Skip to content
  • Features
  • Business
Dashboard

// Legal

Consumer Health Data Privacy Policy

Last updated: 29 August 2026

On this page

1. Categories of consumer health data we collect, and the purpose of collection 2. Categories of sources from which consumer health data is collected 3. Categories of consumer health data that is shared 4. Categories of third parties and specific affiliates with whom consumer health data is shared 5. How to exercise your rights 6. Geofencing 7. Nevada-specific disclosures 8. Consent and authorisation

Required by the Washington My Health My Data Act, RCW 19.373.020, and by Nevada SB 370 (NRS 603A.400 et seq.)

Effective: 27 August 2026

This Consumer Health Data Privacy Policy applies to consumer health data of residents of Washington State and Nevada. It supplements, and prevails over, our general Privacy Policy for that data.

Entity responsible: Sebastian Furmańczyk, ul. Ameriga Vespucciego 12/34, 51-505 Wrocław, Poland. Contact: [email protected].

1. Categories of consumer health data we collect, and the purpose of collection

CategoryPurpose, including how it is used
Heart rate measurementsTo calculate your exertion (effort) score, display heart-rate zone charts, and derive your resting heart rate
Heart-rate variability (HRV)To calculate your recovery score and HRV trends
Resting heart rateTo calculate your recovery score and display it in the vitals widget
Sleep data, including sleep stages and session timesTo calculate sleep duration, sleep debt and your recovery score
Step countsTo display step totals and provide context for exertion
Calories burned (active and basal)To display calorie totals against your goal
Workout and exercise records: type, duration, energy, distanceTo create activities automatically and display your training history
Bodily and biological characteristics: date of birth, gender, weight, heightTo calculate heart-rate zones, calorie targets and training recommendations
Fitness level and training goalTo personalise training targets and AI-generated plans
Precise location associated with workouts (GPS routes) — iOS onlyTo display route maps and derive distance and pace
Data derived, inferred or generated by algorithm from the above — effort score, recovery score, optimal effort, heart-rate zones, sleep debt, baseline deviationsTo provide the core training-analysis features of the app
Health information you write in AI trainer conversationsTo generate training plans and answer training questions

2. Categories of sources from which consumer health data is collected

  • Directly from you — the onboarding wizard, profile settings, manually entered results, and messages to the AI trainer.
  • From your device, with your permission — Apple Health (HealthKit) on iOS and Google Health Connect on Android, which in turn receive data from your wearable devices and other health apps.
  • Derived by us — metrics calculated from the above, as listed in the final rows of the table in section 1.

3. Categories of consumer health data that is shared

We share the following categories of consumer health data with the service providers listed in section 4:

  • heart rate, HRV, resting heart rate, sleep, steps, calories and workout records — with our hosting and backup providers, which store all product data;
  • bodily and biological characteristics (date of birth, gender, weight, height, maximum and resting heart rate), fitness level, training goal, workout history with duration and average/maximum heart rate, and the content of AI trainer conversations — with our AI processing provider;
  • derived scores (effort, recovery) — with our push notification provider, where a notification’s text contains a score;
  • request URLs and diagnostic events that identify which health features you used — with our diagnostics provider;
  • precise location associated with workouts — with our hosting and backup providers, and with our map provider when a route map is rendered in the mobile app.

We share consumer health data with other users only where you choose to, by joining a group or a board. In that case the other members of that group or board can see: your first and last name, your profile picture, your effort and recovery scores, your step count and calories burned; and, where the group’s sharing settings allow it, your training activities (type, duration, heart-rate trace and GPS route) and your vitals (maximum and average heart rate, HRV, resting heart rate, sleep, and time in each heart-rate zone). A board’s owner additionally sees every board member’s email address.

4. Categories of third parties and specific affiliates with whom consumer health data is shared

We have no affiliates. MetconLovers is operated by a single sole trader with no parent, subsidiary or affiliated entities.

The specific third parties with whom consumer health data is shared are:

Third partyCategoryWhat it receives
OVH SAS / KimsufiCloud hosting providerAll consumer health data (it hosts the production database)
Amazon Web Services EMEA SARLCloud storage providerAll consumer health data, in database backups; uploaded images
Cloudflare, Inc.AI inference and cloud infrastructure providerTraining profile, workout history with heart-rate summaries, and AI conversation content
Cloudflare, Inc.Transactional email providerYour email address and the body of service messages, which may name a training board or group you belong to
Cloudflare, Inc.DNS and edge network providerMetadata for HTTP traffic to our services, including the paths of requests to health-related endpoints
Datadog, Inc.Application diagnostics providerRequest URLs and diagnostic events identifying use of health features, together with your user identifier, first name and email address
Google LLC (Firebase Cloud Messaging)Push notification providerNotification content, which may include an effort score
Google LLC (Google Maps)Mapping providerThe geographic area of a workout route, when a route map is rendered in the mobile app

We do not sell consumer health data, and we have not sold it. We do not share it with data brokers, advertisers, insurers, employers, credit bureaus or risk-scoring agencies.

5. How to exercise your rights

To exercise any right below, email [email protected] with the subject line “Consumer Health Data Request”. You may also submit a request through an authorised agent who provides written authorisation.

You have the right to:

  1. Confirm whether we are collecting, sharing or selling your consumer health data, and to access that data — including a list of all third parties and affiliates with whom we have shared or to whom we have sold it, together with an active email address or other online contact for each.

  2. Withdraw consent to our collection of your consumer health data, and separately to withdraw consent to its sharing.

  3. Delete your consumer health data. On receiving a deletion request we delete the data from our production systems and from all live storage, and we notify every third party with whom we have shared it, instructing them to delete it as well. We will confirm completion to you.

    How this works for backups, stated precisely. We keep encrypted disaster-recovery backups on a 90-day rolling cycle. Individual records cannot be surgically removed from a sealed backup image, so your data is purged from backups as that 90-day cycle expires rather than at the instant of your request. During those 90 days the backups are used for one purpose only — restoring the service after a failure — and are not queried, mined or disclosed. If we ever restore a backup taken before your deletion request, we re-apply your deletion immediately upon restore. This is our complete and honest answer for archived and backup systems; we will not promise an instantaneous backup purge that no backup architecture can deliver.

  4. Not be discriminated against for exercising any of these rights.

Our response times. We respond within 45 days of receiving your request. Where reasonably necessary, we may extend that period by a further 45 days, and we will tell you within the first 45 days, with reasons.

Nevada deletion requests. For Nevada residents, we act on a request to delete consumer health data within 30 days of receiving it, as NRS 603A.515 requires — we do not take the longer Washington period for those requests.

Appeals. If we decline your request, we will tell you why and how to appeal. To appeal, reply to our decision or email [email protected] with “Appeal” in the subject line. We will respond to an appeal in writing within 45 days, with our reasoning. If we uphold the refusal, we will provide you with an online mechanism or other method to contact the Washington State Attorney General (https://www.atg.wa.gov/file-complaint) or, for Nevada residents, the Nevada Attorney General.

6. Geofencing

We do not, and will not, implement a geofence around any entity that provides in-person health care services to identify or track consumers seeking health care services, to collect consumer health data, or to send notifications or advertisements related to consumer health data or health care services.

7. Nevada-specific disclosures

For Nevada residents, the following supplements the above:

  • Categories of third parties who may collect consumer health data across websites or applications over time: none. We use no advertising networks, no analytics networks with cross-site tracking, and no tracking pixels. Our diagnostics provider (Datadog) operates only within our own app and websites and does not track you across other operators’ services.
  • Consumer health data collected includes data derived through an algorithm or machine learning — specifically the effort score, recovery score, optimal effort, heart-rate zones, sleep debt and baseline deviations described in section 1.
  • Material changes to this policy will be notified to you in advance by in-app notification or email before they take effect, and the effective date at the top of this document will be updated. We will not apply a material change retroactively to data already collected without obtaining your consent.
  • Effective date: 27 August 2026.

8. Consent and authorisation

We collect, use and share consumer health data only with your consent, obtained separately from any terms of service and after you have been presented with the disclosures in this document, or as necessary to provide a product or service you have requested from us.

We do not sell consumer health data. We therefore do not seek, and have never obtained, the separate written authorisation that RCW 19.373.110 requires before any sale of consumer health data. Consent under RCW 19.373.030 (which governs collection and sharing) and authorisation under RCW 19.373.110 (which governs sale) are distinct requirements: we rely on the former and, because we do not sell, the latter never arises.

This policy covers consumer health data only. Everything else we collect and why is in the full privacy policy.

Questions? Reach us at [email protected].

Built in the garage. For everyone who trains.

Product

  • Features
  • What is an effort score?
  • Business

Legal

  • Privacy
  • Consumer Health Data
  • Terms
© 2026 MetconLovers MetconLovers is not a medical device and does not provide medical advice.