Privacy Policy — Ferry

Introduction

This Privacy Policy discloses the privacy practices for Ferry (the "App"), a mobile application published by KOODALABS LLC ("Koodalabs," "we," "us," or "our") and distributed through the Apple App Store. It supplements the Koodalabs Privacy Policy governing https://koodalabs.com/ and, where the two conflict with respect to the App, this policy controls.

Ferry has a single purpose: to copy health and fitness records that already belong to you from your Google Health account into Apple Health on your iPhone, so that the data recorded by your wearable device sits alongside the rest of your health information. Because that purpose involves health data, this policy describes in specific terms what the App reads, where it sends it, and what it does not do.

Summary

• The App reads health data from your Google Health account only after you grant permission through Google's own sign-in screen.

• The App writes that data to Apple Health on the same device.

• Koodalabs operates no server. Your health data is never transmitted to, stored on, or processed by any system operated by Koodalabs or by any third party.

• Your health data is never used for advertising, marketing, profiling, resale, or model training, and is never disclosed to data brokers.

• You can revoke the App's access at any time from your Google Account, and delete the copied records at any time from the Apple Health app.

Types of Information Collected

Health and Fitness Information. With your explicit authorization, the App reads the following categories of records from your Google Health account:

• Steps, distance travelled, floors climbed, and active energy burned

• Total energy expenditure, from which basal energy is derived

• Heart rate, including intraday measurements recorded throughout the day

• Resting heart rate

• Sleep sessions, including the light, deep, REM, and awake stage breakdown

• Exercise sessions, including type, duration, distance, and energy burned

• Body weight and body fat percentage

• Water intake and dietary energy

• The creation date of your Google Health account, used solely to determine how far back your history extends

Authentication Credentials. The App receives OAuth 2.0 access and refresh tokens from Google. These tokens authorize the App to read the categories above and nothing else.

Purchase Information. If you purchase a subscription, Apple processes the transaction. The App uses RevenueCat, Inc. as a subscription management provider, which receives an anonymous, randomly generated identifier and the status of your subscription. RevenueCat does not receive, and has no access to, any health or fitness data.

Information Not Collected. The App does not collect your name, email address, postal address, telephone number, precise or coarse location, contacts, photographs, advertising identifiers, or device identifiers. The App contains no analytics, attribution, crash-reporting, or advertising software development kits.

Collection Methods and Use of Information

Health and fitness information is read directly from Google's servers by the App running on your device, over an encrypted connection, using the authorization you granted. It is used for one purpose: to create corresponding records in Apple Health on that same device. It is held in device memory only for the duration of a synchronization and is not written to any file, database, log, or cache controlled by Koodalabs.

Authentication tokens are stored in the iOS Keychain, the encrypted credential store provided by Apple, and are used only to authenticate requests to the Google Health API. They are removed from the Keychain when you disconnect your account within the App.

The App records, on your device only, the date of the last successful synchronization and a per-metric history of recent synchronization runs, so that it can display that history to you and determine which dates still require synchronization. This record contains no health values and is deleted when the App is removed.

Release of Information

Koodalabs does not sell, rent, lease, trade, or otherwise disclose your health or fitness information to any third party. Because that information never leaves your device except to be written into Apple Health, there is no mechanism by which such disclosure could occur.

We may disclose information in our possession where required to do so by law, subpoena, or court order, or where necessary to protect the rights, property, or safety of Koodalabs or others. As described above, health and fitness information is not in our possession.

Google User Data and Limited Use

Ferry's use and transfer of information received from Google APIs to any other application adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Specifically, and in accordance with those requirements:

• Data obtained through the Google Health API is used solely to provide and improve the user-facing feature described in this policy, namely synchronization into Apple Health.

• Such data is not transferred to any third party except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition following notice to affected users.

• Such data is not used for serving advertisements, and is not sold.

• No human at Koodalabs reads such data, except where the user has given affirmative consent for a specific support request, where required for security purposes or to comply with applicable law, or where the data has been aggregated and de-identified.

Apple Health Data

The App writes to Apple Health using HealthKit. In accordance with Apple's requirements, information obtained through HealthKit is not used for advertising, marketing, or other use-based data mining, and is not disclosed to third parties. The App requests permission to read from HealthKit only to verify what it has previously written and to avoid creating duplicate records.

Records the App writes to Apple Health are stored by Apple on your device under Apple's own privacy protections. Deleting the App does not automatically delete those records; see "Updating and Correcting Information" below.

Updating and Correcting Information

Revoking access. You may disconnect your Google Health account from within the App at any time, which erases the stored authentication tokens. You may additionally, or alternatively, revoke the App's access from the "Third-party apps & services" section of your Google Account at https://myaccount.google.com/. Revocation takes effect immediately and permanently prevents any further reading of your data.

Deleting synchronized records. Health records the App wrote to Apple Health remain under your control in the Apple Health app, where they may be reviewed and deleted individually or in bulk by source. Because these records are stored by Apple on your device, Koodalabs cannot delete them on your behalf.

Correcting source data. The App does not alter the values it reads. Records that are inaccurate at the source will be inaccurate after synchronization; corrections should be made in the application that produced them.

User Choices on Collection and Use of Information

All access to health data is opt-in. The App cannot read anything until you complete Google's authorization screen, and cannot write anything until you grant HealthKit permission through Apple's system dialog. Both permissions are granular and may be limited or withdrawn at any time. Declining or withdrawing permission does not disable any other function of the App, though synchronization of the affected categories will stop.

Security of Information

Communication between the App and Google's servers uses Transport Layer Security. Authentication tokens are held in the iOS Keychain, which is encrypted by the operating system and protected by your device passcode and biometric authentication. The authorization flow uses Proof Key for Code Exchange (PKCE), so that no client secret is embedded in the App and an intercepted authorization code cannot be redeemed by another party.

No method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but note that the architecture described here materially limits exposure: there is no Koodalabs server holding your health data that could be breached.

Cookies

The App does not use cookies. The Google sign-in screen is presented by Apple's authentication service and is subject to Google's own privacy practices.

Privacy Policies of Third Party Sites

The App interacts with Google (for health data) and Apple (for health storage and payment processing), and uses RevenueCat for subscription management. Each is governed by its own privacy policy, which we encourage you to review:

• Google Privacy Policy — https://policies.google.com/privacy

• Apple Privacy Policy — https://www.apple.com/legal/privacy/

• RevenueCat Privacy Policy — https://www.revenuecat.com/privacy/

This Privacy Policy does not apply to those companies' practices, over which we have no control.

Children

The App is not directed to children under the age of 13, and we do not knowingly collect information from them. If you believe a child has provided information to us, please contact us at the address below.

Your Rights and Choices

Residents of California, and of certain other jurisdictions, have the right to request disclosure of the categories and specific pieces of personal information collected, the right to request deletion, and the right not to be discriminated against for exercising these rights. Koodalabs does not sell personal information as that term is defined under the California Consumer Privacy Act.

Because health and fitness information processed by the App never reaches Koodalabs, we hold no such information to disclose or delete. Requests concerning information held by Google or Apple should be directed to those companies.

Your General Data Protection Regulation ("GDPR") Rights

Where the GDPR applies, you have the right to access, rectify, erase, restrict processing of, and port your personal data, and to object to processing. The lawful basis for the App's processing of health data, which constitutes a special category of personal data under Article 9, is your explicit consent, given through the Google authorization screen and the Apple Health permission dialog. That consent may be withdrawn at any time by the means described above, without affecting the lawfulness of processing carried out before withdrawal.

You also have the right to lodge a complaint with a supervisory authority in your country of residence.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes affecting how health data is handled will be reflected in the App before taking effect. The date below indicates when this policy was last revised.

Contact

Questions about this Privacy Policy, or about the App's handling of health data, may be directed to:

KOODALABS LLC

401 EAST LAS OLAS BLVD, STE 130 FORT LAUDERDALE, FLORIDA 33301

privacy@koodalabs.com

Last Updated: August 28, 2026