ONYX

Training, fuel and recovery.

Privacy Policy

Last updated 30 September 2026

Onyx is a training, nutrition and recovery app for iPhone and Apple Watch, published by Michael Khoshahang, trading as Onyx, in Israel ("Onyx", "we"). It reads health and fitness data, combines it with the workouts and meals you log, and turns both into a small number of figures you can act on. This page says exactly what that involves.

Onyx does not sell your data, does not use it for advertising, does not track you, and never sends a health value to analytics or crash reporting.

What Onyx collects

The data below is linked to you — stored against your account — unless the row says otherwise. None of it is used for tracking, and all of it is collected to run the app for you (App Functionality), apart from the product-interaction events, which are Analytics.

CategoryWhat it includesWhat it is used for
HealthHeart rate, resting heart rate, heart-rate variability, respiratory rate, blood oxygen, wrist temperature, sleep stages and duration, body mass, body-fat percentage and the other body-composition readings your scale writes; nutrition totals from Apple Health.To compute readiness, the recovery battery, the stress index and the body trends the app draws.
FitnessSteps, distance, active and resting energy, exercise and stand minutes, VO₂ max, and the workouts, sets, loads and cardio you log in the app.To compute training load, weekly volume targets, progression and energy balance.
FoodEach food you log: its name and brand, portion, nutrients, meal, time and time zone; the custom foods you save; your nutrition targets.To show your day's intake against your targets, and to write it to Apple Health if you allow it.
ProfileYour birth year (required, to confirm you are 16 or over) and, only if you enter them, your sex and height. Your unit system and goals.To confirm your age and to size your targets and estimates. You can change or clear sex and height in Settings.
Email addressThe address you sign up with, or the one Apple or Google shares when you sign in with them (with Sign in with Apple you can choose Apple's private relay address).To identify your account and to send you a sign-in, confirmation or password-reset code. No marketing, no mailing list.
Account idThe id Onyx gives your account and, with Apple or Google sign-in, the id that company uses for you.To store every row against your account and nobody else's.
NameOnly with Google sign-in: the name on your Google account and its profile-picture link, which Google shares with every sign-in.Kept on your account record. Nothing in the app reads or shows it.
PurchasesWhether you have Onyx Pro and until when. Apple handles the payment and Onyx never sees your card. Your account id goes to Apple with the purchase (the "app account token"), so the purchase stays with your account.To unlock logging.
Crash and performance data (stored without your account id)Apple's MetricKit reports: crash stacks, hangs, launch time, CPU and disk use, with the app and iOS version. Stored without your account id.To find and fix crashes. You can turn it off in Settings → Privacy.
Product interaction (not linked)At most five named events a day — onboarding completed, workout finished, food logged, paywall shown, purchase completed — with the app version and a one-way hash of a random install id. Never a health value.To count how many people use each part of the app. You can turn it off in Settings → Privacy.

Onyx collects no location, no contacts, no photos (progress photos stay on your phone and are never uploaded), no browsing history, and no advertising identifier.

Apple Health

Onyx asks for read access to the Health categories above during setup, and asks to write only when you first use a feature that writes: the foods you log (one entry per item) from the iPhone, and workouts from Apple Watch. You can decline any of it, and every screen still works — a figure that depends on a reading you have not shared says so rather than guessing. A sync only ever reads Health; it never asks for access.

Health data obtained through HealthKit is used only to provide the features described here. It is never used for advertising or marketing, never sold, never shared with a data broker, never sent to analytics or crash reporting, and never disclosed to a third party. Onyx does not write your Health data to iCloud.

You can withdraw access at any time in Settings → Privacy & Security → Health → Onyx.

Where your data goes

Your devices and one private database. Your data lives on the devices you sign in on and in a private database hosted by Supabase (Singapore region), which Onyx uses as infrastructure to store your rows and sync them between your devices. Every row carries your account id, and the database enforces row-level security: a request signed as you can reach your rows and nobody else's. Data is encrypted in transit (TLS) and at rest. Each row also stores the time zone it was logged in, so your past days never move when you travel.

Backups. The database is backed up nightly, encrypted, to storage controlled by Onyx, and each backup is kept for 14 days.

Onyx also talks to these services, each for one purpose and with nothing more than the listed data:

  • Resend — delivers the sign-in, confirmation and reset codes to your email address.
  • Apple and Google — only if you choose to sign in with them. That step happens on their own screen and Onyx never sees your password. Deleting your account also revokes Onyx's Sign in with Apple authorisation with Apple.
  • Have I Been Pwned (api.pwnedpasswords.com) — when you choose a password, the first 5 characters of its SHA-1 hash (never the password) are checked against known breaches.
  • Open Food Facts (world.openfoodfacts.org) — when you scan a food barcode, the barcode number is looked up. No account id, no health value.
  • NIH Dietary Supplement Label Database — when you search or scan a supplement, the search term or barcode is looked up. No account id, no health value.
  • TelemetryDeck (Germany) — the product-interaction events above, unless you turn them off.

The USDA food database is bundled in the app and needs no network. There is no advertising network and no other third party in the data path.

Crash reports and your sign-in. Crash and performance reports are stored without an account id, but they are sent over your signed-in connection, so our host's request logs could associate a report with your account for as long as those logs are kept. Onyx never makes that association.

Support access. Nobody at Onyx browses user data. If helping you requires looking at your rows, that access goes through one audited tool that records who looked, at what, when and why.

What stays on your devices

Onyx keeps a full local database on the phone so the app works with no signal. The Home Screen widgets and the watch read copies kept on your devices; the watch holds no sign-in of its own and makes no requests of its own. Signing out, deleting your account or switching accounts on the phone erases the phone's copy, the widgets' copy and the watch's copy.

Reminders — including the trial reminders before a free trial ends — are local notifications scheduled on your phone. Nothing is sent from a server.

The app's privacy manifests declare the system values it reads (user defaults shared with its widgets and watch, file timestamps, available disk space); none of them leaves the device.

If you tap Settings → Sync → Share diagnostics, the app prepares a file with your account id, app, iOS and device model, time zone and sync counts and error codes — no health values — and you choose where to send it.

Tracking

None. Onyx does not track you across apps or websites, does not build an advertising profile, does not use the Advertising Identifier, and does not show the App Tracking Transparency prompt because it has nothing to ask for.

Keeping and deleting your data

Your data is kept for as long as your account exists, because the app's value is your history. Crash reports are kept for 14 days.

You can delete your account and everything in it at any time, in the app: Settings → Delete account. It removes every row belonging to you and then the account itself, and erases the phone and the watch. It is immediate and permanent; the encrypted backups that still hold it expire within 14 days. Deleting your account does not cancel an App Store subscription — cancel it in your Apple account's Subscriptions.

If you would rather someone did it for you, write to support@onyxtrain.app from the address on the account.

Your rights

You can export everything the app holds for you as one file from History → Export → Everything · all time, and a readable weekly report from Reports. You can delete everything as described above. Wherever you live — including the EU, the UK and Israel — these controls cover access, portability and erasure; write to support@onyxtrain.app for any other request, including correction or objection, and we will answer within 30 days.

Age

Onyx is for people aged 16 and over. The app asks for your birth year, refuses to set up an account for anyone under 16, and deletes what was created. If you believe someone under 16 has an account, write to support@onyxtrain.app and it will be deleted.

Changes to this policy

If this policy changes, the date at the top changes with it, and a change that widens what is collected will be announced in the app before it takes effect.

Contact

Michael Khoshahang, trading as Onyx, Israel — support@onyxtrain.app.