Privacy Policy
Last updated: July 15, 2026. This version replaces and supersedes the prior version dated May 28, 2026.
Aureon FitApp Inc. ("Aureon," "we," "us," or "our") — a corporation federally incorporated in Canada, with its head office in the Province of Ontario — operates the software and services marketed as Aureon Performance (our "Services"). This Privacy Policy describes how we collect, use, disclose, and safeguard personal information across our websites, mobile applications, and related offerings. It is written to satisfy — in substance and in operating practice — Canada's federal PIPEDA and Quebec's Law 25, Ontario's PHIPA, the European Union's GDPR, the United Kingdom's UK GDPR and Data Protection Act 2018, the U.S. FTC Act and FTC Health Breach Notification Rule, and United States state privacy law led by California's CCPA, as amended by the CPRA (with comparable Virginia, Colorado, Connecticut, Utah, and Texas statutes). Platform operators apply their own rules; our practices are summarized here and may be supplemented by store disclosures you approve at install or purchase.
Washington and Nevada residents. Because you have Consumer Health Data rights beyond what this general Policy covers, we maintain a separate, standalone Consumer Health Data Privacy Policy with its own distinct link and its own consent flow — it is not a section or anchor of this document. See the Consumer Health Data Privacy Policy.
Compliance Accountability & Contact
We are Aureon FitApp Inc. — federally incorporated in Canada and operating as Aureon Performance from our head office in Ontario, Canada. We are the data controller — and, under PIPEDA, the accountable organization — for the personal information described here.
To keep accountability unambiguous, electronic channels are split by function:
- · Privacy Lead · EU & UK data-subject inquiries (EU/UK Article 27 representative: Prighter — app.prighter.com/portal/aureonperformance): privacy@aureonperformance.com
- · General Counsel · Corporate legal notices · Compliance-infrastructure mapping: legal@aureonperformance.com
Representative
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
- European Union (EU)
- United Kingdom (UK)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/aureonperformance
Information we collect
Depending on how you interact with us, we may collect categories of information such as:
- Profile variables. Display name, birthdate (for age verification), sex, and the email returned by Apple or Google OAuth — or, for Guest sessions, an anonymous device token rather than an identifying account.
- Usage & performance. In-app activity (e.g., workouts logged, protocol edits, engagement signals), feature usage, and purchase-funnel events, collected via PostHog product analytics — never linked to health data.
- Diagnostics. Crash reports and performance traces, collected via Sentry and scrubbed of biometric, hormone, and authentication-token values before transmission — not linked to your account identity.
- Device & technical. Device type, OS version, app version, locale, IP address, mobile identifiers compatible with platform policies, and similar technical metadata.
- Location. A city-level location string only, derived on-device and reverse-geocoded — we never transmit or store precise GPS coordinates. See Device permissions.
- Payment & billing. Pricing tiers are published at /pricing and mirrored at checkout. Mobile subscriptions are billed through the Apple App Store or Google Play and managed via RevenueCat — we receive subscription status, product identifiers, and renewal dates, never full payment card details. Web checkout via Stripe is currently paused — our website is not processing live subscription purchases at this time.
- Communications. Content you send us (support tickets, feedback, survey responses) and related correspondence metadata.
- Physical biometrics. Height, body weight, body-fat percentage, resting heart rate, peak heart rate, and the free-text biomechanical constraints or injury-rehabilitation history you choose to record — used to calibrate load, scaling, and movement contraindications. Where weight and body-fat percentage are present in Apple Health or Health Connect, they may also be synced read-only (see Biometric & Health Data).
- Special-category data. Where you choose to provide it — clinical biomarkers and hormone-panel values synthesized from the lab documents you upload, the physique reference images you submit for body-composition analysis, and menstrual-cycle tracking details, each processed via Anthropic Claude, provided by Anthropic PBC through its commercial API. These are special-category / sensitive personal data under GDPR Article 9 and equivalent US "sensitive personal information" standards, and are processed only on your explicit, opt-in consent, which you may withdraw at any time. See Biometric & Health Data.
On our website, we also use a small set of cookies and similar technologies (such as browser local storage) — see our Cookie Policy for exactly what is set, by whom, for what purpose, and how to control it.
Device permissions
Aureon requests only the device permissions its features require, matched to the declarations in our Apple App Store and Google Play manifests. Each is optional, prompted in context, and revocable at any time through your operating-system settings:
- · Camera & Photo Library: the Metabolics food-photo pipeline (optical macro- and micro-nutrient analysis of meals you capture or select), the physique and progress images you submit for body-composition analysis, and the profile portrait you choose to set.
- · Document Picker: parsing the clinical lab files you upload for biomarker extraction.
- · Foreground Location: reverse-geocoded to a city-level field only — stored as location_city, never precise coordinates and never background tracking.
- · HealthKit / Health Connect: read-only, scoped to the signal types disclosed at the time you grant OS-level permission — see Biometric & Health Data.
- · Push Notifications: active rest-timer cues and session prompts.
How we use information
We use personal information for purposes including:
- Service delivery. Creating and maintaining accounts, generating and adapting training and nutrition protocols, computing Aureon scores (including BioAge), syncing across devices, and providing customer support.
- Personalization & product improvement. Tailoring recommendations and improving models and workflows, subject to this Policy and applicable law.
- Security, integrity & fraud prevention. Detecting abuse, securing infrastructure, investigating incidents, and enforcing our Terms.
- Legal compliance. Complying with law, regulation, lawful requests, and protecting rights and safety.
- Communications. Transactional messages (billing, security alerts), service announcements, and—where permitted—marketing communications you can opt out of.
Legal Bases for Processing (GDPR · UK GDPR · PIPEDA)
Where cross-border frameworks require an explicit lawful basis, we rely on the following — and only for the purposes stated in this Policy:
- Performance of a contract. Operating your account, computing performance metrics, and delivering the protocols you request.
- Explicit consent. Required under GDPR Article 9 — and aligned with PIPEDA's consent principle — before we read or synthesize any special-category signal: HealthKit / Health Connect metrics and HRV trends, the clinical biomarkers and hormone-panel values drawn from documents you upload, the physique images you submit for body-composition analysis, and menstrual-cycle details. You may withdraw consent at any time through operating-system permissions or in-app controls.
- Legitimate interests. Securing infrastructure, preventing fraud and abuse, maintaining service reliability, and improving product architecture — balanced against your fundamental rights and freedoms.
- Legal obligations. Meeting Canadian federal and provincial record-retention, tax, audit, and statutory disclosure duties.
Canada · PIPEDA & Ontario PHIPA
As a federally incorporated Canadian organization, we handle personal information under the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair-information principles — accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance.
- · Accountability: our Privacy Lead answers for compliance and for every third party that processes data on our behalf.
- · Meaningful consent: consent is scaled to sensitivity — express opt-in for health and biometric signals — and may be withdrawn at any time.
- · Limiting collection: we gather only what a stated performance purpose requires, and we do not silently repurpose it.
- · Access & challenge: you may request what we hold and challenge our handling with the Office of the Privacy Commissioner of Canada.
Ontario PHIPA scope. Aureon Performance is a consumer performance-optimization application — not a health information custodian under Ontario's Personal Health Information Protection Act (PHIPA). We do not deliver health care, and we neither contribute to nor draw from provincial electronic health records. Biometric telemetry you connect stays isolated within your user-managed environment and is processed only for training-load and recovery calibration — never as a custodial health record.
Quebec · Law 25. Quebec residents additionally have a right to data portability, disclosure of any decision made exclusively through automated processing, and the right to have consent obtained expressly and separately for sensitive information such as health data. Cross-border transfers of Quebec residents' personal information are assessed through a transfer impact review before they occur — see International transfers.
Alberta & British Columbia. Residents' rights mirror PIPEDA; Alberta additionally requires notification to its Commissioner for breaches posing a real risk of significant harm.
European Union & United Kingdom · GDPR / UK GDPR
For residents of the European Economic Area, Switzerland, and the United Kingdom, we process personal data as a data controller under the EU GDPR and the UK GDPR read with the Data Protection Act 2018. We operate without a permanent physical establishment in the European Economic Area or the United Kingdom, and Aureon FitApp Inc. has appointed Prighter as its representative in the EU and the UK under Article 27 of the GDPR / UK GDPR: iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria, serves as our EU representative, and Prighter Ltd serves as our UK representative. EU/UK data subjects and supervisory authorities may contact our representative through the public representation portal at app.prighter.com/portal/aureonperformance, or reach us directly at privacy@aureonperformance.com.
You may exercise the rights of access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent without affecting prior lawful processing. You also retain the right to lodge a complaint with your local supervisory authority — an EU member-state Data Protection Authority or the UK Information Commissioner's Office (ICO). Transfers out of the EEA or UK rely on Standard Contractual Clauses (with the UK Addendum where applicable) or another recognized adequacy mechanism — detailed under International transfers.
United States · Multi-State Privacy (CCPA / CPRA)
For United States residents, we honor the consumer rights established by California's Consumer Privacy Act (CCPA), as amended by the Privacy Rights Act (CPRA), and we extend equivalent treatment to residents of states with comparable statutes — Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA). At the federal level, the FTC Act prohibits deceptive or unsubstantiated privacy claims — we keep our marketing consistent with this Policy. You may exercise:
- · Know & access: the categories and specific pieces of personal information we have collected.
- · Delete & correct: removal or correction of your personal information, subject to lawful exceptions.
- · Opt out of sale or sharing: we do not sell personal information for monetary value, and we do not share it for cross-context behavioral advertising — and we honor Global Privacy Control signals regardless.
- · Limit sensitive personal information: health and biometric inputs operate only the features you enable — never advertising inference.
- · No retaliation: we will not deny service, alter pricing, or degrade quality because you exercised a privacy right.
To submit a request, contact privacy@aureonperformance.com with the subject line "US Privacy Request". We verify identity before disclosing or deleting data, and an authorized agent may act on your behalf with proof of permission.
Additional jurisdictions. Where we serve residents of Australia (Privacy Act 1988 / Australian Privacy Principles), Japan (APPI), Singapore (PDPA), South Korea (PIPA), India (Digital Personal Data Protection Act, 2023), Brazil (LGPD), Mexico (LFPDPPP), Argentina (Law 25.326), or South Africa (POPIA), we honor the access, correction, deletion, consent-withdrawal, itemized-consent, and complaint rights those statutes establish, and we disclose that special-category and health-adjacent data may be transferred to and processed in the United States by the sub-processors listed below. Wherever local law grants rights beyond those listed on this page, contact us (Section below) and we will route your request appropriately.
Washington & Nevada · Consumer Health Data
Washington's My Health My Data Act (MHMDA) and Nevada's SB 370 (NRS 603A) regulate a category called "Consumer Health Data" and require a separate, distinctly-linked policy and separate opt-in consents for collecting versus sharing that data — this general Privacy Policy does not, by itself, satisfy either requirement. We do not sell Consumer Health Data and we do not geofence health care facilities. Full detail, definitions, and your rights (including how to submit a request and how to appeal a denial) live in the standalone Consumer Health Data Privacy Policy, which controls over this document for anything concerning Consumer Health Data.
FTC Health Breach Notification Rule & HIPAA status
HIPAA does not apply to Aureon. HIPAA covers "covered entities" (health care providers, insurers, clearinghouses) and their "business associates." We are a direct-to-consumer software company — we do not bill insurers and we do not receive records from a covered entity. We do not represent ourselves as HIPAA-compliant, and no statement in our marketing should be read that way.
What does apply is the FTC Health Breach Notification Rule (16 CFR Part 318), which covers vendors of personal health records like Aureon. If a breach occurs — including an unauthorized disclosure such as a misconfigured storage setting, not only a hack — we will notify affected individuals and the FTC without unreasonable delay and no later than 60 days after discovery, and notify nationwide media if the breach affects 500 or more residents of a state or jurisdiction.
Sharing & disclosure
We may share personal information with:
- Service providers & subprocessors. Vendors that host infrastructure, provide analytics (where permitted), deliver customer-support tooling, security services, payments facilitation (as applicable), email delivery, and AI/ML inference providers—subject to contractual confidentiality and security expectations.
- Legal & safety. Disclosures required by law, regulation, legal process, or governmental requests, or to protect the rights, safety, and security of Aureon, our users, or the public.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate safeguards and notices where required.
We do not sell your personal information for monetary consideration in the conventional sense of selling customer lists to unrelated buyers. We also do not share personal information with data brokers for their independent marketing purposes. Where regional laws define "sale" or "sharing" broadly (such as the California CPRA context), we honor those broader definitions and treat the Global Privacy Control (GPC) browser signal, where enabled, as a valid opt-out-of-sale-and-sharing request for that browsing session.
Sub-processors
This is the complete roster of parties that receive personal information on our behalf — each bound by contractual confidentiality and security obligations, and each limited to the function named below. All are located in the United States unless noted otherwise.
- · Supabase: database, authentication, and file-storage host.
- · Anthropic PBC (Claude): all AI inference, covering the training sessions the app prescribes, nutrition generation, meal-photo analysis, protocol and progress narratives, biomarker summaries, and clinical-document extraction; image-safety moderation on uploaded photos. Anthropic processes the prompt and the model response in order to return a result. Under Anthropic's commercial API terms, customer inputs and outputs are not used to train Anthropic's models by default.
- · RevenueCat: mobile subscription state and entitlement management.
- · Stripe: web payment processing infrastructure — currently paused; no live web subscription purchases are being processed through this channel at this time.
- · PostHog: product-interaction and purchase-funnel analytics — no health data.
- · Sentry: crash and performance diagnostics, not linked to your account.
- · Resend: transactional email (account, security, receipts).
- · Upstash: rate-limiting and cache infrastructure (abuse prevention).
- · Vercel: website hosting.
- · Apple Inc. / Google LLC: app-store distribution, in-app purchase processing, and HealthKit / Health Connect (platform-operated).
Instacart is not a sub-processor. It is a deep link you choose to open from a meal plan; once you follow it, Instacart processes your data directly as an independent controller under its own privacy policy — we do not transmit your data to Instacart on your behalf.
Biometric & Health Data
Where you grant permission, Aureon performs a strictly read-only sync with Apple HealthKit and Android Health Connect — we read the signals you authorize and write nothing back to either framework. Those signals are processed solely to compute Aureon's Recovery, Sleep Quality, Strain, Cardio Baseline, and Metabolic Capacity scores, and to calibrate physical training load and recovery-aware adaptation within the Services. Synced fields are limited to steps, heart rate, resting heart rate, heart-rate variability (HRV), sleep sessions, active calorie-burn expenditure, respiratory rate, blood-oxygen saturation (SpO2), body weight, and hydration (Android Health Connect) — where each is exposed by the platform — and every field is read only, never written back. Each signal contributes to load adaptation, body-composition trending, or recovery scoring as outlined in the HealthKit · Health Connect justification. We do not use Apple HealthKit, Android Health Connect, or analogous health API data for advertising. We do not sell that data to data brokers and do not share it with unrelated third parties for their own marketing purposes.
Custodial status. These inputs are processed solely for load adaptation and recovery scoring within your user-managed environment — they are not custodial health records, and they are not contributed to any provincial health repository. See Canada · PIPEDA & Ontario PHIPA for our full position under Ontario's health-privacy regime.
Artificial intelligence processing
To generate the training sessions the app prescribes, compose nutrition protocols, interpret lab uploads, summarize progress photos, write protocol and biomarker narratives, and screen uploaded images for safety, your inputs are processed by Anthropic Claude, provided by Anthropic PBC through its commercial API. Anthropic processes the prompt and the model response in order to return a result, and under its commercial API terms customer inputs and outputs are not used to train Anthropic's models by default.
Anthropic is the only AI provider that processes your data. No Google AI service is involved in any part of the pipeline. Meal photos are processed in memory for a single analysis and are not persisted.
Where technically feasible, prompts sent for inference are limited to the physiological and behavioral fields the task needs; however, free-text fields you write yourself (for example, injury notes) could still be identifying in edge cases — avoid including unnecessary personal detail in free-text fields.
Human review may occur for safety, quality assurance, abuse prevention, or compliance monitoring. You should avoid submitting unnecessary sensitive PII in chat, notes, or unstructured fields. Retention of model inputs/outputs is managed under operational and security policies (typically retained only as long as needed for service delivery, troubleshooting, safety, and legal compliance, unless a longer period is required by law).
AI-generated outputs (protocols, meal plans, biomarker narratives) are advisory only. No output triggers a legally or similarly significant decision about you within the meaning of GDPR Article 22 — you always remain free to disregard or seek human review of any AI-generated recommendation through our support channels. Full disclaimers appear in our AI Consent Wall and Medical Disclaimer.
Security
We implement administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit (TLS) for all endpoints, row-level access controls in our database limiting each account to its own rows, and encryption at rest provided by our infrastructure providers. No method of transmission or storage is completely secure; we encourage strong, unique passwords and keeping your device's operating system current.
International transfers & Cross-Border Adequacy
We are based in Canada, and most of our infrastructure sub-processors are located in the United States (see Sub-processors). If you are in the EEA, UK, Switzerland, or Quebec, your information will be transferred to and processed in the United States. Where required by GDPR Chapter V or the UK GDPR, we rely on the European Commission's Standard Contractual Clauses (2021 modules), supplemented by the UK International Data Transfer Addendum, or — where a processor is certified — the EU-U.S. Data Privacy Framework, as the transfer mechanism for each affected sub-processor. Quebec's Law 25 requires a transfer impact review before personal information is sent outside Quebec, which we apply to the same transfers described above.
Retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements:
- · Account, workout, nutrition, biometric, and photo records: retained for the life of your account, because the service is built to show your history and long-term trends. When you delete your account, live data is removed immediately and full erasure — including residual encrypted backups, which persist only until standard overwrite cycles complete — is finalized within 30 days.
- · Special-category data (clinical biomarkers, hormone panels, menstrual/reproductive fields): retained for the life of your account, or removed sooner if you withdraw the specific consent that authorized it — special-category data should not outlive the consent behind it.
- · Transactional / billing records: retained as required by Canadian tax and commerce law. Payment processors and platform stores (Apple, Google, RevenueCat, Stripe) may separately retain transaction records under their own policies.
- · Security logs and crash/performance diagnostics: retained for a bounded operational window configured with our infrastructure providers.
- · Account-security events: we keep a separate record of security-relevant account changes — subscription tier changes, email address changes, and account deletion — so we can investigate unauthorized access. These records hold the event, its time, and the account it belongs to. Email addresses captured in them are removed after 90 days, and the records themselves are deleted after 24 months. This is the one category that outlives the 30-day erasure window above: a deletion record that vanished along with the account it documents would be no use for detecting an account takeover. We keep it on the basis of legitimate interest rather than consent.
- · Support communications: retained for the period needed to resolve your issue and maintain quality assurance.
Your Global Rights (GDPR · UK DPA · PIPEDA · US Multi-State)
Aureon extends comprehensive data rights to every account holder — independent of region — and will not penalize you for exercising them:
- · Access & portability: obtain disclosure of — or a machine-readable export of — your compiled performance records.
- · Erasure / deletion: purge profile inputs through in-app deletion — Settings → Danger zone → Terminate account — or via the /data-deletion fallback.
- · Correction / rectification: amend inaccurate parameters inside your settings.
- · Object / restrict: halt non-essential telemetry or third-party inference.
- · Limit sensitive data (US): California and other state residents may restrict the use of physical-health attributes beyond core operation.
- · Opt out via Global Privacy Control: where you visit aureonperformance.com with GPC enabled in a supported browser, we treat that signal as a valid opt-out-of-sale-and-sharing request for that session.
- · Washington & Nevada residents: Consumer Health Data-specific rights (including appeal of a denied request) are addressed in the standalone Consumer Health Data Privacy Policy.
To exercise a right, contact privacy@aureonperformance.com. We verify identity before resolving requests, and you retain the right to lodge a complaint with your home jurisdiction's supervisory privacy authority.
Children
Our Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, contact us so we can take appropriate steps.
Data breach notification
If a breach affecting your personal information occurs, we will notify you and the relevant regulator(s) on the timeline required in your jurisdiction, including — non-exhaustively — 72 hours to the lead EU/UK Data Protection Authority; 60 days to affected individuals and the FTC under the Health Breach Notification Rule (nationwide media at 500+ affected); promptly under PIPEDA and Quebec's Law 25; and as soon as practicable under other applicable regimes.
Changes
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date. Where changes are material and required notices apply, we will provide additional notice as appropriate (for example, in-app messaging or email).
Privacy contacts
Privacy: privacy@aureonperformance.com
Legal: legal@aureonperformance.com