Omni

Privacy Policy

Effective 2 September 2026. Omni is published by Greywhale Software LLC. This policy describes the app as it is being built; Omni is not yet available to the public. If anything here changes before release, the effective date changes with it.

The short version. Omni reads health data from your wearable and analyses it on your phone. We do not sell health data. We do not share it for advertising or marketing. Our servers hold your account, your consent records, and an encrypted copy of what you typed in yourself, and nothing else.

1. What Omni collects

Health and fitness data

Inferences Omni derives

Omni computes scores from the data above, including a daily Vitality score, recovery, sleep and stress scores, an exertion score, and OmniAge, an effective-age estimate. These derived values are health data too, and this policy covers them exactly as it covers the measurements.

Account information

Your email address, or the identifier Apple gives us if you sign in with Apple; your name, birth date, sex, units and time zone; and a record of the consents you have given.

2. Where it comes from

3. Where it is stored

Health data is stored on your device, in an encrypted database that is excluded from your iCloud backup. The analysis that produces every score runs there as well.

Our servers hold only:

That backup is encrypted before it leaves your phone. We cannot read it. Measurements from your tracker are not included, because Apple Health restores them to a new device and your wearable service can supply them again.

One exception, and it applies only to Garmin. Garmin does not let an app fetch data on request; it sends data to us instead. So for Garmin users, and no one else, readings arrive at our servers first and wait there until your phone collects them — normally within minutes. They are encrypted while they wait. But unlike the backup described above, we hold the key to this one, so it is data we could read, and we would rather say that plainly than let the stronger promise cover it. Anything your phone has not collected is deleted after 30 days, and everything is deleted immediately if you delete your account.

4. What it is used for

To provide the app: to show you your data, compute your scores, keep your history, sync your subscription, and let you restore after changing phones. Nothing else. We do not profile you, build advertising audiences, or use your health data to train models.

5. Who else sees it

We do not sell health data and we do not share it with third parties for advertising, marketing, or data mining. The only companies that process anything on our behalf are:

ProcessorWhat it receives
CloudflareHosting for our service: account records, consent records, and the encrypted backup it cannot read.
ResendYour email address, to send confirmation and password-reset messages.
AppleSubscription and purchase records, if you buy a subscription. Apple never receives your health data from us.

We may disclose information if the law requires it. If that ever happens we will tell you, unless we are legally barred from doing so.

6. Google API Limited Use

Omni's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data obtained through Google Health is used only to provide the features described here, is never sold, is never used for advertising, and is never transferred except as required by law or as needed to provide the app.

7. Who is responsible, and where data goes

The data controller is Greywhale Software LLC, a limited liability company registered in the United States, reachable at greywhalesoftware@gmail.com. We have not appointed a Data Protection Officer; the address above reaches the person responsible.

Our servers run on Cloudflare's global network, and email is sent through Resend. If you use Omni from outside the United States, the limited account data described in section 3 may be processed in the United States or in whichever Cloudflare location is nearest to you. Where the law requires a transfer mechanism, we rely on the European Commission's Standard Contractual Clauses as incorporated into our processors' terms. Your health measurements do not cross borders, because they do not leave your device.

8. Lawful basis for processing

For people in the United Kingdom and the European Economic Area, we process data on these bases:

WhatBasis
Health data and the scores derived from itYour explicit consent, given at onboarding and withdrawable at any time
Your account, sign-in, and encrypted backupPerformance of our contract with you
Subscription recordsPerformance of a contract, and our legal obligation to keep financial records
Consent records themselvesOur legal obligation to demonstrate that consent was given
Security, abuse prevention, and keeping the service runningOur legitimate interests, balanced against your rights

9. How long it is kept

10. Deleting your account

You can delete your account from inside the app. Doing so permanently removes your account, your consent records, your encrypted backup, and any stored wearable credentials from our systems, and erases the health database on your device. Copies in our routine database backups age out within 35 days. Deletion cannot be undone.

11. Your rights

Wherever you live, you can:

Residents of California, Washington, Nevada, Connecticut and other states with consumer health data laws have additional rights, described in our Consumer Health Data Privacy Policy. To exercise any right, email greywhalesoftware@gmail.com.

We answer within 30 days, or 45 where a law allows longer, and we will tell you if we need an extension. We do not charge for these requests and we will not treat you differently for making one. We may need to confirm you control the account before acting.

United Kingdom and European Economic Area (UK GDPR / GDPR)

In addition to the above you have the right to: access your data and receive a copy; rectify anything inaccurate; erase your data; restrict or object to processing, including processing based on our legitimate interests; and portability, meaning a machine-readable copy you can take elsewhere, which the in-app export provides. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

You also have the right to complain to your national supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EEA it is the authority for the country you live in. We would rather you told us first, but you do not have to.

We do not make decisions producing legal or similarly significant effects about you by automated means. Omni's scores are information shown to you, not decisions taken about you.

California (CCPA / CPRA)

In the twelve months before the effective date of this policy we collected the categories of personal information listed in section 1: identifiers (email address, account identifier), health and biometric information, and internet activity limited to what our servers must log to operate. We collected them from you and from the services you connect, for the business purposes in section 4. We disclose them only to the service providers named in section 5.

India (DPDP Act)

Greywhale Software LLC is the data fiduciary for the purposes of the Digital Personal Data Protection Act. You may access and correct your data, withdraw consent as easily as you gave it, nominate someone to exercise your rights if you die or become incapacitated, and raise a grievance with us at the address in section 16. If we do not resolve it, you may escalate to the Data Protection Board of India.

12. Children

Omni is not for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will delete it.

13. Security

Health data on your device is held in an encrypted store, protected by your device passcode, and kept out of iCloud backups. The backup on our servers is encrypted on your phone before it is sent. Traffic to our servers uses HTTPS. No system is perfect, and we do not claim otherwise; if a breach affects you we will notify you as the law requires, within 30 days.

14. A note on HIPAA

Omni is a consumer wellness app. It is not a healthcare provider, health plan, or clearinghouse, and it is not a HIPAA-covered entity. We say this plainly rather than implying a compliance status we do not have.

15. Changes

If this policy changes in a way that affects how your data is handled, we will update the effective date and ask you to agree again inside the app before the change applies to you.

16. Contact

Greywhale Software LLC
greywhalesoftware@gmail.com