Terms of Service
Effective Date: February 19, 2026 | Last Updated: August 30, 2026
1. Agreement to Terms
1.1 Acceptance
By downloading, installing, accessing, or using the Sensus mobile application ("App"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, do not use the App.
1.2 Eligibility
You must be at least 13 years of age to use the App. If you are between 13 and 18 years of age (or the age of majority in your jurisdiction), you must have permission from a parent or guardian who agrees to these Terms on your behalf.
By using the App, you represent and warrant that you meet these eligibility requirements. The App is rated 13+ on the Apple App Store and enforces a 13+ minimum through an in-app date-of-birth check during onboarding.
1.3 Updates to Terms
We may update these Terms from time to time. We will notify you of material changes through the App at least 30 days before they take effect. Your continued use of the App after changes become effective constitutes acceptance of the updated Terms.
1.4 Operator
The App is operated by Leilani Matovina, sole trader, Sydney, New South Wales, Australia ("Sensus," "we," "us," or "our").
2. Description of Service
2.1 What Sensus Is
Sensus is a wellness tracking application that enables you to:
- Log and track body sensations, discomfort, and wellness observations via a rapid check-in flow with AI-assisted data extraction
- Review, edit, and correct AI-extracted data before saving
- Answer optional micro-questions during check-in to provide additional context across dimensions such as social connection, stress sources, nutrition quality, routine disruption, medication status, substance use, and (if opted in) menstrual cycle phase
- If your onboarding profile indicates competitive athlete activity level, complete an optional daily two-question structured follow-up at the end of your check-in flow covering validated sport-science dimensions
- View a daily Body Forecast - a prediction of how your body may feel based on your patterns, health data, weather data, and community trends, computed on your device
- Respond to your daily Body Forecast with a one-tap "Daily React" (Spot on, Better, or Worse, or "something's off" which opens the full check-in): a quick subjective note of how today feels compared with the App's read
- View Movement Capacity - an on-device estimate of how recovered each muscle group is after your workouts, shown as qualitative recovery states, a recovery percentage rounded to the nearest five, and a soft "ready when" window rather than an exact time; optionally tell the App which split a strength workout trained or whether an area still feels sore (one-tap categorical inputs)
- Use Movement OS (a daily movement-readiness loop): give an optional one-tap "Felt Read" of how your body feels today (and optionally where, or flag that something hurts and log a short pain episode), view an on-device "Movement Readiness" score, optionally try one short 2-minute wellness movement or a short personalised daily program shaped by your read, and note whether it helped; optionally close the previous day's read (the Outcome Loop) by confirming what you did, which the App uses to grade its own read; if your activity level indicates you train, you may also set your sport and (for competitive athletes) season so the App tunes what it watches and how it talks to you (see Section 3.21)
- Search your body with Ask Sensus and SensusAI - get grounded answers from your data and community research
- Receive Discovery Cards - automated insights surfaced from your data that connect patterns you may not have noticed
- Track your journey through progressive milestones that indicate when new analytical capabilities become available based on your unique logging days
- View patterns, trends, and at-a-glance statistics derived from your logged data
- Receive on-device automated pattern detection, including flare prediction, seasonal pattern analysis, phantom correlations, and recovery trajectory comparisons
- Optionally read health metrics from Apple Health (read-only) to enrich your check-in context
- View cross-modal body signals that correlate your Apple Health metrics with your logged body states (computed entirely on your device)
- Receive fitness-aware cardiac interpretation - the App adjusts what it considers typical ranges for health metrics based on your self-reported activity level (computed entirely on your device)
- Optionally allow reduced-accuracy location access (city-level, approximately 5 km) so the App can retrieve local weather data via Apple WeatherKit to provide weather-body context for your check-ins
- Explore movements and exercises organised by body region, and rate your response to them
- View automatically inferred verified outcomes that track how your body responded to movements over 28-day windows
- Generate healthcare provider summaries for your personal use
- Optionally contribute de-identified data to community insights ("Consensus") via automatic upload to Google Cloud Firestore
- View community health metric signals showing what health metrics correlate with how people feel, based on aggregated categorical health pattern flags from consenting contributors
- View population-level wellness research drawn from peer-reviewed studies, clinical guidelines, and established medical resources, presented as research findings rather than personal recommendations
- View "The Consensus" cohort visualisation (introduced v1.8): a contextual surface that places your own position among a constellation of peer positions representing the cohort that has been matched to you by similarity of pattern signatures. The visualisation displays only aggregate counts and bucketed distributions; no per-peer identity, signature, or check-in is ever exposed. Cohort matching is only surfaced when at least 5 sufficiently similar peers have contributed. If you have not enabled community sharing, the surface shows a locked preview only - no real cohort data is displayed - with an option to opt in. If you have opted in but do not yet have enough data (or too few similar peers have contributed), the surface falls back to population-level wellness research drawn from medical literature.
- Optionally create an account by signing in with Apple or Google to save a contact identity - entirely optional, with "Maybe later" always available so you can use the App fully without one (see Section 6.6). Your account, contact record, and all app data can be deleted in-app at any time.
- Optionally link a practitioner ("Care Team", introduced v1.8.3): if you are working with a physiotherapist, clinician, or other practitioner who uses Sensus, you can link with them by invite code so they can follow your check-ins between appointments, and exchange in-app messages with them (see Section 3.19)
- Optionally use AI-powered features (powered by Google Gemini via Firebase AI / Vertex AI) for personalised insights, Body Forecast narratives, weekly reports, post-check-in intelligence, and conversational chat
- Receive optional notifications for check-in reminders, daily morning Body Forecast alerts, pattern alerts, streak reminders (opt-in), evening check-ins, movement follow-ups, body-memory notifications ("Sensus Noticed"), and - if you have linked a practitioner - a push notification when they message you
2.2 What Sensus Is NOT
IMPORTANT: Sensus is NOT:
- A medical device
- A diagnostic tool
- A substitute for professional medical advice, diagnosis, or treatment
- A replacement for consultation with qualified healthcare providers
- An emergency medical service
- Physical therapy or rehabilitation treatment
- A clinical or therapeutic intervention
- A source of prescriptive health advice or directives
- A clinical measurement system (including the Body Forecast, the Daily React response, Discovery Cards, verified outcomes, phantom correlations, Movement Capacity muscle-recovery estimates, Movement OS readiness scores and felt reads, and the Consensus cohort visualisation, which are observational tools only)
Sensus is not registered as a therapeutic good under the Therapeutic Goods Act 1989 (Cth) and is not intended to diagnose, cure, treat, or prevent any disease or medical condition.
3. Health and Medical Disclaimer
3.1 General Disclaimer
THE CONTENT, FEATURES, AND INFORMATION PROVIDED THROUGH THE APP ARE FOR GENERAL INFORMATIONAL AND EDUCATIONAL PURPOSES ONLY AND DO NOT CONSTITUTE MEDICAL ADVICE, DIAGNOSIS, OR TREATMENT.
3.2 No Healthcare Provider Relationship
Use of the App does not create a doctor-patient, therapist-patient, or any other healthcare provider relationship between you and Sensus or its affiliates.
3.3 Consult Healthcare Providers
ALWAYS SEEK THE ADVICE OF A QUALIFIED HEALTHCARE PROVIDER with any questions you may have regarding a medical condition, symptoms, or treatment. Never disregard professional medical advice or delay seeking it because of something you have seen or read in the App.
3.4 Emergency Situations
IN A MEDICAL EMERGENCY, CALL YOUR LOCAL EMERGENCY SERVICES IMMEDIATELY:
- Australia: Triple Zero (000)
- United States: 911
- United Kingdom: 999
- European Union: 112
- Canada: 911
- Brazil: 192 (SAMU) or 193
- New Zealand: 111
Do not rely on the App for emergency medical situations.
3.4.1 Mental Health Emergencies
If you are in mental health distress or crisis, please contact a mental health crisis line:
- Australia: Lifeline 13 11 14 | Beyond Blue 1300 22 4636 | 13YARN 13 92 76
- United States: 988 Suicide & Crisis Lifeline
- United Kingdom: Samaritans 116 123
- Canada: 9-8-8 Suicide Crisis Helpline
- New Zealand: Lifeline 0800 543 354
- International: findahelpline.com
Sensus is not designed for mental health crisis management and should not be used in place of professional mental health support.
3.5 Movement and Exercise
The movement suggestions in the App are for educational exploration only. Before beginning any movement or exercise program:
- Consult with your healthcare provider, especially if you have existing health conditions
- Stop immediately if you experience pain, discomfort, or adverse symptoms
- Listen to your body and work within your own limitations
- Understand that results vary and are not guaranteed
This applies equally to the optional 2-minute wellness movement, and to any short daily program, that Movement OS may suggest (Section 3.21): each is offered as general wellness exploration, not as treatment, rehabilitation, or a prescription; do only what feels right within your own limits, stop on any pain or adverse symptom, and skip it entirely if in doubt.
3.6 Pattern Detection, Predictions, and Alerts
The App may identify patterns in your logged data, including "Red Flag" alerts, flare predictions, recovery trajectory comparisons, cross-modal body signals, fitness-aware cardiac interpretation, seasonal or weather-related patterns, phantom correlations, verified outcomes, and cohort matching outputs (the Consensus visualisation introduced in v1.8). These are:
- Observations from your data, presented with your specific data points, and in the case of recovery trajectories and cohort matching, drawn from aggregated community signal and published research
- NOT diagnoses, prognoses, or medical assessments
- NOT substitutes for professional evaluation
- NOT prescriptive health advice or directives
- NOT guarantees of future outcomes. Flare predictions, recovery trajectories, body signals, verified outcomes, and cohort matches are statistical estimates only
- Intended only to support your awareness and prompt discussion with healthcare providers
3.7 Verified Outcomes
The App may automatically infer how your body responded to a movement intervention by comparing your logged pain intensity in the 7 days before you started the movement with your intensity at days 7, 14, and 28 after. These outcomes (e.g., "sustained improvement", "temporary relief", "no change", "worsened") are:
- Automatically inferred from your logged data - not reported by you directly
- Based on intensity comparisons only, which may be affected by confounding factors (e.g., other treatments, natural fluctuation, lifestyle changes)
- NOT clinical evaluations of treatment effectiveness
- NOT recommendations to continue or stop any movement or treatment
- If you have opted into community sharing, your de-identified outcome classification and movement frequency may be uploaded to improve community insights
3.8 Phantom Correlations
The App may display "phantom correlations" - delayed effects and protective factors detected across community data. These are:
- Observational correlations only, NOT causal relationships
- Based on aggregated community patterns subject to minimum contributor thresholds
- May reflect regression-to-the-mean, coincidence, or confounding rather than genuine effects
- NOT medical findings, diagnoses, or treatment guidance
- Intended for general awareness and discussion with your healthcare provider
All patterns, correlations, verified outcomes, phantom correlations, body signals, and cohort observations are presented as observations from your data for you to discuss with your healthcare provider. Sensus does not provide prescriptive health advice or directives.
3.9 AI-Generated Content
If you enable AI features (powered by Google Gemini via Firebase AI / Vertex AI), the responses generated, including conversational chat (Ask Sensus, SensusAI), weekly reports, post-check-in insights, and pattern analysis, are:
- For informational purposes only
- NOT medical advice or clinical recommendations
- Generated by artificial intelligence with inherent limitations
- Not reviewed by healthcare professionals before delivery
- Stateless. No conversation history is retained on any server
AI systems can produce inaccurate, incomplete, or fabricated information (commonly called "hallucinations"), especially when asked about health-related topics. Outputs may be confidently wrong. Always verify important information with qualified healthcare professionals before acting on it. You are responsible for exercising judgement about any AI-generated content you see in the App.
3.10 AI-Assisted Data Extraction
When you check in using natural language, the App uses AI to extract structured data from your sentence. You acknowledge that:
- AI extraction is not perfect and may miss, misidentify, or misinterpret elements of your input
- You are presented with a confirmation screen where you can review, edit, add, or remove any extracted data before saving
- You are responsible for reviewing and correcting the extracted data if needed
- Once you confirm and save, the data is treated identically in storage, analysis, and any community uploads
3.11 Body Forecast and Discovery Cards
The Body Forecast is a daily prediction of how your body may feel, computed on your device from your patterns, health data, weather data, and community trends. Discovery Cards are automated insights surfaced from your logged data. They are:
- NOT clinical health scores, medical measurements, or diagnostic indicators
- NOT comparable to clinical scales or medical assessments
- NOT indicators of your physical health, fitness, or medical condition
- Observational and informational tools only
The optional one-tap "Daily React" (introduced v1.8.6) is your own subjective response to the Body Forecast: a quick note of whether today feels Spot on, Better, or Worse than the App's read. It is a self-report only, recorded to capture the difference between how you feel and what your data suggests. It is observational and informational, NOT a clinical assessment, NOT a diagnosis, and NOT a directive about whether, when, or how to act. Where you have opted in to community sharing, the felt-versus-data tendency it produces is one categorical input to the Pattern Signature described in Section 3.18.
3.12 Apple Health Data
If you grant permission for the App to read data from Apple Health, you acknowledge that:
- The App reads Apple Health data in read-only mode. It never writes to or modifies your Apple Health data
- Raw Apple Health values are stored locally on your device by default, and are never shared with advertisers, data brokers, insurers, or employers
- Raw Apple Health values are never uploaded to Sensus community storage. If you opt in to community data sharing, only categorical labels derived from your health data may be uploaded.
- Exception - AI features (separate opt-in): If you enable AI features, relevant raw Apple Health values may be included in prompts sent to Google Vertex AI at the moment of generating an AI response. Google does not retain this data for training or advertising. If you do not enable AI features, no Apple Health values leave your device. See our Privacy Policy for details.
- Apple Health data is used to provide personal context alongside your check-ins, to power on-device cross-modal body signals, and to enable fitness-aware cardiac interpretation
- When multiple data sources exist in Apple Health for the same metric, the App may prioritise the source it determines to be most accurate. This selection occurs entirely on your device.
- The App's use of Apple Health data does not constitute medical monitoring or clinical data collection
- When you disable Apple Health access in the App, a confirmation dialog is shown explaining what the App will no longer be able to do (recovery trends, body-memory notifications, cardiac-fitness adjustments, sleep/HRV/activity correlations). You can confirm or cancel.
- You can revoke Apple Health access at any time via iOS Settings > Health > Sensus
3.13 Weather and Location Data
If you grant location permission, the App uses reduced-accuracy location (city-level, approximately 5 km) to retrieve local weather conditions via Apple WeatherKit. You acknowledge that:
- Location is requested on a one-shot basis during check-in only and is not continuously tracked or stored
- Categorical weather labels are stored locally alongside your check-in entries. The App also keeps a rolling local timeline of recent barometric pressure readings on your device for trend computation; these readings are never transmitted off your device.
- Weather data is used to identify potential weather-body correlations in your patterns
- If you also opt in to community data sharing, only categorical weather labels may be uploaded - never your location coordinates, city names, or raw numeric readings
- You can revoke location access at any time via iOS Settings > Privacy & Security > Location Services > Sensus, and the App will continue to function without weather data
3.14 Community Health Metric Signals
The App may display aggregated health metric signals based on categorical health pattern flags contributed by consenting community members. The App also presents population-level wellness research drawn from peer-reviewed studies and clinical guidelines. These signals and research findings are:
- Based on categorical labels only (for community signals) or published research (for wellness findings), never on raw health values from any contributor
- Statistical aggregations across multiple contributors, subject to minimum contributor thresholds (k-anonymity)
- NOT individual medical findings, diagnoses, or personalised clinical advice
- NOT prescriptive health recommendations or directives
- Observational patterns that may not apply to your individual circumstances
- Intended for general awareness only, not as a basis for health decisions
3.15 Micro-Questions and Sensitive Data
The App may present optional micro-questions during check-in covering dimensions including social connection, stress sources, nutrition quality, routine disruption, medication status, substance use, and menstrual cycle phase. You acknowledge that:
- Micro-questions are optional and you may skip them at any time
- Menstrual cycle phase questions are only shown if you opted into cycle tracking during onboarding
- Your responses are stored locally on your device and used to identify correlations between these factors and how you feel
- If you opt in to community sharing, only the dimension name and selected option are uploaded, never free-text responses
- Micro-question insights are observational correlations, not medical or psychological assessments
3.16 Athlete Follow-Up Prompts
If your onboarding profile indicates competitive athlete activity level, the App may present a daily two-question follow-up screen at the end of your check-in flow. You acknowledge that:
- The follow-up prompt is shown only for the competitive athlete archetype, derived from your onboarding activity level. You may change your activity level via in-app settings to disable the prompt.
- Responses use pre-defined chip categories only; no free-text input
- Responses are stored locally on your device alongside your check-in entry
- If you have opted in to community sharing, only categorical chip values, the archetype label, and a day-of-week / hour bucket are uploaded to community storage; exact dates and personally identifying information are never uploaded
- Athlete follow-up signals are observational structured self-reports intended to support pattern recognition over time. They are NOT clinical assessments, NOT medical advice, and NOT a substitute for evaluation by a qualified sports-medicine professional or healthcare provider
3.17 Notifications
The App may send local notifications (with your permission) including check-in reminders, daily morning Body Forecast alerts, pattern alerts, streak reminders (opt-in), evening check-ins, movement follow-ups, optional post-workout Movement Capacity recovery notices ("your legs are recovering"), and body-memory notifications ("Sensus Noticed"). These notifications are:
- Generated and scheduled entirely on your device, with three exceptions, all of which come from a practitioner you have linked (Section 3.19) and are delivered via push: when they message you, when they update your plan or leave a note for you, and when your club changes your schedule (Section 3.25). None of the three carries its content: they tell you that something changed and nothing about what. All other notification content is produced on-device, and notification text shown on your lock screen is deliberately generic - it never names body regions, sensations, triggers, or health metric specifics
- For informational and motivational purposes only
- NOT urgent medical alerts or emergency notifications
- NOT clinical advice or directives
- Configurable and can be disabled entirely in More > Notifications & Alerts or via iOS Settings
3.18 Cohort Matching ("The Consensus" / Living Map)
The App includes a community-facing surface (introduced in v1.8) called "The Consensus" (also referred to as the Living Map). When you have opted in to community data sharing and have enough check-in history, the App computes a categorical Pattern Signature on your device and uploads it to a Sensus-managed cloud collection. A scheduled server-side process matches your signature against the signatures of other consenting users and returns aggregate statistics about your matched cohort. You acknowledge that:
- The Pattern Signature uploaded to enable matching contains only bucketed values: region focus, body-state fractions, top trigger CATEGORY, sleep bucket, directional trend labels for HRV, resting heart rate, and step count, an optional recovery-speed bucket, a directional felt-versus-data gap tendency label and a felt-tendency label derived from your Daily React or Felt Read responses, optional directional outcome-tendency, readiness-trajectory, read-outcome-tendency, and program-outcome-tendency labels (from Movement OS, only when enough data exists), an optional limiting-discipline label (a directional category - load-limited, symptom-limited, recovery-limited, or mixed - summarising which KIND of constraint your body most often runs into, derived on your device from your staff's own track record; it names the kind of constraint and never a condition, so "symptom-limited" means the physio seat is usually the one with something to say, NOT that anything has been identified or diagnosed), four further optional directional labels derived on your device from your own recent training (a load-felt tendency describing where in your own training range you tend to feel loosest, a protective-exposure label describing how much of your training includes activities such as sprinting, eccentric work or heavy lifting, a competitive-load label describing how much of your training is competitive rather than training, and a usual-surface label; each is a category only, contains no minutes, dates or session records, and is withheld until you have given at least three answers to that question), and a sample-size count. It does not contain free-text, check-in dates, raw health values, individual check-in content, or directly identifying information. (A single timestamp recording when the signature was computed is included; see our Privacy Policy for the full specification.)
- Cohort match results returned to your device contain only privacy-gated aggregate statistics: cohort size (gated to a minimum of 5 peers), average similarity score, and a rolling 60-day cohort state distribution (with each day independently gated). No peer identifiers, no peer signatures, and no per-peer trajectory information are ever returned.
- Peer dot positions in the visualisation are stylised. They are deterministic placements arranged around your central position for legibility, not real spatial projections of any individual peer's pattern.
- Cohort observations (size, distribution, trajectory) are statistical aggregations and may be subject to confounding, regression-to-the-mean, or sampling effects. They are NOT clinical findings, diagnoses, or personalised medical advice.
- Cohort matching is only surfaced when the privacy threshold is met. If you have opted in but the threshold has not yet been met, the surface falls back to population-level wellness research from medical literature. If you have not opted in to community sharing, the surface shows only a locked preview with an option to opt in - no real cohort data is displayed.
- You can revoke community sharing at any time. When you revoke, no further signature uploads occur, your existing match document is no longer updated, and your anonymous community identifier is automatically rotated so any future re-opt-in produces a fresh, unlinked match cohort. De-identified data previously contributed to community pools cannot be retrieved or deleted.
The Consensus / Living Map is an observational, statistical, community-context tool. It is not a diagnostic surface, not a medical measurement, and not a basis for health decisions.
3.19 Practitioner Linking & Sharing ("Care Team")
The App allows you to optionally link with a practitioner (for example, a physiotherapist or clinician) using an invite code they give you, so they can follow your progress between appointments and exchange messages with you. By linking a practitioner, you acknowledge and agree that:
- Sharing is at your direction and explicit, per-practitioner opt-in. Before anything is shared, the App shows you which practitioner and clinic the code belongs to and asks for your consent. What is shared: your display name, your check-ins from the time of linking plus recent history (body state, intensity, regions, sensations, contexts, your personal notes, and categorical weather labels), and health-derived values relevant to your care (sleep, heart rate variability, resting heart rate, steps, and gait metrics). This is the only feature through which identifiable health information leaves your device. See our Privacy Policy (Section 8.10) for full details.
- If Movement OS is enabled, linking also shares ten data-minimised items and, if you choose to write one, your own note: a categorical felt-versus-data gap, your painted felt map (the regions you marked that day and how each one felt, region by region and left and right specific across 29 regions on a front and a back view; a region you did not mark is not sent, and your overall Felt Read level for that day follows from the map because it is the worst region you marked), the App's daily readiness-driven movements and whether each helped (movement, mode, body area, before/after felt, and readiness band only), a categorical read outcome per day from the Outcome Loop (readiness band, the action you took, the next-day outcome, and an optional broad body area only, for example so your practitioner can see when you trained through an "ease off" read), a categorical pain episode when you flag one (the severity word, a broad area, the concern categories, whether it routed to a professional, and the next-day resolution of better, the same, or worse), your practitioner's own recorded read of how a body area is responding, and your recorded footwear if you have entered any (what you train in, how comfortable it feels, and your training surfaces, passed on exactly as you recorded it with no interpretation from the App, see Section 3.22), and your weekly training-load summary (where the week sits against your own previous weeks, the totals behind it, the session count, how the figure was weighted, the acute-to-chronic ratio or the reason it is withheld, and your weekly totals for up to the last sixteen weeks; no individual session, no workout record and no dates, and it describes your training schedule rather than your body), your readiness score (the 0-100 number behind the band, with a label saying which version of the arithmetic produced it so that two of your days can be compared without mistaking a change in the calculation for a change in you; it is not sent while your read is still calibrating, because a calibrating score is driven by how you said you feel rather than by measurement), and your per-muscle recovery read (for each muscle group the App currently has a signal for: the group, its state, its recovery percentage, and whether the session behind it was one you entered by hand; a group the App has no signal for is not sent and its absence is not a statement that the muscle is recovered, and a group you have reported discomfort in carries no percentage because no recovery clock is running for it), and, separately from those ten, two items that are your own words rather than a pre-defined choice: an optional note you write yourself on your daily read (exactly as you typed it, entirely optional, and a note you do not write is not sent), and, if you have declared an injury and described it, what that injury is in your own words for each part you named, together with a single label for who named it, you or your physiotherapist (optional on every part, and a part you do not describe is not sent). Roughly when an injury started is not shared and stays on your device, and clearing a description, or telling the App you are no longer injured, removes it from your practitioner's copy on your next check-in (Section 3.24). Neither free-text item is ever contributed to community data or included in the research record, and the App adds no interpretation to either (see Section 3.24). Your movement-safety (contraindication) profile is not shared, and neither is the raw unrounded recovery fraction the App computes internally behind your per-muscle percentages. All of it is deleted when you unlink.
- Your practitioner is an independent professional, not Sensus. Practitioners are not employees, agents, or representatives of Sensus. They are solely responsible for the professional services and advice they provide to you, for how they use the shared data, and for meeting their own professional, ethical, and legal obligations (including their own privacy obligations). Sensus provides the data-sharing and messaging facility only and does not supervise, verify, endorse, or assume responsibility for any practitioner's care, advice, qualifications, or conduct.
- Messaging is NOT for emergencies or urgent clinical needs. In-app messages are not monitored by Sensus, are not guaranteed to be read by your practitioner within any particular timeframe, and must not be used for urgent symptoms or emergencies. In an emergency, contact your local emergency services (Section 3.4). For urgent clinical concerns, contact your practitioner or another healthcare provider directly through their normal channels.
- No availability guarantee. We do not guarantee that any practitioner will view your shared data, respond to messages, or take any action based on them. Sharing data with a practitioner does not create any obligation on Sensus to monitor your data or alert anyone about its contents.
- Practitioner reports. Your practitioner may use the shared data to generate progress summaries or reports (for example, a summary for your GP) as part of their professional service to you. Such reports are produced by and are the responsibility of your practitioner.
- Unlinking deletes everything. You can unlink a practitioner at any time (More > Care Team). Unlinking stops all sharing and deletes all shared check-ins, the message thread, and your client record from the practitioner's view. "Delete All My Data" does the same for every linked practitioner.
- Push notifications. When your practitioner messages you, a push notification is delivered to your device (via the Apple Push Notification service and Firebase Cloud Messaging). It never contains the message content. A device push token is stored against your account solely to deliver these notifications and is removed when you unlink your last practitioner or delete your data.
- Identity separation is preserved. Practitioner sharing uses your signed-in account identity and is kept strictly separate from the anonymous community identifier. Linking a practitioner never connects your identity to your de-identified community contributions, Pattern Signature, or cohort matches.
3.20 Movement Capacity (Muscle Recovery)
The App includes a feature (introduced in v1.8.5) called Movement Capacity, which estimates how recovered each of your muscle groups is after activity. It maps the workouts recorded in Apple Health (type and duration) to muscle groups and applies a recovery model, optionally refined by your own health signals (such as heart-rate-variability trend, sleep, and age band) and by one-tap inputs you may provide (which split a strength workout trained, and whether an area still feels sore). You acknowledge and agree that:
- It is an estimate, shown as qualitative states only. Movement Capacity presents general recovery states (for example "recovering," "sore," "recovered") and a soft "ready when" window. The percentage it shows is rounded to the nearest five and describes where a muscle group sits in its own recovery window. It is not a clinical measurement, and you should not infer one from it. A muscle group is shown only when the App has a real signal for it; absence of a reading is not a statement that a muscle is fully recovered.
- It is observational and educational, NOT medical or training advice. Recovery estimates are NOT diagnoses, NOT clinical assessments of tissue healing or injury, NOT physiotherapy or rehabilitation guidance, and NOT a prescription of whether, when, or how hard to train. They are derived from general population research and proxies (such as workout duration and your own signals) and may be inaccurate for your individual circumstances.
- Do not use it to decide whether to train through pain or injury. Movement Capacity must not be relied on to determine readiness to exercise, to return to sport, to load an injured or painful area, or to skip professional assessment. A muscle group reading as "recovered" does not mean it is safe to load, and a reading of "aggravated" or "sore" is not a diagnosis. For any pain, injury, or training-load decision, consult a qualified healthcare or sports-medicine professional (Section 3.3). In an emergency, see Section 3.4.
- The lifting estimate depends on your input and may be incomplete. Apple Health reports only that a "strength" workout occurred, not which muscles it trained. Where you have not told the App what you trained, it shows a general whole-body read rather than guessing specific muscles. Any split the App predicts for you is a convenience guess that you can always correct.
- Community recovery signals are de-identified and statistical. If you have opted in to community sharing, answering a recovery self-check contributes one anonymous, categorical data point (a body area, a coarse age band, an HRV trend label relative to your own baseline, a general training-type label, and a "still sore" value) used to improve estimates for people with similar profiles. It contains no raw values, no dates, and no identifying information, and is aggregated into a qualitative per-cohort tendency surfaced only when at least 5 distinct contributors are present. These community tendencies are statistical aggregations subject to confounding and sampling effects - they are NOT clinical findings or personalised advice. See our Privacy Policy (Sections 3.2 and 5.4) for details. You can turn community sharing off at any time.
Movement Capacity is an observational recovery estimate, not a medical measurement and not a training prescription. Always defer to your own body, your pain, and a qualified professional over any recovery state the App shows.
3.21 Movement OS (Daily Movement Readiness)
The App includes an optional feature set (introduced in the Movement OS release) that gives you a daily read of how ready your body is to move and one small thing you might do about it: a one-tap "Felt Read" of how your body feels, an on-device "Movement Readiness" score, an optional 2-minute wellness movement or a short personalised daily program shaped by your read, a "did it help" re-test, and an optional next-day "Outcome Loop" that closes the previous day's read. You acknowledge and agree that:
- Movement Readiness is observational, NOT a clinical or training measure. The 0-100 readiness score is a general, on-device read composed from your Movement Capacity, systemic signals, and your own Felt Read. It is NOT a diagnosis, NOT a measure of injury, tissue, or fitness, and NOT a prescription of whether, when, or how hard to train or move. It may be inaccurate for your individual circumstances, and is especially limited if you have not connected Apple Health or logged activity.
- The Felt Read is your subjective self-report. It records how your body feels to you: you paint the regions behaving differently today on a front and a back view, choosing loose, stiff, or sore for each, and you may flag that something hurts. It is used to personalise the read and to surface where your felt experience and the App's signals differ. It is what you felt, not a measurement. Marking a region records your own impression of it and is NOT a finding, a diagnosis, or evidence of injury or damage to that part of your body, and Sensus does not tell your practitioner what a marked region means. It is not a clinical assessment and is not verified by anyone. If you link a practitioner, your painted map is shared with them (Section 3.19).
- The Pain Episode is your subjective pain report, not a clinical assessment. When you flag that something hurts, the App collects a short, pre-defined report - how much (a word such as twinge, nagging, strong, or "can't ignore it"), where (a broad area: legs, core, or upper body), and what you are noticing - and the next morning asks whether it is better, the same, or worse. It is your own self-report, categorical only and not verified by anyone, and is NOT a diagnosis, NOT a pain measurement, and NOT a clinical or medical record. A genuine concern signal routes you to a professional (a general, observational nudge, not urgent triage, see the prompt terms below and Section 3.3); it does not mean something is wrong. For any pain or injury, consult a qualified professional; in an emergency, see Section 3.4.
- The optional movement is wellness exploration only. Any movement the App suggests is general wellness content, not treatment, rehabilitation, physiotherapy, or a prescription, and is governed by the movement-safety terms in Section 3.5: do only what feels right within your limits, stop on any pain or adverse symptom, and skip it if in doubt. The App's movement suggestions are intentionally limited to gentle, general-wellness movements.
- The Daily Program is general wellness, not medical advice. Under your read, the App may suggest a short personalised daily session, a small set of general movements shaped by your read, your training profile, and any linked practitioner plan. It is general wellness and educational content only, NOT treatment, rehabilitation, physiotherapy, a training plan, or a prescription, and is governed by the same movement-safety terms in Section 3.5. Anything about a declared or active injury defers to your practitioner: the App does not program an injured area and routes you to a professional for it. The App does not claim the program prevents injury or improves any medical outcome. Do only what feels right within your limits, and stop on any pain or adverse symptom.
- The movement-safety (contraindication) profile is a safety aid, not a guarantee. If you tell the App about conditions such as recent surgery, pregnancy, or a practitioner's restriction, it uses that on your device to be more conservative about what it suggests. This does not guarantee that any suggestion is safe or appropriate for you, and it does not replace your own judgement or professional advice. You remain responsible for deciding what is safe for you to do.
- A "worth a look" prompt is not clinical triage. When your felt read and the App's signals diverge, or when you report that something hurts, the App may suggest it could be worth checking in with a professional. This is a general, observational nudge, NOT a diagnosis, NOT urgent triage, and NOT a substitute for professional assessment. It does not mean something is wrong, and the absence of such a prompt does not mean nothing is. For pain, injury, or any health concern, consult a qualified professional (Section 3.3); in an emergency, see Section 3.4.
- Athlete context tunes the experience, it is not advice. Your sport and season change what the App watches for you and how it talks to you. They do not generate medical or training recommendations. If you type a custom sport and have AI features enabled, that short sport name alone may be sent to Google Vertex AI to map it to broad body areas (Sections 3.9 and our Privacy Policy, Section 8.4).
- The Outcome Loop grades the App's own read, not you. After a day's read, the App may record what you did that day (pushed, eased, or rested, auto-detected from your Apple Health workouts where available and correctable by you) and, using your next-day Felt Read, grade how well its OWN read called that day. This is a reflection on the App's read, never a judgement of you and never an instruction: it does not tell you to push, ease, or rest, and a past day reading well after you pushed is NOT permission to train through pain or injury. The recorded action is your own report or an inference from Apple Health, is not clinical, and is not verified by anyone. Always defer to your body, your pain, and a qualified professional over anything the loop shows (Section 3.3).
Movement OS is an observational daily read and optional wellness movement, not a medical or training prescription. Always defer to your own body, your pain, and a qualified professional over any readiness score, suggestion, or prompt the App shows.
3.22 Footwear
The App lets you optionally record what you train in (chosen from a short pre-defined list), how comfortable it feels, and the surfaces you play or train on. You acknowledge and agree that:
- The App records your footwear. It does not assess it. Sensus does not tell you whether what you wear is suitable for you, for your sport, or for the surface you train on. It does not rank one choice against another, does not recommend that you change or buy anything, and does not evaluate footwear you have not recorded.
- The App does not link footwear to injury risk. It does not claim that any footwear, or any combination of footwear and surface, causes, contributes to, raises, lowers, or prevents injury of any kind. Published research on footwear and injury is mixed and is largely drawn from running populations, and the App makes no claim from it about you.
- Comfort is your subjective self-report. How your footwear feels to you is your own impression, categorical only and not verified by anyone. It is not a measurement, not a clinical assessment, and not an indicator of anything about your body.
- It is context for a human, not advice from the App. If you link a practitioner (Section 3.19), what you recorded is shared with them exactly as you entered it, with no interpretation added. Whether your footwear matters for you is a judgement for a qualified professional who can see you move, not for the App. This limit also binds the App's AI features, which are instructed to report what you recorded without judging it.
- It is optional and changeable. You can leave it blank, and you can change or clear it at any time in your profile. It is stored on your device, is not part of the anonymised Pattern Signature, and is removed by "Delete All My Data." If you switch on the injury research record (Section 3.23), what you recorded is carried in the daily row as a category; it is not contributed to the community in any other way.
Sensus records what you train in so that you and any practitioner you link can see it. It does not judge your footwear and makes no claim that footwear affects your risk of injury. For any question about what you should be wearing, consult a qualified professional.
3.23 Injury Research Record
The App includes an optional research record, contributed only if you have community data sharing switched on and this record enabled. Its purpose is to study what tends to keep people injury free, what was present when they got hurt, and what changes are worth flagging. It is a materially larger contribution than the categorical Pattern Signature described in Section 3.18, which is why it is described here separately. You acknowledge and agree that:
- It has two parts. A daily row, one per day you use the App, carries your training load for the week and how it sits against your own previous weeks; the sessions you recorded that day, each as a type, a duration BAND rather than exact minutes, an effort rating, the surface, whether it was a match or training, and whether it involved activities such as sprinting, eccentric work or heavy lifting; the regions you painted on the body map and the state you gave each; your muscle recovery states and roughly how many whole hours each has left; your readiness score and band; your Felt Read level and whether you flagged a concern; your footwear; and, for each of your staff's seats, the call it made that morning and whether that call turned out to hold. An injury event, one per pain episode, carries the area and region, the severity word you chose, how long the episode lasted, what you recorded about the moment it began, whether it stopped you training, and how it resolved.
- The injury event records what the App said before an episode, and what you did instead. For each of the days leading up to an episode it carries what each of your staff's seats said and the action you took. We state this plainly because it includes days on which the App advised caution and you trained anyway. Those days are recorded as a number of days before the episode began, never as calendar dates. It is a sequence of what was said and what was done. It is NOT an assertion that anything you did caused anything that followed, and nothing in this record establishes a cause.
- It is observational and is not a finding about you. Everything in it is your own self-report or the App's own on-device read, categorical or bucketed, and not verified by anyone. It is NOT a diagnosis, NOT a measure of injury or tissue damage, NOT a clinical record, and NOT evidence that anything is wrong with you. Sensus does not use it to tell you your risk of injury, and you must not treat it as doing so. For any pain, injury, or health concern, consult a qualified professional (Section 3.3); in an emergency, see Section 3.4.
- What it never contains. No free text of any kind. No raw Apple Health values: only the direction each is moving relative to your own baseline, so a label such as "below your usual" rather than a number. No time of day, and no date finer than the calendar day. No training plan, which is a statement about the future rather than a record of anything. Nothing that identifies you.
- It only goes one way. The record is written from your device and is never readable by another user. Only aggregate findings are returned, and only for groups of at least 5 contributors, on the same k-anonymity basis as the rest of the community surfaces (Section 3.18).
- When it starts. Daily rows begin from the day you switch the record on and are not backfilled, because there is no honest way to reconstruct what your readiness or training load would have read on a past day. Pain episodes from the previous six months ARE included, because an episode is not finished until it resolves and its outcome often lands weeks after it began.
- You can switch it off. Revoking community sharing stops all further contributions and rotates your anonymous identifier, exactly as described in Section 3.18. De-identified data already contributed to community pools cannot be retrieved or deleted.
The injury research record is an observational, de-identified research contribution. It is not a diagnosis, not a measurement of your body, and not a statement that anything you did caused anything that followed. Sensus does not predict injury and does not tell you your risk of injury.
3.24 What You Write About a Declared Injury
If you tell the App you are currently injured, you choose the body parts involved from a pre-defined list, and for each one you may write a short description of what it is in your own words. You may also tag who named it, you or your physiotherapist, and say roughly when it started by picking one of four coarse ranges. All of it is optional. You acknowledge and agree that:
- The App records what you write. It does not assess it. Sensus does not confirm, correct, or grade your description. It does not tell you whether what you have written is right, it does not name a condition of its own, and it does not diagnose. Writing "calf strain" does not mean the App agrees that you have one.
- Who named it is a label you choose, not a verification. Marking a description as named by your physiotherapist records what you have told us and nothing more. The App does not contact your practitioner, does not check it with anyone, and does not treat it as clinically confirmed.
- Roughly when it started marks elapsed time only. The ranges are deliberately broad because most people do not remember the day. Anything the App shows you from it describes how long it has been. It is not a stage of healing, not an assessment of how your body is recovering, and not a date by which you can expect to be better. Where the App shows published recovery ranges, those describe groups of people studied in research and say nothing about you.
- It is free text, and what you put in it is your responsibility. Please do not include information about other people. Because it is your own words rather than a pre-defined choice, it is never contributed to community data and is never included in the injury research record (Section 3.23), both of which are made up of categories only.
- It is context for a human, not advice from the App. If you link a practitioner (Section 3.19), what you wrote is shared with them exactly as you typed it, with no interpretation added, together with who you said named it. Roughly when it started is not shared. What your description means, and what should be done about it, is a judgement for a qualified professional who can see you, not for the App.
- It is optional and changeable. You can declare an injury and describe none of it. You can change or clear a description at any time in your profile, which also removes it from any linked practitioner's copy, and "Delete All My Data" removes it entirely. That removal travels with your next check-in rather than the moment you save, so it clears within a day for anyone checking in regularly. If you clear it and then stop using the App without checking in again, it stays on their copy until you unlink them, which deletes everything shared with that practitioner.
3.25 Your Club's Schedule
If you link a club, school, or team (Section 3.19), they may share their training pattern and their fixtures with you. Where you have both a shared schedule and a current recovery read, the App shows what is coming up next alongside which muscle groups are still recovering. You acknowledge and agree that:
- It is your club's information, and Sensus does not verify it. The training days, match dates, times, opponents, and venues are entered by your club. Sensus does not create them, check them, or correct them, and a fixture can be moved or cancelled without the App knowing. The App shows how long ago your club last imported its fixtures so that you can judge how current they are. Always confirm the details with your club.
- It is not a statement about whether you should play. Where a recovery estimate is shown beside a fixture, it describes how long the App estimates a muscle group still has to recover, and nothing more. It is not a statement that you are ready, fit, available, or selected, and it is not a clearance to train or to play. Those are decisions for your club and for a qualified professional who can see you.
- The recovery estimate is deliberately approximate. It is shown in rough terms rather than as an exact number of hours or a named day, because it is an estimate drawn from groups of people and applied to you, not a measurement of your tissue. Section 3.20 governs it in full.
- It is only ever sent to you, and you cannot change it in the App. The schedule is read only on your device. Nothing you do with it, including opening it, is sent back to your club. It is never contributed to community data and it is never included in the injury research record (Section 3.23).
- A change to it may notify you. If your club changes a training day or a fixture in the near term, you may receive a push notification (Section 3.17). Like every other push, it is deliberately generic: it does not name your club, an opponent, a venue, or a date.
- It goes when the link goes. Unlinking that club deletes the schedule they shared with you, together with everything else shared under Section 3.19.
4. User Responsibilities
4.1 Accurate Information
You agree to provide accurate and complete information when using the App and to keep this information current. When the App presents AI-extracted data for your confirmation, you are responsible for reviewing and correcting any inaccuracies before saving. Data you add, edit, or confirm is treated as your input.
4.2 Device Security
You are responsible for maintaining the security of your device and access to the App, including:
- Keeping your device passcode secure
- Not sharing access to your device or the App with others
- Notifying us if you believe your data has been compromised
4.3 Lawful Use
You agree to use the App only for lawful purposes and in accordance with these Terms. You agree NOT to:
- Use the App in any way that violates applicable laws or regulations
- Attempt to gain unauthorised access to any part of the App or its systems
- Interfere with or disrupt the App or servers
- Transmit any malware, viruses, or harmful code
- Reverse engineer, decompile, or disassemble the App
- Use the App to harm, threaten, or harass others
- Misrepresent your identity or affiliation
- Use the App for any commercial purpose without our consent
- Submit false, misleading, or fabricated data to community features
- Attempt to re-identify, link, or otherwise determine the real-world identity of any other user, or attempt to circumvent the privacy controls applied to community data including pattern signatures and cohort match results
4.4 Healthcare Decisions
You acknowledge and agree that:
- You are solely responsible for your healthcare decisions
- The App is a tool to support your awareness, not replace medical care
- You will consult qualified healthcare providers for medical concerns
- You will not rely solely on the App for health-related decisions
- Flare predictions, pattern alerts, body signals, community health signals, recovery trajectories, verified outcomes, phantom correlations, athlete follow-up signals, body-memory notifications, Movement Capacity recovery estimates, and cohort matching observations (the Consensus visualisation) are informational estimates and not clinical guidance
5. Intellectual Property
5.1 Our Intellectual Property
The App and its contents, including but not limited to text, graphics, images, logos, icons, software, algorithms, knowledge bases, movement libraries, and audio, are owned by Leilani Matovina trading as Sensus ("Sensus") and are protected by copyright, trademark, and other intellectual property laws.
5.2 Limited License
We grant you a limited, non-exclusive, non-transferable, revocable license to use the App for personal, non-commercial purposes in accordance with these Terms.
5.3 Your Content
You retain ownership of the data and content you input into the App ("Your Content"). By using the App, you grant us a limited license to:
- Store, process, and display Your Content to provide the App's functionality
- Create de-identified, aggregated insights if you opt into community features
- Use Your Content to improve the App (in de-identified form)
5.4 Consensus Knowledge Base
The Consensus Knowledge Base contains information drawn from peer-reviewed medical literature, clinical guidelines (including Cochrane Reviews, NICE Guidelines, and PubMed-indexed studies), and established medical institution resources. This content is curated by Sensus and presented for informational purposes only. Original sources retain their respective copyrights and licensing terms.
5.5 Feedback
If you provide feedback, suggestions, or ideas about the App, you grant us the right to use this feedback without obligation to you.
6. Privacy
6.1 Privacy Policy
Your use of the App is also governed by our Privacy Policy, which describes how we collect, use, and protect your information in compliance with global privacy laws including GDPR, CCPA, PIPEDA, LGPD, and Australian Privacy Principles.
6.2 Data Processing
By using the App and providing affirmative consent through in-app permission flows where required, you acknowledge the following data processing activities:
- Local storage of your wellness data on your device (encrypted with iOS Keychain, AES-256)
- Local reading of Apple Health data (read-only) if you grant permission
- Local one-shot retrieval of reduced-accuracy location for weather data via Apple WeatherKit, if you grant location permission
- Local storage of categorical weather labels alongside your check-in entries and a rolling local pressure timeline for trend computation (not transmitted off-device)
- Local computation of your Body Forecast, Discovery Cards, on-device pattern analysis, cross-modal body signals, verified outcomes, and phantom correlations
- Local generation and scheduling of notifications. No data is transmitted to any server to produce these notifications.
- Optional processing by AI services (Google Gemini via Firebase AI / Vertex AI) if you enable those features. When enabled, this may include relevant raw Apple Health values for accurate body-state reasoning, along with your training profile. Free-text notes and personally identifying information are never included in AI prompts, with one exception. If you open the in-app chat with one of your staff seats, that seat's own sentence is sent with your question so it can explain what it just said, and where you have described a declared injury (Section 3.24) that sentence contains your words.
- Optional automatic contribution of de-identified data to community insights ("Consensus") via Google Cloud Firestore if you opt in
- Optional upload of categorical health pattern flags if you have both Apple Health and community sharing enabled. Raw health values are never uploaded to community storage.
- Optional upload of micro-question responses (dimension name and selected option only) if you have community sharing enabled
- Optional upload of verified outcome classifications if you have community sharing enabled
- Optional upload of athlete follow-up responses (categorical chip values, archetype label, day-of-week and hour bucket) if you have both competitive athlete activity level and community sharing enabled
- Optional upload of your Pattern Signature (categorical bucketed values only, see Section 3.18) to a Sensus-managed Firestore collection if you have community sharing enabled. The signature is recomputed on your device and re-uploaded periodically as your check-in history evolves.
- Receipt of cohort match results written by a scheduled server-side process to a document keyed to your anonymous community identifier. The results contain only aggregate cohort statistics (size, average similarity, 60-day state distribution) and never contain peer identifiers or peer signatures.
- Optional storage of a minimal account contact record (Firebase user ID, sign-in provider, email or Apple private-relay address, display name if provided, platform, and timestamps) if you choose to sign in with Apple or Google. This record is owner-scoped and kept strictly separate from the anonymous community identity (see Section 6.6).
- Optional practitioner sharing ("Care Team"): if you link a practitioner by invite code, your display name, check-ins (including notes), and health-derived values are shared with that practitioner, and in-app messages between you are stored in our Firebase backend, readable only by the two of you. A device push token is stored to deliver message notifications. All of this is deleted when you unlink (see Section 3.19).
- Attestation of your App instance to our backend via Firebase App Check (Apple App Attest) as an anti-abuse measure. This uses a device-generated cryptographic key and does not collect personal data.
6.3 Automated Processing
The App performs automated processing of your data to generate the Body Forecast, flare predictions, pattern detection, verified outcomes, Discovery Cards, body-memory notifications, fitness-aware health metric labels, Movement Capacity recovery estimates, and cohort matching (the Consensus visualisation). These automated outputs are presented as informational observations only and do not produce legal effects or similarly significant effects on you. You can view the data points that informed any automated output within the App.
6.4 Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, or port your data. See our Privacy Policy for details on exercising your rights.
6.5 Community Data Consent
If you opt in to community data sharing ("Consensus"):
- De-identified data from your check-ins is automatically uploaded to Google Cloud Firestore when you save a check-in
- If you also have Apple Health connected, categorical health pattern flags may be uploaded alongside your de-identified check-in data. These flags never contain raw health values.
- Micro-question responses and verified outcome classifications may also be uploaded
- If your onboarding profile indicates competitive athlete activity level, athlete follow-up responses (categorical chip values only) may also be uploaded
- Your Pattern Signature (categorical bucketed values described in Section 3.18) is uploaded to enable cohort matching. The signature is recomputed and re-uploaded periodically as your data evolves.
- Data is de-identified on your device before upload (see our Privacy Policy for the full de-identification process)
- You can revoke consent at any time in the App's settings. When you revoke, no further data of any type (including Pattern Signatures) will be uploaded, the upload-tracking state of every community uploader is cleared, and your anonymous community identifier is automatically rotated so that any future re-opt-in produces a fresh, unlinked identity that cannot be associated with your prior contributions.
- Previously contributed de-identified data cannot be retrieved or deleted, as it is not linked to your identity
6.6 Account Sign-In (Optional)
Creating an account is entirely optional - you can use the App fully without one by choosing "Maybe later." If you choose to sign in (via Sign in with Apple or Sign in with Google), you acknowledge that:
- We store a minimal contact record - your Firebase user identifier, sign-in provider, email (or Apple private-relay address), display name if provided, platform, and first-seen / last-seen timestamps - in a Sensus-managed Firebase collection, so we can reach you for support, account recovery, important product or policy updates, and occasional invitations to give feedback or take part in research
- This contact record is the only directly-identifying information stored on a server. It is owner-scoped (only you, while signed in, can read or write it) and is kept strictly separate from the anonymous community identifier used for Consensus features - your sign-in identity is never linked to your de-identified community contributions, Pattern Signature, or cohort matches
- Your wellness and Apple Health data is not stored in this record or tied to your account; it remains on your device
- If you sign in with Apple and choose "Hide My Email," Apple provides a private relay address rather than your real email, and emails we send are forwarded to you by Apple without us seeing your real address
- You can delete your account and contact record in-app at any time via More > Privacy & Data > Delete All My Data (which also unlinks any practitioners, deletes practitioner-shared data, and deletes the sign-in account itself), or by contacting contact@joinsensus.com
7. Third-Party Services
7.1 Third-Party Integrations
The App may integrate with third-party services, including:
- Apple HealthKit: For optional read-only access to health metrics. Raw health values are stored locally. If you opt in to community sharing, only categorical labels are uploaded. If you enable AI features, relevant raw values may be included in prompts sent to Google Vertex AI. See our Privacy Policy for details.
- Apple WeatherKit: For retrieving local weather conditions based on reduced-accuracy location. Categorical weather labels are stored locally alongside your check-in entries. Location coordinates are not stored or uploaded.
- Google Cloud Firestore: For storing de-identified community data ("Consensus"), categorical health pattern flags, micro-question aggregates, verified outcome aggregates, athlete follow-up aggregates, Pattern Signatures (one document per anonymous user), and cohort match results (one document per anonymous user, server-written and client-read), and - if you link a practitioner - your practitioner-shared check-ins, messages, and client record (Section 3.19). Hosted in Australia (australia-southeast1). Community collections are only used if you opt in to community insights; practitioner collections only if you link a practitioner. See our Privacy Policy for details on what data is and is not uploaded, including the explicit non-exposure of peer identities in cohort match results.
- Google Gemini (via Firebase AI / Vertex AI): For optional AI-powered features. Your training profile and, for Body Forecast and Ask Sensus, relevant raw Apple Health values are included in AI prompts to enable accurate reasoning about your body state. AI conversations are stateless from the App's side. No history is retained on any server.
- Firebase Authentication (with Sign in with Apple & Sign in with Google): For optional account sign-in. If you choose to sign in, a minimal contact record is stored (see Section 6.6). Sign-in is optional and the App is fully usable without an account. See our Privacy Policy.
- Firebase Cloud Messaging & Apple Push Notification service: For delivering practitioner-message notifications if you link a practitioner (Section 3.19). The notification never contains message content; a device push token is stored solely for delivery and removed on unlink or data deletion.
- Firebase App Check (with Apple App Attest): An anti-abuse security service that verifies requests to our backend originate from a genuine, untampered copy of the App on a real device. It uses a device-generated cryptographic key and does not collect personal data. See our Privacy Policy.
- Apple Services: For App Store distribution and device functionality
7.2 Third-Party Terms
Your use of third-party services is subject to their respective terms and privacy policies. We are not responsible for third-party services, including their availability, accuracy, or performance.
7.3 Third-Party Links
The App may contain links to third-party websites or resources. We are not responsible for the content, accuracy, or practices of these external sites.
8. Disclaimers and Limitation of Liability
8.1 "As Is" Disclaimer
THE APP IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
8.2 No Guarantee
We do not warrant that:
- The App will be uninterrupted, timely, secure, or error-free
- The results obtained from using the App will be accurate or reliable
- The quality of the App will meet your expectations
- Any errors in the App will be corrected
- AI-generated content, AI-assisted data extraction, pattern detection, flare predictions, body signals, fitness-aware health metric labels, verified outcomes, phantom correlations, athlete follow-up signals, body-memory notifications, recovery trajectories, Movement Capacity recovery estimates, Movement OS readiness scores, felt-versus-data reads, and movement suggestions, or cohort matching outputs (the Consensus visualisation, Pattern Signature, cohort size, average similarity, cohort trajectory) will be accurate, complete, or applicable to your situation
- Community health metric signals or population-level wellness research will be accurate, representative, or applicable to your individual circumstances
- Body Forecast predictions, Discovery Cards, or any AI-generated wellness insights reflect any clinical or medical measure of health
- Apple Health data displayed in the App matches the data in the Apple Health app (due to timing, caching, or data availability)
- Weather data retrieved via Apple WeatherKit will be accurate, current, or available at all times
- Cohort matching will produce a surfaced cohort at any particular time, or that the matched cohort will be representative of any particular condition, demographic, or clinical population
- Any linked practitioner will view your shared data, respond to messages within any timeframe, or take any action based on them; or that practitioner-message push notifications will be delivered without delay or failure
8.3 Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, SENSUS AND ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AND AFFILIATES SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO:
- Loss of profits, data, use, or goodwill
- Personal injury or property damage
- Any damages arising from your use of or inability to use the App
- Any damages arising from health decisions made based on App content, pattern detection, body signals, community health signals, population-level wellness research, AI-generated insights, flare predictions, verified outcomes, phantom correlations, athlete follow-up signals, body-memory notifications, recovery trajectory comparisons, Movement Capacity recovery estimates, Movement OS readiness scores or movement suggestions, or cohort matching observations (the Consensus visualisation)
- Any damages arising from reliance on Body Forecast predictions, Discovery Cards, or notification content
- Any damages arising from inaccuracies in AI-assisted data extraction, Apple Health data, or weather data displayed by the App
- Any damages arising from actions taken or not taken based on micro-question insights, athlete follow-up signals, or weather-body correlations
- Any damages arising from the acts, omissions, advice, care, or data handling of any practitioner you choose to link, or from reliance on in-app messaging for urgent or emergency communication
8.4 Maximum Liability
To the extent permitted by law, our total liability for any claims arising from your use of the App shall not exceed the greater of:
- The amount you paid for the App (if any) in the 12 months preceding the claim; or
- AUD $100 (or equivalent in your local currency)
8.5 Consumer Protection Laws
Your Consumer Rights
Australia: If you are an Australian consumer, you may have rights under the Australian Consumer Law that cannot be excluded. Nothing in these Terms is intended to exclude, restrict, or modify rights that cannot be excluded under the Competition and Consumer Act 2010 (Cth).
European Union/UK: If you are a consumer in the EU or UK, you may have additional rights under consumer protection laws that cannot be waived, including rights under the Consumer Rights Directive and unfair contract terms legislation.
Other Jurisdictions: These Terms do not limit any mandatory consumer protection rights in your jurisdiction.
9. Indemnification
To the extent permitted by applicable law, you agree to indemnify, defend, and hold harmless Sensus and its officers, directors, employees, agents, and affiliates from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising from:
- Your use of the App
- Your violation of these Terms
- Your violation of any rights of another person or entity
- Any content you submit or transmit through the App
- Any health or medical decisions you make based on information from the App
- Any attempt to re-identify, link, or determine the real-world identity of another community contributor
10. Termination
10.1 Termination by You
You may stop using the App and delete it from your device at any time. Uninstalling the App will delete your locally stored data.
10.2 Termination by Us
We may suspend or terminate your access to the App at any time, with or without cause, and with or without notice, including if we reasonably believe you have violated these Terms.
10.3 Effect of Termination
Upon termination:
- Your license to use the App is immediately revoked
- You must delete the App from your device
- Previously contributed de-identified community data (including categorical health pattern flags, micro-question aggregates, verified outcome aggregates, athlete follow-up aggregates, and Pattern Signatures) will remain in the system, as it is not linked to your identity
- Practitioner-shared data is different: unlinking a practitioner or using "Delete All My Data" deletes your shared check-ins, messages, and client record from the practitioner's view (Section 3.19)
- Provisions that by their nature should survive termination will survive (including disclaimers, limitations of liability, and dispute resolution)
10.4 Service Discontinuation
We reserve the right to modify, suspend, or discontinue the App (or any part thereof) at any time, with or without notice. We will not be liable to you or any third party for any modification, suspension, or discontinuation.
11. Dispute Resolution
11.1 Informal Resolution
Before initiating any formal dispute resolution, you agree to first contact us at contact@joinsensus.com and attempt to resolve the dispute informally for at least 30 days.
11.2 Governing Law
These Terms are governed by and construed in accordance with the laws of New South Wales, Australia, without regard to conflict of law principles.
11.3 Jurisdiction
Subject to any applicable consumer protection laws that may provide otherwise, you agree that any legal action or proceeding arising from these Terms shall be brought exclusively in the courts of New South Wales, Australia, and you consent to the jurisdiction of such courts.
11.4 Class Action Waiver
To the extent permitted by law, you agree that any dispute resolution proceedings will be conducted only on an individual basis and not in a class, consolidated, or representative action. This waiver does not apply where prohibited by applicable consumer protection law, including in the EU/UK and certain US state jurisdictions.
11.5 Consumer Rights
If you are a consumer, nothing in this section limits your right to bring legal proceedings in your country of residence in accordance with applicable consumer protection laws.
12. Apple App Store Terms
If you download the App from the Apple App Store, the following additional terms apply:
12.1 Acknowledgement
You acknowledge that these Terms are between you and Sensus only, not with Apple, and Sensus (not Apple) is solely responsible for the App and its content.
12.2 Scope of License
The license granted to you is limited to a non-transferable license to use the App on any Apple-branded device you own or control, as permitted by the App Store Terms of Service.
12.3 Maintenance and Support
Sensus is solely responsible for providing maintenance and support services for the App. Apple has no obligation to provide any maintenance or support.
12.4 Warranty
Sensus is solely responsible for any product warranties, whether express or implied. Apple has no warranty obligation.
12.5 Product Claims
Sensus (not Apple) is responsible for addressing any claims relating to the App or your use of it, including product liability claims, consumer protection claims, and intellectual property claims.
12.6 Third-Party Beneficiary
Apple and its subsidiaries are third-party beneficiaries of these Terms. Upon your acceptance, Apple has the right to enforce these Terms against you as a third-party beneficiary.
13. General Provisions
13.1 Entire Agreement
These Terms, together with our Privacy Policy, constitute the entire agreement between you and Sensus regarding the App and supersede all prior agreements.
13.2 Severability
If any provision of these Terms is found to be unenforceable, the remaining provisions will continue in full force and effect.
13.3 Waiver
Our failure to enforce any right or provision of these Terms will not be considered a waiver of that right or provision.
13.4 Assignment
You may not assign or transfer these Terms or your rights under them without our prior written consent. We may assign our rights and obligations without restriction.
13.5 Force Majeure
We will not be liable for any failure or delay in performance due to circumstances beyond our reasonable control, including natural disasters, war, terrorism, pandemics, or failures of third-party services.
13.6 Notices
We may provide notices to you through the App, by email (if you have provided one), or by other reasonable means. You may contact us at contact@joinsensus.com.
13.7 Language
These Terms are written in English. Any translations are provided for convenience only. In case of conflict, the English version prevails.
14. Contact Information
If you have any questions about these Terms, please contact us:
Sensus
Operated by Leilani Matovina
Sydney, New South Wales, Australia
Email: contact@joinsensus.com
Website: joinsensus.com
15. Acknowledgement
By using the App, you acknowledge that:
- You have read and understood these Terms of Service
- You agree to be bound by these Terms
- You meet the eligibility requirements (13+ years of age)
- You understand that the App is NOT a medical device and does NOT provide medical advice
- You understand that Sensus is not registered as a therapeutic good under the Therapeutic Goods Act 1989 (Cth)
- You understand that Body Forecast predictions and Discovery Cards are awareness tools, not clinical health measures
- You understand that pattern detection, flare predictions, body signals, community health signals, verified outcomes, phantom correlations, athlete follow-up signals, body-memory notifications, recovery trajectories, Movement Capacity recovery estimates, Movement OS readiness scores and movement suggestions, and cohort matching observations (the Consensus / Living Map visualisation) are informational estimates, not diagnoses
- You understand that all insights, patterns, body signals, and cohort observations are presented as observations from your data, not as prescriptive health advice or directives
- You understand that AI-generated content and AI-assisted data extraction are not reviewed by healthcare professionals, may contain errors, and can produce inaccurate or fabricated information ("hallucinations")
- You understand that you are responsible for reviewing and correcting AI-extracted data before saving, and for verifying any AI-generated information with qualified healthcare professionals
- You understand that raw Apple Health values are stored locally by default, never uploaded to Sensus community storage, and never shared with advertisers or data brokers
- You understand that when AI features are enabled (opt-in), relevant raw Apple Health values may be included in prompts sent to Google Vertex AI so the AI can accurately reason about your body state, and that Google does not retain this data for training or advertising
- You understand that when community sharing is enabled (opt-in), only categorical labels derived from your health data are uploaded, never raw values
- You understand that when community sharing is enabled, your device computes a categorical Pattern Signature (region focus, body-state fractions, top trigger category, sleep bucket, directional trend labels for HRV, resting heart rate and step count, an optional recovery-speed bucket, and sample size) and uploads it to enable cohort matching, and that this signature does not contain free-text, check-in dates, or raw health values
- You understand that cohort match results returned to your device contain only aggregate statistics (cohort size, average similarity, 60-day state distribution) and that no peer identifier, no peer signature, and no per-peer trajectory is ever exposed to you or to any other user
- You understand that peer dot positions in the Consensus visualisation are stylised placements for legibility, not real spatial projections of any individual peer's pattern
- You understand that revoking community consent stops all further uploads, clears the upload-tracking state of every community uploader, and rotates your anonymous community identifier so any future re-opt-in produces a fresh, unlinked identity
- You understand that account sign-in (Sign in with Apple or Google) is optional, that a minimal contact record is stored if you sign in, and that this record is owner-scoped and kept strictly separate from your anonymous community contributions and never linked to them (see Section 6.6)
- You understand that linking a practitioner is optional and explicit, that it shares your check-ins (including notes), display name, and health-derived values with that practitioner, and that all shared data is deleted when you unlink (see Section 3.19)
- You understand that linked practitioners are independent professionals solely responsible for their own care, advice, and data handling, and that Sensus provides the sharing and messaging facility only
- You understand that in-app messaging with a practitioner is not monitored in real time and must never be used for emergencies or urgent clinical needs
- If your profile indicates competitive athlete activity level, you understand that the optional daily follow-up prompt is structured self-reporting for pattern recognition, not a clinical assessment, and that only categorical chip values (no free text) are uploaded if community sharing is enabled
- You understand that body-memory notifications ("Sensus Noticed") are generated entirely on your device, are informational only, and are not clinical advice
- You understand that Movement OS (the Felt Read, the Pain Episode, Movement Readiness score, optional 2-minute wellness movement or daily program, the Outcome Loop that grades the App's own read, and any "worth a look" prompt) is observational and wellness-only, not a diagnosis, not a training prescription, and not clinical triage, that any suggested movement is governed by the movement-safety terms (Section 3.5), that a past day reading well after you pushed is not permission to train through pain, and that you remain responsible for deciding what is safe for you to do (Section 3.21)
- You understand that location is used only for weather retrieval at reduced accuracy and is not stored or uploaded
- You agree not to attempt to re-identify, link, or determine the real-world identity of any other community contributor, or to circumvent the privacy controls applied to community data
- You will consult qualified healthcare providers for medical concerns
- You have read and agree to our Privacy Policy
Legal Framework Compliance
These Terms of Service are designed to comply with applicable laws in:
- Australia: Australian Consumer Law, Competition and Consumer Act 2010, Therapeutic Goods Act 1989, Privacy Act 1988, Australian Privacy Principles
- European Union/UK: Consumer Rights Directive, Unfair Contract Terms, GDPR (including Articles 13-14 transparency, Article 22 automated decision-making)
- United States: State consumer protection laws, CCPA/CPRA
- Canada: Consumer protection legislation, PIPEDA
- Brazil: LGPD
- Global: Apple App Store Guidelines, Apple HealthKit Guidelines
These Terms of Service were last updated on July 10, 2026.
For questions, contact us at contact@joinsensus.com.