Omni

Consumer Health Data Privacy Policy

Effective 2 September 2026. Published by Greywhale Software LLC. This is a separate document from our general Privacy Policy, as Washington's My Health My Data Act requires. It also covers residents of Nevada, Connecticut, California and other states with consumer health data laws. Omni is not yet available to the public.

Categories of consumer health data we collect

Where we collect it from

Why we collect it

To provide the app's features to you and no one else: displaying your data, computing your scores, keeping your history, and restoring what you entered if you change phones. We do not use consumer health data for advertising, marketing, profiling, or model training.

How it is stored

Consumer health data is stored on your device in an encrypted database that is excluded from your iCloud backup, and the analysis runs there. The health data that reaches our servers is an encrypted backup of what you entered by hand, which we cannot read.

One exception, and it applies only to Garmin. Garmin does not let an app fetch data on request; it sends data to us instead. So for Garmin users, and no one else, readings arrive at our servers first and wait there until your phone collects them — normally within minutes. They are encrypted while they wait. But unlike the backup described above, we hold the key to this one, so it is data we could read, and we would rather say that plainly than let the stronger promise cover it. Anything your phone has not collected is deleted after 30 days, and everything is deleted immediately if you delete your account.

Categories we share, and with whom

We do not sell consumer health data. We have never sold it and we do not have a mechanism to do so. No signed authorisation for a sale will be sought, because no sale will occur.

We share consumer health data with no third party for that party's own purposes. The service providers who process data on our behalf, under contract, are:

RecipientWhat they receivePurpose
Cloudflare, Inc.Account records, consent records, and the encrypted backup of hand-entered data, which is unreadable to them and to usHosting and storage
Resend (Plus Five Five, Inc.)Your email address only. No health data.Account emails
Apple Inc.Subscription records only. No health data.Payments and subscriptions

We may disclose data where the law compels it. We will tell you when that happens unless we are legally prohibited.

Your rights

To exercise any of these, email greywhalesoftware@gmail.com from the address on your account, or use the export and delete controls in the app. We will respond within 45 days, and will tell you if we need a permitted extension.

Employees and contractors

Access to systems holding consumer health data is limited to those who need it to operate the service. The hand-entered backup is encrypted on your device, so it is not readable by anyone at Greywhale Software regardless of access.

Changes

Material changes will be posted here with a new effective date, and you will be asked to agree again in the app before the change applies to you.

Contact

Greywhale Software LLC
greywhalesoftware@gmail.com