Skip to content
  • Features
  • Business
Dashboard

// Legal

Privacy Policy

Last updated: 29 August 2026

On this page

1. At a glance 2. Who we are and what this policy covers 3. Our principles 4. Definitions 5. Information we collect 6. Where your information is stored 7. How and why we use your data, and our legal bases 8. AI trainer 9. Profiling and automated decision-making 10. How we share your information 11. What you share with other users 12. International transfers 13. How long we keep your data 14. Deleting your account and your data 15. Your rights 16. Consents and how to withdraw them 17. Local storage, identifiers and cookies 18. Security 19. Security incident notification 20. Children 21. Not a medical device, not medical advice 22. Changes to this policy 23. Contact us ANNEX A — Processors and recipients ANNEX B — EEA, United Kingdom and Switzerland B.1 EEA B.2 United Kingdom B.3 Switzerland ANNEX C — United States C.1 HIPAA does not apply C.2 California (CCPA/CPRA) C.3 Washington My Health My Data Act C.4 Other states ANNEX C-1 — CONSUMER HEALTH DATA PRIVACY POLICY ANNEX D — Canada, Australia, Brazil D.1 Canada (PIPEDA) D.2 Australia (Privacy Act 1988) D.3 Brazil (LGPD) ANNEX E — Language versions

Version: 1.1
Effective: 27 August 2026
Last updated: 29 August 2026
What changed: section 2.4 now points at the published Terms of Service.


1. At a glance

This summary helps you understand quickly what we do with your data. It does not replace the full text — sections 2–23 are what binds us.

  • Who we are. MetconLovers is operated by Sebastian Furmańczyk, a sole trader based in Wrocław, Poland. Contact: [email protected].
  • What we collect. Account data (email, name), a training profile (date of birth, gender, weight, height, goals) and — with your explicit consent — health data from Apple Health and Google Health Connect: heart rate, heart-rate variability (HRV), resting heart rate, sleep, steps, calories and workouts. On iOS we also read GPS workout routes.
  • This is special category data. Health data receives heightened protection under Article 9 GDPR. We process it solely on the basis of your explicit consent, which you can withdraw at any time.
  • Your data goes to our servers. This is not an on-device-only app. Raw heart-rate series and full GPS traces are uploaded to and stored on our servers in Frankfurt, Germany (EEA). We say this plainly because some apps claim otherwise.
  • We use AI. The AI trainer runs on Cloudflare Workers AI. We send it your training profile and your conversation history. The models are hosted by Cloudflare — their authors receive nothing, and Cloudflare does not use your data to train models. See section 8.
  • Three commitments. (1) We do not sell your data. (2) We do not use health data for advertising, marketing or use-based data mining. (3) We do not disclose health data to third parties without your consent, except as described in section 10.
  • You can delete your account. In the app: Settings → Privacy → Delete account. We erase your data within 30 days. Details and exceptions: section 14.
  • You have rights. Access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to complain to the Polish supervisory authority. Section 15.
  • Minimum age: 16.

2. Who we are and what this policy covers

2.1 The controller

The controller of your personal data is:

Sebastian Furmańczyk, sole trader (jednoosobowa działalność gospodarcza)
ul. Ameriga Vespucciego 12/34
51-505 Wrocław, Poland
Tax ID (NIP): 895-223-49-10
Business register number (REGON): 520252182
Email: [email protected]

Referred to below as “we”, “us”, “the Controller” or “MetconLovers”.

We have not appointed a Data Protection Officer. We are not required to at our current scale of processing. For all data protection matters, write to [email protected] — it is answered personally.

2.2 What this policy covers

This policy applies to every surface of the MetconLovers product:

  • the MetconLovers iOS app (App Store),
  • the MetconLovers Android app (Google Play),
  • the web dashboard at dashboard.metconlovers.com,
  • the marketing site at metconlovers.com,
  • home-screen widgets on iOS and Android,
  • background health-data synchronisation,
  • the AI trainer inside the app.

Together, the “Services” or the “App”.

2.3 What this policy does NOT cover

  • Apple Health (HealthKit) and Google Health Connect — these are operating-system features. Apple and Google process the data held in them under their own terms. We only read the data you permit us to read.
  • Payments handled by Stripe — card details, bank details and identity verification data are collected directly by Stripe on Stripe-hosted pages. They never reach our servers.
  • App Store and Google Play purchases — subscriptions are billed by Apple and Google under their own terms.
  • Third-party sites and services linked from the Services.

2.4 Related documents

  • Terms of Service — the contract between you and us. It is what Article 6(1)(b) GDPR refers to wherever this policy relies on it. It covers the subscription, the marketplace, content rules and liability; it does not govern your personal data, which is what this policy is for.
  • Annexes A–E to this policy (at the end of this document).
  • Consumer Health Data Privacy Policy — a standalone document required by Washington State law, published at its own separate link. Its full text is at Annex C-1 below.

Conflict clause: where a regional annex (B, C, D) is more favourable to you or more specific than the main body, the annex prevails for people in that region. The Consumer Health Data Privacy Policy prevails over this policy for consumer health data of Washington residents.


3. Our principles

Five commitments we treat as binding:

  1. We do not sell your data. Ever. We are not a data broker and we earn no revenue from reselling information about our users.
  2. Health data is never used for advertising. We do not use heart rate, sleep, HRV or any other health metric to target advertising, for marketing, or for use-based data mining — neither ourselves nor through third parties.
  3. We minimise what we send onward. The AI trainer receives a defined subset of your profile, not your whole account. The push provider receives your device token and the notification’s text — and that text sometimes contains your effort score or another user’s name. We set that out in Annex A rather than claiming we send it nothing health-related.
  4. We take government and litigant requests seriously. We do not hand data to authorities or civil litigants without a valid legal basis. Where the law permits, we will tell you about a request before we comply with it.
  5. We tell the truth about the architecture. If data leaves your device, we say so. If something is stored indefinitely, we say so. We do not use the words “anonymous” or “end-to-end encrypted” unless they are true.

4. Definitions

TermMeaning
Services / AppAll surfaces listed in section 2.2
AccountYour individual profile in the Services
Training dataHeart rate, HRV, resting heart rate, sleep, steps, calories burned, workouts, GPS routes, and the metrics derived from them (effort, recovery, heart-rate zones, sleep debt, distance, pace)
Health profileDate of birth, gender, weight, height, maximum heart rate, resting heart rate, fitness level, training goal
Special category dataData concerning health within the meaning of Articles 4(15) and 9(1) GDPR. This covers both Training data and the Health profile
GroupA social feature that lets you compare results with other users
BoardA training plan run by a coach or gym that you can join or purchase
AI trainerThe conversational feature described in section 8
ProcessorA supplier that processes data on our behalf and on our instructions (Article 28 GDPR)
GDPRRegulation (EU) 2016/679
PKEThe Polish Electronic Communications Law of 12 July 2024 (Dz.U. 2024 item 1221)

5. Information we collect

5.1 Information you provide

DataWhen
Email addressSign-up; sign-in with Google or Apple
PasswordSign-up (stored only as a bcrypt hash — never in plain text)
First and last nameSign-up, or from your Google / Apple account
Profile picture (avatar)Optional, from your device’s photo library
Date of birth, genderOnboarding wizard
Weight, heightOnboarding wizard
Units (metric / imperial)Onboarding wizard
Fitness level, training goalOnboarding wizard
Sleep goal, step goal, calorie goalOnboarding and settings
Manually set heart-rate zones, maximum heart rate, resting heart rateSettings (optional — we calculate these automatically by default)
Board content: training plans, notes, exercise descriptionsUsing the boards feature
Workout results: text comments, photos, links to activitiesPosting results
Group names, descriptions, group imagesCreating a group
Email addresses of people you inviteSending invitations
Messages to the AI trainerUsing the AI trainer
Notification preferences (push and email)Settings

5.2 Health data from Apple Health and Google Health Connect

This is special category data under Article 9(1) GDPR. We read it only after you give explicit consent — separately in our app and separately at operating-system level.

iOS — Apple Health (HealthKit)

We request read permissions only. The app never writes data to Apple Health.

HealthKit data typeWhat we use it for
HKQuantityTypeIdentifierHeartRate — heart rateEffort score, heart-rate zone charts, deriving resting heart rate
HKQuantityTypeIdentifierRestingHeartRate — resting heart rateRecovery score, vitals widget
HKQuantityTypeIdentifierHeartRateVariabilitySDNN — heart-rate variability (HRV)Recovery score, HRV trends
HKQuantityTypeIdentifierStepCount — stepsSteps page, effort context
HKQuantityTypeIdentifierActiveEnergyBurned — active energyCalories page, calorie goal
HKQuantityTypeIdentifierBasalEnergyBurned — basal energyCalories page, calorie goal
HKCategoryTypeIdentifierSleepAnalysis — sleep analysis (light, deep, REM, awake stages)Sleep duration, sleep debt, recovery score
HKWorkoutType — workouts (type, start, end, duration, energy, distance)Automatic activity creation
HKSeriesType workoutRouteType — workout routesRoute map, distance, pace — see section 5.3

We also read the name of the app or device that wrote each workout (for example, your watch model), so we know where a record came from.

Android — Google Health Connect

We request read permissions only.

Health Connect permissionWhat we use it for
READ_HEART_RATEAs above
READ_HEART_RATE_VARIABILITYAs above
READ_RESTING_HEART_RATEAs above
READ_SLEEPAs above
READ_STEPSAs above
READ_ACTIVE_CALORIES_BURNEDAs above
READ_TOTAL_CALORIES_BURNEDAs above
READ_EXERCISEAs above
READ_HEALTH_DATA_IN_BACKGROUNDBackground reading — see below

On Android we read no location data at all. The app does not declare ACCESS_FINE_LOCATION or ACCESS_COARSE_LOCATION and does not read exercise routes from Health Connect.

Reading in the background

So that your effort and recovery scores stay current without you having to open the app, we read health data while the app is closed:

  • iOS: we register HealthKit observers for workouts and heart rate. Each new heart-rate sample from a worn watch can wake the app (throttled to one recalculation every 4 minutes).
  • Android: a periodic task runs roughly every 15 minutes when a network connection is available, using the READ_HEALTH_DATA_IN_BACKGROUND permission.

On first sync we look back a maximum of 30 days. You can turn background reading off — see section 16.

5.3 Location data (workout routes)

iOS only. If Apple Health holds a route trace for a workout (for example, from a sports watch or a running app), we read it and upload it to our servers at full resolution. Each route point contains:

  • latitude and longitude,
  • altitude,
  • speed and speed accuracy,
  • horizontal accuracy,
  • a timestamp.

From the route we derive total distance, maximum and average speed, and the geographic centre of the route (to centre the map).

What we do not do:

  • We do not track your current location. The app contains no real-time location-tracking component and does not enable the user-location display on maps.
  • On Android we collect no location data whatsoever.

A note about maps: when you view a route map in the mobile app, map tiles are fetched from Google Maps — which means the geographic area of your workout is disclosed to Google. The web dashboard uses no external maps; it draws the route locally without fetching any tiles.

GPS routes require separate consent and you can decline them while still sharing your other health data.

5.4 Data generated by using the Services

DataSource
Screen names, interaction events (taps)App diagnostics (Datadog)
Network request URLs and response timingsApp diagnostics
Application errors and crash reportsApp diagnostics
Push notification token (FCM)Firebase Cloud Messaging
IP address, request date and time, path requestedServer logs
Your user identifier on essentially every request, and for some operations your email address (sign-in, sign-up, password reset, message delivery)Application logs
Widget configuration, theme preferenceLocal device / browser storage
Subscription identifier and purchase stateRevenueCat, App Store, Google Play

5.5 Data we derive

We calculate the following from the data in sections 5.1–5.3. These are also data concerning health:

  • Effort — a daily and per-activity exertion score, broken down by heart-rate zone (time and value in each zone),
  • Recovery — a daily recovery score,
  • Optimal effort — a suggested exertion level,
  • Heart-rate zones — calculated using the heart-rate reserve (Karvonen) method from your maximum and resting heart rate,
  • Resting heart rate — derived from your lowest overnight readings where not supplied directly,
  • Sleep debt and deviations of HRV and resting heart rate from your personal baseline,
  • Distance, pace and speed — from GPS routes,
  • AI conversation titles — generated automatically from your opening message,
  • Workout type classification — automatic tagging of board sessions.

5.6 Data from other sources

In accordance with Articles 14(1)(d) and 14(2)(f) GDPR, we tell you that we also receive data from:

SourceCategories of data
Apple Health / Google Health ConnectThe health data in section 5.2, plus the name of the app or device that wrote it
Sign in with AppleEmail address (may be a @privaterelay.appleid.com relay address, which we accept and treat as valid)
Google Sign-InEmail address, first name, last name
StripeSeller account identifier, verification status, payment confirmations
RevenueCat / App Store / Google PlaySubscription status and expiry date
Other usersGroup and board invitations containing your email address; memberships; results posted on shared boards

5.7 Data about other people

Social features work in both directions. When you join a group or a board, you see other people’s data and they see yours. Section 11 sets out exactly what. By using these features, you undertake not to use other users’ data outside the Services.


6. Where your information is stored

We state this plainly, because it is often described imprecisely:

Your raw health data leaves your device. Complete heart-rate series and full GPS traces are uploaded to and stored on our servers. This is not a local-only app.

WhatWhere
Production database (accounts, training data, boards, results, notifications)Dedicated server at Kimsufi (OVH), Frankfurt am Main, Germany — EEA
Database backupsAmazon S3, region eu-central-1 (Frankfurt) — EEA
Uploaded photos, avatars, exercise videoAmazon S3, region eu-central-1 (Frankfurt) — EEA
AI trainer conversations, thread titles, cached training profileCloudflare — global infrastructure, see section 12
App diagnostics dataDatadog, region EU1 (European Union)
Cached widget values (effort, recovery, resting HR, HRV, sleep)On your device, in storage shared with the widget extension
Session token and user profileOn your device, and in browser local storage for the web dashboard

7. How and why we use your data, and our legal bases

7.1 Purposes and legal bases

For data concerning health, two bases are always required: an Article 6 basis and an Article 9(2) exception. Article 9 GDPR contains no “necessary for a contract” exception — which is why we process health data on the basis of your explicit consent (Article 9(2)(a) GDPR).

PurposeArticle 6 basisArticle 9 basisNotes
Creating and running your account, authenticationArt. 6(1)(b) — necessary for the contract—Providing an email address is a contractual requirement; you cannot create an account without it
Reading and storing health data from Apple Health / Health ConnectArt. 6(1)(a) — consentArt. 9(2)(a) — explicit consentProviding this data is voluntary, but the core function of the product will not work without it
Reading health data in the backgroundArt. 6(1)(a) — consentArt. 9(2)(a)Separate consent
Reading GPS workout routes (iOS)Art. 6(1)(a) — consentArt. 9(2)(a) — the route is read from a workout record and forms part of that health record, so we apply the same regime to it as to other health dataSeparate consent
Calculating effort, recovery, heart-rate zones, sleep debtArt. 6(1)(a) — consentArt. 9(2)(a)Section 9. These metrics are calculated from health data, so we base them on the same consent that permits reading it — not on the contract
AI trainerArt. 6(1)(a) — consentArt. 9(2)(a) — explicit consentSeparate consent, required before first use. Section 8
Social features: boards, leaderboards, membershipsArt. 6(1)(b) — necessary for the contract—Section 11
Sharing health data with other group membersArt. 6(1)(a) — consentArt. 9(2)(a)The consent is your decision to join a group with a given sharing scope — see section 11.2
Push and email notifications about events in the ServicesArt. 6(1)(b) — performance of the contract—We send service notifications only, never marketing. Section 16
Handling payments, subscriptions and marketplace purchasesArt. 6(1)(b)——
Issuing and retaining accounting recordsArt. 6(1)(c) — legal obligation—Polish Accounting Act; Tax Ordinance
Diagnostics, crash reporting, app stabilityArt. 6(1)(a) — consent (terminal-equipment identifiers, art. 399 PKE)—You may decline without losing functionality
Security of the Services, abuse detection, system integrityArt. 6(1)(f) — legitimate interests—Our interest: keeping the Services secure and protected from unauthorised access
Establishing, exercising and defending legal claimsArt. 6(1)(f)Art. 9(2)(f) where health data is involvedOur interest: being able to defend against claims
Demonstrating GDPR compliance (consent records)Art. 6(1)(c) with Art. 5(2) GDPR——

7.2 Our health-data commitments

For all data read from Apple Health (HealthKit) and Google Health Connect, and for all metrics derived from it, we commit unconditionally that:

  1. We do not sell it — not to advertising platforms, not to data brokers, not to information resellers, not to anyone.
  2. We do not use it for advertising, marketing or use-based data mining.
  3. We do not disclose it to third parties without your consent — other than to the processors listed in Annex A, which act solely on our instructions, and where required by law.
  4. We do not transfer it to insurers, employers, credit-assessment institutions or risk-scoring agencies.
  5. We do not send it to iCloud and we do not store it in any iCloud account of ours. A caveat: the app writes cached values needed by the widgets onto your device (effort score, recovery score, resting heart rate, HRV, sleep duration). If you have the system iCloud backup enabled on iOS, or Android Auto Backup on Android, those values may be included in your device’s backup to your own account. That is a backup in your cloud and under your control, not a transfer to us — but we say so plainly, and we are working to exclude this data from system backups.
  6. We do not use it to train artificial-intelligence models — neither ours nor anyone else’s.
  7. We use it solely to provide and improve features that are visible to you in the Services’ interface.

Data read from Health Connect is transferred onward only in four cases: (a) with your explicit consent, (b) for security purposes such as investigating an incident, (c) where required by law, (d) as part of a merger, acquisition or sale of assets — after notifying you first and after obtaining your explicit consent.

Human access to health data is restricted to cases where it is necessary (your support request, a legal obligation, investigating a security incident, or processing in aggregated and de-identified form).


8. AI trainer

8.1 What it is

The AI trainer is a conversational feature that builds training plans and answers training questions using your profile and workout history. It is live in the Services and requires separate, explicit consent before first use.

8.2 Exactly what data reaches the model

We send the language model:

Profile (9 fields):
gender, date of birth, maximum heart rate, resting heart rate, weight, height, fitness level, training goal, units (metric/imperial).

Note: our server hands the AI trainer service the entire profile settings object, and the narrowing to the nine fields above happens in code running on Cloudflare’s side. This means the remaining settings fields (calorie goal, sleep goal, step goal, maximum effort, notification preferences) pass through Cloudflare’s infrastructure in transit, even though they never enter the model prompt and are not stored there.

Workout history:
for each training day, the date and workout text; for linked activities, the type, duration, average heart rate and maximum heart rate.

Conversation content:
all of your messages and the assistant’s replies. If you write about an injury, pain or a health problem, that information goes to the model and is stored in your conversation history.

What we do NOT send to the model:
your recovery score, sleep data, effort score, step and calorie goals, notification settings, heart-rate zones, location data or GPS routes, email address, name, avatar, subscription data or payment data.

8.3 Who processes it

Processing takes place in Cloudflare Workers AI. The models we use are hosted by Cloudflare — their authors receive none of your data.

Cloudflare states that it does not use customer content to train the models made available in Workers AI, or to improve Cloudflare or third-party services. Your data is therefore not used to train models.

8.4 Storing and deleting conversations

  • Each conversation’s history is stored by Cloudflare (Durable Objects), capped at the 200 most recent messages in a thread.
  • A thread registry (identifier, owner, title, timestamps) is stored in Cloudflare D1.
  • We keep conversations for 12 months from the last message in the thread, unless you delete the thread sooner.
  • Deleting an individual conversation deletes its content. Deleting your account deletes all of your conversations — see section 14.
  • For a limited period we retain model-invocation logs (Cloudflare AI Gateway), which may contain the content of requests and responses. We treat these as special category data and apply the same retention period as for conversations.

8.5 A second, separate AI feature — automatic workout tagging

Besides the AI trainer, we use a language model in one further, narrower place: to recognise automatically what type of training a board session contains (for example “strength”, “gymnastics”, “metcon”).

  • What is sent: only the workout text from a board session.
  • What is not in that request: your identifier, name, email address, health profile, heart rate or any health data. The request is not linked to a person.
  • Who processes it: Cloudflare Workers AI, the same provider as in section 8.3.
  • Legal basis: Article 6(1)(b) GDPR — necessary for the contract. This feature is not covered by the AI trainer consent and runs whether or not you use the AI trainer, because it processes no health data and no identifying data.
  • If you type personal information into a workout description, it will go into that request. Do not put information in workout descriptions that you do not want transmitted.

8.6 Limitations you should know about

  • Turning the feature off does not retract what has already been sent. You can withdraw consent to the AI trainer at any time — this stops further processing and lets you delete the history, but it does not undo processing that has already taken place.
  • Language models make mistakes. The AI trainer’s answers may be wrong. See section 21.
  • Conversation titles are generated automatically from the opening sentences of your message and may contain a health topic.

9. Profiling and automated decision-making

9.1 That we profile

Yes. The Services automatically analyse your health data to calculate metrics describing your fitness and recovery. This is profiling within the meaning of Article 4(4) GDPR.

9.2 Meaningful information about the logic (Article 13(2)(f) GDPR)

Heart-rate zones. From your date of birth we calculate your maximum heart rate, unless you have set it manually — in which case we use your value. From your maximum and resting heart rate we calculate six zones using the heart-rate reserve (Karvonen) method: rest, very light, light, moderate, hard, maximum.

Effort score. Each heart-rate reading is assigned to a zone. Time spent in a zone is multiplied by a coefficient that increases with the zone’s intensity. The sum across the day (or the activity) gives the effort score.

Recovery score. We compare three signals against your personal baseline from recent days: heart-rate variability during sleep, resting heart rate, and sleep duration relative to your sleep goal. Deviations above and below the baseline are converted into a recovery score and a sleep-debt figure.

AI trainer. A language model generates plan suggestions from the data described in section 8.2.

9.3 Significance and consequences

These outputs are informational and training-related only. We do not take decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22(1) GDPR. In particular, these scores do not determine access to the service, pricing, insurance, employment or creditworthiness, and are not passed to any party that would make such decisions.

9.4 Safeguards offered voluntarily

Although Article 22 does not apply here, we provide you with:

  • the ability to manually override your maximum heart rate, resting heart rate and heart-rate zone boundaries (Settings → Fitness Preferences),
  • the ability to manually correct activity type, distance and pace,
  • the right to obtain an explanation of a specific score — write to [email protected],
  • the right to contest a score and express your point of view.

An honest caveat: the first two mechanisms — manual editing of heart-rate zones and editing of historical data — are currently available only with a paid subscription. The last two, the right to an explanation and the right to contest a score, are available to you always and free of charge, regardless of subscription, and we handle them at the email address above. The same goes for every right in section 15 — exercising them never requires a subscription.


10. How we share your information

10.1 Processors

The complete, current list — with the data each receives and where it processes — is in Annex A. We have data processing agreements meeting the requirements of Article 28 GDPR with all of them.

In summary, they are providers of: hosting and infrastructure, file storage and backups, AI processing, push notifications, transactional email, app diagnostics, and subscription management.

10.2 Third-party assurance

We confirm that any third party to whom we entrust data — including analytics tools, third-party SDKs and any affiliated entities — will provide the same or equal protection of user data as stated in this privacy policy and as required by the app store guidelines. We secure this commitment through a data processing agreement.

The scope of that commitment. It covers processors — suppliers acting on our instructions — which is every entry in Annex A marked “Processor”. It does not cover the parties Annex A marks as independent controllers: Apple (Sign in with Apple), Google (Sign-In and Maps) and Stripe in respect of the payment itself. Those parties process data under their own terms, which we neither set nor control; we can only point you to their own privacy policies. We could not honestly guarantee another company’s standards, so we do not.

We have no affiliates. MetconLovers is operated by one individual; there is no parent, subsidiary or affiliated company we could pass data to.

10.3 Other users

See section 11.

10.4 Public authorities and litigants

We may disclose data where mandatory law requires it — on a valid order from a court, prosecutor or other competent authority. We apply the principle in section 3(4) when we do.

10.5 Change of ownership

In the event of a merger, acquisition or sale of the business, data may be transferred to the acquirer. We will tell you in advance, and the acquirer will be bound by this policy until it is changed in accordance with section 22.

10.6 What we do not do

We do not sell personal data. We do not share it for behavioural advertising. We use no advertising networks. We embed no marketing pixels in the Services.


11. What you share with other users

11.1 Default

By default your training data is private. It becomes visible to others only when you join a group or a board, or share a link yourself.

11.2 Groups

Once you join a group, the other members see on the leaderboard: your first name, last name, profile picture, effort score, recovery score, step count and calories burned.

Each group has two independent settings that determine how much its members see of one another:

SettingWhat it shares when on
Activity accessTraining activities: type, duration, effort score, and — when opened in detail — the heart-rate trace and GPS route
Readings accessVitals: maximum and average heart rate, HRV, resting heart rate, sleep, and time in each heart-rate zone — for the day, week and month

You need to know how these settings work:

  • They are settings on the group, not personal settings of yours. They are chosen by whoever creates the group and apply identically to every member.
  • You cannot change them for yourself alone. If you join a group with readings access enabled, your HRV, resting heart rate and sleep data become visible to the other members.
  • Check the sharing scope before you join. It is shown on the group screen and in the invitation.
  • Where a group does not share a category, the data is not served. We check this on the server on every request — not merely by hiding a screen in the app.

Your real control is the decision to join a group and to stay in it. You can leave a group at any time — from that moment your data is no longer visible to its members. We consider this insufficient and intend to change it so that each member decides their own sharing scope; until that ships, the description above is what applies.

The group join code is visible to every member of the group, so share it carefully.

11.3 Boards

  • The board owner sees the member list, their results, and the email address of every board member — not only those who paid. For paid boards they additionally see purchase history and each person’s lifetime spend.
  • Board members see other members’ results with the comment, photo and — for linked activities — duration, average and maximum heart rate, and effort score.

11.4 Invitations

When you invite someone, you supply their email address. We send that address a message containing your first name and the group or board name. Only invite people who expect it.

11.5 Sharing by link

You can share a link to an activity, a comparison or a training day. The link preview shown in messengers and social media is deliberately generic — it contains none of your data or scores. The content opens only after signing in to the Services.

Once you share something outside the Services — a screenshot, text, or a link in an open group — we lose control over it and cannot retract it.


12. International transfers

12.1 What stays in the EEA

The primary copy of your account data, training data, GPS routes and content stays in the European Economic Area. The exception is the AI trainer data described in section 12.2 — that has no EEA copy and is held solely by Cloudflare.

  • production database — a server in Frankfurt am Main, Germany,
  • database backups — Amazon S3, region eu-central-1 (Frankfurt),
  • uploaded photos and video — Amazon S3, region eu-central-1 (Frankfurt),
  • diagnostics data — Datadog, region EU1 (European Union).

12.2 What may be processed outside the EEA

ProviderDataMechanism
Cloudflare, Inc. — Workers AI, Durable Objects, D1, AI Gateway, transactional emailAI trainer conversations, thread titles, cached training profile, workout history sent to the model; email addresses and message contentStandard Contractual Clauses in our data processing agreement with Cloudflare
Datadog, Inc.Diagnostics data stored in the EU, but access by personnel outside the EEA is possibleSCCs in the data processing agreement
Google LLC — Firebase Cloud MessagingDevice token, notification contentSCCs and, to the extent applicable, the European Commission’s adequacy decision on the EU–US Data Privacy Framework
RevenueCat, Inc.User identifier, subscription state. No health dataSCCs
Stripe (Stripe Payments Europe Ltd. and Stripe, Inc.)Email address, user identifier, transaction dataSCCs
Apple, Google (federated sign-in)Only within your own relationship with those providersTheir own terms

An important caveat about Cloudflare: Cloudflare’s infrastructure operates globally, and we do not currently guarantee that AI trainer conversations and the cached profile are processed exclusively within the EEA. If that matters to you, do not use the AI trainer — the rest of the Services works without it, and all other data stays in the EEA.

12.3 Obtaining a copy of the safeguards

You can obtain a copy of the Standard Contractual Clauses underpinning any given transfer by writing to [email protected].

We rely on Standard Contractual Clauses as our primary transfer mechanism. Where a provider additionally holds an EU–US Data Privacy Framework certification, we treat it as a supplementary rather than sole mechanism — so the level of protection does not depend on the future of that adequacy decision.


13. How long we keep your data

Data categoryRetention period
Account data: email, password, first name, last name, avatarFor as long as you have an account; erased within 30 days of an account deletion request
Health profile: date of birth, gender, weight, height, max/resting HR, level, goalsAs above
Training data: heart rate, HRV, sleep, steps, calories, workoutsAs above
GPS routesAs above
Derived metrics: effort, recovery, zones, sleep debtAs above
Content: boards, plans, notes, results, photosAs above. Exception: results you posted on someone else’s board remain visible to that board owner in a form stripped of your identifying data
AI trainer conversations and model-invocation logs12 months from the last message in a thread; sooner if you delete the thread or your account
Records of emails and push notifications sent12 months
Account activation and password reset tokensUntil used or expired; no longer than 7 days
Push notification tokenUntil account deletion, or until the device stops being registered for notifications
Server logs and diagnostics data30 days
Database backups90 days (rolling)
Accounting records and billing data5 years counted from the beginning of the year following the financial year concerned — art. 74(2)(8) of the Polish Accounting Act of 29 September 1994. Data needed for tax purposes — until the tax liability limitation period expires, i.e. as a rule 5 years from the end of the calendar year in which the payment deadline fell (art. 86 § 1 in conjunction with art. 70 § 1 of the Tax Ordinance of 29 August 1997)
Records of consent given and withdrawn3 years after withdrawal — to demonstrate accountability (Art. 5(2) GDPR)
Data needed to defend a specific, asserted legal claimUntil the matter concludes with a final decision. The rule: we do not hold health data “just in case” for the length of a limitation period — we erase it on the schedule above. The only exception is where a claim has already been asserted against us and the data is necessary to defend it; we then rely on Article 9(2)(f) GDPR and retain only the data needed for that particular matter

General criterion: we keep data for as long as it is necessary for the purpose for which we collected it, unless a legal provision requires longer retention.


14. Deleting your account and your data

14.1 How to delete your account

  • In the mobile app: Settings → Privacy → Delete account.
  • By email: send a request from your account’s email address to [email protected]. This is the route to use if you cannot reach the app — we act on it exactly as we do on an in-app deletion.

Account deletion is permanent and irreversible. It is not a suspension, deactivation or “freeze”.

14.2 What we delete

Within 30 days of your request, we erase from production systems:

  • account and authentication data (email, password hash, first name, last name, avatar, tokens),
  • your entire health profile,
  • all training data: heart-rate readings, HRV, sleep, steps, calories, activities, GPS routes,
  • all derived metrics: effort, recovery, zones, sleep debt,
  • group and board memberships and your results,
  • all AI trainer conversations, together with the thread registry and the cached profile held at Cloudflare,
  • uploaded photos and avatars,
  • your push notification token,
  • records of emails and notifications sent to you.

14.3 What we retain, and why

WhatWhyFor how long
Accounting records for payments madeLegal obligation — Polish Accounting Act and Tax OrdinancePeriods in section 13. To be precise: our own purchase record, which served only to control access to a board, is deleted along with your account. The accounting record of the transaction is the one held by Stripe as the payment processor — that is what the periods above apply to, and it sits outside our systems
A record of the fact and date that consents were given and withdrawnDemonstrating accountability (Art. 5(2) GDPR)3 years
A record of the deletion request itself (date, email address)Demonstrating that we fulfilled the request3 years
Data needed to defend against a specific, asserted claimArt. 6(1)(f) — establishment and defence of legal claimsUntil the matter concludes

14.4 What deletion does not undo

  • Backups. We erase data from production systems immediately, but backups rotate over 90 days. Until the oldest backup expires, your data may still be present in one. We use backups solely for disaster recovery; if we restore a backup taken before your deletion, we reapply the deletion.
  • Content shared with others. Results posted on other people’s boards remain visible to the board owner — but we strip your identifying data from them.
  • Content taken outside the Services. We do not control screenshots or links you sent to others yourself.
  • Data in Apple Health and Google Health Connect. Deleting your account does not delete data in those apps — that is your data in your operating system. You can delete it in your system settings.

14.5 Disconnecting data sources without deleting your account

You do not have to delete your account to stop sharing health data with us. You can revoke permissions at any time in Settings → Health → MetconLovers (iOS) or in the Health Connect app (Android). From that point we read no new data. Data we read earlier can be erased by exercising your right to erasure (section 15).


15. Your rights

15.1 The rights you have

RightBasisHow to exercise it
Access to your data and a copy of itArt. 15 GDPR[email protected]
Rectification of inaccurate dataArt. 16 GDPRSettings → Profile or by email
Erasure (“right to be forgotten”)Art. 17 GDPRSettings → Privacy → Delete account or by email
Restriction of processingArt. 18 GDPR[email protected]
Data portability — receiving your data in a machine-readable format and transmitting it to another controllerArt. 20 GDPR[email protected]
Objection to processing based on legitimate interestsArt. 21(1) GDPR[email protected]
Withdrawal of consent at any timeArt. 7(3) GDPRSection 16
Complaint to a supervisory authorityArt. 77 GDPRBelow

15.2 Your right to object — presented separately

You have the right to object at any time to processing of your personal data based on our legitimate interests (Article 6(1)(f) GDPR), on grounds relating to your particular situation.

You also have the right to object at any time to processing of your personal data for direct marketing purposes. This objection is unconditional — once raised, we will stop such processing immediately.

Send objections to [email protected].

15.3 Response times

We respond without undue delay and in any event within one month of receiving your request. For complex matters we may extend this by a further two months — we will tell you within the first month, with reasons.

Exercising your rights is free of charge. We charge a fee or refuse only where requests are manifestly unfounded or excessive, in particular because of their repetitive character (Art. 12(5) GDPR).

Before acting on a request, we may ask you to confirm your identity — this protects your data from unauthorised access.

15.4 Complaint to a supervisory authority

If you believe we are processing your data unlawfully, you can complain to the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych
(President of the Personal Data Protection Office)
ul. Stanisława Moniuszki 1A
00-014 Warszawa, Poland
Telephone: +48 22 531 03 00
Email: [email protected]
e-Delivery address: PL-67085-31860-RWFHC-35
Website: https://uodo.gov.pl

You may also complain to the supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement (Art. 77(1) GDPR). You also have the right to an effective judicial remedy (Arts. 78 and 79 GDPR).


16. Consents and how to withdraw them

16.1 The separate consents

Consents are granular — you can grant one and refuse another. Refusing does not block access to your account.

ConsentHow it is givenWhat happens if you refuseHow to withdraw
Health data from Apple Health / Health ConnectIn-app consent screen plus the system dialogEffort and recovery metrics will not work; you can still use boards and enter results manuallySystem Settings → Health → MetconLovers (iOS) or the Health Connect app (Android); plus Settings → Privacy in the app
Background data readingA separate screen after enabling syncData updates only when you open the appSettings → Privacy → Background sync
GPS workout routes (iOS)A separate permission in the HealthKit dialogNo route maps, no GPS-derived distance or paceRevoke the route permission in System Settings → Health
AI trainerA consent screen before your first conversationThe AI trainer is unavailable; the rest of the Services works normallySettings → Privacy → AI trainer. Withdrawing also lets you delete your conversation history
Diagnostics and crash reportingA consent screen at first launchThe app works normally; we detect bugs more slowlySettings → Privacy → Diagnostics
Sharing data in a groupYour decision to join a group whose sharing scope is shown to you before you joinOther members see only the basic leaderboardLeave the group — the scope is a setting of the group, not a personal one. See section 11.2
Marketing messagesWe currently send no marketing messages. If we start, we will ask for separate consent under art. 398 PKE——

16.2 Withdrawing consent

Withdrawing consent is as easy as giving it (Art. 7(3) GDPR) — in every case it takes one toggle in the app or in your system settings. We do not require an email, a reason, or a conversation with support.

Withdrawing consent does not affect the lawfulness of processing carried out on the basis of that consent before it was withdrawn.

Worked example. If you allow heart-rate reading in June and withdraw consent in September: from September we read no new measurements and your charts stop updating. Activities saved between June and September still show the heart rate recorded at that time — until you exercise your right to erasure (section 15), which removes them from our systems.

16.3 Service notifications

We send notifications relating to the operation of the Services only. Currently these are:

Email: account activation, password reset, group invitation, invitation accepted, invitation rejected, board invitation, new result on your board, a user joined your board, a user left your board, board access removed, board administrator rights granted.

Push: the same events, plus “nudges” from members of your group.

Your account stores four notification consent settings — separately for boards and for readings, separately for push and for email. An honest caveat: these settings are not currently enforced at send time, and the app does not yet have a screen where you can change them. Until both of those ship, you receive all of the service notifications listed above. If you want them stopped sooner, write to [email protected], or revoke the app’s notification permission in your system settings — that will stop push notifications, but not emails.

Messages essential to operating your account — activation and password reset — are always sent; you cannot opt out of these without deleting your account.

We send no newsletter and no marketing messages.


17. Local storage, identifiers and cookies

17.1 Websites

Our websites (metconlovers.com and dashboard.metconlovers.com) use no cookies. We use no Google Analytics, no Google Tag Manager, no Meta pixel and no other analytics or tracking tools. We embed no third-party fonts, videos, maps or chat widgets. That is why we display no cookie banner — there is nothing for it to govern.

The web dashboard stores two keys in browser local storage:

KeyContentsNature
metconlovers.sessionAccess token, refresh token and your user profile — required to maintain your sessionStrictly necessary
ml-dashboard-themeLight/dark theme preferencePreference

Both are removed when you sign out or clear your browser data.

17.2 Mobile app

In the mobile app we store data and identifiers in your terminal equipment. Under art. 399 of the Polish Electronic Communications Law this requires your consent, which we ask for at first launch (except where storage is strictly necessary to provide the service you requested).

WhatWhyBasis
Session token and account dataKeeping you signed inStrictly necessary
Cached widget values: effort, recovery, resting HR, HRV, sleepDisplaying widgets without launching the appNecessary for the feature you requested
Recovery signatures (about 30 days)Avoiding re-sending the same data repeatedlyNecessary — minimising processing
Last-sync timestampsReading only new dataNecessary
Cached board list and thumbnailsThe boards widgetNecessary for the feature
Diagnostics session identifier (Datadog)Diagnostics and crash reportingConsent
Push notification token (Firebase)Delivering notificationsConsent
Subscriber identifier (RevenueCat)Verifying an active subscriptionNecessary for billing

We do not use the advertising identifier (IDFA / GAID). We do not track you across apps or websites. We do not present the App Tracking Transparency prompt, because we do not track you within Apple’s meaning of the term.


18. Security

We apply technical and organisational measures appropriate to the risk of processing special category data (Article 32 GDPR):

  • Encryption in transit. The app and the dashboard connect to our services over HTTPS with TLS only. Traffic is encrypted the whole way between your device and the edge of our infrastructure.
  • Passwords. We store bcrypt hashes only. We do not know your password and cannot recover it.
  • Access control. Only the service owner has access to production systems. Access to health data is limited to the cases described in section 7.2.
  • Internal identifiers. In our databases we identify users by a random UUID, not by email address.
  • Location. The primary copy of your data and its backups are held in data centres in Germany, within the European Union.
  • Minimisation. We read only the health data types needed for specific features, and we never write data back to Apple Health or Health Connect.
  • Processor agreements. We have an Article 28-compliant data processing agreement with every supplier that processes data on our behalf.

What we do not claim — and why we say so plainly:

  • We do not use end-to-end encryption. We can technically read the data stored on our servers; that is necessary to calculate your metrics.
  • We do not claim your data is “anonymous”. It is pseudonymised, which means it can be linked back to you given access to additional information.
  • Your session token is not anonymous. The authentication token the app presents to our services carries your profile inside it — including your email address, first name, last name, date of birth, gender, weight, height and heart-rate zones. The token is cryptographically signed but it is not encrypted: anyone who obtains it can read those fields. We are working to reduce the token’s contents to an identifier alone.
  • We do not claim the data on your device is encrypted by us. The session token and the cached profile are held in the app’s storage without additional encryption on our part — they are protected by the operating system’s app isolation. On Android, app data may be included in the system’s automatic backup (Android Auto Backup) to your Google account.

No method of transmission or storage is completely secure. We commit to improving our safeguards continuously, but we cannot guarantee absolute security.


19. Security incident notification

In the event of a personal data breach:

  • We will notify the Polish supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Art. 33 GDPR).
  • We will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms (Art. 34 GDPR). We will describe the nature of the breach, its likely consequences, and the measures we have taken.
  • Because we process data concerning health, we treat every breach as potentially high-risk and assume a notification duty by default.
  • Where the laws of other jurisdictions impose additional notification duties — including the U.S. Federal Trade Commission’s Health Breach Notification Rule (16 CFR Part 318), which may apply to us as a vendor of personal health records — we will comply with those as well.

20. Children

The Services are intended only for people aged 16 and over.

We do not direct the Services at children and we do not knowingly collect personal data from anyone under 16. By registering an account you confirm that you are at least 16 years old.

If we learn that an account was created by someone under 16, we will delete it and all associated data without undue delay. If you are a parent or guardian and believe your child has given us their data, write to [email protected] — we will act immediately.

The 16-year threshold follows Article 8(1) GDPR; Poland has not lowered it in national law. We apply it uniformly to all users regardless of country, which also means we do not knowingly collect data from children under 13 and are not subject to verifiable-parental-consent obligations under COPPA.


21. Not a medical device, not medical advice

MetconLovers is a training and recreational app. It is not a medical device.

  • The Services do not diagnose, treat, cure, mitigate, prevent or monitor any disease or medical condition.
  • Effort, recovery, sleep, resting heart rate and HRV metrics are indicative and training-related. They are not clinical parameters and should not be the basis for health decisions.
  • The AI trainer’s answers are generated by a language model and may contain errors. They are not medical, dietary or physiotherapy advice.
  • Data accuracy depends on your measuring device (watch, band or phone), which is outside our control.

Consult a doctor before starting or significantly changing a training programme — particularly if you have a medical condition, take medication, are pregnant, or experience concerning symptoms. If you feel suddenly unwell, contact medical services, not this app.


22. Changes to this policy

We may update this policy when the product, our suppliers or the law change.

  • Every version is published at the same URL with a version number and an effective date.
  • For material changes — a new processing purpose, a new category of data, a new recipient of health data, or a change of legal basis — we will notify you in advance and prominently, by in-app notification or email. We will not rely on silently republishing a new version.
  • If a change introduces a new purpose for processing special category data, we will ask for fresh, explicit consent. Continuing to use the Services will not substitute for that consent.
  • Previous versions are available on request to [email protected].

23. Contact us

MatterContact
All data protection matters, exercising your rights, complaints[email protected]
Postal correspondenceSebastian Furmańczyk, ul. Ameriga Vespucciego 12/34, 51-505 Wrocław, Poland

Accountable person: Sebastian Furmańczyk (owner — personally accountable for data protection at MetconLovers).

Data Protection Officer: none appointed. We are not required to appoint one at our current scale of processing. Direct all matters to the address above.

EU representative: not applicable — we are established in Poland, within the European Union.

We respond to data protection enquiries within the timeframes in section 15.3.



ANNEX A — Processors and recipients

As at 27 August 2026. ⚠ marks processing that may occur outside the EEA.

PartyRoleWhat it receivesWhere it processes
OVH SAS / KimsufiProcessor — dedicated server hostingAll production data: accounts, health data, GPS routes, content, job queues, logsFrankfurt am Main, Germany — EEA
Amazon Web Services EMEA SARL (S3)Processor — file and backup storageDatabase backups; uploaded photos and avatars; exercise videoeu-central-1, Frankfurt — EEA
Cloudflare, Inc. — Workers AI, Durable Objects, D1, AI GatewayProcessor — AI trainerAI trainer conversations, thread titles, user identifier, training profile (gender, date of birth, max/resting HR, weight, height, fitness level, goal), workout history with duration and average/maximum heart rate⚠ Global infrastructure
Cloudflare, Inc. — transactional emailProcessor — email deliveryRecipient email address, subject and message body (contains your first name and, in group messages, another user’s first and last name)⚠ Global infrastructure
Cloudflare, Inc. — DNS and edgeProcessorHTTP traffic metadata for *.metconlovers.com⚠ Global infrastructure
Datadog, Inc.Processor — diagnostics and crash reportingUser identifier, first name, email address, screen names, interactions, request URLs, errors, crash reportsRegion EU1 — European Union. ⚠ Access by personnel outside the EEA is possible
Google LLC — Firebase Cloud MessagingProcessor — push notificationsDevice token, notification title and body (may contain another user’s first and last name and an effort score)⚠ Google global infrastructure. Firebase Analytics is disabled
RevenueCat, Inc.Processor — subscription managementUser identifier, device identifiers, purchase receipts, subscription state. No health data, no email address⚠ United States
Stripe Payments Europe, Ltd. and Stripe, Inc.Independent controller for the payment; processor for platform-side customer recordsEmail address, user identifier, transaction amount and identifiers, name of the board purchased. Card, bank and identity-verification data is collected by Stripe directly and never reaches us⚠ Ireland and United States
GitLab, Inc.Processor — source code and deployment infrastructureSource code and deployment configuration. We do not store the database or users’ training data there. The deployment configuration does, however, contain access credentials for production systems⚠ United States
Apple Inc. — Sign in with AppleIndependent controller (identity provider)Only within your own relationship with Apple. We receive the email address from the identity tokenApple
Google LLC — Google Sign-InIndependent controller (identity provider)Only within your own relationship with Google. We receive email address, first name and last nameGoogle
Google LLC — Google Maps (mobile app only)Independent controllerMap tile requests for the area of your workout route. The web dashboard uses no external maps⚠ Google global infrastructure
Apple HealthKitNot a processor — an operating-system data sourceData stays on your device; we read it with your consentYour device
Google Health ConnectNot a processor — an operating-system data sourceAs aboveYour device

Updates: we will notify you of any new processor of health data in accordance with section 22.


ANNEX B — EEA, United Kingdom and Switzerland

B.1 EEA

The main body of this policy is written to the GDPR and applies in full to people in the EEA. Our lead supervisory authority is the President of the Personal Data Protection Office (details in section 15.4).

B.2 United Kingdom

For people in the United Kingdom we apply the UK GDPR and the Data Protection Act 2018 on the same terms as the GDPR. Differences:

  • Supervisory authority: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom; https://ico.org.uk
  • The UK digital consent age is 13, but we apply a single threshold of 16 to all users — which is more protective.
  • Transfers out of the UK: we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.

B.3 Switzerland

For people in Switzerland we apply the revised Swiss Federal Act on Data Protection (nFADP) on terms equivalent to the GDPR. Supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.


ANNEX C — United States

This annex applies to residents of the United States.

C.1 HIPAA does not apply

MetconLovers is not a covered entity or a business associate under HIPAA. The data we process is not “protected health information” (PHI) under HIPAA. We do not claim HIPAA compliance and we hold no HIPAA certification — no such certification exists.

Your data is instead protected by this policy and by state consumer privacy laws, including the Washington My Health My Data Act.

C.2 California (CCPA/CPRA)

Categories of Sensitive Personal Information we collect: health information, and precise geolocation (workout routes, iOS only).

We do not sell and do not share personal information as those terms are defined in the CCPA — not now, and not in the preceding twelve months. We do not engage in cross-context behavioural advertising. For that reason we do not publish a “Do Not Sell or Share My Personal Information” link.

Right-to-limit statement: We do not use or disclose sensitive personal information for purposes other than those specified in section 7027(m) of the CCPA regulations. Accordingly, we do not offer a “Limit the Use of My Sensitive Personal Information” option.

To be precise about the second limb of that exemption: we do derive metrics about you from your health data — your effort score, recovery score, heart-rate zones and sleep debt. We treat these as characteristics inferred from sensitive personal information, and we use them only to deliver the training features you can see in the app, which falls within section 7027(m). We do not use them to infer anything beyond your training state, and we do not disclose them for any purpose outside that list.

Your rights: to know, access, delete, correct, port your data, and not to be discriminated against for exercising them. Send requests to [email protected]. We apply no adverse terms and no price differences to people who exercise their rights.

Authorised agents: a request may be submitted on your behalf by an authorised agent who provides written authorisation; we may ask you to confirm it.

C.3 Washington My Health My Data Act

Our Consumer Health Data Privacy Policy, required by RCW 19.373.020, is reproduced in full at Annex C-1 and is also published as a standalone page reachable by its own separate and distinct link from our homepage, our app store listings, and the app’s settings screen.

We do not implement geofences around facilities providing health care services. We do not sell consumer health data — not for monetary consideration and not for any other valuable consideration.

C.4 Other states

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota and Maryland) have rights to access, correct, delete and port their data, and to opt out of sale, targeted advertising and profiling with significant effects.

We process sensitive data — including health data and precise geolocation — only with your explicit consent, and we never sell it.

Appeals: if we refuse a request, you may appeal by writing to [email protected] with “Appeal” in the subject line. We will respond within 45 days with our reasoning and, if we maintain the refusal, with information about how to complain to your state attorney general.

Maryland: we collect, process and share health data and precise geolocation only as strictly necessary to provide or maintain the specific product or service you have requested, and we never sell it. Maryland’s ban on selling sensitive data admits no consent cure, and we do not seek one.

Opt-out preference signals (Global Privacy Control): our websites conduct no targeted advertising and no sale of data, so there is no processing for a GPC signal to switch off. Should we ever introduce such processing, we will honour GPC signals in the states that require it.


ANNEX C-1 — CONSUMER HEALTH DATA PRIVACY POLICY

Required by the Washington My Health My Data Act, RCW 19.373.020, and by
Nevada SB 370 (NRS 603A.400 et seq.).

This annex is published in full, as a separate and distinct document, at
Consumer Health Data Privacy Policy. That page is the
operative text and is the version to read, cite and link to.

ANNEX D — Canada, Australia, Brazil

D.1 Canada (PIPEDA)

Accountable individual: Sebastian Furmańczyk, [email protected].

Your data is processed and stored outside Canada — primarily in Germany (European Union) and, as described in section 12, also in the United States and other countries. While there, it is subject to local law, including the possibility of lawful access by foreign authorities.

You may complain to the Office of the Privacy Commissioner of Canada (https://priv.gc.ca).

D.2 Australia (Privacy Act 1988)

In accordance with Australian Privacy Principle 1.4, we tell you that personal information may be disclosed to overseas recipients located in: Germany, Ireland and the United States, and — for providers with global infrastructure (Cloudflare, Google) — in other countries where those providers operate data centres.

You may complain to the Office of the Australian Information Commissioner (https://oaic.gov.au).

D.3 Brazil (LGPD)

Encarregado (data protection officer): Sebastian Furmańczyk, [email protected].

Health data is sensitive personal data (dados pessoais sensíveis) under the LGPD, and we process it solely on the basis of specific and highlighted consent for the stated purposes (art. 11(I) LGPD). You have the rights set out in art. 18 LGPD. Supervisory authority: Autoridade Nacional de Proteção de Dados (ANPD).


ANNEX E — Language versions

This policy is published in two language versions: Polish and English. Both are intended to express the same meaning.

In the event of any discrepancy between the versions, the Polish version prevails — except for Annex C (United States) and Annex C-1 (Consumer Health Data Privacy Policy), for which the English version prevails, as it is drafted in the language of the applicable law.


End of document.

Questions? Reach us at [email protected].

Built in the garage. For everyone who trains.

Product

  • Features
  • What is an effort score?
  • Business

Legal

  • Privacy
  • Consumer Health Data
  • Terms
© 2026 MetconLovers MetconLovers is not a medical device and does not provide medical advice.