Skip to main content
Back to Metric
Orion Designs LLC

Privacy Policy

Last Updated: July 27, 2026
Effective Date: August 1, 2026

Orion Designs LLC ("Orion," "we," "our," "us") operates Metric, a health and fitness application. This Privacy Policy explains how Metric collects, uses, stores, and discloses information when you use the Metric iPhone and Apple Watch apps, widgets, website, APIs, and related services (the "Services").

This Policy applies to Metric. It does not describe unrelated products or services, and it does not replace the privacy notices of Apple, Garmin, or other third parties whose services you choose to connect.

1. Who Is Responsible

Orion Designs LLC is responsible for the personal information described in this Policy. Our mailing address is 6513 Harold Ave, Cocoa, FL 32927, USA. Privacy questions and requests may be sent to privacy@joinmetric.com.

2. Information Metric Collects

Account, Profile & Purchase Information

  • Authentication information. Supabase Auth and, when selected, Sign in with Apple process identifiers, session credentials, and information such as your e-mail address. Orion does not receive your Apple ID password.
  • Profile information. Username, first and last name, e-mail address, biography, avatar, preferred language, account privacy setting, social connections, and pending follow relationships.
  • Subscription and purchase information. Apple may provide Metric with App Store transaction and subscription records, including product and transaction identifiers, purchase and expiration dates, entitlement status, price, currency, and related App Store notification data. Apple processes payment-card information; Orion does not receive full payment-card details.

Health, Fitness, Nutrition & Location Information

  • Apple Health. With the permissions you grant in iOS, Metric may read health and activity information from HealthKit, including workouts, workout routes, steps, distance, pace, energy, heart rate, resting heart rate, heart-rate variability, cardio fitness, sleep, body measurements, blood-oxygen data where available, and nutrition data. Metric may also write workouts and nutrition entries to Apple Health when you use those features.
  • Metric health records. Depending on the features you use, Metric may send selected workout and health information to Orion's backend, including workout dates and duration, route or starting-location data, distance, pace, calories, heart rate, steps, device source, VO2 max, resting heart rate, heart-rate variability, body composition, sleep score, biological-age estimates, ageing-rate history, and related derived metrics.
  • Nutrition records and iCloud. Food names, dates, meal type, serving size, calories, macronutrients, micronutrients, caffeine, and nutrition goals are stored in Metric's local Core Data store. Metric uses Apple's CloudKit through your iCloud account to sync those records across your Apple devices when iCloud is enabled.
  • Workout location. Metric may collect precise location and route points while recording supported workouts. Location can also be included in a workout you upload, a route you save or share, or a live workout when you enable live location sharing. Route privacy controls can hide points near the beginning and end of a route, but sharing any route can still reveal sensitive places.

Garmin Connect Information

Connecting Garmin is optional. If you connect Garmin Connect, Metric receives and stores OAuth access and refresh tokens, token-expiration dates, the granted scope, a Garmin user identifier, and the date you connected. Garmin may send Metric activity summaries and details such as activity identifiers, workout type and name, dates, duration, distance, pace, calories, heart rate, steps, device name, starting location, samples, laps, and other fields included in Garmin's activity payloads.

Disconnecting Garmin asks Garmin to revoke Metric's access and removes the stored Garmin connection credentials from your Metric profile. It stops future Garmin imports, but it does not automatically remove workouts or activity details already imported into Metric, or information retained by Garmin under Garmin's own policies.

Social & Live Workout Information

  • Social content. Posts, workout summaries, photos, captions, post layouts, comments, likes, follows, saved routes, route comments, achievements, and notification preferences.
  • Live workouts. Session identifiers, workout type and title, status, elapsed time, distance, calories, heart rate, pace, current location and route when sharing is enabled, viewer join and leave events, reactions, comments, and engagement summaries. Metric uses Ably to transmit live workout state, presence, reactions, and comments between authorised participants. Orion's backend also stores live-session records, the latest snapshot, view events, reactions, comments, and engagement summaries.
  • Public or shared information. Information you make visible through a profile, post, route, live workout, or share link may be seen by the audience shown in the App. Live workouts are currently shared with authorised followers.

AI Feature Information

When you use server-backed Cortex, AI nutrition analysis, or AI-generated training plans, Metric sends OpenAI the information needed to provide the requested feature. Depending on your request, this may include prompts, meal descriptions or photographs, generated responses, training goals and preferences, recent workout summaries, and health, fitness, sleep, nutrition, or body-measurement information returned by Metric tools. Orion also sends a pseudonymous safety identifier derived from your Metric user identifier.

Server-backed Cortex uses OpenAI response storage to maintain conversation continuity. AI nutrition requests and training-plan requests use separate server-backed processing. If you select Apple Intelligence for Cortex and it is available, Cortex chat processing occurs on device; AI nutrition analysis and AI-generated training plans still use OpenAI.

Device, Communications & Service Information

  • Device platform, App version, preferred locale, push-notification token, notification preferences, and technical request or error information produced when the Services run.
  • E-mail address and name used for transactional messages. Metric uses Resend to deliver messages such as welcome e-mails. Resend open tracking may record that an e-mail was opened, together with related delivery and message metadata.
  • If you grant Contacts permission, Metric reads names and phone numbers on device so you can choose a person to invite through Messages. The contact picker does not upload your address book to Orion's backend.
  • The public website does not provide Metric account sign-in. Website and hosting systems may still process routine request information such as IP address, user agent, requested URL, timestamps, and server errors when pages or share links are requested.

3. How We Use Information

PurposeExamplesTypical Basis
Provide the ServicesAuthenticate users, sync workouts, store nutrition entries, operate social features, and deliver purchasesContract
Process health and location informationHealth dashboards, workout recording, routes, biological-age insights, and live location sharingConsent; Contract where permitted
Connect third-party servicesImport Garmin activities and sync nutrition records through CloudKitConsent; Contract
Provide AI featuresCortex, nutrition estimates, and personalised training plansConsent for sensitive information; Contract where permitted
Communicate with youTransactional e-mails, push notifications, account notices, and support repliesContract; Consent; Legitimate interests
Protect and improve the ServicesDebugging, abuse prevention, security, reliability, and feature supportLegitimate interests; Legal obligation
Comply with lawRespond to lawful requests and preserve records when requiredLegal obligation

The legal basis that applies depends on your location and the context. Where we rely on consent, you may withdraw it, but withdrawal does not make earlier processing unlawful.

4. When Information Is Shared

Metric shares information in the following circumstances:

  • At your direction. With other users, followers, or people who open a share link when you publish or share a profile, workout, route, post, comment, reaction, or live workout.
  • Apple. HealthKit for health and workout data, CloudKit for iCloud nutrition sync, Sign in with Apple for authentication, Apple Push Notification service for notifications, and the App Store for purchases and subscription events.
  • Garmin. Garmin Connect for the optional account connection, token lifecycle, activity imports, permission changes, and disconnection.
  • Supabase. Authentication, PostgreSQL database services, and storage for profile and social media files.
  • Railway. Railway hosts Metric's public website, API, and worker services and may process network and service logs.
  • Ably. Realtime delivery of live workout state, presence, reactions, and comments, using scoped tokens tied to a Metric user and live session.
  • OpenAI. Processing for server-backed Cortex, nutrition analysis, and training-plan generation.
  • Resend. Transactional e-mail delivery and configured open tracking.
  • Legal and safety reasons. When reasonably necessary to comply with law, enforce our terms, investigate misuse, or protect users, Orion, or the public.
  • Business transfers. In connection with a merger, financing, reorganisation, acquisition, or sale of assets, subject to applicable law.

Orion does not sell personal information or share personal information for cross-context behavioural advertising. We do not use HealthKit or Garmin health data for advertising.

5. Storage, Retention & Deletion

The Services use Supabase for authentication, relational data, and media storage; Railway for the public website, APIs, and background workers; Apple CloudKit for iCloud nutrition sync; Ably for realtime live-workout messaging; Resend for e-mail; and OpenAI for the AI features described above. These providers may process information in the United States and other countries where they operate.

We retain information for as long as reasonably necessary to provide the feature for which it was collected, maintain the Services, resolve disputes, meet legal obligations, and protect the Services. Retention depends on the type of information, whether you keep an account or connected feature active, and provider backup, security, and legal requirements. Different categories and providers may therefore have different retention periods.

  • Metric backend. Profile, social, workout, health, Garmin-imported, training-plan, notification, and related records generally remain while your account or the relevant feature is active, unless you delete particular content or request deletion.
  • Apple Health and on-device data. Revoking Metric's Health permission stops future access but does not delete data already stored in Apple Health. Use Apple's controls to review or delete Apple Health data and local App data.
  • CloudKit nutrition data. Nutrition entries synced through CloudKit are associated with your iCloud account. Deleting a nutrition entry in Metric syncs that change through the Core Data/CloudKit store.
  • Garmin. Disconnecting removes current Garmin connection credentials and stops new imports. Already imported workouts and details are separate Metric records and are not removed merely by disconnecting Garmin.
  • AI records. OpenAI processes and may retain inputs and outputs under the applicable service configuration and its policies. Server-backed Cortex currently uses stored response objects for conversation continuity. Training plans you generate are stored in Metric's backend; nutrition entries you save are stored locally and may sync through CloudKit and Apple Health.
  • E-mail and realtime records. Resend and Ably may retain delivery, tracking, message, or service records according to the service configuration and their policies. Orion's backend separately stores the live-workout records described above.

You may request account deletion in Metric or by e-mailing privacy@joinmetric.com. We may retain information when required by law or for another permitted purpose.

6. Security

We use technical and organisational measures intended to protect personal information, including authenticated API access, access controls, and scoped credentials for supported integrations. The Services also depend on the safeguards provided by the third-party services listed above. No method of storage or transmission is completely secure.

7. Your Controls

  • Apple Health: manage each authorised data type in iOS Settings or the Health app, and use Apple controls to review or delete Health data.
  • Garmin: connect or disconnect Garmin in Metric Settings. Disconnecting does not remove activities already imported.
  • Profile and live workouts: use Metric Settings to make your account private, control live location sharing, and choose a route privacy radius.
  • CloudKit: delete nutrition entries in Metric and manage Metric's iCloud data through Apple's iCloud controls.
  • AI: select Apple Intelligence for Cortex when available. This choice does not change the OpenAI processing used for AI nutrition analysis or AI-generated training plans.
  • Contacts, location, and notifications: change device permissions in iOS Settings and notification preferences in Metric Settings.
  • Account and content: delete supported content in the App, use Delete Account to request account deletion, or contact us by e-mail.

8. Your Privacy Rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information; to restrict or object to certain processing; to withdraw consent; or to appeal or complain to a regulator. Submit a request to privacy@joinmetric.com. We may need to verify your identity and will respond as required by applicable law.

California residents may also have rights under the CCPA/CPRA. The categories Metric may process include identifiers, account and commercial information, internet or electronic activity, geolocation, user-provided content, and sensitive personal information such as health and precise-location data. Orion does not sell personal information or share it for cross-context behavioural advertising.

9. International Processing

Orion is based in the United States, and the providers used by Metric may process information in the United States and other countries. Privacy protections and government access rules may differ from those in your home country. Where required, we use an applicable legal basis or transfer mechanism for international processing.

10. Children

Metric is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information to Metric, contact us so we can review the account and take appropriate action.

11. Health & Medical Disclaimer

Metric is a wellness and fitness product, not a medical device. It does not diagnose, treat, cure, or prevent disease and does not provide medical advice. Consult a qualified healthcare professional before making medical decisions or beginning an exercise or nutrition programme.

12. Changes to This Policy

We may update this Policy as Metric changes. We will post the revised Policy with a new "Last Updated" date and provide additional notice when required by law.

13. Contact Us

E-mail: privacy@joinmetric.com
Mail: Privacy, Orion Designs LLC,
    6513 Harold Ave, Cocoa, FL 32927 USA