Voke

Privacy policy

Effective 7 October 2026.

1. Who we are

Voke is an iPhone app and web service that shows you your own health data and lets you share chosen parts of it with people you invite. It is made and run by Rida F’kih, an individual in Alberta, Canada (“Voke”, “we”, “us”). Rida is responsible for your personal data and is Voke’s privacy officer.

For privacy questions, requests or complaints, email [email protected]. This includes questions about the service providers outside Canada that handle your data for us. To report a security problem, email [email protected].

This policy covers the Voke iPhone app, the website at voke.co and the services behind them, including the connection Voke offers to AI apps. It doesn’t cover the apps and services you connect to Voke, such as Apple Health, Google, or an AI app you choose to connect. Their own policies apply to them.

More detail is on these pages:

2. What we collect

2.1 Your account

  • Your name, or the name you choose to show to people in your circles.
  • The email address Apple gives us when you sign in with Apple. It’s often a private relay address. We don’t show it to other users.
  • Your Apple account identifier, which Apple provides so we can recognise you when you sign in.
  • An Apple sign-in token, which we keep encrypted so we can revoke Voke’s access when you delete your account.

Voke has no passwords. You sign in with Apple only.

2.2 Health data you connect

You choose which sources to connect, and within each source which data Voke may read. Voke only reads. It never writes to Apple Health or your Google account.

  • Apple Health. With your permission on your iPhone, Voke reads data from the Health app, which can include data from Apple Watch and other apps that write to it. Your iPhone uploads it to Voke. When you first connect, Voke reads up to 365 days of history.
  • Google Health. If you connect your Google account, Voke’s server reads the Google Health data you approve on Google’s consent screen, which can include data from Fitbit and Pixel Watch devices. When you first connect, Voke reads up to 365 days of history.

Depending on what you allow, Voke reads these types:

  • Sleep: sleep sessions and sleep stages, and temperature changes during sleep.
  • Heart: heart rate, resting heart rate, heart rate variability, heart rate zones and time in each zone, and VO2 max (from Apple Health).
  • Vitals: blood oxygen, breathing rate, and wrist temperature during sleep (from Apple Health).
  • Activity: steps, distance, floors climbed, active and resting energy burned (calories), active minutes, active zone minutes and sedentary periods.
  • Workouts: workout type, time and effort.
  • Body: weight.

Voke doesn’t read nutrition, mindfulness, cycle tracking or reproductive health data, ECGs, heart rhythm notifications, or your location or workout routes.

We also record which device or app each reading came from (for example “Apple Watch” or “Fitbit”), so Voke doesn’t count the same thing twice.

From this data Voke works out derived values such as daily summaries, naps, heart events, activity entries and scores, including a daily readiness score. Heart events are patterns in your heart rate data, not medical alerts. See the health disclaimer.

2.3 Your connections and devices

  • Connected sources. For each source you connect: the source, your Google account’s user identifier (for Google), your device’s time zone, when it last synced, and a sign-in token that lets Voke keep reading. Google tokens are encrypted with your account’s own key.
  • Your iPhones. When you sign in on an iPhone, the app creates a security key on that device. We store its public half, a label for the device and when it was used, so we can confirm that requests and uploads really come from your phone. If you allow notifications, we store your device’s notification token.
  • Sign-in sessions. For each session: when it started and expires, and the IP address and app version (user agent) it was opened from.

2.4 Your sharing

Your circles, who’s in them, invites you sent, which categories and levels you share with each circle, and whether you let other people’s AI see your data.

We keep a log each time another person or an AI reads your data: who read it, which categories, at what level, for which dates and when.

2.5 AI features

  • Ask Voke. The questions you ask and the answers you get. We don’t store the health data the assistant looked up to answer; it reads it again each time.
  • Morning summary. The summary written for each morning.
  • Connected AI apps. Which AI apps you’ve connected, the categories each may read, whether each may read people in your circles, and when each was connected, first used and disconnected.
  • Your AI setting. Whether you’ve turned AI features off.

2.6 Security and technical records

  • Security records. Sign-ins, sign-outs, device changes and similar account events, with your account ID and the device key involved.
  • Operations records. Server logs and job records, such as request times, error codes and job outcomes. They’re written so they don’t contain health values.
  • Google change notices. Messages Google sends to tell Voke new data is ready for your account.

We don’t use analytics, advertising or tracking tools in the app or on the website.

2.7 The website

The voke.co website is hosted by Cloudflare. Like any website host, Cloudflare processes your IP address and basic request details, such as the page you asked for and your browser type, to deliver the site and protect it from attacks. Voke doesn’t set tracking cookies.

2.8 Beta sign-ups and email

If you ask for a beta invite on the website, we keep your email address and when you signed up. We use it only to invite you to the TestFlight beta and to email you about the beta. The website, which Cloudflare runs, stores it in a Cloudflare D1 database in the United States: one entry per address, with the time you signed up. Signing up again with the same address doesn’t add a second entry. We may also send a note with your address and sign-up time to the Voke team’s inbox ([email protected]) at Fastmail, so we know to send your invite. To invite you, we give your email address to Apple, which sends the TestFlight invitation.

If you email us, we keep your email address and what you send us in our Fastmail mailbox, so we can answer.

2.9 TestFlight

If you test Voke through TestFlight, Apple shares with us your tester email address and name, and any feedback, screenshots and crash reports you choose to send. Apple’s own privacy policy covers what Apple collects through TestFlight.

3. How we use it

We use your data only to:

  1. Show you your own health data, summaries and scores.
  2. Show the data you choose to share to the people you choose.
  3. Answer your questions in Ask Voke and write your morning summary, unless you turn AI features off (see section 7).
  4. Let AI apps you connect read the categories you approved.
  5. Keep your account secure: confirm requests come from your devices, stop misuse and investigate problems.
  6. Run, fix and improve the service. For example, we check how long syncing takes or why a job failed.
  7. Reply to you and send service messages, such as a notice that an AI app was connected to your account.
  8. Meet legal obligations.

We don’t sell your data, use it for advertising, or share it with data brokers. We don’t use your health data to build or train AI models.

Voke’s scores and summaries are worked out automatically from your data. They’re for your own information and the people you share with. Voke doesn’t use them to make any decision that has a legal or similarly significant effect on you.

4. Legal bases and consent

We collect, use and share your health data only with your express consent. Where the GDPR or UK GDPR applies, health data is a special category of data, and we rely on your explicit consent (Article 9(2)(a)).

  • Reading health data from a sourceBasis: Your consent, given for each data type in Apple Health and on Google’s consent screen
  • Sharing with people in your circlesBasis: Your consent, given for each category and level
  • Letting an AI app you connect read your dataBasis: Your consent, given when you approve the connection on your phone
  • Letting other people’s AI read what you shareBasis: Your consent, given with “Let their AI see this too” for each circle
  • Ask Voke and the morning summaryBasis: Your consent. See section 7.3 for how this is set today
  • Running your account and the features you useBasis: Contract
  • Security records, abuse prevention and backupsBasis: Legitimate interests in keeping the service and your data safe
  • Keeping records the law requiresBasis: Legal obligation

Withdrawing consent. You can withdraw consent at any time, and it doesn’t affect what we did before:

  • Stop reading a source: remove Voke’s access in the Health app (Settings, Health, Data Access & Devices, Voke) or in your Google account’s third-party connections. Voke stops reading new data. You can’t yet delete one source’s data from inside the app, so if you want the data Voke already imported from that source deleted, email [email protected] and we’ll delete it within 30 days. Deleting your account deletes everything.
  • Stop sharing: lower a category to none, remove someone, or leave or delete a circle.
  • Stop AI: turn off “Use AI features” in your account settings, or disconnect an AI app.

5. Who can see your data

5.1 You

You can see all of your own data.

5.2 People you share with

Nobody sees your health data until you join or create a circle and choose what to share. For each circle, you choose a level per category, and it applies to everyone in that circle. To share differently with one person, make a circle with just the two of you. The levels are:

  • Score: scores only.
  • Summary: scores plus daily totals.
  • Detail: scores, daily totals, charts, sessions and minute-by-minute data.

The categories you can share are sleep, heart, activity, workouts, vitals and readiness.

When you set up Voke, the sharing step comes with three choices already selected: sleep at detail level, heart at summary level and readiness as a score. Activity is not selected. Untick anything you don’t want to share before you tap Continue, because Continue shares the selected categories with your circle. You can change any of them later. Circles you create or join after setup start with nothing selected.

Weight and heart events are never shared, whatever you choose. People in your circles see your display name. They never see your email address or your device and account identifiers.

When you lower a level, remove someone, leave a circle or delete it, they lose access straight away.

5.3 AI

  • Ask Voke and the morning summary read your data on your behalf. Ask Voke can also read data people in your circles share with you, but only where they’ve turned on “Let their AI see this too” in a circle you share with them. See section 7.
  • AI apps you connect can read only the categories you approved, and people in your circles only where those people allowed it.

5.4 Operator access

Voke is run by one person, Rida F’kih, who is the only person with operator access to Voke’s systems. Voke’s systems process your data automatically to run the service. Rida doesn’t look at your health data, and would access it only to fix a problem you’ve asked for help with, to protect the service or other users, or where the law requires, and only as far as needed.

Some operator tasks, such as maintenance commands, are run with the help of an AI assistant (Claude, made by Anthropic) on Rida’s own computer, under Rida’s direction. Those tasks work with account and operations records. Anthropic is listed in section 6 as a service provider. Access to production systems is limited to these tools and to Voke’s own service, and every use of an encryption key is logged.

5.5 Legal requests

We disclose data to authorities only when Canadian law, or law that applies to us, requires it. Where the law allows, we tell you first.

5.6 Business transfers

If Voke is sold, merged or reorganised, your data may transfer to the new owner, who must keep to this policy. We’ll tell you before it happens. Health data and data from Google will only transfer with your explicit consent, given before the transfer.

6. Service providers

These companies process data for us, only to provide the service. Each is bound by a contract that limits what it can do with your data and requires it to protect your data at least as well as this policy does.

  • Amazon Web ServicesWhat they do: Hosting, database, encrypted storage, encryption keys, logs and backupsData they handle: All Voke dataWhere: Montréal and Calgary, Canada
  • Vercel (AI Gateway)What they do: Routes Ask Voke and morning summary requests to an AI modelData they handle: Your question, conversation and the health data needed to answerWhere: United States
  • AI model hosts reached through VercelWhat they do: Run the AI model that writes Ask Voke answers and morning summariesData they handle: Same as VercelWhere: United States
  • CloudflareWhat they do: Hosts the voke.co website, runs DNS for voke.co, and stores beta sign-ups in a D1 databaseData they handle: Website visitors’ IP addresses and request details, and beta sign-up email addresses with their sign-up time. App traffic doesn’t pass through CloudflareWhere: Global network; beta sign-ups are stored in the United States
  • FastmailWhat they do: Email for voke.co: the note to the Voke team about a new beta sign-up, sent to [email protected], and emails you send usData they handle: Beta sign-up email addresses and sign-up times in those notes, and your emails to usWhere: United States
  • AnthropicWhat they do: Runs the AI assistant used for operator tasks (section 5.4)Data they handle: Account and operations recordsWhere: United States

Apple also handles some of your data, as an independent company under its own privacy policy rather than on our instructions: Sign in with Apple, delivering notifications to your iPhone (notifications never contain health values), and TestFlight beta invitations and feedback. Apple processes this in the United States and other countries where it operates.

Google and Apple Health are sources you connect, not our service providers. Their own privacy policies cover what they do with your data. AI apps you connect are also not our service providers (section 7.2).

7. AI features

7.1 Ask Voke and the morning summary

When you ask Ask Voke a question, or when Voke writes your morning summary:

  • Your question, earlier messages in that conversation, and the health data the assistant looks up are sent through Vercel’s AI Gateway to an AI model. The model is DeepSeek V4.1 Flash, an openly published model, run in the United States by hosting companies Vercel works with. Your data is not sent to DeepSeek, the company that made the model.
  • Every request asks for zero data retention and no training on your data, and Voke uses only hosts that Vercel lists as offering zero data retention. Under Vercel’s terms, some hosts may still keep data for a short time to check for abuse.
  • Every request asks to be processed in the United States. If the answer reports it was served elsewhere, Voke discards it, but by then your request has already been sent.
  • For the morning summary, Voke’s code picks the readings and works out the trends; the AI only writes a one-sentence summary and two or three suggestions.
  • Answers are plain text. Voke strips links and images from them. AI answers can be wrong. See the health disclaimer.

7.2 AI apps you connect

You can connect an AI app that supports the Model Context Protocol (MCP), such as Claude or ChatGPT. You approve each connection on your phone and choose which categories it can read. The connection is read-only.

When you connect an AI app, you’re directing Voke to send it the data you chose, which can include data that came from Apple Health or Google. That data goes to the company that runs the app, under your account with them. Their privacy policy and data retention apply, not ours, and Voke’s zero data retention setting doesn’t apply to them. Check their settings, for example whether they use your chats to train their models. Voke can’t control what they do.

Every read by an AI app, and by Ask Voke, is logged, and you can see the log in the app. You can disconnect an AI app at any time in your account settings, and it stops working straight away.

7.3 Turning AI off

Today, AI features are on when you create an account: unless you turn them off, Voke sends the health data needed for Ask Voke and your morning summary to Vercel and the AI model host described in section 7.1. You can turn them off with one switch, “Use AI features”, in your account settings. Turning it off:

  • disconnects every AI app you connected;
  • deletes your Ask Voke chats and morning summaries;
  • deletes other people’s Ask Voke messages that used your data; and
  • stops everyone else’s AI, including Ask Voke for people in your circles, from reading your data.

You can turn it back on later. Deleted chats don’t come back, and you’ll need to connect your AI apps again.

7.4 When someone stops sharing

If a person stops sharing a category with you, leaves your circle, or turns off AI for you, Voke deletes your Ask Voke messages that used their data. This runs in the background shortly afterwards.

8. Apple Health (HealthKit)

  • Voke reads HealthKit data only after you allow it on your iPhone, and only the types you allow. You can change this at any time in the Health app or in Settings.
  • Voke doesn’t write anything to Apple Health.
  • HealthKit data is never used for advertising or marketing, and never sold, including to advertising platforms, data brokers or information resellers.
  • HealthKit data isn’t stored in iCloud.
  • HealthKit data is used only to provide Voke’s health features to you, the people you choose to share with, and the AI features described in section 7. It’s disclosed to third parties only with your consent, or to the service providers in section 6 who process it for us under contract.

9. Google user data

If you connect your Google account, Voke asks Google for read-only access to the Google Health data groups you approve: activity and fitness, health metrics and measurements, and sleep. Voke uses this data only to show it to you, to show it to people you choose to share with, and for the AI features described in section 7.

Voke’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, Voke:

  • uses Google user data only to provide or improve user-facing features that are visible and prominent in the app;
  • transfers it to others only to provide those features (sharing with people you choose, Ask Voke and the morning summary, and AI apps you connect), for security, to comply with the law, or as part of a merger, sale or reorganisation, and in that last case only after getting your explicit consent first;
  • doesn’t use it for advertising, and doesn’t sell it;
  • doesn’t let people read it, except with your consent, for security, to comply with the law, or for internal operations where the data has been aggregated and anonymised; and
  • doesn’t use it to develop, improve or train general AI or machine learning models, and the AI model hosts Voke uses can’t train on it either.

If you remove Voke’s access in your Google account, Voke stops reading new data. Data Voke has already imported stays in your Voke account until you delete your account, or until you ask us by email to delete it (section 4). More detail is on how Voke uses your Google data.

10. Where your data is stored and transferred

Voke stores your data on Amazon Web Services in Montréal, Canada (ca-central-1). Backups are kept in Montréal and in Calgary, Canada (ca-west-1). Encryption keys stay in Canada.

Some processing happens outside Canada:

  • Google sends your Google Health data from its own servers.
  • Apple processes sign-in, notifications and TestFlight.
  • Ask Voke and morning summary requests are processed in the United States by Vercel and an AI model host.
  • Cloudflare serves the website from its global network and stores beta sign-ups in the United States. Notes about new sign-ups and emails to us are handled by Fastmail in the United States.
  • Anthropic processes operator records in the United States.
  • An AI app you connect processes data wherever its operator does.

Data processed in another country is subject to that country’s laws, and courts and authorities there may be able to access it. For questions about our service providers outside Canada, email [email protected].

For people in the EU, EEA, UK or Switzerland: Canada has an adequacy decision for commercial organisations covered by PIPEDA. Transfers to the United States rely on the Standard Contractual Clauses (and the UK addendum) in each provider’s data processing terms, or on the provider’s certification under the EU-US Data Privacy Framework and its UK and Swiss extensions. You can ask us for a copy of the safeguards.

11. How we protect it

  • Your own key. Each account has its own data key. Your health data, your Ask Voke chats, your morning summaries and your Google sign-in tokens are stored encrypted with keys derived from it (AES-256-GCM). The data key is itself encrypted by a key held in AWS Key Management Service, and is never written to disk unencrypted. Your Apple sign-in token is encrypted separately with a server key.
  • Encrypted in transit and at rest. Connections to Voke use TLS. The database and backups are encrypted at rest.
  • Not end-to-end. Voke’s server decrypts your data while it works, to compute scores, serve it to people you share with and answer AI questions. Your account details (name, email, identifiers), circles and the sharing log aren’t encrypted with your own key. The operator could technically access them; section 5.4 says when that would happen.
  • Signed devices. Each iPhone you sign in on holds its own key in its Secure Enclave. Uploads from Apple Health are signed with it, and actions like deleting your account, removing a circle member or signing out other devices need a fresh signature from the device.
  • Least access. Only the Voke service can use the encryption keys. Every use of a key is logged by AWS.

No system is perfectly secure. If a breach of security safeguards creates a real risk of significant harm to you, we’ll tell you directly and report it to the Privacy Commissioner of Canada and Alberta’s Information and Privacy Commissioner, and to any other regulator the law requires, such as the US Federal Trade Commission. We keep a record of every breach for at least 24 months.

12. How long we keep it

  • Your account, health data and connected sourcesKept: Until you delete your account
  • Data from a source you disconnect outside VokeKept: Until you delete your account or ask us by email to delete it
  • Ask Voke chatsKept: 30 days after each message, then deleted
  • Morning summariesKept: Until you turn off AI features or delete your account
  • Sharing log (who read your data)Kept: Until you, or the person who read your data, delete their account. Deleting either account removes the entries
  • Sign-in sessions, with IP address and user agentKept: Until you sign out of that session, remove that device or delete your account
  • Google change noticesKept: Until you delete your account
  • Security recordsKept: Kept after your account is deleted, to protect the service and investigate misuse. They hold your account ID, event types and device key IDs, but not your name, email or health data
  • Key destruction recordKept: Kept permanently after your account is deleted. It holds only your account ID and when your key was destroyed, so we can prove it was destroyed
  • Beta sign-up email addresses and sign-up times, in Cloudflare and in sign-up notes at FastmailKept: Until the beta ends or you ask us to remove yours
  • Support emailsKept: As long as needed to answer you, and no more than 2 years
  • Server logsKept: 30 days
  • Database backupsKept: Up to 35 days
  • Off-site backupsKept: 30 days

Backups are full copies of the database. They contain your encrypted health data, chats and summaries, and also your account details in readable form: name, email, Apple and Google identifiers, session IP addresses and user agents, circles, sharing settings and the sharing log.

13. Deleting your account

You can delete your account in the app: open your account from the top of the Feed, tap Delete account and confirm. If you can’t use the app, email [email protected] from the address on your account, and we’ll delete it within 30 days. See /delete-account.

When you delete your account:

  1. Straight away, you’re signed out everywhere, removed from every circle, and nobody can see your data any more. Circles you ran are handed to another admin, or to the longest-standing member if there’s no other admin. A circle with nobody else in it is deleted.
  2. Voke revokes its access to your Apple and Google accounts.
  3. Voke deletes your account, health data, connected sources, chats, summaries, sharing settings, sharing log and Google change notices, and destroys your data key.
  4. Within 7 days, no copy of your key exists anywhere, including backups, so your encrypted health data, chats and summaries can’t be read by anyone.
  5. Your account details in backups (name, email, identifiers, IP addresses, circles and the sharing log) are deleted as the backups expire, within 35 days. We don’t restore them, and if we ever had to restore a backup, we’d delete your account again first.

We keep the security records and the key destruction record described in section 12.

You can sign up again later with the same Apple account, as a new account with no data.

14. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and get a copy;
  • correct it;
  • delete it;
  • withdraw consent;
  • object to or restrict some processing;
  • get your data in a portable, commonly used format;
  • know which third parties received your data;
  • appeal our answer to a request; and
  • complain to a privacy regulator.

Email [email protected]. We’ll answer within 30 days. If a request is complex, we may extend that once, and we’ll tell you why within the first 30 days. We may need to confirm it’s you, for example by asking you to send the request from the app or the email on your account. Requests are free.

Appeals. If we refuse a request, or you disagree with our answer, reply to our answer with “appeal” and tell us why. We’ll review the decision and answer within 45 days, with our reasons. If you’re still not satisfied, you can contact a regulator below.

  • Canada: you can complain to the Office of the Privacy Commissioner of Canada, or to your provincial commissioner, such as the Office of the Information and Privacy Commissioner of Alberta or Quebec’s Commission d’accès à l’information.
  • EU, EEA, UK and Switzerland: you can complain to your local data protection authority.
  • US states: we don’t sell personal data or share it for targeted advertising. Residents of states with consumer health data laws, such as Washington, Nevada and Connecticut, have the rights set out in our consumer health data notice, including a list of everyone who received your health data, and an appeal to your state attorney general.

15. Children

Voke is for people 18 and older. We don’t knowingly collect data from anyone under 18. If you think someone under 18 has an account, email [email protected] and we’ll delete it.

16. Changes

If we change this policy, we’ll update the date at the top. If a change affects how your data is used or shared, we’ll tell you in the app before it takes effect, and we’ll ask for your consent again where the law requires it.

17. Contact

Rida F’kih, operator of Voke, Alberta, Canada Privacy officer: Rida F’kih Privacy: [email protected] Security: [email protected]