Effective August 5, 2026
Harden Privacy Policy
Harden is a general-wellness heart-rate variability (HRV), readiness, and workout app provided by New River Codeworks LLC. This policy covers the current invitation-only Android build.
The short version
- Harden does not have health-history sync or a first-party cloud backup.
- Harden does not automatically upload or sync the seven-category history to New River Codeworks. A Coach request sends the disclosed subset through Supabase to the selected AI provider only when you tap Send. An export or support message can also leave the phone only when you choose to share or send it. Separately, Android can place private app data in your operating-system-managed Google backup.
- Readings, readiness, trends, notes, workouts, training plans, planned workouts, deterministic guidance, export, and restore work without an account.
- The optional AI Coach requires passwordless email sign-in. A Coach request goes through Supabase to the AI provider selected in Settings: Anthropic or OpenAI.
- Harden has no advertising, analytics, attribution, crash-reporting, or tracking SDKs. New River Codeworks does not sell personal information or use it for advertising.
- Deleting local data and deleting an account are separate actions.
Who is responsible
New River Codeworks LLC is responsible for the Harden app and for personal information handled through the optional account, Coach, and support process.
New River Codeworks LLC 8401 Mayland Dr Ste A Richmond, VA 23294 USA
Email: support@newrivercodeworks.com Website: newrivercodeworks.com
What stays on your phone
Harden stores its current health and activity history in seven tables in private app storage:
- Readings: reading time; raw beat-to-beat intervals; HRV and heart-rate results; duration, protocol, source, quality, algorithm-version, tag, and saved strap-name fields.
- Daily summaries: daily HRV, mean heart rate, readiness, tags, protocol, quality, algorithm-version, and update fields.
- Notes: the date, text, and time of notes you create.
- Coach messages: successful questions and answers, including the selected provider.
- Workouts: date and times, activity label, optional note, average and maximum heart rate, and a downsampled heart-rate series when available.
- Training plans: an optional goal label, whether the goal is open-ended or has a target date, the target date, and created/updated fields.
- Planned workouts: calendar date, activity, optional duration or distance target, optional note, completed/skipped state, and any link to the workout that completed it.
Harden also keeps settings outside those tables, including reading and posture settings, appearance, reminders, selected AI provider, the last-used strap name, disclosure and review-prompt state, repair/version markers, and—if you sign in—a Supabase session.
Harden has no dedicated demographic or training-profile fields and does not calculate or store a calorie estimate as a structured feature. If you type personal details into a note, Coach question, or support email, that text is handled as described below.
The local database does not have a separate Harden-provided encryption layer. It is protected by Android app-private storage and the security of your phone. Use a screen lock and keep your operating system current.
Android device backup
Harden is currently available only on Android. Android can include Harden's private app data in the device backup stored in your Google account when backup is enabled on your phone. That backup may include the seven local tables and app settings.
This is an Android operating-system service, not Harden sync:
- New River Codeworks does not receive, view, or control the backup.
- The backup is not sent to Anthropic or OpenAI.
- Signing in to Harden does not enable or disable Android backup.
- Restoring an Android backup can bring Harden history onto a restored or replacement phone.
- Turning backup off in Android settings stops future backup activity but may not delete a backup that already exists.
Harden's Delete all data control cannot reach a backup held in your Google account. If you restore an older device backup after deleting local data, that older data can return. Google controls the backup's security, retention, and deletion controls.
Optional account
You do not need an account for Harden's local features. An account is required only to send a Coach question.
If you choose passwordless email sign-in:
- Harden sends the email address you enter to Supabase.
- Supabase creates or authenticates an account, assigns an account ID, sends or arranges delivery of a one-time code, and issues a session.
- Harden stores the session in private app settings on that device.
- Harden uses the verified account ID to authenticate Coach requests, enforce a monthly question allowance, store monthly usage counts and any allowance override, and provide self-service account deletion.
Signing in does not upload, sync, or back up the seven-table local history. Network services may create security, delivery, and operational metadata such as authentication events and request logs. New River Codeworks does not use that information for advertising.
Optional AI Coach
Harden calculates readiness and ordinary daily guidance on your phone without AI. The separate Coach is optional. Opening the Coach screen or choosing an example does not send a request. A request is sent only after a signed-in user enters a question and taps Send.
What Harden sends to Supabase
The authenticated Coach request can include:
- Your question, trimmed to no more than 2,000 characters
- Up to 10 of today's notes
- Today's date, RMSSD, mean heart rate, and readiness score, if available
- Up to 7 recent daily rows and up to 30 recent daily rows, each containing date, RMSSD, mean heart rate, and readiness score
- Your personal RMSSD baseline mean and standard deviation, if available
- Harden's deterministic guidance headline and detail, plus its confidence and internal rule label when present
- The AI provider selected in Settings
The Supabase session token is sent in the authorization header. Supabase obtains the account ID from the verified session, not from the Coach request body.
What Supabase sends to Anthropic or OpenAI
The server builds a prompt and sends it to the selected provider. The provider receives:
- Fixed safety and response instructions
- The dates, HRV, heart-rate, readiness, and baseline information described above
- The deterministic guidance headline and detail
- The recent note text
- Your question
The provider prompt does not add your email address, account ID, or Supabase access token. It also does not include the guidance confidence or internal rule label. Before forwarding note text, Supabase limits each included note to 200 characters.
Harden does not automatically add raw beat-to-beat intervals, SDNN, pNN50, tags, a strap address or identifier, workout records or workout heart-rate series, training plans, planned workouts, prior Coach conversations, or export files. Text included within the question and note limits described above is sent even if it belongs to one of those categories or identifies you or another person.
Coach answers, allowance, and logs
The provider returns an answer through Supabase. Harden stores a successful question, answer, provider, and timestamp in the local Coach-messages table. Failed, refused, and quota-exhausted questions are not saved in that local table.
Harden's application database on Supabase does not store the successful prompt or answer through this Coach path. It does store the user-keyed monthly allowance and usage count. The Coach function emits an operational event containing the account ID, provider, outcome, and latency. On a failure, a short validation or provider-error detail can also enter platform logs and may contain limited provider-returned text.
The providers and hosting platform may process request content, responses, network metadata, logs, and backups under the settings and terms that apply to New River Codeworks' accounts. This policy does not promise zero provider retention, zero training use, a fixed provider-deletion period, or immediate deletion from platform logs and backups.
The server instructs the AI not to diagnose, discuss medication, make clinical claims, or contradict Harden's deterministic guidance. These are safeguards, not guarantees. Provider output is not separately checked by a second model or post-generation clinical review.
Export and restore
Settings > Data > Export all data is available without an account, purchase, or subscription. Harden creates a plain, readable JSON file containing all seven local history categories: readings and raw intervals, daily summaries and tags, notes, local Coach messages, workouts, training plans, and planned workouts.
The export does not include most app preferences, the Supabase account, server usage records, platform logs, support emails, or provider records.
Harden writes the export to app cache and opens Android's share sheet. You choose where to save or send it. The file is not encrypted by Harden. Once another app or service receives it, that copy follows the destination's security and retention rules. Harden's deletion controls cannot remove a copy saved elsewhere. An app-cache copy can remain until Android or the user clears it or the app is removed.
Harden can restore its own export format and fill in supported content that is not already on the phone. The restore engine and overall totals include all seven history categories, but the current preview and completion screens do not show separate statistic rows for training plans and planned workouts. Review your calendar after a restore. Older archives can also reconstruct some day tags differently between preview and completed restore. Keep the original export until you have checked the restored history.
Support and diagnostics
Send feedback and Report a problem prepare an email in your chosen mail app. The prepared diagnostic block contains:
- App version
- Device model
- Operating-system name and version
- Total reading count
- Whether any history was imported
- Appearance mode
The prepared block does not automatically include HRV or heart-rate values, raw intervals, readiness scores, reading dates, notes, workout records, location, or the strap address. You can review and edit the email before sending it. Anything you add is included. If a mail app cannot open, Harden may copy the prepared text to your clipboard.
We keep support correspondence for as long as we need it to answer you and to keep a record of the issue, and we delete it when we no longer do. If you want us to delete an email you sent us, write to support@newrivercodeworks.com and ask.
Bluetooth and location
Harden uses Bluetooth to find and connect to a compatible device advertising the standard Bluetooth Heart Rate Service and to receive heart-rate and beat-to-beat data.
Harden does not read, store, or share location. Android 11 and earlier can require a location permission before allowing Bluetooth scans. That is an operating-system permission requirement; Harden still does not use a location API or store location. Android 12 and later use Bluetooth-specific permissions.
Harden does not keep the strap's Bluetooth address. It can save the strap's readable display name with a reading and as the remembered last-used strap.
Advertising, analytics, and sale
Harden currently contains no advertising, analytics, attribution, crash-reporting, or tracking SDKs.
New River Codeworks does not sell personal information, share it for targeted advertising, create advertising profiles from health information, or use health information for advertising.
Why Harden uses information
Harden uses information stored locally to take readings, calculate HRV and readiness, maintain a personal baseline, show trends and deterministic guidance, save notes and tags, record workouts, show planned sessions, manage local reminders and settings, and export or restore your history.
Account information is used for passwordless authentication, authenticated Coach access, allowance/usage records, service security, and account deletion.
Coach request information is used to generate the answer you requested, enforce the allowance, prevent abuse, and operate the feature. Support information is used to answer the request and investigate the issue you describe.
How long information is kept
- Local history and Coach messages: until you delete them, clear Harden's app storage, or uninstall the app.
- App settings and disclosure record: until you change the setting or clear app storage. Delete all data does not clear most settings or the disclosure record.
- Android device backup: under the retention and deletion controls of Android and your Google account. Harden cannot see or delete it.
- Supabase account, allowance, and monthly usage rows: no automatic time-based purge is implemented. They remain until account deletion or an authorized administrative action.
- Coach and account operational logs, authentication-delivery records, AI-provider records, and platform backups: for the periods used by the applicable service and account configuration; some records may persist after account deletion.
- Support correspondence: kept while we need it to answer you and to keep a record of the issue, then deleted. Ask us and we will delete it sooner.
- Exports: wherever you save or send them, until you or that destination deletes them. An app-cache copy can remain as described above.
Deleting information
Delete data on the phone
Open Settings > Data > Delete all data. After two confirmations, Harden runs deletion across the seven local history tables and clears the saved last-used strap name. The tables are cleared in separate database operations, so an interruption or failure can leave only part of the history deleted. If the action fails or the app closes during deletion, reopen Harden, run it again, and check the history screens.
This action does not:
- delete or sign you out of the optional account;
- clear most app preferences or the disclosure record;
- delete an export in app cache or a copy saved elsewhere;
- delete support correspondence, provider records, or Supabase platform logs; or
- delete an Android backup held in your Google account.
Delete the optional account
A signed-in user can open Settings > Account > Delete account. After two confirmations, Harden calls its authenticated account-deletion service. The service deletes the Supabase authentication user and user-keyed Harden rows in six server tables: readings, daily summaries, Coach messages, notes, Coach usage, and entitlements. Those four content tables exist defensively in the server schema even though the current app has no health-history sync.
After a successful response, the app attempts to sign out and clear the local session on that device, then offers local deletion separately.
Account deletion does not delete the seven-table history on your phone, Android backups, exports saved elsewhere, support correspondence, or separate AI-provider and platform records, logs, or backups. The account-deletion service itself emits an operational event containing the account ID, outcome, and latency, plus limited failure detail when applicable.
If you cannot use the in-app control, email support@newrivercodeworks.com. Signing out, uninstalling Harden, or deleting local data does not by itself delete the account.
Security
Harden uses Android app-private storage for local records and HTTPS for account and Coach requests. Supabase verifies a signed-in session before accepting those requests. AI-provider keys remain on the server and are not included in the app.
No method of storage or transmission is completely secure. The local database is not separately encrypted by Harden, and exported JSON files are readable. Protect your phone, email account, one-time codes, and exports.
Children
Harden is intended for people age 16 or older and is not directed to children under 16. New River Codeworks does not knowingly collect personal information from children under 16.
If you believe a child under 16 created an account or sent personal information to support, email support@newrivercodeworks.com.
Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, or to withdraw a consent you gave.
For information on your phone, use Harden's export and local-deletion controls. New River Codeworks cannot remotely inspect, correct, recover, or delete the local database.
For account, Coach-service, operational, or support information, use in-app account deletion or email support@newrivercodeworks.com. We may ask for reasonable information to verify the request.
Account, Coach, and support services may process information in the United States and other locations used by their service providers. Mandatory rights and protections that apply where you live are not waived by this policy.
Harden does not sell personal information or use it for targeted advertising.
Changes to this policy
We may update this policy when Harden or legal requirements change. The revised policy will show a new effective date, and Harden will provide any notice required by law.
Harden stores a disclosure version and acknowledgment time on the device. When that version changes, the app can show the updated disclosure again.
Contact
New River Codeworks LLC 8401 Mayland Dr Ste A Richmond, VA 23294 USA
support@newrivercodeworks.com newrivercodeworks.com
---