Last updated: September 7, 2026
Techie Industries LLC, a Colorado limited liability company, operates Roni. Roni is not affiliated with, endorsed by, sponsored by, or connected to Tonal Systems, Inc. Tonal is a trademark of Tonal Systems, Inc. Roni uses Tonal's APIs to read your training data and push custom workouts to your machine, but Tonal does not provide a public API or officially support third-party integrations.
When you connect your Tonal account, your email and password are sent to Tonal's authentication system (Auth0) to obtain an access token. Your password is used once for this request and is not stored, logged, or retained in any form. The resulting authentication token and refresh token are encrypted using AES-256-GCM before being stored in our database. These tokens allow the service to read your data and push workouts on your behalf.
Through your Tonal token, the service reads:
The service writes:
We do not access your Tonal payment information, personal contacts, or any Tonal data unrelated to your training. For Roni Pro, we store the limited billing metadata described below, but not full card or payment-instrument details.
If you subscribe to Roni Pro, Polar processes checkout, payment, taxes, invoices, and subscription management. Roni stores the Polar customer and subscription identifiers, product, status, billing-period end, and cancellation state needed to provide access. Roni does not receive or store your full payment-card details.
Chat is normally processed by the AI provider selected for your account: Google Gemini, Anthropic Claude, OpenAI, or OpenRouter. The selected provider receives your message, relevant conversation history, Roni's coaching instructions, and the training context needed to answer. Connected fitness context may include Garmin and Fitbit activity or recovery summaries and MyFitnessPal daily nutrition totals. Grocery coaching may also include your saved food plans, pantry checks, preferences, and feedback. The selected provider's linked terms and privacy policy apply to its processing. Roni does not train its own AI model on your data.
For accounts using Roni's managed Gemini service, Roni may route a request through Vercel AI Gateway and use OpenAI or Anthropic as a fallback when Gemini is unavailable, rate-limited, or otherwise unable to complete the request. A fallback provider receives the same categories of chat and training context described above. Cross-provider fallback is not applied to requests that use a user-provided AI key.
Separately, Roni sends each chat message to Google's Gemini embedding service to support conversation search and memory, even when another coaching provider is selected. Google's linked Gemini terms apply to that processing.
The service is hosted on Convex (database and backend) and Vercel (frontend). PostHog receives product usage analytics and account identifiers including your internal user ID, email, and name when available. Sentry receives application errors and diagnostics; it may receive your internal Convex user ID and email when known so errors can be attributed. Tokens and chat contents are not sent to Sentry. We do not sell this data or use it for advertising.
Roni uses Kroger-family stores for grocery shopping. Instacart shopping has been retired, and Roni no longer creates Instacart shopping links or sends new grocery lists to Instacart.
What you report buying or eating is used to personalize your coaching, not sold or used for ads.
When you connect a Kroger-family shopper account (such as King Soopers), Roni stores encrypted access tokens and your store and fulfillment preferences so it can build your retailer cart when you ask for a grocery plan or choose to build a cart. Roni selects products and estimates package quantities; you can adjust them on the retailer's website. Roni sends grocery search terms to find products, then sends product codes, package quantities, and your pickup or delivery choice to add them to your cart, never your coaching conversation, health or training context, or meal reasoning. Roni never places orders, makes payments, or reads your retailer cart; you check out on the retailer's site. Disconnecting removes the tokens from Roni but cannot remove items already in your retailer cart. Roni keeps a record of each cart request in your account and data export. Kroger handles its own account, shopping, and payment data under its privacy policy.
Your grocery plans and feedback are included in your Roni data export. You can delete a saved grocery list or delete your account to remove these records from Roni. Deleting a list does not remove copies in your chat history. Information already shared with Kroger, or previously shared with Instacart, remains subject to each provider's own retention and deletion controls.
Connecting Garmin Connect is optional. Garmin requires Roni Pro and remains subject to provider approval. When you connect, Roni uses Garmin's official Activity API and Health API so the AI coach can factor rides, runs, and other non-Tonal sessions into your training plan. Roni is not affiliated with, endorsed by, or sponsored by Garmin. Garmin and Garmin Connect are trademarks of Garmin Ltd.
The connection uses Garmin's OAuth 1.0a user-authorized flow. You enter your Garmin username and password on Garmin's own site; those credentials are never sent to or seen by Roni. Garmin returns a long-lived access token and access token secret, both of which are encrypted with AES-256-GCM before being written to our database.
During the handshake we may request the following Garmin permissions. You decide which to grant, and you can change them any time from your Garmin Connect account settings:
We store only the summary data Garmin sends us: activity metrics such as activity type, start time, duration, distance, elevation gain, pace, calories, and heart rate, and daily wellness rollups such as sleep, stress, resting heart rate, HRV, body battery, and step counts. We do not store GPS tracks, per-second samples, or route details. Raw webhook payloads are retained for up to 14 days for operational replay and error recovery, then automatically deleted.
When you first connect, Roni may request a limited initial backfill of your recent history (currently up to 30 days of activities) so the coach has context from the start. After that, Garmin pushes new data to Roni automatically as it is recorded: we do not poll or scrape your account.
We do not sell, rent, or share Garmin data with advertisers, data brokers, or any other third party, except the AI provider that generates your coaching, as described above. Garmin data is used inside Roni only to power the coach, and it is processed under the same infrastructure and AI terms described in the “AI and third parties” section above.
You can disconnect Garmin at any time from the Settings page in Roni, which asks Garmin to remove Roni's registration and marks the connection inactive so no further webhooks are processed. You can also revoke Roni's access directly from your Garmin Connect account settings; Garmin sends us a deregistration webhook and we mark the connection disconnected in response. Deleting your Roni account additionally removes all stored Garmin connection records, activity summaries, wellness summaries, and webhook-event log entries.
Connecting Fitbit is optional and available on every plan, subject to provider approval. Roni uses the official Google Health API in read-only mode so the AI coach can account for cross-training and recovery. Roni is not affiliated with or endorsed by Google or Fitbit.
Authorization happens on Google's site. Your Google password is never sent to or seen by Roni. Google returns access and refresh tokens, which Roni encrypts with AES-256-GCM before storing. Roni requests read-only access to activity and fitness, sleep, and health metrics and measurements; it does not request permission to write health data.
Roni imports only records identified by Google Health as originating from Fitbit or the legacy Fitbit Web API. The initial and recurring sync window is currently up to 30 days. Stored summaries can include workout type, time, duration, distance, pace, calories, average heart rate, sleep duration and stages, resting heart rate, and daily HRV. Roni does not store GPS tracks or per-second heart-rate samples from Google Health.
Fitbit data flows one way into Roni and is used only to personalize coaching under the same infrastructure and AI terms described above. Roni polls Google Health periodically for updates and does not write workouts or other data back to Fitbit.
Disconnecting Fitbit marks the connection inactive, removes the encrypted credentials from active use, asks Google to revoke Roni's grant, and starts removing data imported under that connection. If Google revocation fails, Roni shows a warning and you can revoke access directly in your Google account. Deleting your Roni account removes stored Fitbit connection records, OAuth artifacts, activity summaries, and wellness summaries; Roni also attempts to revoke an active Google grant during account deletion.
Connecting MyFitnessPal is optional. You can sign in through a user-operated MyFitnessPal browser session hosted by Browserbase inside Roni; Roni does not store your MyFitnessPal password. The unofficial browser companion can also transfer a session from your signed-in MyFitnessPal browser tab using a short-lived pairing code. This is not an official MyFitnessPal OAuth connection. Session credentials are encrypted with AES-256-GCM before storage and let Roni read your diary while the session remains valid.
On mobile, you can also sign in on MyFitnessPal's website inside the app. Roni uses the resulting browser session to connect your account, with the same encrypted session storage and import limits; it does not store the password you enter on that website.
Roni stores daily calorie, protein, carbohydrate and fat totals and a food-entry count. Imports cover up to 31 days at a time. Roni does not store individual food or meal records from this import and does not write food entries or other data to MyFitnessPal. Your manual Roni entries take precedence over imported totals. Nutrition targets are values you set in Roni, not targets imported from MyFitnessPal.
Your selected AI provider may receive these daily totals as context for coaching, under the AI processing terms above. Roni does not sell this data or use it for advertising. The connection relies on an unofficial session and may stop working if MyFitnessPal changes its service or your session expires. Disconnecting in Settings stops new imports and removes the stored session. Account deletion removes stored MyFitnessPal connection records, pairing codes, login sessions, and nutrition records from active application storage.
Native health connections are optional. You choose the metrics and device permissions: sleep, steps, resting heart rate, heart-rate variability, active energy, exercise time, weight, and optional distance, cardio fitness, body composition, nutrition, and hydration. Roni reads selected daily summaries from the most recent seven days, with source labels, and stores them with your connection and consent settings in your authenticated account. It does not write records to Apple Health or Health Connect.
These summaries enter AI coaching context only when you enable coaching consent. The AI providers and processing described above then apply. You can change device permissions, disconnect and remove imported summaries from Roni, or export and delete your account data. Disconnecting in Roni does not alter original records on your device. Optional background sync depends on your permission and the operating system and may stop when your authenticated session expires.
Roni stores weight check-ins, progress notes, and private body-progress photos you save. Body-progress photos are not sent to your coach or added to chat. Photos you explicitly attach in Coach are shared for that conversation under the AI processing terms above. Camera and photo-library access are requested when you choose those features. You can delete progress entries and photos, and account deletion removes their stored files.
Calendar access is optional. Availability is reduced to busy time windows on the device; event titles, notes, and attendees are not sent to Roni. You review availability before choosing to share it in Coach. Adding a workout opens the system calendar editor so you decide whether to save it. Nearby-store search sends your chosen ZIP code or an approximate foreground location to Kroger to find stores. Roni does not track your location in the background.
If you enable notifications, Roni stores a device push token, notification preferences, and delivery metadata. Expo and Apple or Google process the token, brief notification content, and the identifier needed to open the relevant Roni item. Local workout reminders are scheduled on your device. You can change notification permissions in system settings, disable Roni alerts, or remove this device's push registration. Signing out clears local workout reminders; deleting your account removes its push registrations and delivery records from Roni.
Connecting Hevy requires Roni Pro and Hevy Pro, which is a separate subscription. You provide an API key from Hevy's developer settings and explicitly consent to Roni processing connected workout data with its AI for coaching. The API key is encrypted before storage.
Roni syncs your Hevy workout history and exercise templates for coaching. It sends a routine to Hevy only after you approve it. Disconnecting stops syncing and using Hevy data for coaching. Account deletion removes stored Hevy connection, workout, template, and routine records from active application storage.
Disconnecting Tonal stops new reads from that connection. If token revocation is not confirmed, Roni keeps the refresh token encrypted only to retry revocation. It deletes that token when revocation succeeds or you delete your Roni account. Disconnecting keeps your saved training history.
You can disconnect your Tonal account and delete your Roni account at any time. Account deletion removes your Roni account and associated application records from active storage. Polar and Roni may retain limited transaction and billing records where needed for payment processing, tax, fraud prevention, dispute resolution, and applicable law. Revocation requests to connected providers can fail, so you can also revoke access directly in each provider's account settings.
This service accesses Tonal through unofficial APIs that may change or become unavailable without notice. Using this service could theoretically affect your Tonal account, though no such issues have been reported. By using Roni, you acknowledge this risk and agree that Techie Industries LLC is not liable for any impact to your Tonal account or subscription to the maximum extent permitted by law.
For questions, data deletion requests, or concerns, email support@roni.coach.