Legal
Consumer Health Data Privacy Policy
Effective & last updated: September 25, 2026
This is a separate, standalone policy. It is not a section of, an anchor inside, or a substitute for Aureon's general Privacy Policy. Washington's My Health My Data Act and Nevada's consumer health data law both require Consumer Health Data disclosures to live on their own, distinctly linked page, not inside a combined privacy document. If you are looking for Aureon's privacy practices generally (account data, billing, cookies, international transfers), see the general Privacy Policy. This page governs Consumer Health Data specifically, as that term is defined by Washington RCW 19.373 (the "My Health My Data Act," or "MHMDA") and Nevada SB 370 (NRS 603A), and it controls over the general Privacy Policy wherever the two address the same subject.
Who this policy is for, and why it exists
Washington's My Health My Data Act (RCW 19.373) and Nevada's consumer health data law (NRS 603A, enacted as SB 370) regulate a category of information called "Consumer Health Data", which is broader than what most people think of as "medical records." Both laws require any business that collects Consumer Health Data from consumers connected to Washington or Nevada to publish a standalone policy like this one, and both require separate, affirmative opt-in consent before that data is collected, and a second, separate opt-in before it is shared with anyone outside the company. Washington's law carries a private right of action, which means an individual consumer, not just the state Attorney General, can sue over a violation. Nevada's law is enforced by its Attorney General only.
Aureon FitApp Inc. ("Aureon," "we," "us," "our") is a federally incorporated Canadian company operating the fitness and performance software marketed as Aureon Performance (the "Services"), available as a mobile app and companion website worldwide. Aureon processes recovery, sleep, biometric, reproductive, clinical-lab, and self-declared clinical data as a core part of what the Services do, and the Services are available to Washington and Nevada residents (and to anyone whose Consumer Health Data is collected while they are physically in Washington or Nevada). This policy therefore applies to Aureon's handling of Consumer Health Data regardless of where you happen to live. We do not gate these protections by geography.
This policy tells you: what we consider Consumer Health Data and why we collect it; how our collection consent and sharing consent are kept separate; that we do not sell Consumer Health Data; that we do not geofence health care facilities; and exactly how to exercise your rights.
Definitions (plain language)
- · "Consumer Health Data": under both statutes, any personal information linked (or reasonably linkable) to you that identifies your past, present, or future physical or mental health status. It is defined broadly and explicitly includes individual health conditions or diagnoses; biometric data; reproductive or sexual health information; gender-affirming care information; bodily functions, vital signs, symptoms, or measurements; and any information a company derives or infers from other data (including through an algorithm) that identifies your health status. The section "What Consumer Health Data Aureon collects, and why" below lists exactly what this covers at Aureon.
- · "Collect": gathering, deriving, receiving, buying, or otherwise obtaining Consumer Health Data, including passively (for example, reading a signal from Apple Health or Health Connect).
- · "Share" / "Sharing": disclosing, releasing, disseminating, making available, or otherwise communicating Consumer Health Data to a person or entity other than the consumer, by any means. Both statutes carve out disclosures to a company's own processors (vendors that process data solely on the company's behalf and instructions, and do not use it for their own independent purposes). Those disclosures are not "sharing" under the statutes, but we still name our processors below for transparency.
- · "Sell" / "Sale": exchanging Consumer Health Data for money or other valuable consideration with a third party.
- · "Geofence": technology that uses GPS, Wi-Fi, Bluetooth, cell-tower, or similar signals to establish a virtual boundary around a physical location.
- · "Consumer": under Washington's law, a natural person who resides in Washington, or whose Consumer Health Data is collected in Washington. Under Nevada's law, a natural person who resides in Nevada, or whose Consumer Health Data is collected in Nevada. Both statutes exclude data about a person acting in an employment or business-to-business capacity.
What Consumer Health Data Aureon collects, and why
Aureon generates and adapts training, recovery, and nutrition guidance, and that depends on understanding your physiology. Below is every category of Consumer Health Data we collect, and the specific purpose each serves.
- Wearable, smart-scale & device health data (read-only, through Apple Health on iPhone or Health Connect on Android, and only for the data types you allow). On both platforms: steps, heart rate, resting heart rate, heart-rate variability (HRV), sleep sessions and sleep stages, active calories burned, respiratory rate, blood-oxygen saturation (SpO2), body weight, body-fat percentage, lean body mass, height, VO2 max as your wearable recorded it, and the start and end times of workouts recorded on your wearable. On Android only: hydration (water intake), bone mass, body water mass, and basal metabolic rate. Used to compute Aureon's Recovery, Sleep Quality, Strain, Cardio Baseline, and Metabolic Capacity scores; to calibrate training load day to day; to show your body composition, VO2 max, and BMI on the Biometrics Progress page; to keep your profile weight current and recalculate the hydration and protein targets that depend on it; to log your water intake; and to keep the real duration of a workout you finish on your wearable.
- Clinical biomarkers & hormone panels (Apex Plus tier, from a document you choose to upload): bloodwork values and hormone-panel results extracted from lab documents you submit. Used to generate your BioAge, a biological-age estimate, and biomarker-based narrative insights.
- Declared clinical context & allergies (choices you make at intake or in Settings): clinical context you choose to declare from a fixed list (celiac, type 1 diabetes, type 2 diabetes, high blood pressure), and the food allergies you select from a list or type in. Clinical context is used only to constrain how meals are composed and to add one training technique cue. Allergies are used to keep those foods out of every meal plan and meal swap, and each finished plan is checked against them. Never used for advertising or audience building.
- Reproductive / menstrual-cycle data: biological sex, whether cycle tracking is enabled, last menstrual period start date, and average cycle length. Used for menstrual-phase-aware training and nutrition periodization.
- Injury history & biomechanical constraints (free text you enter): injuries, rehab status, and movement limitations you describe. Used to exclude contraindicated movements and scale load around an active injury.
- Progress / physique photos (camera capture you start): body-composition reference images, stored in your account. If you separately opt in to progress photo analysis (asked on the capture screen, and changeable in Settings, then Privacy controls), the photos are analyzed to write your progress reading. Without that opt-in they are stored and shown to you, and nothing else.
- Movement data from the form checker (Apex Plus tier, camera use you authorize in the camera view): while you lift, the camera image is analyzed on your device in real time so the form checker can report on your set. Camera frames are never recorded, stored, or sent to Aureon or to anyone else, and no video is saved. A compressed skeleton trace of each rep and the scores derived from it are saved on your device only and are not uploaded. Withdrawing this consent in Settings, then Privacy controls, stops the analysis and deletes that on-device data.
- AI coach conversations: the messages you send to the in-app coach and the replies it writes, which can refer to your training, recovery, and other health data. Used to answer your questions. If you turn on spoken replies, the text of each reply is also converted to audio (see the processors below).
- Aureon Scores (derived, not directly entered): BioAge, Recovery, Strain, Sleep Quality, Cardio Baseline, and Metabolic Capacity, each computed from the categories above. Used to turn raw signals into a readable picture of your performance and recovery.
- Body measurements & workout logs: height, weight, body-fat percentage, and the sets, reps, and load you log in training sessions. Used for load progression, volume tracking, and periodization.
Camera uses, in full: the app uses your camera for four things. Progress photos and form analysis are described above. Meal photos are sent to our AI processor to read their nutrient content and are then discarded; Aureon does not store them. Kitchen or pantry photos are sent to our AI processor so the ingredients on the shelf can be listed for meal planning, and are then discarded; Aureon does not store them either. Your photo library is used only for the profile portrait you choose to set.
Not health data, disclosed for completeness: Aureon also collects a city-level location (read once from your device, converted to a city name, and stored only as that city name; we never store precise GPS coordinates) to power the Arena "Local" leaderboard feature. This is ordinary location data, not Consumer Health Data. It does not reveal or reasonably indicate an attempt to obtain health care, and it is never used near, or in connection with, any health care facility (see "No geofencing of health care facilities" below).
We do not use any Consumer Health Data listed above to build advertising profiles, and we do not permit any sub-processor to use it for advertising. There is no advertising identifier of any kind (no IDFA, no Android Advertising ID) anywhere in the Services.
How we collect it: directly from you (text fields, choices you make from fixed lists, uploaded lab documents, photos you choose to capture, and messages you send to the coach); from your device's health platform (Apple Health through HealthKit, and Android Health Connect, read-only, and only for the specific data types you allow when you grant permission on your device; we never write data back); from your device's camera during a set you choose to analyze, processed on the device itself; and derived by Aureon (the Aureon Scores above are computed by our systems from the categories above, and under both statutes this derived data is itself Consumer Health Data).
Your separate consent choices: collect vs. share
Both statutes require two distinct, unbundled opt-ins: one before Aureon may collect your Consumer Health Data, and a wholly separate one before Aureon may share it with anyone outside the company. Neither consent may be bundled into a single "I agree to the Terms" checkbox, and withdrawing one does not withdraw the other.
(a) Consent to collect. Before any Consumer Health Data described above is read or processed, Aureon presents a dedicated consent step, separate from account creation and from the Terms of Service, describing what will be collected and why. Collection of a given category (for example, reproductive-cycle data, or a clinical lab upload) does not begin until you affirmatively grant that consent. You can withdraw collection consent at any time, and doing so stops future collection of that category.
(b) Consent to share. Aureon's default posture is that we do not share your Consumer Health Data with anyone outside the company. The processors described below handle data solely on our instructions, for our purposes, under contract. They are not independent recipients, so routing data to them is not "sharing" under either statute. If that ever changes (for example, if we were to integrate a genuinely independent third-party service that would receive your Consumer Health Data for its own purposes), we will not do so under any consent you have already given. We will first present a new, separate, distinctly labeled sharing consent describing exactly who would receive the data and why, and we will proceed only if you affirmatively opt in. You may decline, and you may withdraw that consent later without affecting your ability to use the rest of the Services, to the extent the shared feature is not itself the thing you are requesting.
We do not sell Consumer Health Data
Aureon does not sell Consumer Health Data, and we have no plans to. No Consumer Health Data described above is exchanged with any third party for money or other valuable consideration.
Both statutes prohibit selling Consumer Health Data without a valid, signed authorization from the consumer, a document that is legally distinct from an ordinary consent or from a terms-of-service acceptance. If Aureon's practices were ever to change and a sale were contemplated, we would first obtain an authorization that, at minimum: names the specific data to be sold and identifies both Aureon and the buyer by name and contact information; states plainly that we will not condition any product, service, or price on you signing it; states your right to revoke the authorization at any time and describes how; confirms any resale by the buyer would itself require a valid authorization or another lawful basis; and expires automatically no more than one year from the date you sign it.
Until and unless that changes, which we do not anticipate, you can treat "no sale of Consumer Health Data" as an unconditional commitment.
Who processes Consumer Health Data on our behalf
Aureon uses a small set of vendors, acting strictly as our processors (not as independent third parties), to operate the Services:
- · Supabase: our database, authentication, and file-storage provider. All Consumer Health Data that Aureon stores on its servers lives here, access-controlled to your own account.
- · Anthropic PBC (Claude): our AI processor for text and images. It generates the training sessions the app prescribes, composes nutrition plans and meal swaps, writes the in-app coach's replies, analyzes meal and kitchen photos, analyzes progress photos if you have opted in to progress photo analysis, writes protocol and progress narratives, summarizes biomarker values, extracts values from uploaded lab documents, and runs image-moderation safety checks on uploaded photos. Anthropic processes the prompt and the model response in order to return a result. Under Anthropic's commercial API terms, customer inputs and outputs are not used to train Anthropic's models by default.
- · ElevenLabs: text to speech. When you turn on spoken replies in the in-app coach chat, ElevenLabs receives the text of each coach reply and returns it as audio. It does the same for replies from the support assistant on our website when a visitor plays one aloud. It receives reply text only. It does not receive your health platform data, photos, or lab documents, though a reply can mention health information you discussed with the coach.
None of these vendors receives Consumer Health Data for their own independent purposes, none is permitted to use it for advertising, and none of this constitutes "sharing" under "Consent to share" above. We do not use any analytics or crash-reporting vendor to process Consumer Health Data. Our analytics and crash-diagnostics pipeline is deliberately kept free of health signals.
No geofencing of health care facilities
Both statutes prohibit implementing a geofence around any entity that provides in-person health care services in order to (a) identify or track consumers seeking health care, (b) collect Consumer Health Data from them, or (c) send them communications, notifications, or advertisements related to their health data or to health care services.
Aureon does not do this, in any form. Our only location functionality is a single, one-time, city-level location read used solely to group users for the Arena "Local" leaderboard feature. We do not use precise GPS, we do not persist coordinates, we do not track movement over time, we do not draw any boundary around a clinic, pharmacy, hospital, or any other health care facility, and we do not send location-triggered messages of any kind.
Your rights, and exactly how to exercise them
You have the following rights over your Consumer Health Data, regardless of where you live, though the specific statutory backing differs by jurisdiction (see "Jurisdictional notes" below):
- · Confirm whether Aureon is processing your Consumer Health Data.
- · Access the Consumer Health Data we hold about you. In practice: Settings, then Legal & Privacy, then Export my data inside the app, or contact us below.
- · Withdraw your collection consent, which stops future collection of a given category. In practice: revoke the relevant permission in your device's Apple Health or Health Connect settings (this stops that data feed immediately), use the in-app controls under Settings, then Privacy controls, or contact us below and we will process the withdrawal on our end.
- · Withdraw your sharing consent. This applies only if you have ever affirmatively opted into a sharing arrangement described above; withdrawing stops future sharing.
- · Delete your Consumer Health Data. In practice: Settings, then Danger zone, then Terminate account inside the app deletes your account's live Consumer Health Data immediately and queues full erasure (including from the processors named above), or use the Data Deletion fallback page, or contact us below.
- · Appeal a denial of any of the above.
How to submit a request. Email privacy@aureonperformance.com with the subject line "Consumer Health Data Request: Washington" or "Consumer Health Data Request: Nevada" (whichever applies to you), and tell us which right you are exercising. We will verify your identity as the account holder before acting on the request.
Response timeline. We will respond as soon as practicable, and no later than 45 days after we receive a verifiable request. If we reasonably need more time, we will notify you within that initial 45-day window and take up to an additional 45 days.
If we deny your request, we will explain why, and you may appeal by replying to our decision within a reasonable time. We will decide your appeal within 45 days of receiving it. If we uphold the denial, we will tell you how to submit a complaint to the relevant regulator:
- · Washington residents: the Washington State Attorney General's Office. Washington's My Health My Data Act carries a private right of action, so you are not required to complain to the Attorney General before pursuing other remedies available to you under the Act; consult your own counsel about your options.
- · Nevada residents: the Nevada Attorney General's Office. Nevada's law is enforced by the Attorney General and does not create a private right of action.
Jurisdictional notes
- · Who is protected: in Washington, residents and anyone whose Consumer Health Data is collected while in Washington. In Nevada, residents and anyone whose Consumer Health Data is collected while in Nevada.
- · Separate collect/share consent: required under both statutes.
- · Sale requires signed authorization: required under both statutes.
- · Geofencing health facilities: prohibited under both statutes.
- · Enforcement: in Washington, the Attorney General and a private right of action (individuals can sue). In Nevada, the Attorney General only, with no private right of action.
- · Small-business exemption: none specific to Consumer Health Data under Washington's law; Nevada has limited carve-outs (e.g., HIPAA-covered entities, GLBA-covered financial institutions) that do not apply to Aureon.
Because Aureon's product is available worldwide and does not geofence itself out of Washington or Nevada, we apply the protections in this policy uniformly rather than trying to detect where you are located.
Retention and security
We retain Consumer Health Data only for as long as your account is active, plus a limited window to complete deletion requests. When you delete your account, live data is removed immediately and full erasure, including residual encrypted backups, is finalized within 30 days (see the in-app deletion steps above and the retention detail in our general Privacy Policy). Form checker traces and scores never leave your device, and withdrawing the camera consent deletes them. Consumer Health Data is encrypted in transit, access-controlled to your own account by row-level security in our database, and never logged in raw form in our diagnostic or crash-reporting systems.
Changes to this policy
We may update this policy as our practices, or the law, change. We will post the revised version here with an updated effective date. Where a change is material (for example, a new category of Consumer Health Data, or a change to whether we share or sell it), we will seek fresh, separate consent before the change takes effect for you, not merely post a notice.
Contact us
Registered address: Aureon FitApp Inc., 350 Bay St, Suite 1300B, Toronto, Ontario
Email: privacy@aureonperformance.com (subject line: "Consumer Health Data Request: Washington" or "Consumer Health Data Request: Nevada")
This policy is separate from, and controls over, Aureon's general Privacy Policy for anything concerning Consumer Health Data as defined above.