METRIQ BODY← Home

Legal

Consumer Health Data Privacy Policy

Effective July 24, 2026 · Last updated July 26, 2026

This policy is separate from our general Privacy Policy and applies specifically to consumer health data. It exists to satisfy Washington's My Health My Data Act (MHMDA), Nevada SB 370, and the consumer health data provisions of Connecticut's privacy law.

We apply these protections to every user, not only residents of those states.

1. What counts as consumer health data here

These laws define consumer health data broadly — any personal information that identifies your past, present, or future physical or mental health status. In our service, that includes:

  • Your body measurements and composition — weight, height, estimated body fat, target weight.
  • Bodily functions and vital signs from a connected wearable — sleep, heart-rate variability, resting heart rate, respiratory rate, readiness or recovery scores.
  • Physical activity and exercise data — workouts, sets, weights, reps, steps, active energy.
  • Nutrition and dietary data — calorie and protein intake, dietary pattern, food exclusions including allergies.
  • Injury or physical limitation areas you tell us to program around.
  • Whether you are using a physician-prescribed GLP-1 medication.
  • Self-reported sleep and stress levels.
We collect this information for one purpose: to compute and adapt your fitness and nutrition protocol. We do not use it for advertising, profiling unrelated to your plan, or any purpose you did not ask for.

2. How we collect it, and your consent

We collect consumer health data only from you, and only when you actively provide it:

  • By completing the assessment — each answer is given knowingly and is optional in the sense that you may stop at any time.
  • By logging your own nutrition, training, and check-ins inside the app.
  • By connecting a wearable device, which requires you to complete a separate authorization on that provider's own website and grants read-only access.

We do not buy health data, we do not obtain it from data brokers, and we do not infer it from your browsing behaviour. We do not use geofencing of any kind, and specifically do not operate any geofence around healthcare facilities.

We treat your use of the assessment and the app as your affirmative, opt-in consent to collect the health data described above for the purpose of building your protocol. You can withdraw that consent at any time — see section 5.

3. Who we share it with

We share consumer health data only with the service providers that make the product function, and only to the extent they need it:

RecipientCategory of dataWhy
NeonAll stored health dataDatabase hosting
VercelData in transitApplication hosting
ResendEmail address, headline targetsSending your results and account email
Oura / WHOOPBiometrics you authorizeSource of the data, only if connected

A current list of all our processors is in the Privacy Policy. On request we will give you a specific list of every affiliate, contractor, and third party that has received your consumer health data, along with contact details for each.

4. We never sell consumer health data

We do not sell your consumer health data, and we will not. Under MHMDA, selling health data requires a separate signed authorization from you — we do not seek one, because selling health data is not part of our business model and never will be. If that ever changed, it would require your explicit, separate, signed consent, which you would be free to refuse.

We also do not share consumer health data with advertising networks, analytics platforms that build cross-site profiles, or any party that would use it for its own purposes.

5. Your rights over health data

You have the right to:

  • Confirm and access — find out whether we hold consumer health data about you and get a copy of it.
  • Know the recipients — receive a list of every third party we have shared your consumer health data with, including how to contact them.
  • Withdraw consent — revoke your consent to our collection and sharing of your health data. Disconnecting a wearable in the app takes effect immediately.
  • Delete — have your consumer health data deleted. When you exercise this right we delete it from our live systems and instruct our processors to do the same, including from backups on their normal cycles.

To exercise any of these rights, email omar@homeheroiq.com with the subject line “Health Data Request.” We will verify your identity by confirming control of the email address on the account, and respond within 45 days. We will not charge you, and we will not discriminate against you for asking.

If we deny a request, you may appeal by replying to our decision. If we deny the appeal, you may complain to the Washington State Attorney General or your own state's attorney general.

6. How long we keep health data

We keep consumer health data for as long as your account is active, because your history is the product — progression, streaks, and adaptation all depend on it. When you delete your account or withdraw consent, we delete the associated health data. Disconnecting a wearable immediately stops collection of new data from that device.

7. Security of health data

Consumer health data is stored in an access-controlled database that is not reachable from the public internet, encrypted in transit, and accessible in our systems only through authenticated requests tied to your own account. Wearable access tokens are held server-side only.

8. Contact

Metriq Body is the entity responsible for the consumer health data described here. Questions, requests, or complaints: omar@homeheroiq.com.

Processor list current as of July 26, 2026: Vercel, Vercel Web Analytics, Neon, Stripe, Resend, Oura Health, WHOOP.