Legal
Consumer Health Data Privacy Policy
Effective & last updated: July 14, 2026
This is a separate, standalone policy. It is not a section of, an anchor inside, or a substitute for Aureon's general Privacy Policy. Washington's My Health My Data Act and Nevada's consumer health data law both require Consumer Health Data disclosures to live on their own, distinctly-linked page — not buried inside a combined privacy document. If you are looking for Aureon's privacy practices generally (account data, billing, cookies, international transfers), see the general Privacy Policy. This page governs Consumer Health Data specifically, as that term is defined by Washington RCW 19.373 (the "My Health My Data Act," or "MHMDA") and Nevada SB 370 (NRS 603A), and it controls over the general Privacy Policy wherever the two address the same subject.
Who this policy is for, and why it exists
Washington's My Health My Data Act (RCW 19.373) and Nevada's consumer health data law (NRS 603A, enacted as SB 370) regulate a category of information called "Consumer Health Data" — information broader than what most people think of as "medical records." Both laws require any business that collects Consumer Health Data from consumers connected to Washington or Nevada to publish a standalone policy like this one, and both require separate, affirmative opt-in consent before that data is collected, and a second, separate opt-in before it is shared with anyone outside the company. Washington's law carries a private right of action — meaning an individual consumer, not just the state Attorney General, can sue over a violation. Nevada's law is enforced by its Attorney General only.
Aureon FitApp Inc. ("Aureon," "we," "us," "our") is a federally incorporated Canadian company operating the fitness and performance software marketed as Aureon Performance (the "Services"), available as a mobile app and companion website worldwide. Because Aureon processes recovery, sleep, biometric, reproductive, and clinical-lab data as a core part of what the Services do, and because the Services are available to Washington and Nevada residents (and to anyone whose Consumer Health Data is collected while they are physically in Washington or Nevada), this policy applies to Aureon's handling of Consumer Health Data regardless of where you happen to live — we do not gate these protections by geography.
This policy tells you: what we consider Consumer Health Data and why we collect it; how our collection consent and sharing consent are kept separate; that we do not sell Consumer Health Data; that we do not geofence health care facilities; and exactly how to exercise your rights.
Definitions (plain language)
- · "Consumer Health Data" — under both statutes, any personal information linked (or reasonably linkable) to you that identifies your past, present, or future physical or mental health status. It is defined broadly and explicitly includes individual health conditions or diagnoses; biometric data; reproductive or sexual health information; gender-affirming care information; bodily functions, vital signs, symptoms, or measurements; and — importantly — any information a company derives or infers from other data (including through an algorithm) that identifies your health status. Section "What we collect" below lists exactly what this covers at Aureon.
- · "Collect" — gathering, deriving, receiving, buying, or otherwise obtaining Consumer Health Data, including passively (for example, reading a signal from Apple Health or Health Connect).
- · "Share" / "Sharing" — disclosing, releasing, disseminating, making available, or otherwise communicating Consumer Health Data to a person or entity other than the consumer, by any means. Both statutes carve out disclosures to a company's own processors (vendors that process data solely on the company's behalf and instructions, and do not use it for their own independent purposes) — those are not "sharing" under the statute, but we still disclose our processors to you for transparency.
- · "Sell" / "Sale" — exchanging Consumer Health Data for money or other valuable consideration with a third party.
- · "Geofence" — technology that uses GPS, Wi-Fi, Bluetooth, cell-tower, or similar signals to establish a virtual boundary around a physical location.
- · "Consumer" — under Washington's law, a natural person who resides in Washington, or whose Consumer Health Data is collected in Washington. Under Nevada's law, a natural person who resides in Nevada, or whose Consumer Health Data is collected in Nevada. Both statutes exclude data about a person acting in an employment or business-to-business capacity.
What Consumer Health Data Aureon collects, and why
Aureon's core function — generating and adapting training, recovery, and nutrition guidance — depends on understanding your physiology. Below is every category of Consumer Health Data we collect, and the specific purpose each serves.
- Wearable & device vitals (read-only, via Apple HealthKit / Android Health Connect, where you grant permission) — steps, heart rate, resting heart rate, heart-rate variability (HRV), sleep sessions, active-calorie burn, respiratory rate, blood-oxygen saturation (SpO2), body weight, and hydration: used to compute Aureon's Recovery, Sleep Quality, Strain, Cardio Baseline, and Metabolic Capacity scores, and to calibrate training load day to day.
- Clinical biomarkers & hormone panels (Apex Plus tier — a document you choose to upload) — bloodwork values and hormone-panel results extracted from lab documents you submit: used to generate your BioAge (a PhenoAge-style biological-age estimate) and biomarker-based narrative insights.
- Reproductive / menstrual-cycle data — biological sex, whether cycle tracking is enabled, last menstrual period start date, and average cycle length: used for menstrual-phase-aware training and nutrition periodization.
- Injury history & biomechanical constraints (free text you enter) — injuries, rehab status, and movement limitations you describe: used to exclude contraindicated movements and scale load around an active injury.
- Progress / physique photos (camera capture you initiate) — body-composition reference images: used to track body-composition change over time via AI-assisted analysis.
- Aureon Scores (derived, not directly entered) — BioAge, Recovery, Strain, Sleep Quality, Cardio Baseline, and Metabolic Capacity, each computed from the categories above: the whole point of the product — turning raw signals into an interpretable performance/recovery picture.
- Body measurements & workout logs — height, weight, body-fat percentage, and sets/reps/load logged in training sessions: used for load progression, volume tracking, and periodization.
Not health data, disclosed for completeness: Aureon also collects a city-level location (derived from a one-time device location read, reverse-geocoded, and stored as a city string — we never persist precise GPS coordinates) to power the Arena "Local" leaderboard feature. This is ordinary location data, not Consumer Health Data — it does not reveal or reasonably indicate an attempt to obtain health care, and it is never used near, or in connection with, any health care facility (see "No geofencing of health care facilities" below).
We do not use any Consumer Health Data listed above to build advertising profiles, and we do not permit any sub-processor to use it for advertising. There is no advertising identifier of any kind (no IDFA, no Android Advertising ID) anywhere in the Services.
How we collect it: directly from you (text fields, uploaded lab documents, captured photos you choose to submit); from your device's health platform (Apple HealthKit and Android Health Connect, read-only, and only for the specific signal types disclosed at the time you grant OS-level permission — we never write data back); and derived by Aureon (the Aureon Scores above are computed by our systems from the categories above; under both statutes, this derived/inferred data is itself Consumer Health Data).
Your separate consent choices: collect vs. share
Both statutes require two distinct, unbundled opt-ins — one before Aureon may collect your Consumer Health Data, and a wholly separate one before Aureon may share it with anyone outside the company. Neither consent may be bundled into a single "I agree to the Terms" checkbox, and withdrawing one does not withdraw the other.
(a) Consent to collect. Before any Consumer Health Data described above is read or processed, Aureon presents a dedicated consent step — distinct from account creation and distinct from the Terms of Service — describing what will be collected and why. Collection of a given category (for example, reproductive-cycle data, or a clinical lab upload) does not begin until you affirmatively grant that consent. You can withdraw collection consent at any time, and doing so stops future collection of that category going forward.
(b) Consent to share. Aureon's default posture is that we do not share your Consumer Health Data with anyone outside the company. The sub-processors described below process data solely on our instructions, for our purposes, under contract — they are not independent recipients, so routing data to them is not "sharing" under either statute. If that ever changes — for example, if we were to integrate a genuinely independent third-party service that would receive your Consumer Health Data for its own purposes — we will not do so under any consent you have already given. We will first present a new, separate, distinctly-labeled sharing consent describing exactly who would receive the data and why, and we will proceed only if you affirmatively opt in. You may decline, and you may withdraw that consent later without affecting your ability to use the rest of the Services, to the extent the shared feature is not itself the thing you are requesting.
We do not sell Consumer Health Data
Aureon does not sell Consumer Health Data, and we have no plans to. No Consumer Health Data described above is exchanged with any third party for money or other valuable consideration.
Both statutes prohibit selling Consumer Health Data without a valid, signed authorization from the consumer — a document that is legally distinct from an ordinary consent or from a terms-of-service acceptance. If Aureon's practices were ever to change and a sale were contemplated, we would first obtain an authorization that, at minimum: names the specific data to be sold and identifies both Aureon and the buyer by name and contact information; states plainly that we will not condition any product, service, or price on you signing it; states your right to revoke the authorization at any time and describes how; confirms any resale by the buyer would itself require a valid authorization or another lawful basis; and expires automatically no more than one year from the date you sign it.
Until and unless that changes — which we do not anticipate — you can treat "no sale of Consumer Health Data" as an unconditional commitment.
Who processes Consumer Health Data on our behalf
Aureon uses a small set of infrastructure vendors, acting strictly as our processors (not as independent third parties), to operate the Services:
- · Supabase — our database, authentication, and file-storage provider. All Consumer Health Data at rest lives here, access-controlled to your own account.
- · Anthropic PBC (Claude). Our only AI processor. Generates the training sessions the app prescribes, composes nutrition plans, analyzes meal and progress photos, writes protocol and progress narratives, summarizes biomarker values, extracts values from uploaded lab documents, and runs image-moderation safety checks on uploaded photos. Anthropic processes the prompt and the model response in order to return a result. Under Anthropic's commercial API terms, customer inputs and outputs are not used to train Anthropic's models by default.
None of these vendors receives Consumer Health Data for their own independent purposes, none is permitted to use it for advertising, and none of this constitutes "sharing" under "Consent to share" above. We do not use any analytics or crash-reporting vendor to process Consumer Health Data — our analytics and crash-diagnostics pipeline is deliberately kept free of health signals.
No geofencing of health care facilities
Both statutes prohibit implementing a geofence around any entity that provides in-person health care services in order to (a) identify or track consumers seeking health care, (b) collect Consumer Health Data from them, or (c) send them communications, notifications, or advertisements related to their health data or to health care services.
Aureon does not do this, in any form. Our only location functionality is a single, one-time, city-level location read used solely to group users for the Arena "Local" leaderboard feature. We do not use precise GPS, we do not persist coordinates, we do not track movement over time, we do not draw any boundary around a clinic, pharmacy, hospital, or any other health care facility, and we do not send location-triggered messages of any kind.
Your rights, and exactly how to exercise them
You have the following rights over your Consumer Health Data, regardless of where you live, though the specific statutory backing differs by jurisdiction (see "Jurisdictional notes" below):
- · Confirm whether Aureon is processing your Consumer Health Data.
- · Access the Consumer Health Data we hold about you.
- · Withdraw your collection consent — stopping future collection of a given category. In practice: revoke the relevant permission in your device's Apple Health / Health Connect settings (stops that specific vitals feed immediately), use the in-app privacy controls under Settings → Privacy, or contact us below and we will process the withdrawal on our end.
- · Withdraw your sharing consent — relevant only if you have ever affirmatively opted into a sharing arrangement above; withdrawing stops future sharing.
- · Delete your Consumer Health Data. In practice: Settings → Danger zone → Terminate account inside the app deletes your account's live Consumer Health Data immediately and queues full erasure (including from the processors named above), or use the Data Deletion fallback page, or contact us below.
- · Appeal a denial of any of the above.
How to submit a request. Email privacy@aureonperformance.com with the subject line "Consumer Health Data Request — Washington" or "Consumer Health Data Request — Nevada" (whichever applies to you), and tell us which right you are exercising. We will verify your identity as the account holder before acting on the request.
Response timeline. We will respond as soon as practicable, and no later than 45 days after we receive a verifiable request. If we reasonably need more time, we will notify you within that initial 45-day window and take up to an additional 45 days.
If we deny your request, we will explain why, and you may appeal by replying to our decision within a reasonable time. We will decide your appeal within 45 days of receiving it. If we uphold the denial, we will tell you how to submit a complaint to the relevant regulator:
- · Washington residents: the Washington State Attorney General's Office (Washington's My Health My Data Act carries a private right of action — you are not required to complain to the Attorney General before pursuing other remedies available to you under the Act; consult your own counsel about your options).
- · Nevada residents: the Nevada Attorney General's Office (Nevada's law is enforced by the Attorney General; it does not create a private right of action).
Jurisdictional notes
- · Who is protected: Washington — residents, and anyone whose Consumer Health Data is collected while in Washington. Nevada — residents, and anyone whose Consumer Health Data is collected while in Nevada.
- · Separate collect/share consent: required under both statutes.
- · Sale requires signed authorization: required under both statutes.
- · Geofencing health facilities: prohibited under both statutes.
- · Enforcement: Washington — the Attorney General and a private right of action (individuals can sue). Nevada — Attorney General only, no private right of action.
- · Small-business exemption: none specific to Consumer Health Data under Washington's law; Nevada has limited carve-outs (e.g., HIPAA-covered entities, GLBA-covered financial institutions) that do not apply to Aureon.
Because Aureon's product is available worldwide and does not geofence itself out of Washington or Nevada, we apply the protections in this policy uniformly rather than trying to detect where you are located.
Retention and security
We retain Consumer Health Data only for as long as your account is active, plus a limited window to complete deletion requests — when you delete your account, live data is removed immediately and full erasure, including residual encrypted backups, is finalized within 30 days (see the in-app deletion mechanics above and the retention detail in our general Privacy Policy). Consumer Health Data is encrypted in transit, access-controlled to your own account by row-level security in our database, and never logged in raw form in our diagnostic or crash-reporting systems.
Changes to this policy
We may update this policy as our practices, or the law, change. We will post the revised version here with an updated effective date, and where a change is material — for example, a new category of Consumer Health Data, or a change to whether we share or sell it — we will seek fresh, separate consent before the change takes effect for you, not merely post a notice.
Contact us
Aureon FitApp Inc.
Email: privacy@aureonperformance.com (subject line: "Consumer Health Data Request — Washington" or "— Nevada")
This policy is separate from, and controls over, Aureon's general Privacy Policy for anything concerning Consumer Health Data as defined above.