// Legal
Consumer Health Data Privacy Policy
Last updated: 29 August 2026
Required by the Washington My Health My Data Act, RCW 19.373.020, and by Nevada SB 370 (NRS 603A.400 et seq.)
Effective: 27 August 2026
This Consumer Health Data Privacy Policy applies to consumer health data of residents of Washington State and Nevada. It supplements, and prevails over, our general Privacy Policy for that data.
Entity responsible: Sebastian Furmańczyk, ul. Ameriga Vespucciego 12/34, 51-505 Wrocław, Poland. Contact: [email protected].
1. Categories of consumer health data we collect, and the purpose of collection
| Category | Purpose, including how it is used |
|---|---|
| Heart rate measurements | To calculate your exertion (effort) score, display heart-rate zone charts, and derive your resting heart rate |
| Heart-rate variability (HRV) | To calculate your recovery score and HRV trends |
| Resting heart rate | To calculate your recovery score and display it in the vitals widget |
| Sleep data, including sleep stages and session times | To calculate sleep duration, sleep debt and your recovery score |
| Step counts | To display step totals and provide context for exertion |
| Calories burned (active and basal) | To display calorie totals against your goal |
| Workout and exercise records: type, duration, energy, distance | To create activities automatically and display your training history |
| Bodily and biological characteristics: date of birth, gender, weight, height | To calculate heart-rate zones, calorie targets and training recommendations |
| Fitness level and training goal | To personalise training targets and AI-generated plans |
| Precise location associated with workouts (GPS routes) — iOS only | To display route maps and derive distance and pace |
| Data derived, inferred or generated by algorithm from the above — effort score, recovery score, optimal effort, heart-rate zones, sleep debt, baseline deviations | To provide the core training-analysis features of the app |
| Health information you write in AI trainer conversations | To generate training plans and answer training questions |
2. Categories of sources from which consumer health data is collected
- Directly from you — the onboarding wizard, profile settings, manually entered results, and messages to the AI trainer.
- From your device, with your permission — Apple Health (HealthKit) on iOS and Google Health Connect on Android, which in turn receive data from your wearable devices and other health apps.
- Derived by us — metrics calculated from the above, as listed in the final rows of the table in section 1.
3. Categories of consumer health data that is shared
We share the following categories of consumer health data with the service providers listed in section 4:
- heart rate, HRV, resting heart rate, sleep, steps, calories and workout records — with our hosting and backup providers, which store all product data;
- bodily and biological characteristics (date of birth, gender, weight, height, maximum and resting heart rate), fitness level, training goal, workout history with duration and average/maximum heart rate, and the content of AI trainer conversations — with our AI processing provider;
- derived scores (effort, recovery) — with our push notification provider, where a notification’s text contains a score;
- request URLs and diagnostic events that identify which health features you used — with our diagnostics provider;
- precise location associated with workouts — with our hosting and backup providers, and with our map provider when a route map is rendered in the mobile app.
We share consumer health data with other users only where you choose to, by joining a group or a board. In that case the other members of that group or board can see: your first and last name, your profile picture, your effort and recovery scores, your step count and calories burned; and, where the group’s sharing settings allow it, your training activities (type, duration, heart-rate trace and GPS route) and your vitals (maximum and average heart rate, HRV, resting heart rate, sleep, and time in each heart-rate zone). A board’s owner additionally sees every board member’s email address.
4. Categories of third parties and specific affiliates with whom consumer health data is shared
We have no affiliates. MetconLovers is operated by a single sole trader with no parent, subsidiary or affiliated entities.
The specific third parties with whom consumer health data is shared are:
| Third party | Category | What it receives |
|---|---|---|
| OVH SAS / Kimsufi | Cloud hosting provider | All consumer health data (it hosts the production database) |
| Amazon Web Services EMEA SARL | Cloud storage provider | All consumer health data, in database backups; uploaded images |
| Cloudflare, Inc. | AI inference and cloud infrastructure provider | Training profile, workout history with heart-rate summaries, and AI conversation content |
| Cloudflare, Inc. | Transactional email provider | Your email address and the body of service messages, which may name a training board or group you belong to |
| Cloudflare, Inc. | DNS and edge network provider | Metadata for HTTP traffic to our services, including the paths of requests to health-related endpoints |
| Datadog, Inc. | Application diagnostics provider | Request URLs and diagnostic events identifying use of health features, together with your user identifier, first name and email address |
| Google LLC (Firebase Cloud Messaging) | Push notification provider | Notification content, which may include an effort score |
| Google LLC (Google Maps) | Mapping provider | The geographic area of a workout route, when a route map is rendered in the mobile app |
We do not sell consumer health data, and we have not sold it. We do not share it with data brokers, advertisers, insurers, employers, credit bureaus or risk-scoring agencies.
5. How to exercise your rights
To exercise any right below, email [email protected] with the subject line “Consumer Health Data Request”. You may also submit a request through an authorised agent who provides written authorisation.
You have the right to:
-
Confirm whether we are collecting, sharing or selling your consumer health data, and to access that data — including a list of all third parties and affiliates with whom we have shared or to whom we have sold it, together with an active email address or other online contact for each.
-
Withdraw consent to our collection of your consumer health data, and separately to withdraw consent to its sharing.
-
Delete your consumer health data. On receiving a deletion request we delete the data from our production systems and from all live storage, and we notify every third party with whom we have shared it, instructing them to delete it as well. We will confirm completion to you.
How this works for backups, stated precisely. We keep encrypted disaster-recovery backups on a 90-day rolling cycle. Individual records cannot be surgically removed from a sealed backup image, so your data is purged from backups as that 90-day cycle expires rather than at the instant of your request. During those 90 days the backups are used for one purpose only — restoring the service after a failure — and are not queried, mined or disclosed. If we ever restore a backup taken before your deletion request, we re-apply your deletion immediately upon restore. This is our complete and honest answer for archived and backup systems; we will not promise an instantaneous backup purge that no backup architecture can deliver.
-
Not be discriminated against for exercising any of these rights.
Our response times. We respond within 45 days of receiving your request. Where reasonably necessary, we may extend that period by a further 45 days, and we will tell you within the first 45 days, with reasons.
Nevada deletion requests. For Nevada residents, we act on a request to delete consumer health data within 30 days of receiving it, as NRS 603A.515 requires — we do not take the longer Washington period for those requests.
Appeals. If we decline your request, we will tell you why and how to appeal. To appeal, reply to our decision or email [email protected] with “Appeal” in the subject line. We will respond to an appeal in writing within 45 days, with our reasoning. If we uphold the refusal, we will provide you with an online mechanism or other method to contact the Washington State Attorney General (https://www.atg.wa.gov/file-complaint) or, for Nevada residents, the Nevada Attorney General.
6. Geofencing
We do not, and will not, implement a geofence around any entity that provides in-person health care services to identify or track consumers seeking health care services, to collect consumer health data, or to send notifications or advertisements related to consumer health data or health care services.
7. Nevada-specific disclosures
For Nevada residents, the following supplements the above:
- Categories of third parties who may collect consumer health data across websites or applications over time: none. We use no advertising networks, no analytics networks with cross-site tracking, and no tracking pixels. Our diagnostics provider (Datadog) operates only within our own app and websites and does not track you across other operators’ services.
- Consumer health data collected includes data derived through an algorithm or machine learning — specifically the effort score, recovery score, optimal effort, heart-rate zones, sleep debt and baseline deviations described in section 1.
- Material changes to this policy will be notified to you in advance by in-app notification or email before they take effect, and the effective date at the top of this document will be updated. We will not apply a material change retroactively to data already collected without obtaining your consent.
- Effective date: 27 August 2026.
8. Consent and authorisation
We collect, use and share consumer health data only with your consent, obtained separately from any terms of service and after you have been presented with the disclosures in this document, or as necessary to provide a product or service you have requested from us.
We do not sell consumer health data. We therefore do not seek, and have never obtained, the separate written authorisation that RCW 19.373.110 requires before any sale of consumer health data. Consent under RCW 19.373.030 (which governs collection and sharing) and authorisation under RCW 19.373.110 (which governs sale) are distinct requirements: we rely on the former and, because we do not sell, the latter never arises.
This policy covers consumer health data only. Everything else we collect and why is in the full privacy policy.