Privacy Policy

Apeachure Science · UEN 53523038M · Last updated 10 May 2026

Overview

This policy explains what data Apeachure Science collects when you use our services, how we use it, where it's stored, who can access it, and what control you have over it.

Apeachure Science is a Singapore-registered business (UEN 53523038M) operating two AI assistant services:

This policy applies to both services and to billing data we collect when you subscribe. Where a section applies to only one service, we say so explicitly.

We comply with Singapore's Personal Data Protection Act 2012 (PDPA) and apply equivalent protections globally. If you are subject to additional laws (e.g. GDPR), those rights apply on top of what's described here.

1. What We Collect

1.1 Account information (all services)

When you onboard with any Apeachure Science service, we collect:

1.2 Brobot — health & fitness data

If you subscribe to Brobot, we additionally collect:

If you connect a wearable device or fitness platform, we collect data from it daily:

SourceWhat We Collect
GarminSteps, heart rate, HRV, sleep (hours + stages), stress, VO2max, training load, calories, SpO2, body battery
WhoopHRV, recovery score, strain, sleep performance, respiratory rate
OuraHRV, readiness score, sleep stages, resting HR, SpO2, stress, activity, workouts
Samsung HealthSteps, distance, calories, heart rate, HRV, sleep + stages, workouts, SpO2, weight
Apple HealthSteps, distance, heart rate, HRV (SDNN), sleep + stages, workouts, weight
StravaWorkouts only: activity name, sport type, duration, distance, elevation, heart rate, power. No sleep or recovery data.
TrainingPeaksPlanned and completed workouts, Training Stress Score (TSS), fitness metrics (CTL/ATL/TSB)

When you send Brobot a photo or description of a meal, we estimate the macronutrient content (calories, protein, carbs, fats) and log it. Brobot also maintains a daily session log of key topics discussed during coaching to maintain continuity across sessions.

1.3 Wheatley — assistant data

If you subscribe to Wheatley, we additionally collect (with your authorisation):

1.4 Billing & payment information

When you subscribe to any service, we collect billing data necessary to process your payment:

We do not see, store, or process your full card number, expiry, or CVV on our servers. Card details are entered directly into a payment form hosted by our PCI-DSS Level 1 certified payment processor, Airwallex (Singapore) Pte. Ltd. Airwallex tokenises your card and returns only a non-sensitive reference to us. Your card data never enters apeachure.science infrastructure.

2. How We Use Your Data

Your data is used solely to provide the services you've subscribed to:

We never use your data for advertising, never sell it to third parties, and never aggregate it across customers for any purpose.

3. Where Your Data is Stored

On our server

Your account data, service-specific data (health, calendar, contacts, conversations), and per-customer secrets (e.g. OAuth tokens, encrypted cards for Wheatley) are stored as files on a private server operated by Apeachure Science. Files are organised per-customer and isolated from other customers' data.

Sensitive material at rest — payment cards used by Wheatley for shopping, personal interaction logs, and the underlying disk volume — is encrypted (AES-256). The volume is unlocked at boot and remains mounted while the server is running. If the server is powered off or the drive is removed, the data is encrypted and inaccessible without the passphrase.

Airwallex (billing data)

When you subscribe, your card details are submitted directly to Airwallex (Singapore) Pte. Ltd., which is PCI-DSS Level 1 certified. Airwallex stores your card on its own infrastructure and provides us only a tokenised reference. Subscription metadata (status, billing email, last-four digits) is held by us; the underlying card data is held by Airwallex under its own privacy policy.

Google Sheets (Brobot — coach collaboration, opt-in)

If you opt into coach collaboration, a Google Sheet containing your daily Brobot health metrics is stored in Google Drive and shared with Brobot's service account, your personal trainer (if you've approved this), and you. Brobot writes to specific columns only and never modifies your trainer's columns, formulas, or formatting.

Google Drive (Brobot — Samsung Health)

If you use Samsung Health with Brobot, your phone exports a daily health backup to a Google Drive folder you share with Brobot's service account. The folder and its contents remain in your Google Drive under your ownership.

Google services (Wheatley)

Wheatley's calendar and contact features operate on your own Google account via OAuth — the underlying data lives in your Google Calendar and Google Contacts under your ownership. Wheatley reads, writes, and updates entries on your behalf using the access you grant; it does not maintain a parallel copy in our infrastructure (a denormalised cache of contacts you've enrolled is kept locally for performance, but Google Contacts remains the source of truth).

4. Third-Party Services

Apeachure Science relies on the following third-party services to function. Each receives only the minimum data necessary for its role:

ServiceRoleWhat It Receives
Anthropic (Claude AI)Powers the AI agents (Brobot & Wheatley)Your messages, contextual data summaries, profile, and recent history during active sessions and scheduled summary generation
AirwallexPayment processorCard details (entered directly into Airwallex's hosted form), billing identity, transaction amounts, currency, and merchant of record (Apeachure Science)
Google CloudDrive, Sheets, Calendar, Contacts APIsFor Brobot: health data written to your coach sheet, Samsung Health exports read from your Drive folder. For Wheatley: calendar events, contacts data, on your behalf via OAuth.
CloudflareStatic site hosting and secure tunnel for OAuth callbacksStatic page content (no personal data); OAuth authorization codes pass through during integration setup (not stored)
Whoop / Oura / Strava / Garmin / TrainingPeaks / Apple Health (HAE) / Samsung HealthHealth data providers (Brobot)OAuth tokens or webhook secrets exchanged to fetch your health data on your behalf
Shopify-platform merchantsOnline retailers (Wheatley shopping)Shipping address, billing identity, card details (entered via Wheatley's automated checkout). Each merchant's privacy policy governs subsequent handling.
WhatsApp / Discord / TelegramMessage deliveryYour inbound and outbound messages with the assistant on whichever channel you've connected

About the AI

Brobot and Wheatley are powered by Anthropic's Claude AI. When you interact with either assistant or when scheduled tasks generate output, your data is sent to Anthropic's servers for processing. Anthropic's data handling practices are governed by their own privacy policy and terms of service. Apeachure Science does not train any AI models on your data.

5. Data Sharing

With your trainer (Brobot, opt-in only)

If you opt into coach collaboration during Brobot onboarding, we share your daily health and nutrition metrics with your personal trainer via a shared Google Sheet. You are always asked for explicit consent before this is set up. Your trainer sees body weight, nutrition totals, steps, cardio minutes, sleep hours, resting heart rate, HRV, and a brief note summarising what you discussed with Brobot that day. Your trainer does not have access to your full conversation history, your personal profile beyond what appears in the sheet, or any other customer's data.

With merchants (Wheatley shopping)

When Wheatley places an order on your behalf, the shipping address, billing identity, and card details necessary for that order are submitted to the merchant's checkout. Each merchant's own privacy policy governs how they subsequently handle that data.

Between customers

We enforce strict customer isolation. Your data is never shared with, referenced by, or visible to any other customer. The agents will not confirm or deny the existence of other customers. These isolation rules are built into the agents' core operating instructions and cannot be overridden.

With Apeachure Science staff

The operator of Apeachure Science has access to the server where your data is stored, for purposes of running and maintaining the service. The operator can view your files for troubleshooting but does not routinely access your conversations or data outside of explicit support requests.

For legal compliance

We may disclose data when required by Singapore law, by a valid court order, or to comply with applicable tax and accounting obligations. We will, where lawful, notify you before doing so.

6. Data Retention

Service data (account information, health/calendar/conversation history, etc.) is retained for as long as your subscription is active.

7. Security

We take the following measures to protect your data:

Audit logging

Every data sync, coach sheet update, and billing event is logged to an audit file with a timestamp, customer ID, and summary of what was accessed or written. This allows us to answer "when was my data last accessed?" if you ask. Deletion events are also logged for accountability.

8. Your Rights

Export your data

You can ask the assistant for a copy of all your stored data at any time — say something like "can I have a copy of my data?" and we'll generate a zip containing your profile, service-specific data (health/calendar/contacts/conversations), and billing summary. The zip is delivered to your primary channel. OAuth tokens and Wheatley's encrypted cards are excluded for security; your Google Sheet (if applicable) is already in your Google Drive and accessible directly.

Correct your data

If any data we hold about you is inaccurate, you can ask the assistant to correct it, or email us (see §12).

Disconnect an integration

You can disconnect any integration at any time by asking the assistant. This revokes our access to that service and deletes the stored tokens. Data already collected remains in your files unless you request deletion.

Disconnect your trainer (Brobot)

If you no longer want your trainer to see your data, remove their access from the Google Sheet directly (via Share settings), or ask Brobot/the operator to update your configuration.

Delete your data

You can request permanent deletion of your service data at any time by telling the assistant ("delete my data" or "remove my account"). After confirmation, we will:

Billing records are retained for the legally-required five years (see §6) but are not used for any purpose other than tax/accounting compliance.

Pause your account

If you'd like to take a break without deleting everything, ask the assistant to "pause" your account. This stops all scheduled jobs while keeping your data intact. Billing pauses or continues based on the option you choose.

9. Children

Apeachure Science services are not designed for use by anyone under 18. We do not knowingly collect data from minors. If you believe a minor has been onboarded, please contact us immediately at the email in §12.

10. Changes to This Policy

We may update this policy as our services evolve. Material changes will be communicated to active customers via their primary communication channel before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

11. International Transfers

Apeachure Science operates from Singapore, but our third-party processors (Anthropic, Google Cloud, Cloudflare, Airwallex, your wearable providers) operate globally. Where data is transferred outside Singapore, we rely on each processor's own safeguards (contractual clauses, adequacy decisions, and equivalent measures) to ensure your data continues to receive protection consistent with the PDPA.

12. Contact

If you have questions about this policy, your data, or your rights, contact us:

For urgent service-level requests (delete my data, pause my account, disconnect an integration), the fastest path is to message the assistant directly on your subscribed channel.