear on their phone's lock screen. Which sign it was, they only see inside the app.
- You can turn off the water reminder in Your account and block notifications in your phone's or browser's settings.
12. Cookies and storage on your device
The app itself does not use cookies or tracking or analytics tools. It stores on your own device only what it needs to work:
- Your session, so you do not need to sign in every time.
- The chosen theme (light or dark), the weigh-in reminder interval and the last supplement used.
- Whether you have already dismissed some welcome messages.
- The version of the Android app, while in use.
- A photo not yet analyzed (already cropped, in the case of the body), for up to 24 hours, so it is not lost if the app closes.
- The photo of each plate analysis, for up to 24 hours, so you can redo the analysis. It only leaves the device again if you ask to redo it.
- Where to open the app when you tap a notification.
- Whether you closed the free trial notice.
- When the app moves to its new address, the preferences above are carried once from the old address to the new one, together with your session, through a code valid for 2 minutes.
When you log out, the session is deleted from the device.
Google ads (free plan, from age 13). When the app shows ads, Google AdSense may use cookies and device identifiers to show, cap and measure ads. Google's script is only loaded on the screens that may have the ad banner, and never for people under 13; today it is also not loaded on the paid plan or during the free trial. For teenagers, and for adults who have not chosen personalized ads, the request is marked as non-personalized. Google's cookies follow Google's privacy policy. You can change your choice in Your account › Cookies and ads.
13. Ads and payments
The paid plan is charged through Mercado Pago, and the app does not receive or store your card details. The 7-day free trial does not ask for a card and charges nothing.
The free plan may show Google AdSense ads, in a banner fixed at the bottom of some screens, above the button bar:
- Before the first ad, adults choose between personalized and non-personalized ads, in a separate consent (Your account › Cookies and ads). Until they choose, non-personalized ads apply.
- People under 13 see no ads. From 13 to 17, only non-personalized, age-appropriate ads.
- There are no ads on the pregnancy, cycle, body, treatment, AI chat, camera and consent screens.
- Your health data is never used to choose ads, and Tharpa Health does not send Google your health data, photos, measurements or meals.
- Today, the paid plan and the free trial show no ads.
14. Your rights
You can access, correct, export and delete your data, and withdraw consent. Most of this can be done in the app itself, in Your account. The document “Your rights and the LGPD” explains each right and where to exercise it.
15. Changes to this Policy
This Policy is in effect from September 15, 2026. It will be reviewed by a lawyer. If anything relevant changes, the app asks for your acceptance again before continuing.
Each version has a date. When there is a relevant change, the app shows the new version and asks for your acceptance before continuing. If you do not accept, you can delete the account from the acceptance screen itself.
16. Who we are and contact
Tharpa Health is a health tracking app. The data controller is Tharpa Group, a sole proprietorship (empresário individual), CNPJ 50.150.833/0001-07.
Contact and data requests: [email protected]. The Data Protection Officer (DPO) answers at the same email.
Your rights and the LGPD
The Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018) guarantees that you control your personal data. Here is each right, in plain words, and where to exercise it in Tharpa Health.
1. Your rights and where to exercise them
The paths below are in Your account, unless stated otherwise.
- Knowing whether we process your data: yes, we process the data you enter. The Privacy Policy lists all of it.
- Accessing your data: everything you have entered appears on the app's screens. To get a complete copy, tap Export my data.
- Correcting data: use Edit profile (weight, goal weight, goal). Entries such as meals, water and symptoms can be corrected or deleted on the screen where they appear. The date of birth of a person under 18 is corrected by the primary guardian. Whatever cannot be corrected in the app, request it in Suggestion or bug? Tell me or by email.
- Portability: Export my data generates a formatted report (HTML) with all your entries, organized by type and with dates, which opens in the browser and can be printed or saved as a PDF, for you to keep or take to another service. The images of the body photos are not included in the file because of their size, but the file says how many there are. They remain in the app, in Body, in the Timeline. If you need the data in another format, request it by email.
- The pregnancy partner is included in Export my data: the pregnant person sees who the partner is (or was), since when, what she allowed and when, and the logged warning signs; the partner sees whose partner they are (or were) and since when. The pregnancy data is not included in the partner's copy.
- The menstrual cycle is included in Export my data: the marked days, with the flow, and each day's entries, including your notes. They are included in the copy even if the module is turned off, because they remain stored until you delete them. This is sensitive data: keep the file carefully.
- Deletion: Delete my account deletes your registration and your entries, immediately and permanently. A body photo can be deleted on its own in Body, in the Timeline. The menstrual cycle data can also be deleted on its own, without deleting the account, in Privacy and your data, in Menstrual cycle, with the Delete my cycle data button. The pregnancy data, including the bump photos, can be deleted on its own on the Pregnancy screen, with the Delete my pregnancy data button. The Tharpa Walks data can be deleted on its own on the Walks screen, with the Delete my Walks data button, and each activity can be deleted on its own. The pregnancy partner link can be undone at any time, by the pregnant person (Pregnancy › Partner) or by the partner (Pregnancy › Stop following). Each item allowed to the partner can be turned off in Pregnancy › Partner › What {name} sees, and each logged warning sign can be deleted there.
- Walks photos are included in Export my data (with the image, the caption, whether it is hidden, its moderation status and how many likes it received), along with who you follow, who follows you, follow requests, the likes you gave (on photos and stories, and the stories you viewed) and the comments you wrote (with the text, on which photo or post and whose; of the comments on your photos and posts, only how many there are — the text belongs to whoever wrote it). Each posted activity comes in the copy with the post's status (hidden or not, route hidden or not, moderation and date), without coordinates. The copy also includes the groups and challenges you take part in (with the goal, the deadline, how the group ended and the medal), the activities you shared on walls and the messages you sent in groups that haven't disappeared yet. Each photo can be deleted on its own in Walks › Profile, and Delete my Walks data also deletes the photos, the posts, the profile, the blocks, the followers and who you follow, the requests, the likes and the comments (yours and the ones on your photos and posts), removes you from every group and challenge, deletes your messages and medals and takes your activities off the walls. If you turned on "Show up for people nearby", the copy includes the stored area (the center of the square), the date and each time you turned the option on or off. Delete my Walks data also deletes the area. The copy also includes the bio, your Walks settings, the stories currently up (the date and the status; the image is in the app while the story is up) and the tags you made and the ones you were tagged in. The copy includes your Walks segments (the name, the shape without coordinates, the best time and the stored passes). Each segment can be deleted on its own; passes also go when you delete the activity they came from; and everything goes with Delete my Walks data and with your account.
- The copy includes your Walks Chat conversations (with whom) and the messages you sent that have not yet expired; of the photos, only that they were sent (the images are temporary and are in the app). The other person's messages are not included: they are that person's data. The copy also includes your training plans.
- Knowing who we share with: the Policy lists the providers. In Other people you see who follows your summary and what each person sees. Minors see, in their own account, who the guardian is, what the guardian sees and the requests waiting for an answer.
- Knowing what happens if you do not consent: without consent, the app cannot process your health data and cannot be used. The acceptance screen offers Decline and delete my account.
- Withdrawing consent: see section 2.
- Anonymization, blocking or deletion of unnecessary data or data processed in breach of the law: request it by email.
- Objection to processing you consider irregular: request it by email.
- Review of automated decisions: the AI's analyses are suggestions and do not decide anything about you. If you want an analysis to be reviewed by a person, request it by email.
2. Consent: how to give it and how to withdraw it
The first time you use the app, and whenever the Policy changes in a relevant way, the Your privacy screen appears. You mark that you have read and agree, and tap Accept and continue. The acceptance is recorded with the version and the date, in a history that cannot be changed without the change being visible.
You can withdraw each authorization whenever you want:
- Consent to the Policy: in Your account, in the Privacy and your data section, tap Withdraw consent and confirm. If you prefer, request it by email. For people under 18, the guardian is the one who withdraws it (section 4). The withdrawal is recorded in the history. Without consent, the app goes back to the acceptance screen and does not go further; you can accept again or delete the account. Withdrawing consent does not by itself delete what has already been recorded: for that, use Delete my account.
- Sharing with another person: in Other people, disconnect or stop sharing. Today's meals and Sleep can be turned off for each person, in the Who sees your summary block.
- Consent to the menstrual cycle module: in Your account, in the Privacy and your data section, open Menstrual cycle and tap Turn off the module. Turning it off is the withdrawal of this consent: it is recorded in the history, the cycle leaves the screens immediately and the app stops accepting entries. Nothing is deleted, and you can turn it on again whenever you want. To delete, use Delete my cycle data, in the same place — these are two separate things on purpose, so that someone who only wants to hide the screen does not lose the history by accident.
- The adolescent's agreement (12 to 17) to Symptoms, Daily check-in, Vital signs or Menstrual cycle: in Your account, undo it whenever you want, without explaining. The category stops appearing to the guardian and to the companion.
- Device data: in My devices, disconnect the device. You can also remove the permission in the Health Connect settings on your phone.
- Notifications: turn off the water reminder in Water reminder (notification), or block notifications in your phone's or browser's settings. The daily pregnancy tip is turned off with its own switch, on the Pregnancy screen; it also stops on its own when you end the tracking, turn off the module or delete the pregnancy data.
- Guardian authorization for a minor: in Minors in your care, open the minor and tap Withdraw authorization. A companion taps Stop following.
- Posting activities with the route (walks_trajeto_publico): in Walks › Profile › ☰ Settings and activity › Profile privacy, turn off "Post my activities with the route". The posts leave others' view right away; nothing is deleted (to delete, use Delete post or Delete my Walks data).
- Storing heart rate from watch activities (walks_batimento_relogio): on the "Watch (Wear OS)" card on the Walks screen, turn off "Store heart rate from watch activities". The app stops storing the heart rate of your next activities; nothing is deleted (to delete, delete the activity, your Walks data or your account).
- AI comments during pregnancy (gestacao_ia): on the Pregnancy screen, turn off "AI comments during pregnancy". The AI stops receiving the pregnancy line and the bump photos right away. The consent also ends on its own when you end the tracking, turn off the module or delete the pregnancy data.
Withdrawing an authorization does not make unlawful what was done while it was valid. Each withdrawal is also recorded.
3. How to contact the Data Protection Officer
- Write to [email protected]. In the subject line, say which right you want to exercise.
- Send it from the email registered on the account and include your public ID (it appears in Your account, in the format TH-XXXX-XXXX). This helps confirm that the request is yours, without asking for documents. If you do not have access to that email, we may ask for another form of confirmation.
- In the app, you can also write in Suggestion or bug? Tell me. The message arrives with your email and your ID.
- We answer as soon as possible. Confirmation that we process your data and simplified access are available immediately, in the app itself. A complete statement is sent within 15 days, as provided by law.
- Requests are free of charge.
4. Rights of people under 18
People under 18 have the same rights. Since consent is given by the guardian, some requests go through the guardian:
- The guardian gives and withdraws consent, in Your account, in the Minors in your care section.
- The guardian chooses what they follow and can change it at any time. The minor always sees, in their own account, what is being followed.
- From 12 to 17, Symptoms, Daily check-in, Vital signs and Menstrual cycle only appear to the guardian if the adolescent agrees, in Your account. They can decline or undo it whenever they want, without explaining (Privacy Policy, section 10).
- Of the menstrual cycle, the guardian and the companion see only whether they are menstruating today, the prediction of the next period and that day's cramps. The free-text note is never shared, at any age.
- The minor can see their own data, export it in Export my data and delete the account in Delete my account, even with the account paused.
- The copy of the minor's data includes the Walks activities (with the drawing of the route, without coordinates) and each request and answer about the Walks authorization. The guardian's copy includes each decision they made about the minor's Walks, without the activities.
- Requests about the minor's data can be made by the guardian or by the minor at [email protected]. Requests from the guardian are checked against the link registered in the app.
- At 18, the link ends automatically, and the person starts exercising all rights on their own, beginning with a new acceptance of the Policy.
5. Filing a complaint with the ANPD
If you believe your rights were not respected, you can file a complaint with the Brazilian National Data Protection Authority (ANPD), on the website gov.br/anpd. We ask that you contact the Data Protection Officer first, because that way we solve it faster, but this is not mandatory.
You can also turn to consumer protection agencies.
6. Who is who
- Data subject: you, the person the data refers to.
- Controller: Tharpa Group, a sole proprietorship (empresário individual), CNPJ 50.150.833/0001-07, which decides how data is processed in Tharpa Health.
- Data Protection Officer (DPO): serves you and the Brazilian National Data Protection Authority (ANPD) at [email protected].
- ANPD: the public body that oversees compliance with the LGPD.
Your health data is sensitive data. That is why the law requires your consent and extra care.