NUTRISYNCBuilders Hub
🏠 🛠
NUTRISYNC · Docs

⌚ Propuesta 33 · Wearables

Epic O — conectar NutriSync con las plataformas de salud del teléfono: qué leemos, qué alimenta, qué NO debemos hacer y en qué orden · para decisión de founders · 5-ago-2026

1 · Resumen ejecutivo

NutriSync le pide hoy a la usuaria que teclee cada día lo que su teléfono ya sabe: si durmió, si se movió, si tuvo el periodo. Conectar con Apple Health y Health Connect elimina ese trabajo y, sobre todo, mejora lo que de verdad importa: saber en qué fase del ciclo está. La temperatura de muñeca que mide un reloj de noche confirma la ovulación mejor que cualquier calendario.

Recomendación: hacer solo las dos plataformas de teléfono antes del 8-oct — Apple Health primero, Health Connect después. Descartar Fitbit y Strava por ahora (razones en §3). Las apps de reloj, después del lanzamiento y solo si el piloto muestra demanda.

2 · Lo que ya está construido

Esto no se empieza de cero. De una sesión anterior (Epic E) ya existe:

  • Tabla health_signal con clave única por (usuaria, proveedor, tipo, instante): la misma muestra no puede entrar dos veces aunque se sincronice cien veces.
  • Tabla connected_providers con registro del consentimiento y de su retirada, con fecha. Auditable.
  • Pantalla «Dispositivos conectados» en Ajustes, con consentimiento explícito.
  • Registro de 9 proveedores con sus permisos declarados.

Y de esta sesión, el contrato de datos: la traducción de lo que dan las plataformas a nuestro modelo, en funciones puras con 21 casos de prueba. Falta el conector nativo, no el andamiaje.

3 · Dos hallazgos que cambian el plan

3.1 · Fitbit se apaga en septiembre

Google cierra la Web API de Fitbit en septiembre de 2026 — semanas antes de nuestro lanzamiento. La sustituta es la Google Health API, cuyos permisos son todos Restricted: exigen una revisión de privacidad y seguridad de Google, con entidad legal y política de privacidad detrás. Sin la SL constituida no se pasa esa revisión.

Consecuencia: integrar Fitbit hoy sería construir algo que muere solo. Y hay una razón mejor para no hacerlo: quien tiene un Fitbit puede volcar sus datos en Health Connect, así que la integración con Android ya lo cubre indirectamente.

3.2 · El contrato de Strava pelea contra el producto

El acuerdo de API de Strava de 2026 prohíbe usar sus datos para entrenar modelos de IA o aprendizaje automático — que es exactamente la Propuesta 32 — y prohíbe mostrar los datos de Strava de una usuaria a nadie que no sea ella misma, lo que impide cualquier función de comunidad, coach o comparación. Además exige suscripción de pago para el tier estándar.

Consecuencia: para una app cuyo valor está en inferir sobre los datos, ese contrato es un muro. Strava es una red social de deporte; nosotros no lo somos. Además, quien registra en Strava suele volcar también en Apple Health o Health Connect: la vía indirecta funciona sin firmar nada.

3.3 · Y una distinción que conviene hacer explícita

«App de Apple Watch» y «Apple Health» suenan a lo mismo y son dos proyectos distintos:

Apple Health (HealthKit)App de Apple Watch
Qué esDependencia nativa en la app iOS que ya tenemosAplicación aparte, con su propia interfaz
StackEl mismo: Expo + EAS buildSwift + SwiftUI, código nuevo que no comparte nada
Su equivalente AndroidHealth Connect, también nativoKotlin + Compose para Wear OS: un tercer código
Qué aportaLos datos, sin que nadie los tecleeComodidad de registrar desde la muñeca

Los datos vienen de la plataforma de salud del teléfono, no de la app del reloj. Un reloj Apple ya escribe en Apple Health sin que nosotros hagamos nada. Por eso las apps de reloj son un proyecto de comodidad, no de datos — y llegan después.

4 · Qué leemos y para qué

Regla: cada señal que pedimos tiene que tener un uso concreto en la app. El texto de la derecha es literalmente lo que verá la usuaria en el diálogo de permisos. Si no sabemos escribirlo, no lo pedimos: pedir «por si acaso» es lo que hace que la gente diga que no a todo.

SeñalPara qué le sirve a ella
SueñoRellena tu descanso del día sin que lo tecleesesencial
EntrenamientosMarca el movimiento que ya has hecho en tu anillo del díaesencial
Flujo menstrualSi ya registras tu periodo en Salud, no lo repites aquíesencial
Temperatura de muñecaLa subida tras la ovulación confirma en qué fase estásopcional
Energía activaAjusta las recomendaciones de nutrición a lo que gastas de verdadopcional
PasosDistingue un día activo de uno sedentarioopcional
Frecuencia en reposoSeñal de recuperación: sube cuando el cuerpo pide descansoopcional
Variabilidad cardiacaAcompaña a la fase del ciclo y ayuda a decidir intensidadopcional

Solo tres son esenciales. Con esas tres la integración ya aporta; el resto se puede denegar sin romper nada.

5 · La regla que gobierna todo: lo objetivo se rellena, lo subjetivo se correlaciona

El reloj mide hechos, no sentimientos. Puede saber cuántos minutos dormiste; no puede saber si descansaste. Puede medir tu variabilidad cardiaca; no puede saber cómo estás.

Técnicamente podríamos rellenar el ánimo a partir de la frecuencia en reposo y la HRV. No debemos. El día que una mujer se sienta perfectamente y la app le diga que está de mal humor, hemos perdido su confianza para siempre. Y el riesgo de fondo es peor: ánimo + ciclo es exactamente el terreno donde un producto como el nuestro puede acabar reforzando el estereotipo de «estás así porque te va a venir la regla». Con un número detrás, suena a ciencia. No lo es.

Señal medidaAlimentaCómo
Sueñosleep_qualitySugerencia que ella puede cambiar
EntrenamientoAnillo de movimientoDirecto
Flujoflow_levelDirecto
Energía activa, pasosRecomendación de nutriciónCalibra la ración a lo que gasta
TemperaturaConfirmación de fase (Epic M)La señal de más valor
HRV, frecuencia en reposoIntensidad recomendada«Hoy tu cuerpo pide menos», nunca «estás triste»
Ánimo, energía percibidaNada. Los escribe ellaSe usan como eje para explicar patrones
Dónde está el valor real: el ánimo que ella registra, cruzado con los datos del reloj, permite decirle algo que no puede ver sola — «en tus últimos tres ciclos, los días que dormiste menos de seis horas registraste menos energía». Eso es un patrón de sus propios datos, no una máquina diciéndole cómo se siente. Es la diferencia entre un espejo y un juez.

6 · La señal que más mueve la aguja: temperatura y fase

El núcleo de NutriSync es sincronizar nutrición y movimiento con la fase del ciclo. Hoy la fase se estima por calendario, con la incertidumbre que eso arrastra en ciclos irregulares. Los relojes con sensor de temperatura (Apple Watch Series 8 y posteriores, y varios Wear OS) miden la temperatura de muñeca durante el sueño; la subida sostenida tras la ovulación es una señal fisiológica real.

Aviso que hay que grabar antes de construirlo: la temperatura confirma que hubo ovulación — no la predice. Es retrospectiva. Cualquier redacción que insinúe que sirve para evitar un embarazo es un problema legal y humano. Nuestros documentos legales ya tocan este punto y hay que mantener la coherencia.

Bien usada, mejora la precisión de la fase sin prometer nada que no podamos cumplir: «tu ciclo se comportó como esperábamos» o «esta vez ovulaste más tarde de lo previsto, ajustamos».

7 · Lo que la ley y las tiendas exigen

  • RGPD artículo 9. Datos de salud = categoría especial. Requieren consentimiento explícito, separado y revocable. Ya está resuelto en el modelo: connected_providers guarda cuándo se dio y cuándo se retiró.
  • Regla de Apple (App Store 5.1.3). Los datos de HealthKit no pueden usarse para publicidad, marketing ni minería de datos, ni compartirse con terceros con ese fin. Solo para mejorar la gestión de salud de la usuaria o investigación con permiso. Esto afecta al modelo de negocio: cierra la puerta a monetizar datos de salud, hoy y siempre.
  • Consecuencia para la IA (Propuesta 32). Si en algún momento se envía contexto a un modelo, no puede ir con datos identificables. Ya está declarado en la Propuesta 32 §2 y sigue valiendo.
  • Minimización. Leemos ventanas cortas y agregados, no el historial completo de su vida. Menos datos = menos riesgo y menos que explicar.

8 · Fases y esfuerzo

O1 · Apple Health, lectura — permisos, primera sincronización, sugerencias en el registro diario y el anillo. ≈1 sprint exige build nativo EN CURSO
O2 · Apple Health, escritura — devolver a Salud el periodo que ella registra aquí. Reciprocidad: la app no solo toma. ≈2 días
O3 · Health Connect (Android) — misma lógica, otro conector. Cubre Samsung Health, y de rebote Fitbit y Garmin, porque vuelcan ahí. ≈1 sprint
O4 · Temperatura → fase — confirmación de ovulación dentro de Epic M. ≈1 sprint depende de O1
O5 · Patrones personales — correlaciones entre lo que ella registra y lo que mide el reloj. Encaja con Epic N. después del lanzamiento
O6 · Apps de reloj (watchOS y Wear OS) — dos bases de código nativas nuevas, dos revisiones de tienda, dos ciclos de release. después del lanzamiento solo si el piloto lo pide

9 · Riesgos

RiesgoMitigación
La usuaria deniega los permisos y la app parece rotaLas tres señales esenciales se piden con su porqué; todo lo demás es opcional y la app funciona igual sin nada
Datos contradictorios (ella dice una cosa, el reloj otra)Gana ella, siempre. El reloj rellena huecos, no corrige
Los relojes baratos dan datos malosGuardamos el proveedor de cada muestra: si una fuente es ruidosa, se puede desactivar sin tocar el resto
Sincronizar consume bateríaSin lectura en segundo plano en la fase 1: se sincroniza al abrir la app
Apple rechaza la app por los textos de permisoEscritos explicando para qué, no qué. Se revisan antes de enviar

10 · Qué esperamos de vosotras

Tres cosas distintas, y conviene no mezclarlas: decisiones (dirección), diseño (cómo se ve y se siente) y lógica (qué hace el sistema cuando nadie mira). Sin las tres, O1 se queda a medias.

10.1 · Decisiones — founders

#DecisiónRecomendaciónBloquea
D15¿Wearables antes o después del 8-oct?Antes solo O1–O3 (las dos plataformas de teléfono). Aprovecha el piloto, que ya tiene iPhone en la manoTodo Epic O
D16¿Se rellena el ánimo con datos del reloj?No. Lo objetivo se rellena, lo subjetivo se correlaciona (§5)O1 y O5
D17¿Fitbit y Strava?No por ahora. Fitbit muere en septiembre; Strava prohíbe lo que hacemos. Ambos llegan de rebote vía Health ConnectAlcance de O3
D18¿Temperatura para confirmar fase?, con la redacción de §6: confirma, no predice, y jamás como anticonceptivoO4
D19¿Apps de reloj?Después del lanzamiento, y solo si el piloto lo pide. Son dos códigos nativos nuevosO6

10.2 · Diseño — cuatro pantallas nuevas

Cuatro piezas visuales, en orden de necesidad. Las tres primeras bloquean O1.

PiezaQué tiene que resolverCuidado con
Antesala del permisoExplicar POR QUÉ pedimos cada cosa antes de que salte el diálogo de iOS. Una sola oportunidad: si dice que no, iOS no vuelve a preguntarQue no parezca un trámite. Es el momento en que se gana o se pierde la confianza
Estado de conexiónEn «Dispositivos conectados»: conectado / sin permiso / no disponible en este teléfono, y la última sincronización«No disponible» no es un error — un iPhone sin reloj sigue dando sueño y pasos
Tarjeta de sugerencia«Tu reloj dice que dormiste 7 h 20. ¿Lo anotamos?» con aceptar o descartarTiene que verse claramente como una propuesta, no como un dato ya guardado
Tarjeta de patrón (O5)Contar una correlación de sus propios datos en una fraseNunca en tono de diagnóstico ni de juicio. Un espejo, no un juez

Formato: como siempre, pack del builder. Todo lo nuestro se inyecta después como bloque registrado.

10.3 · Lógica — seis reglas que hay que fijar

Son decisiones de producto disfrazadas de detalles técnicos. Si no las fijamos nosotras, las fija el código por accidente.

#ReglaPropuesta
L1¿La sugerencia se aplica sola o requiere un toque?Un toque. Que aparezca algo en su diario sin que ella lo apruebe rompe la regla de §5
L2Umbrales de sueño → etiqueta<4 h muy pobre · 4–5,5 inquieto · 5,5–7 normal · 7–8,5 reparador · >8,5 profundo. Revisar con criterio nutricional
L3Si dos fuentes dan el mismo dato distintoGana la plataforma del teléfono; guardamos ambas con su origen
L4Cuánto histórico leemos la primera vez30 días. Suficiente para ver un ciclo completo, poco para ser invasivo
L5Qué pasa si retira el permisoSe deja de leer y se marca la fecha. ¿Se borra lo ya leído? — decisión vuestra, tiene coste y tiene lectura legal
L6¿Contamos su actividad real en la racha?, si aceptó la sugerencia. Una racha que ignora lo que hizo de verdad desmotiva
L5 es la que más pesa. Borrar lo ya leído al revocar es lo más respetuoso y lo que menos explicaciones exige ante el RGPD; conservarlo mantiene sus gráficas históricas intactas. No hay respuesta obvia y no debería decidirla yo.
NutriSync Collective · Propuesta 33 · Epic O — Wearables · 5 de agosto de 2026
Las cifras de esfuerzo son estimaciones de sprint, no compromisos. Las citas de las reglas de Apple, Google y Strava se comprobaron en sus fuentes el 5-ago-2026 y conviene revalidarlas antes de construir.

⌚ Proposal 33 · Wearables

Epic O — connecting NutriSync to the phone's health platforms: what we read, what it feeds, what we must NOT do, and in what order · for founder decision · 5 Aug 2026

1 · Executive summary

Today NutriSync asks each woman to type in what her phone already knows: whether she slept, whether she moved, whether her period started. Connecting to Apple Health and Health Connect removes that chore and, more importantly, improves the thing that matters most: knowing which phase of her cycle she's in. The wrist temperature a watch measures overnight confirms ovulation better than any calendar can.

Recommendation: ship only the two phone platforms before 8 Oct — Apple Health first, Health Connect next. Drop Fitbit and Strava for now (reasons in §3). Watch apps come after launch, and only if the pilot asks for them.

2 · What already exists

This doesn't start from zero. From an earlier session (Epic E) we already have:

  • health_signal table with a unique key on (user, provider, type, timestamp): the same sample cannot land twice, however many times we sync.
  • connected_providers table recording consent and its withdrawal, with timestamps. Auditable.
  • "Connected devices" screen in Settings, behind explicit consent.
  • A registry of 9 providers with their declared scopes.

And from this session, the data contract: the translation from what the platforms hand us into our model, written as pure functions with 21 unit tests. What's missing is the native connector, not the scaffolding.

3 · Two findings that change the plan

3.1 · Fitbit shuts down in September

Google is closing the Fitbit Web API in September 2026 — weeks before our launch. Its replacement, the Google Health API, classifies every scope as Restricted: they require a Google privacy and security review, which in turn requires a legal entity and a published privacy policy. Without the company incorporated, that review can't be passed.

Consequence: building Fitbit today means building something that dies on its own. And there's a better reason not to: anyone with a Fitbit can push their data into Health Connect, so the Android integration already covers it indirectly.

3.2 · Strava's contract fights our product

Strava's 2026 API agreement forbids using their data to train AI or machine-learning models — which is precisely Proposal 32 — and forbids showing a user's Strava data to anyone but herself, which rules out any community, coaching or comparison feature. It also now requires a paid subscription for the standard developer tier.

Consequence: for an app whose value lies in reasoning over data, that contract is a wall. Strava is a social network for sport; we are not. And people who log in Strava usually also push to Apple Health or Health Connect: the indirect route works without signing anything.

3.3 · A distinction worth making explicit

"Apple Watch app" and "Apple Health" sound like the same thing. They are two different projects:

Apple Health (HealthKit)Apple Watch app
What it isA native dependency in the iOS app we already haveA separate application with its own interface
StackThe same one: Expo + EAS buildSwift + SwiftUI, new code sharing nothing
Android equivalentHealth Connect, also nativeKotlin + Compose for Wear OS: a third codebase
What it buysThe data, without anyone typing itThe convenience of logging from the wrist

The data comes from the phone's health platform, not from the watch app. An Apple Watch already writes into Apple Health without us doing anything. That's why watch apps are a convenience project, not a data project — and why they come later.

4 · What we read, and why

The rule: every signal we request must have a concrete use in the app. The text on the right is literally what she will read in the permission dialog. If we can't write it, we don't ask for it — asking "just in case" is what makes people decline everything.

SignalWhat it does for her
SleepFills in your rest for the day without you typing itessential
WorkoutsMarks the movement you've already done on your daily ringessential
Menstrual flowIf you already log your period in Health, you don't repeat it hereessential
Wrist temperatureThe post-ovulation rise confirms which phase you're inoptional
Active energyTunes nutrition guidance to what you actually burnoptional
StepsTells an active day from a sedentary oneoptional
Resting heart rateA recovery signal: it rises when the body is asking for restoptional
Heart rate variabilityTracks with cycle phase and helps decide intensityoptional

Only three are essential. With those three the integration already earns its place; everything else can be declined without breaking anything.

5 · The rule that governs everything: objective fills, subjective correlates

A watch measures facts, not feelings. It can know how many minutes you slept; it cannot know whether you rested. It can measure your heart rate variability; it cannot know how you are.

We could technically fill in mood from resting heart rate and HRV. We must not. The day a woman feels perfectly fine and the app tells her she's in a bad mood, we have lost her trust for good. And the deeper risk is worse: mood plus cycle is exactly the terrain where a product like ours can end up reinforcing the stereotype that "you're like this because your period is coming". With a number behind it, that sounds like science. It isn't.

Measured signalFeedsHow
Sleepsleep_qualityA suggestion she can change
WorkoutMovement ringDirect
Flowflow_levelDirect
Active energy, stepsNutrition guidanceCalibrates portions to what she burns
TemperaturePhase confirmation (Epic M)The highest-value signal
HRV, resting heart rateRecommended intensity"Your body is asking for less today", never "you're sad"
Mood, perceived energyNothing. She writes themUsed as the axis that explains patterns
Where the real value sits: the mood she logs, crossed with what the watch measures, lets us tell her something she can't see on her own — "across your last three cycles, on the days you slept under six hours you logged lower energy". That's a pattern from her own data, not a machine telling her how she feels. It's the difference between a mirror and a judge.

6 · The signal that moves the needle: temperature and phase

The core of NutriSync is syncing nutrition and movement to cycle phase. Today phase is estimated from the calendar, with all the uncertainty that carries in irregular cycles. Watches with a temperature sensor (Apple Watch Series 8 and later, and several Wear OS models) measure wrist temperature during sleep; the sustained rise after ovulation is a real physiological signal.

A warning to lock in before building it: temperature confirms that ovulation happened — it does not predict it. It is retrospective. Any wording that hints it can be used to avoid pregnancy is both a legal and a human problem. Our legal documents already address this and the wording must stay consistent.

Used well, it improves phase accuracy without promising anything we can't deliver: "your cycle behaved as expected", or "you ovulated later than predicted this time, so we've adjusted".

7 · What the law and the stores require

  • GDPR Article 9. Health data is a special category. It requires explicit, separate, revocable consent. Already solved in the model: connected_providers records when consent was given and when it was withdrawn.
  • Apple's rule (App Store 5.1.3). HealthKit data may not be used for advertising, marketing or data mining, nor shared with third parties for those purposes. Only to improve the user's health management, or for health research with permission. This constrains the business model: it closes the door on monetising health data, now and permanently.
  • Consequence for AI (Proposal 32). If context is ever sent to a model, it cannot carry identifiable data. Already declared in Proposal 32 §2 and it still holds.
  • Minimisation. We read short windows and aggregates, not her entire life history. Less data means less risk and less to explain.

8 · Phases and effort

O1 · Apple Health, read — permissions, first sync, suggestions in the daily log and the ring. ≈1 sprint requires a native build IN PROGRESS
O2 · Apple Health, write — push the period she logs here back into Health. Reciprocity: the app doesn't only take. ≈2 days
O3 · Health Connect (Android) — same logic, different connector. Covers Samsung Health, and indirectly Fitbit and Garmin, because they write there. ≈1 sprint
O4 · Temperature → phase — ovulation confirmation inside Epic M. ≈1 sprint depends on O1
O5 · Personal patterns — correlations between what she logs and what the watch measures. Fits with Epic N. after launch
O6 · Watch apps (watchOS and Wear OS) — two new native codebases, two store reviews, two release cycles. after launch only if the pilot asks

9 · Risks

RiskMitigation
She declines permissions and the app looks brokenThe three essential signals are asked for with their reason; everything else is optional and the app works without any of it
Contradictory data (she says one thing, the watch another)She wins, always. The watch fills gaps, it doesn't correct anyone
Cheap watches produce poor dataWe store the provider of every sample: a noisy source can be switched off without touching the rest
Syncing drains batteryNo background reads in phase 1: we sync when the app opens
Apple rejects the app over permission wordingWritten to explain what for, not what. Reviewed before submission

10 · What we need from you

Three different things, and they shouldn't be blurred: decisions (direction), design (how it looks and feels) and logic (what the system does when nobody is watching). Without all three, O1 ships half-built.

10.1 · Decisions — founders

#DecisionRecommendationBlocks
D15Wearables before or after 8 Oct?Only O1–O3 before (the two phone platforms). It capitalises on the pilot, which already has iPhones in handAll of Epic O
D16Should mood be filled from watch data?No. Objective fills, subjective correlates (§5)O1 and O5
D17Fitbit and Strava?Not for now. Fitbit dies in September; Strava forbids what we do. Both arrive indirectly via Health ConnectScope of O3
D18Temperature for phase confirmation?Yes, with the wording in §6: it confirms, it doesn't predict, and never as contraceptionO4
D19Watch apps?After launch, and only if the pilot asks. They are two new native codebasesO6

10.2 · Design — four new screens

Four visual pieces, in order of need. The first three block O1.

PieceWhat it must solveWatch out for
Permission pre-screenExplain WHY we ask for each thing before the iOS dialog appears. One shot only: if she declines, iOS never asks againIt must not feel like paperwork. This is the moment trust is won or lost
Connection stateIn "Connected devices": connected / permission denied / not available on this phone, plus last sync"Not available" is not an error — an iPhone without a watch still gives sleep and steps
Suggestion card"Your watch says you slept 7h20. Shall we log it?" with accept or dismissIt must read clearly as a proposal, not as something already saved
Pattern card (O5)Tell one correlation from her own data in a single sentenceNever in a diagnostic or judgemental tone. A mirror, not a judge

Format: builder pack as always. Everything of ours is injected afterwards as a registered block.

10.3 · Logic — six rules to lock down

These are product decisions dressed as technical details. If we don't settle them, the code settles them by accident.

#RuleProposal
L1Does a suggestion apply itself or need a tap?A tap. Anything appearing in her diary without her approval breaks the rule in §5
L2Sleep thresholds → label<4h very poor · 4–5.5 restless · 5.5–7 okay · 7–8.5 restful · >8.5 deep. To be reviewed against nutrition criteria
L3When two sources disagree on the same figureThe phone platform wins; we keep both with their origin
L4How much history do we read on first connect?30 days. Enough to see a full cycle, little enough not to feel invasive
L5What happens when she revokes permissionWe stop reading and record the date. Do we delete what was already read? — your call; it has a cost and a legal reading
L6Does real activity count towards her streak?Yes, if she accepted the suggestion. A streak that ignores what she actually did is demotivating
L5 carries the most weight. Deleting what was already read on revocation is the most respectful option and the easiest to defend under GDPR; keeping it preserves her historical charts intact. There is no obvious answer and it shouldn't be mine to make.
NutriSync Collective · Proposal 33 · Epic O — Wearables · 5 August 2026
Effort figures are sprint estimates, not commitments. The Apple, Google and Strava rules cited here were checked against their sources on 5 Aug 2026 and should be re-validated before building.