Privacy policy
This policy explains what personal data we collect, why, what we do with it, and the rights you have over it. We have written it to be readable and to describe the product as it is built today. The law behind it is the UK GDPR and the Data Protection Act 2018.
The short version: we do not sell your data, we do not run targeted advertising, and the health information you log in the app, or read from Apple Health, is there only because you switched it on and can be deleted by you at any time.
It sits alongside our Customer Terms of Service, Site Terms of Service, Booking Terms, App Terms of Service, Community Guidelines and Advisor Terms.
1. Who we are
ORUS is a trading name of Eight Hours Group Ltd, registered in England and Wales, company number 17031572, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
Eight Hours Group Ltd is the data controller for the personal data described in this policy, except where we say otherwise in sections 4.3 and 8.
We are registered with the Information Commissioner’s Office under registration reference ZC181817.
Contact: hello@orus.uk
2. Where this policy applies
This policy covers orus.uk, the ORUS app, our events, and our communications with you. Where we operate a store for another market, that store links to its own version of this policy, and the differences are set out in section 12.
3. What we collect
3.1 Account and profile
Email address, password (stored as a salted hash by our authentication provider), display name, and any profile details you add, including a photograph if you upload one.
3.2 Orders and payments
What you ordered, delivery address, order history, and returns. We never see or store your full card details. Payment is handled by our payment providers, who send us only a confirmation and the last four digits.
3.3 Wellness profile
Age range, sleep window, primary disruptors, exercise frequency, caffeine cut-off, goals and any free-text notes. Voluntary.
3.4 Health and wellbeing data (special category)
If you switch on the relevant features, our servers hold:
- Training sessions, plans, schedules, check-ins, soreness, body goals, and your training thresholds and zones (FTP, threshold heart rate, threshold pace) where you or a coach set them
- Meals logged, protein, energy, plant and portion counts, water, targets, any meal plan, recipe or supplement a coach prescribes, and a coach's comments on meals you have shared with them
- Weight, body measurements, progress entries and progress photographs
- Sleep schedule, declared bedtime and wake times, sleep check-ins and wind-down routines
- Journal entries, symptom tags, habits and weekly check-ins
- Your wellness profile: age range, sleep window, disruptors, exercise frequency, caffeine cut-off, goals and notes
- What you have chosen to share with a coach, your intake form and health questionnaire, coaching check-ins, and the record of what a coach looked at
Some health data never reaches our servers at all and is kept only on your phone:
- Apple Health readings (see the connected sources above)
- WHOOP readings, which pass through our server to the phone and are not stored on it
- The supplement list and reminder times you keep for yourself
- Menstrual cycle tracking, which is off by default
This is special category data under Article 9 of the UK GDPR and we treat it accordingly. Sections 4.2 and 4.3 explain our lawful basis.
3.5 Advisor conversations and memory
Your messages to ORUS Advisor, its responses, and the durable “memory facts” it derives from your conversations. You can view, edit and delete every memory fact and wipe conversations at any time.
3.6 Community and social
Clubs you belong to and follow, posts and comments, people you follow, messages you send, and what you have chosen to share.
3.7 Bookings
Which practitioner, venue, class, event or course you booked, when, what you paid, and whether you were checked in.
3.8 Recommendations from a coach
Where a coach you work with recommends a product to you through ORUS, we record that the recommendation was made, and the note they wrote with it. We never tell a brand who recommended its product.
3.9 Reviews
Rating, review text, photos and the display name attributed to the review.
3.10 Technical
IP address, device and browser type, app version, and error diagnostics collected by our error monitoring tool. Used to keep the service working and secure.
3.11 Cookies and similar technologies
See section 10.
4. Why we use it, and our lawful basis
4.1 Ordinary personal data
| What we do | Lawful basis |
|---|---|
| Create and run your account | Performance of a contract |
| Process orders, deliveries, returns and refunds | Performance of a contract |
| Take bookings and pass details to the provider | Performance of a contract |
| Run ORUS Credit and referrals | Performance of a contract |
| Send transactional emails (orders, password resets, booking confirmations) | Performance of a contract |
| Provide community features and messaging | Performance of a contract |
| Keep the service secure and prevent fraud | Legitimate interests: protecting our users and our business |
| Understand which products and content work, in aggregate | Legitimate interests: improving what we offer |
| Measure how the site is used with Google Analytics | Consent, given through the cookie banner |
| Handle complaints, disputes and legal claims | Legitimate interests, and legal obligation where applicable |
| Meet tax, accounting and consumer law obligations | Legal obligation |
| Send marketing emails | Consent, or the soft opt-in for existing customers. Unsubscribe any time |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can object at any time. See section 9.
Important. The bases in this table are our Article 6 bases for ordinary personal data. Health and wellbeing data, including anything read from Apple Health, is special category data and needs a second condition under Article 9. For that we rely only on your explicit consent, never on legitimate interests. Sections 4.2 and 4.3 explain this.
4.2 Health and wellbeing data
For everything listed in section 3.4, our condition for processing special category data is your explicit consent under Article 9(2)(a) of the UK GDPR.
That means:
- Each health feature stays off until you turn it on and give clear, specific consent.
- Consent is separate per feature. Turning on nutrition logging does not turn on cycle tracking, and connecting Apple Health does not share anything with a coach.
- You can withdraw consent at any time from Consent and data in the app, without affecting anything we did before you withdrew it.
- Withdrawing consent for a feature means we stop processing that data and delete it, unless we are required to keep something by law.
- We do not rely on legitimate interests for health data, and we will not use it for marketing, profiling for advertising, or automated decisions that produce legal or similarly significant effects.
We have carried out a Data Protection Impact Assessment covering these features. See section 12A.
4.3 The sources you can connect: Apple Health and WHOOP
The app can read from Apple Health on your iPhone so that it can show and interpret your own readings, and it can connect directly to a WHOOP account (section 4.3A). Those are the only two sources today. If we add another, this policy is updated before it goes live, the list below changes, and you are asked to consent to that source separately. Connecting is optional, and separate from every other health feature.
What the app asks to read, each one a separate line on the iOS permission screen that you can allow or refuse individually:
- sleep, including stages and time in bed
- heart rate variability
- resting heart rate
- respiratory rate
- sleeping wrist temperature
- steps
- active energy
- workouts
- weight
- blood pressure (systolic)
- blood pressure (diastolic)
What the app writes: a workout you log in ORUS, only if you allowed writing. Nothing else is written.
Where the readings live: On your phone. Readings are kept in a daily record on the device and are not uploaded to our servers as a stream. The home-screen widget reads the same record. iOS may wake the app in the background when a new sleep, heart or workout reading arrives so that record stays current; that refresh also stays on the phone. There is no table of Apple Health readings in our database. Apple does not tell an app which read permissions were refused; a refused type simply returns nothing.
The one time a summary leaves the phone. When you send a message to ORUS Advisor, the app attaches a summary of your latest readings so the Advisor can answer against your own baseline rather than a general average: your readiness score; last night’s sleep hours, stages, efficiency and sleep debt; heart rate variability, resting heart rate and respiratory rate, each with your recent baseline and the change against it; the direction of your sleeping wrist temperature against its baseline; active energy and steps with their change; today’s workouts as type, duration and energy; the last seven days beside the seven before them as averages of those same readings (sleep hours, readiness, heart rate variability, resting heart rate and workout minutes, with how many nights were recorded); and when the readings were last synced. That summary is used to build the reply and is sent to our AI provider under section 7. It is not stored with the conversation; the words you typed are. You can use every health feature without ever writing to the Advisor.
Coaches see none of it by default. Connecting Apple Health shares nothing with any coach, club or practitioner. Sharing a stream with a coach is a separate switch per stream on the Your coach screen, off until you turn it on, and each change is written to a consent ledger you can read.
Disconnecting is on the Wearables screen in the app. It stops the app reading Apple Health and clears the record held on your phone. Because nothing from Apple Health is held on our servers, there is no keep-or-delete question to answer. A summary already inside a stored Advisor reply stays until you wipe that conversation.
Who controls what. Apple Health is Apple’s, on your phone, under Apple’s terms with you. We do not control what it records or how accurate it is. What the app reads becomes a copy on the device that we are responsible for, under this policy. We do not use Apple Health data for advertising or marketing, we do not share it with third parties for their own purposes, we do not use it to train AI models, and we do not sell it. This is required by Apple and it is also our own policy.
4.3A WHOOP, connected directly
On the Wearables screen you can connect a WHOOP account. You are sent to WHOOP's own sign-in page, where WHOOP asks you to allow ORUS access; you can refuse, and you can revoke it later from either side.
What we ask WHOOP for, each a separate permission on WHOOP's screen:
- sleep: hours asleep, efficiency and respiratory rate
- recovery: WHOOP's recovery score, heart rate variability and resting heart rate
- daily strain and energy
- workouts: the sport and how long
- your WHOOP user id, so WHOOP's change notices can be matched to your account
What our server holds: the connection itself, meaning an access token, a refresh token and your WHOOP user id, in a table no app or website session can read. Where the readings live: On your phone. Our server holds the connection and fetches readings only when your phone asks, handing them straight to the phone's daily record; no reading is kept on the server. When a record changes, WHOOP sends our server a notice carrying only the record's id and kind; our server then asks your phone to fetch the latest, and the readings still go to the phone alone.
Disconnecting is on the same Wearables screen. It asks WHOOP to revoke our access and deletes the connection from our server. Because no reading is held on the server, there is nothing else to delete there; the copy on your phone clears with the rest of your health record.
Who controls what. WHOOP is WHOOP's, under WHOOP's terms with you. What the app fetches becomes a copy on your device that we are responsible for, under this policy, and everything said above about Apple Health data applies to it: no advertising, no third parties for their own purposes, no model training, no sale.
5. ORUS Advisor and automated processing
The Advisor uses your messages, and any wellness profile and memory facts you have given it, to generate responses and suggest products and content. The Advisor Terms describe it in full.
- Your messages are sent to our AI provider to generate a response, and to a second provider that turns each message into a numerical form so the right products and answers can be found. See section 7.
- Where you have enabled health features or connected Apple Health, the Advisor may include the summary described in section 4.3 in the context it sends to our AI provider, so that it can answer against your own baseline rather than a general average. You can use the health features without using the Advisor.
- The Advisor produces suggestions, not decisions. We have assessed it against Article 22 of the UK GDPR and concluded it does not carry out solely automated decision-making producing legal or similarly significant effects: it recommends content and products, a human is never bound by its output, and it is not used to assess your health, set prices for you, price risk, or determine eligibility for anything.
- Prices are never personalised. Everyone sees the same price for the same item in the same market.
- The Advisor is not a clinician. Its output is not medical advice.
- You can delete individual memory facts, or all of them, and wipe your conversation history.
If you have not enabled health features or connected Apple Health, the Advisor does not have access to health data.
7. Our service providers
Everyone who handles data on our behalf, or receives your IP address when a page loads, as the code stands today. This table is generated from the same register our build checks against the code, so a provider cannot be added to the product without appearing here.
| Provider | What they do | Where | Transfer basis |
|---|---|---|---|
| Supabase | Authentication and the database, including the health data you log in the app. | EU | Within adequacy |
| Shopify | The storefront, checkout, card payments and order fulfilment for products. | US / global | IDTA with transfer risk assessment |
| Vercel | Hosting for the site and the app's server, plus aggregate, cookieless measurement of page speed and how many people visit each page. | US / global edge | IDTA with transfer risk assessment |
| Anthropic | Generates the ORUS Advisor's replies from your messages, and the console assistant's drafts for club owners. | US | IDTA with transfer risk assessment |
| Voyage AI | Turns each Advisor message into a numerical form so the Advisor can find the right products and answers. Receives the text of the message. | US | IDTA with transfer risk assessment |
| OpenAI | Turns the Advisor's reply into speech, only when you switch Spoken replies on in the app. Receives the reply text, never your message. | US | IDTA with transfer risk assessment |
| Stripe | Payments and payouts for bookings, tickets, courses and clubs, and the identity verification of hosts who take money. | US / EU | IDTA with transfer risk assessment |
| Mux | Hosts course videos. When you play a lesson, Mux receives your IP address and a playback token tied to your enrolment. | US | IDTA with transfer risk assessment |
| Resend | Sends our transactional email: orders, bookings, club invitations and account messages. | US | IDTA with transfer risk assessment |
| Klaviyo | Holds the newsletter list: the email address you give the newsletter form, and nothing else. | US | IDTA with transfer risk assessment |
| Google Analytics | Measures how the site is used, only if you accept cookies. Paid orders are reported with an order id and value, and linked to your visit only if you accepted. | US | IDTA with transfer risk assessment |
| WHOOP | If you connect a WHOOP, our server holds the connection to your WHOOP account (an access token and your WHOOP user id) and fetches your recovery, sleep, strain and workout records from WHOOP when your phone asks, passing them to the phone without storing them. WHOOP also tells our server when one of those records changes, by id only. | US | IDTA with transfer risk assessment |
| Expo | Delivers push notifications to the app: the device token and the text of the notification. | US | IDTA with transfer risk assessment |
| Your browser's push service | Carries web notifications you turn on, through Apple, Google or Mozilla depending on your browser. | US / global | IDTA with transfer risk assessment |
| Apple | Distributes the app through TestFlight and the App Store, and carries app notifications. | US / global | IDTA with transfer risk assessment |
| Sentry | Error monitoring and diagnostics, which may include an IP address. | US / EU | IDTA with transfer risk assessment |
| Google Workspace | Our business email. | EU / US | IDTA with transfer risk assessment |
| Royal Mail and carriers | Deliver orders. | UK | N/A |
| OpenStreetMap | The map on a class or event page loads from openstreetmap.org, which receives your IP address when the map loads. | UK | N/A |
| Fontshare | The site's typeface loads from api.fontshare.com, which receives your IP address. | Global | IDTA with transfer risk assessment |
| Unsplash | Cover photographs on some journal articles load from images.unsplash.com, which receives your IP address. No personal data is sent. | US | N/A |
| postcodes.io | Turns a club venue's postcode into map coordinates. A venue's address, never a member's. | UK | N/A |
| Spotify, YouTube and Apple Podcasts | A podcast episode embedded in a community post plays through their players, under their terms, when you press play. | US / global | N/A |
Anthropic. Your messages to the Advisor are processed to generate a response. Under our agreement, Anthropic does not retain them beyond the request lifecycle and does not use them to train models. Where you have connected Apple Health, this may include the summary described in section 4.3.
Each processes data on our instructions under a written contract with confidentiality and security obligations.
International transfers. Some providers are outside the UK. Where that happens we rely on UK adequacy regulations, or on Standard Contractual Clauses with the UK International Data Transfer Addendum, together with a transfer risk assessment. You can ask us for details.
8. Practitioners, venues and course providers
When you book a class, session or consultation, we pass the provider the information they need to deliver it: your name, what you booked and when, and anything you choose to tell them. Reaching you is done through ORUS messaging; we do not hand a host your email address or phone number.
From that point the provider is a data controller in their own right for the information you give them and anything they record about you, including any health information you share as part of their service. Their own privacy policy applies to that, not ours. If you want to know how a practitioner handles your data, ask them directly.
There is a narrow exception. Where a provider records something into ORUS systems on our instructions and for our purposes, completing a booking record for example, they act as our processor for that step, under written terms that meet Article 28 of the UK GDPR.
At the moment of booking itself, we and the provider may determine purposes together. Where that is so, we are joint controllers for that step within the meaning of Article 26, and the essence of our arrangement is this: we are responsible for telling you what happens at booking and for handling requests about our booking records; the provider is responsible for everything they record in delivering the service. Either of us will help you reach the other. You may exercise your rights against either of us.
We require providers to comply with data protection law, but we do not control what they do with the information you give them.
Connecting Apple Health does not give any coach, club or practitioner access to it. Where you work with a coach through ORUS they see only what you choose to share with them, stream by stream, and you can withdraw that at any time.
9. Your rights
You have the right to:
- Access a copy of the data we hold about you
- Rectify anything inaccurate
- Erase your data (the “right to be forgotten”)
- Restrict how we use it
- Object to processing based on legitimate interests, and to direct marketing at any time
- Portability: receive your data in a machine-readable format
- Withdraw consent at any time, including for any health feature or for Apple Health
- Not be subject to solely automated decisions with legal or similarly significant effects
Several of these are built into the product rather than requiring a request:
- Advisor memory: review, edit or delete any individual memory fact at /me/advisor
- Advisor conversations: wipe your entire history at /me
- Health data: export a diary or delete it by area from the Consent and data screen in the app, without deleting your account
- Apple Health: connect or disconnect, and see which types the app reads, from the Connected devices screen in the app
- Sharing with a coach: switch each stream on or off from the Your coach screen
- Account closure: from the app (Account, then Delete account, reversible for 30 days), or by emailing us
For anything else, email hello@orus.uk. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or 0303 123 1113. We would rather you came to us first.
10. Cookies and similar technologies
- Strictly necessary: Supabase authentication tokens and Shopify cart cookies, plus security. The site cannot work without these and they do not require consent.
- Functional: your consent preference (orus_consent and its date), region and currency selection, referral attribution (orus_ref), and the campaign you first arrived from (orus_utm), used only to attribute your own order.
- Analytics, only if you accept: Google Analytics sets its cookies (_ga and _ga_*) to measure how the site is used. Decline and no analytics script loads and no analytics cookie is set. Paid orders are reported to Google Analytics with an order id and value from our server; they are linked to your visit only if you accepted cookies.
- Aggregate measurement without cookies: Vercel counts page views and measures page speed without identifying you and without setting a cookie.
- We do not use advertising cookies or third-party tracking pixels.
- Error monitoring collects technical diagnostics, which may include an IP address.
You can change your choice by clearing the orus_consent cookie in your browser, after which the banner asks again, and you can control cookies generally in your browser.
11. How long we keep things
| Data | Retention |
|---|---|
| Account data | Until you close your account, then deleted within 30 days |
| Health and wellbeing data on our servers | Until you delete it, or until you withdraw consent for that feature |
| Apple Health readings | On your phone only, until you disconnect or delete the app |
| Advisor conversations and memory | Until you delete them, or account closure |
| Order and transaction records | 6 years from the end of the financial year of the sale (tax law) |
| Booking records | 6 years, for tax and to defend claims |
| Reviews | While your account is active, or until you ask us to remove one. Removed on account closure unless the review is anonymised |
| Community posts and messages | Until you delete them or close your account; content you posted is then attributed to a deleted account rather than to you |
| Credit ledger | 6 years from the end of the financial year of the transaction |
| Coach recommendation records | While the coaching relationship is active, then 12 months |
| Complaints and disputes | 6 years from resolution |
| Marketing consent records | 6 years from withdrawal, as evidence of consent |
| Consent records for health features and coach sharing | 6 years from withdrawal, as evidence of explicit consent |
| Error diagnostics | 90 days |
Where we must keep a record for tax purposes we keep the minimum needed and restrict access to it.
12. Other markets
Where we sell into a market outside the United Kingdom, local data protection law may give you additional or different rights. Each market we operate in has its own annex at the end of this policy, setting out who the controller is there, which law applies, who your local contact is, how breaches and complaints are handled, and the basis on which data leaves that country. Where an annex conflicts with the main policy, the annex applies for that market.
Markets with an annex today: Malaysia. Where you deal with more than one ORUS store, the annex for each market applies to the data collected by that store.
12A. Data Protection Impact Assessment
We have carried out a Data Protection Impact Assessment covering the health features, the Apple Health connection described in section 4.3, the ORUS Advisor, and sharing with a coach, because each involves either special category data or profiling. We review it when we materially change any of those features, and before adding a new connected source.
13. Security
- Traffic between your device and our servers is encrypted with TLS.
- The database is encrypted at rest.
- Health data you log is stored on EU-hosted Supabase servers and isolated per user by row-level security, so your rows cannot be read by another account.
- Apple Health readings never reach our servers, so there is no server copy to secure; the copy on your phone sits inside the app’s own protected storage.
- Access by our staff is limited to those who need it, and health data access is restricted further.
- We use a managed authentication provider rather than building our own password handling.
No system is perfectly secure.
If a personal data breach occurs, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it where the breach is likely to result in a risk to people’s rights and freedoms. Where the breach is likely to result in a high risk to you, we will tell you directly and without undue delay, and explain what happened, what we are doing about it, and what you can do to protect yourself.
14. Children
ORUS is for adults. You must be 18 or over to hold an account. We do not knowingly collect data from anyone under 18. If you believe we have, contact hello@orus.uk and we will delete it.
15. Changes to this policy
The current version is always at this URL with the date it was last updated. If we make a material change, particularly to how we handle health data or Apple Health, or add a new service that handles your data or a new source you can connect, we will tell you by email or in the app before it takes effect, and where the change requires it we will ask for fresh consent.
16. Contact
Eight Hours Group Ltd (trading as ORUS) · Company number 17031572 · 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ · Email: hello@orus.uk · Account deletion: same address, subject “Account deletion request”
Annex MY: Malaysia
This annex applies to personal data collected through the ORUS Malaysia store, the app where you use it as a person in Malaysia, and ORUS classes, events and bookings taking place in Malaysia. Malaysia’s Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024, applies to that data rather than the UK GDPR.
MY.1 Who the controller is
Until a Malaysian operating company is incorporated and named in this annex, Eight Hours Group Ltd is the data controller for the Malaysia market, at the address in section 16. When a Malaysian operating company takes over that role we will update this annex and tell affected users before the change takes effect.
MY.2 How the law differs from the UK
- The Act is consent-led. There is no general “legitimate interests” basis, so where the main policy relies on legitimate interests we rely instead on your consent or on a specific ground in the Act.
- Sensitive personal data, which includes health data and anything read from Apple Health, requires your explicit consent. This matches how we already treat it.
- The Act uses the term “data controller”, which replaced “data user” under the 2024 Amendment Act.
- Your rights of access, correction, withdrawal of consent, and to limit processing come from the Act. The rights listed in section 9 are given effect in Malaysia through the equivalent provisions.
MY.3 Your local contact and our Data Protection Officer
Where the Act requires it, we appoint a Data Protection Officer who is resident in Malaysia or readily contactable there, and who is proficient in Bahasa Melayu and English. Their contact details are published on the Malaysia store and notified to the Commissioner as required. Until that appointment is published, contact hello@orus.uk, marked for the attention of the Malaysia data protection contact.
We keep the appointment under review against the thresholds in the Act, which include processing the personal data of a large number of people, processing sensitive personal data at scale, and carrying out regular and systematic monitoring. Continuous health tracking is capable of meeting the last of these.
MY.4 Data breaches
Where a breach affecting Malaysian personal data causes or is likely to cause significant harm, or affects a large number of people, we notify the Commissioner as soon as possible and in any event within the period the Act requires, and we notify affected individuals where the Act requires it. This is a separate route from the UK notification described in section 13, and where a breach affects both markets we make both notifications.
MY.5 Data leaving Malaysia
Our infrastructure is hosted outside Malaysia: the database in the EU, and some providers in the United States, as set out in section 7. Before transferring Malaysian personal data we carry out a transfer impact assessment and rely on the grounds available under the Act, including your consent where required, and contractual protections with each recipient equivalent to those described in section 7.
MY.6 Apple Health
Section 4.3 applies in Malaysia, with two differences: your explicit consent is required for the sensitive personal data read, and the transfer of the Advisor summary outside Malaysia is covered by MY.5. Apple remains an independent party in the sense described in section 4.3, under its own terms with you.
MY.7 Complaints
Raise anything with us first at hello@orus.uk. If you are not satisfied, you may complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi), whose contact details are at pdp.gov.my. The Information Commissioner’s Office in the United Kingdom does not supervise processing carried out under this annex.
MY.8 Language
This policy is provided in English. Where we publish a Bahasa Melayu translation and there is a conflict, the English version governs, except where Malaysian law requires otherwise.
Version 3.0 · Effective 7 September 2026 · Eight Hours Group Ltd, trading as ORUS · The current version of this policy is always at this address. Previous versions are available on request from hello@orus.uk.