Consumer Health Data Privacy Policy
Categories of consumer health data we collect
- Sleep measurements: duration, stages, efficiency, awakenings, and timing.
- Cardiac measurements: resting heart rate, heart rate variability, and heart rate through the day.
- Activity measurements: steps, active energy, active minutes, distance, and recorded workouts.
- Body measurements: weight, body fat percentage, and measurements you take yourself.
- Other physiological measurements: blood oxygen, breathing rate, skin temperature deviation.
- Blood biomarker results you enter from a lab panel.
- Health status you declare, such as being unwell or injured, and notes you record about a day.
- Inferences we derive from the above, including daily vitality, recovery, sleep, stress and exertion scores, and OmniAge, an effective-age estimate. These are consumer health data under these laws and we treat them as such.
Where we collect it from
- Apple Health on your device, with your per-category permission.
- Google Health, carrying data from Fitbit, Pixel and Health Connect devices, with your authorisation.
- Other wearable services you connect yourself.
- Directly from you, when you log something in the app.
Why we collect it
To provide the app's features to you and no one else: displaying your data, computing your scores, keeping your history, and restoring what you entered if you change phones. We do not use consumer health data for advertising, marketing, profiling, or model training.
How it is stored
Consumer health data is stored on your device in an encrypted database that is excluded from your iCloud backup, and the analysis runs there. The health data that reaches our servers is an encrypted backup of what you entered by hand, which we cannot read.
One exception, and it applies only to Garmin. Garmin does not let an app fetch data on request; it sends data to us instead. So for Garmin users, and no one else, readings arrive at our servers first and wait there until your phone collects them — normally within minutes. They are encrypted while they wait. But unlike the backup described above, we hold the key to this one, so it is data we could read, and we would rather say that plainly than let the stronger promise cover it. Anything your phone has not collected is deleted after 30 days, and everything is deleted immediately if you delete your account.
Categories we share, and with whom
We do not sell consumer health data. We have never sold it and we do not have a mechanism to do so. No signed authorisation for a sale will be sought, because no sale will occur.
We share consumer health data with no third party for that party's own purposes. The service providers who process data on our behalf, under contract, are:
| Recipient | What they receive | Purpose |
|---|---|---|
| Cloudflare, Inc. | Account records, consent records, and the encrypted backup of hand-entered data, which is unreadable to them and to us | Hosting and storage |
| Resend (Plus Five Five, Inc.) | Your email address only. No health data. | Account emails |
| Apple Inc. | Subscription records only. No health data. | Payments and subscriptions |
We may disclose data where the law compels it. We will tell you when that happens unless we are legally prohibited.
Your rights
- To know and to access — get a copy of the consumer health data we hold, including a list of everyone it has been shared with, and export it from inside the app.
- To withdraw consent — for collection, for sharing, or both, at any time.
- To delete — have your consumer health data deleted from our systems and from your device. We will pass the deletion request to any service provider holding it.
- To appeal — if we decline a request, you may appeal by replying to our decision. If we deny the appeal you may contact your state Attorney General.
To exercise any of these, email greywhalesoftware@gmail.com from the address on your account, or use the export and delete controls in the app. We will respond within 45 days, and will tell you if we need a permitted extension.
Employees and contractors
Access to systems holding consumer health data is limited to those who need it to operate the service. The hand-entered backup is encrypted on your device, so it is not readable by anyone at Greywhale Software regardless of access.
Changes
Material changes will be posted here with a new effective date, and you will be asked to agree again in the app before the change applies to you.
Contact
Greywhale Software LLC
greywhalesoftware@gmail.com
