Privacy Policy
Last updated: September 25, 2026. This version replaces and supersedes the prior version dated July 15, 2026.
Aureon FitApp Inc. ("Aureon," "we," "us," or "our"), a corporation federally incorporated in Canada with its head office in the Province of Ontario, operates the software and services marketed as Aureon Performance (our "Services"). This Privacy Policy describes how we collect, use, disclose, and safeguard personal information across our websites, mobile applications, and related offerings. It is written to satisfy, in substance and in operating practice, Canada's federal PIPEDA and Quebec's Law 25, Ontario's PHIPA, the European Union's GDPR, the United Kingdom's UK GDPR and Data Protection Act 2018, the U.S. FTC Act and FTC Health Breach Notification Rule, and United States state privacy law led by California's CCPA, as amended by the CPRA (with comparable Virginia, Colorado, Connecticut, Utah, and Texas statutes). Platform operators apply their own rules; our practices are summarized here and may be supplemented by store disclosures you approve at install or purchase.
Washington and Nevada residents. Because you have Consumer Health Data rights beyond what this general Policy covers, we maintain a separate, standalone Consumer Health Data Privacy Policy with its own distinct link and its own consent flow. It is not a section or anchor of this document. See the Consumer Health Data Privacy Policy.
Compliance Accountability & Contact
We are Aureon FitApp Inc., federally incorporated in Canada and operating as Aureon Performance from our head office in Ontario, Canada. We are the data controller and, under PIPEDA, the accountable organization for the personal information described here.
Registered address: Aureon FitApp Inc., 350 Bay St, Suite 1300B, Toronto, Ontario
To keep accountability unambiguous, electronic channels are split by function:
- · Privacy Lead · EU & UK data-subject inquiries (EU/UK Article 27 representative: Prighter, app.prighter.com/portal/aureonperformance): privacy@aureonperformance.com
- · General Counsel · Corporate legal notices · Compliance-infrastructure mapping: legal@aureonperformance.com
Representative
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
- European Union (EU)
- United Kingdom (UK)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/aureonperformance
Information we collect
Depending on how you interact with us, we may collect categories of information such as:
- Profile variables. Display name, birthdate (for age verification), sex, and the email returned by Apple or Google OAuth, or, for Guest sessions, an anonymous device token rather than an identifying account.
- Usage & performance. In-app activity (e.g., workouts logged, protocol edits, engagement signals), feature usage, and purchase-funnel events, collected via PostHog product analytics and never linked to health data.
- Diagnostics. Crash reports and performance traces, collected via Sentry, scrubbed of biometric, hormone, and authentication-token values before transmission, and not linked to your account identity.
- Device & technical. Device type, OS version, app version, locale, IP address, mobile identifiers compatible with platform policies, and similar technical metadata.
- Location. A city-level location string only, derived on-device and reverse-geocoded. We never transmit or store precise GPS coordinates. See Device permissions.
- Payment & billing. Mobile subscriptions are billed through the Apple App Store or Google Play, which show the price at the time of purchase, and managed via RevenueCat. We receive subscription status, product identifiers, and renewal dates, never full payment card details. Web prices are shown on /pricing, but web checkout via Stripe is currently paused: our website is not processing live subscription purchases at this time.
- Communications. Content you send us (support tickets, feedback, survey responses) and related correspondence metadata.
- AI coach conversations. The messages you send to the in-app AI coach and the replies it gives you. Anthropic processes them to write each reply. When a reply is played aloud, its text is sent to ElevenLabs to produce the audio. Each message is deleted automatically 30 days after it is sent.
- Physical biometrics. Height, body weight, body-fat percentage, resting heart rate, peak heart rate, and the free-text biomechanical constraints or injury-rehabilitation history you choose to record, used to calibrate load, scaling, and movement contraindications. Where you allow it, some of these values are also read from Apple Health or Health Connect. The full list of what we read is under Health data sync.
- Declared clinical context and allergies. Clinical context you choose to declare from a fixed list (celiac, type 1 diabetes, type 2 diabetes, high blood pressure), and the food allergies you list, picked from a fixed list or typed in yourself. Clinical context is used only to constrain how meals are composed and to add one training technique cue. Allergies are treated as hard exclusions when meals are composed. Both are included in the AI requests that compose your meals, and clinical context also in the workout requests it adds a cue to. Clinical context is special-category health data, and the section that collects it appears only after you give health-data consent. Neither is ever used for advertising or audience building.
- Special-category data. Where you choose to provide it: clinical biomarkers and hormone-panel values synthesized from the lab documents you upload, the physique reference images you submit for body-composition analysis, and menstrual-cycle tracking details, each processed via Anthropic Claude, provided by Anthropic PBC through its commercial API. These are special-category / sensitive personal data under GDPR Article 9 and equivalent US "sensitive personal information" standards, and are processed only on your explicit, opt-in consent, which you may withdraw at any time. See Biometric & Health Data.
On our website, we also use a small set of cookies and similar technologies (such as browser local storage and session storage). See our Cookie Policy for exactly what is set, by whom, for what purpose, and how to control it.
Device permissions
Aureon requests only the device permissions its features require, matched to the declarations in our Apple App Store and Google Play manifests. Each is optional, prompted in context, and revocable at any time through your operating-system settings:
- · Camera: four uses.
- · Meal photos you take, analyzed for macro- and micronutrients, then discarded and never stored.
- · Kitchen or pantry shelf photos, analyzed so the ingredients can be listed for meal planning, then discarded and never stored.
- · Physique and progress photos you submit for body-composition analysis.
- · Live form analysis while you lift. Camera frames are analyzed on your phone in real time and are never recorded, stored, or sent to Aureon or anyone else. No video is saved. A compressed movement trace and the scores taken from it are saved on your phone only, and withdrawing this consent in Settings deletes them.
- · Photo Library: the profile portrait you choose to set.
- · Document Picker: parsing the clinical lab files you upload for biomarker extraction.
- · Foreground Location: reverse-geocoded to a city-level field only, stored as location_city, never precise coordinates and never background tracking.
- · HealthKit / Health Connect: read-only, limited to the data types listed under Health data sync, and only the ones you allow when your phone asks.
- · Push Notifications: active rest-timer cues and session prompts.
How we use information
We use personal information for purposes including:
- Service delivery. Creating and maintaining accounts, generating and adapting training and nutrition protocols, computing Aureon scores (including BioAge), syncing across devices, and providing customer support.
- Personalization & product improvement. Tailoring recommendations and improving models and workflows, subject to this Policy and applicable law.
- Security, integrity & fraud prevention. Detecting abuse, securing infrastructure, investigating incidents, and enforcing our Terms.
- Legal compliance. Complying with law, regulation, lawful requests, and protecting rights and safety.
- Communications. Transactional messages (billing, security alerts), service announcements, and, where permitted, marketing communications you can opt out of.
Legal Bases for Processing (GDPR · UK GDPR · PIPEDA)
Where cross-border frameworks require an explicit lawful basis, we rely on the following, and only for the purposes stated in this Policy:
- Performance of a contract. Operating your account, computing performance metrics, and delivering the protocols you request.
- Explicit consent. Required under GDPR Article 9, and aligned with PIPEDA's consent principle, before we read or synthesize any special-category signal: Apple Health and Health Connect data, the clinical biomarkers and hormone-panel values drawn from documents you upload, the physique images you submit for body-composition analysis, menstrual-cycle details, and any clinical context you declare. You may withdraw consent at any time through operating-system permissions or in-app controls.
- Legitimate interests. Securing infrastructure, preventing fraud and abuse, maintaining service reliability, and improving product architecture, balanced against your fundamental rights and freedoms.
- Legal obligations. Meeting Canadian federal and provincial record-retention, tax, audit, and statutory disclosure duties.
Canada · PIPEDA & Ontario PHIPA
As a federally incorporated Canadian organization, we handle personal information under the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair-information principles: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance.
- · Accountability: our Privacy Lead answers for compliance and for every third party that processes data on our behalf.
- · Meaningful consent: consent is scaled to sensitivity (express opt-in for health and biometric signals) and may be withdrawn at any time.
- · Limiting collection: we gather only what a stated performance purpose requires, and we do not silently repurpose it.
- · Access & challenge: you may request what we hold and challenge our handling with the Office of the Privacy Commissioner of Canada.
Ontario PHIPA scope. Aureon Performance is a consumer performance-optimization application, not a health information custodian under Ontario's Personal Health Information Protection Act (PHIPA). We do not deliver health care, and we neither contribute to nor draw from provincial electronic health records. Biometric telemetry you connect stays isolated within your user-managed environment and is processed only for training-load and recovery calibration, never as a custodial health record.
Quebec · Law 25. Quebec residents additionally have a right to data portability, disclosure of any decision made exclusively through automated processing, and the right to have consent obtained expressly and separately for sensitive information such as health data. Cross-border transfers of Quebec residents' personal information are assessed through a transfer impact review before they occur. See International transfers.
Alberta & British Columbia. Residents' rights mirror PIPEDA; Alberta additionally requires notification to its Commissioner for breaches posing a real risk of significant harm.
European Union & United Kingdom · GDPR / UK GDPR
For residents of the European Economic Area, Switzerland, and the United Kingdom, we process personal data as a data controller under the EU GDPR and the UK GDPR read with the Data Protection Act 2018. We operate without a permanent physical establishment in the European Economic Area or the United Kingdom, and Aureon FitApp Inc. has appointed Prighter as its representative in the EU and the UK under Article 27 of the GDPR / UK GDPR: iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria, serves as our EU representative, and Prighter Ltd serves as our UK representative. EU/UK data subjects and supervisory authorities may contact our representative through the public representation portal at app.prighter.com/portal/aureonperformance, or reach us directly at privacy@aureonperformance.com.
You may exercise the rights of access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent without affecting prior lawful processing. You also retain the right to lodge a complaint with your local supervisory authority: an EU member-state Data Protection Authority or the UK Information Commissioner's Office (ICO). Transfers out of the EEA or UK rely on Standard Contractual Clauses (with the UK Addendum where applicable) or another recognized adequacy mechanism, detailed under International transfers.
United States · Multi-State Privacy (CCPA / CPRA)
For United States residents, we honor the consumer rights established by California's Consumer Privacy Act (CCPA), as amended by the Privacy Rights Act (CPRA), and we extend equivalent treatment to residents of states with comparable statutes: Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA). At the federal level, the FTC Act prohibits deceptive or unsubstantiated privacy claims, and we keep our marketing consistent with this Policy. You may exercise:
- · Know & access: the categories and specific pieces of personal information we have collected.
- · Delete & correct: removal or correction of your personal information, subject to lawful exceptions.
- · Opt out of sale or sharing: we do not sell personal information for monetary value, we do not share it for cross-context behavioral advertising, and we honor Global Privacy Control signals regardless.
- · Limit sensitive personal information: health and biometric inputs operate only the features you enable, never advertising inference.
- · No retaliation: we will not deny service, alter pricing, or degrade quality because you exercised a privacy right.
To submit a request, contact privacy@aureonperformance.com with the subject line "US Privacy Request". We verify identity before disclosing or deleting data, and an authorized agent may act on your behalf with proof of permission.
Additional jurisdictions. Where we serve residents of Australia (Privacy Act 1988 / Australian Privacy Principles), Japan (APPI), Singapore (PDPA), South Korea (PIPA), India (Digital Personal Data Protection Act, 2023), Brazil (LGPD), Mexico (LFPDPPP), Argentina (Law 25.326), or South Africa (POPIA), we honor the access, correction, deletion, consent-withdrawal, itemized-consent, and complaint rights those statutes establish, and we disclose that special-category and health-adjacent data may be transferred to and processed in the United States by the sub-processors listed below. Wherever local law grants rights beyond those listed on this page, contact us (Section below) and we will route your request appropriately.
Washington & Nevada · Consumer Health Data
Washington's My Health My Data Act (MHMDA) and Nevada's SB 370 (NRS 603A) regulate a category called "Consumer Health Data" and require a separate, distinctly-linked policy and separate opt-in consents for collecting versus sharing that data. This general Privacy Policy does not, by itself, satisfy either requirement. We do not sell Consumer Health Data and we do not geofence health care facilities. Full detail, definitions, and your rights (including how to submit a request and how to appeal a denial) live in the standalone Consumer Health Data Privacy Policy, which controls over this document for anything concerning Consumer Health Data.
FTC Health Breach Notification Rule & HIPAA status
HIPAA does not apply to Aureon. HIPAA covers "covered entities" (health care providers, insurers, clearinghouses) and their "business associates." We are a direct-to-consumer software company: we do not bill insurers and we do not receive records from a covered entity. We do not represent ourselves as HIPAA-compliant, and no statement in our marketing should be read that way.
What does apply is the FTC Health Breach Notification Rule (16 CFR Part 318), which covers vendors of personal health records like Aureon. If a breach occurs, including an unauthorized disclosure such as a misconfigured storage setting and not only a hack, we will notify affected individuals and the FTC without unreasonable delay and no later than 60 days after discovery, and notify nationwide media if the breach affects 500 or more residents of a state or jurisdiction.
Sharing & disclosure
We may share personal information with:
- Service providers & subprocessors. Vendors that host infrastructure, provide analytics (where permitted), deliver customer-support tooling, security services, payments facilitation (as applicable), email delivery, AI inference, and text-to-speech, subject to contractual confidentiality and security expectations.
- Legal & safety. Disclosures required by law, regulation, legal process, or governmental requests, or to protect the rights, safety, and security of Aureon, our users, or the public.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate safeguards and notices where required.
We do not sell your personal information for monetary consideration in the conventional sense of selling customer lists to unrelated buyers. We also do not share personal information with data brokers for their independent marketing purposes. Where regional laws define "sale" or "sharing" broadly (such as the California CPRA context), we honor those broader definitions and treat the Global Privacy Control (GPC) browser signal, where enabled, as a valid opt-out-of-sale-and-sharing request for that browsing session.
Sub-processors
This is the complete roster of parties that receive personal information on our behalf. Each is bound by contractual confidentiality and security obligations, and each is limited to the function named below. All are located in the United States unless noted otherwise.
- · Supabase: database, authentication, and file-storage host.
- · Anthropic PBC (Claude): all AI inference, covering the training sessions the app prescribes, nutrition generation, meal-photo and kitchen-photo analysis, protocol and progress narratives, biomarker summaries, clinical-document extraction, the in-app AI coach chat, and the website support assistant; image-safety moderation on uploaded photos. Anthropic processes the prompt and the model response in order to return a result. Under Anthropic's commercial API terms, customer inputs and outputs are not used to train Anthropic's models by default.
- · ElevenLabs: text-to-speech for spoken replies in the in-app AI coach chat and the website support assistant. When a reply is played aloud, ElevenLabs receives the text of that reply and returns the audio. It receives nothing else from your account.
- · RevenueCat: mobile subscription state and entitlement management.
- · Stripe: web payment processing infrastructure. Currently paused: no live web subscription purchases are being processed through this channel at this time.
- · PostHog: product-interaction and purchase-funnel analytics in the mobile app, with no health data.
- · Sentry: crash and performance diagnostics, not linked to your account.
- · Resend: transactional email (account, security, receipts).
- · Upstash: rate-limiting and cache infrastructure for abuse prevention, and the short-lived store for website support assistant conversations (see Website support assistant).
- · Vercel: website hosting.
- · Apple Inc. / Google LLC: app-store distribution, in-app purchase processing, and HealthKit / Health Connect (platform-operated).
Instacart is not a sub-processor. It is a deep link you choose to open from a meal plan. Once you follow it, Instacart processes your data directly as an independent controller under its own privacy policy. We do not transmit your data to Instacart on your behalf.
Biometric & Health Data
Where you grant permission, Aureon performs a strictly read-only sync with Apple HealthKit and Android Health Connect: we read the data types you authorize and write nothing back to either framework. Those signals are processed solely to compute Aureon's Recovery, Sleep Quality, Strain, Cardio Baseline, and Metabolic Capacity scores, to show your body-composition and fitness readings on your Biometrics Progress page, to set the nutrition targets tied to your body weight, to add the hydration your phone records to your daily hydration log on Android, and to calibrate physical training load and recovery-aware adaptation within the Services. The complete list of data types we read, with the purpose of each and the platforms that provide it, is under Health data sync. We do not use Apple HealthKit, Android Health Connect, or analogous health API data for advertising. We do not sell that data to data brokers and do not share it with unrelated third parties for their own marketing purposes.
Custodial status. These inputs are processed solely for load adaptation and recovery scoring within your user-managed environment. They are not custodial health records, and they are not contributed to any provincial health repository. See Canada · PIPEDA & Ontario PHIPA for our full position under Ontario's health-privacy regime.
Artificial intelligence processing
To generate the training sessions the app prescribes, compose nutrition protocols, list the ingredients in kitchen photos, interpret lab uploads, summarize progress photos, write protocol and biomarker narratives, reply to you in the AI coach chat, and screen uploaded images for safety, your inputs are processed by Anthropic Claude, provided by Anthropic PBC through its commercial API. Anthropic processes the prompt and the model response in order to return a result, and under its commercial API terms customer inputs and outputs are not used to train Anthropic's models by default.
Anthropic is the only provider that generates AI output from your data. When a coach chat reply or a website support assistant reply is played aloud, ElevenLabs turns the text of that reply into speech. It generates no content of its own. No Google AI service is involved in any part of the pipeline. Meal photos and kitchen photos are processed in memory for a single analysis and are not persisted.
Where technically feasible, prompts sent for inference are limited to the physiological and behavioral fields the task needs. Free-text fields you write yourself (for example, injury notes) could still be identifying in edge cases, so avoid including unnecessary personal detail in them.
Human review may occur for safety, quality assurance, abuse prevention, or compliance monitoring. You should avoid submitting unnecessary sensitive PII in chat, notes, or unstructured fields. Retention of model inputs/outputs is managed under operational and security policies (typically retained only as long as needed for service delivery, troubleshooting, safety, and legal compliance, unless a longer period is required by law).
AI-generated outputs (protocols, meal plans, biomarker narratives) are advisory only. No output triggers a legally or similarly significant decision about you within the meaning of GDPR Article 22. You always remain free to disregard or seek human review of any AI-generated recommendation through our support channels. Full disclaimers appear in our AI Consent Wall and Medical Disclaimer.
Website support assistant
The chat assistant on this website answers questions about Aureon. When you send it a message, that message and the recent turns of your conversation are sent to Anthropic to write the next reply. If you play a reply aloud, its text is sent to ElevenLabs to produce the audio.
Up to eight recent turns are held in our Upstash cache and deleted automatically 30 minutes after your last message. The conversation is not saved to our database, analytics, or error logs, and it is not linked to your name, email, or Aureon account. To limit abuse, a salted hash of your IP address is kept with the conversation instead of the address itself. The conversation id sits in your browser's session storage and ends when you close the tab (see the Cookie Policy).
Please do not share health details or other sensitive information in this chat. For questions about your account, email support@aureonperformance.com.
Security
We implement administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit (TLS) for all endpoints, row-level access controls in our database limiting each account to its own rows, and encryption at rest provided by our infrastructure providers. No method of transmission or storage is completely secure; we encourage strong, unique passwords and keeping your device's operating system current.
International transfers & Cross-Border Adequacy
We are based in Canada, and most of our infrastructure sub-processors are located in the United States (see Sub-processors). If you are in the EEA, UK, Switzerland, or Quebec, your information will be transferred to and processed in the United States. Where required by GDPR Chapter V or the UK GDPR, we rely on the European Commission's Standard Contractual Clauses (2021 modules), supplemented by the UK International Data Transfer Addendum, or, where a processor is certified, the EU-U.S. Data Privacy Framework, as the transfer mechanism for each affected sub-processor. Quebec's Law 25 requires a transfer impact review before personal information is sent outside Quebec, which we apply to the same transfers described above.
Retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements:
- · Account, workout, nutrition, biometric, and photo records: retained for the life of your account, because the service is built to show your history and long-term trends. When you delete your account, live data is removed immediately, and full erasure (including residual encrypted backups, which persist only until standard overwrite cycles complete) is finalized within 30 days.
- · Special-category data (clinical biomarkers, hormone panels, menstrual/reproductive fields, declared clinical context): retained for the life of your account, or removed sooner if you withdraw the specific consent that authorized it. Special-category data should not outlive the consent behind it.
- · AI coach conversations: each message is deleted automatically 30 days after it is sent.
- · Website support assistant conversations: deleted automatically 30 minutes after your last message.
- · Transactional / billing records: retained as required by Canadian tax and commerce law. Payment processors and platform stores (Apple, Google, RevenueCat, Stripe) may separately retain transaction records under their own policies.
- · Security logs and crash/performance diagnostics: retained for a bounded operational window configured with our infrastructure providers.
- · Account-security events: we keep a separate record of security-relevant account changes (subscription tier changes, email address changes, and account deletion) so we can investigate unauthorized access. These records hold the event, its time, and the account it belongs to. Email addresses captured in them are removed after 90 days, and the records themselves are deleted after 24 months. This is the one category that outlives the 30-day erasure window above: a deletion record that vanished along with the account it documents would be no use for detecting an account takeover. We keep it on the basis of legitimate interest rather than consent.
- · Support communications: retained for the period needed to resolve your issue and maintain quality assurance.
Your Global Rights (GDPR · UK DPA · PIPEDA · US Multi-State)
Aureon extends comprehensive data rights to every account holder, independent of region, and will not penalize you for exercising them:
- · Access & portability: get a machine-readable copy of your records. In the app, go to Settings, then Legal & Privacy, then Export my data. It builds a JSON and CSV export and opens your phone's share sheet. If you cannot use the app, email privacy@aureonperformance.com with the subject line "Data Export".
- · Erasure / deletion: purge profile inputs through in-app deletion (Settings → Danger zone → Terminate account) or via the /data-deletion fallback.
- · Correction / rectification: amend inaccurate parameters inside your settings.
- · Object / restrict: halt non-essential telemetry or third-party inference. To turn off product analytics in the app, go to Settings, then Privacy controls, then Usage analytics.
- · Limit sensitive data (US): California and other state residents may restrict the use of physical-health attributes beyond core operation.
- · Opt out via Global Privacy Control: where you visit aureonperformance.com with GPC enabled in a supported browser, we treat that signal as a valid opt-out-of-sale-and-sharing request for that session.
- · Washington & Nevada residents: Consumer Health Data-specific rights (including appeal of a denied request) are addressed in the standalone Consumer Health Data Privacy Policy.
To exercise any other right, contact privacy@aureonperformance.com. We verify identity before resolving requests, and you retain the right to lodge a complaint with your home jurisdiction's supervisory privacy authority.
Children
Our Services are not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe we have collected information from someone under 18, contact us so we can take appropriate steps.
Data breach notification
If a breach affecting your personal information occurs, we will notify you and the relevant regulator(s) on the timeline required in your jurisdiction, including, non-exhaustively: 72 hours to the lead EU/UK Data Protection Authority; 60 days to affected individuals and the FTC under the Health Breach Notification Rule (nationwide media at 500+ affected); promptly under PIPEDA and Quebec's Law 25; and as soon as practicable under other applicable regimes.
Changes
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last updated" date. Where changes are material and required notices apply, we will provide additional notice as appropriate (for example, in-app messaging or email).
Privacy contacts
Privacy: privacy@aureonperformance.com
Legal: legal@aureonperformance.com
Registered address: Aureon FitApp Inc., 350 Bay St, Suite 1300B, Toronto, Ontario