METRIQ BODY← Home

Legal

Privacy Policy

Effective July 24, 2026 · Last updated July 26, 2026

The short version: we collect what the engine needs to build your protocol, we don't sell it, and you can delete it. This page explains the detail without hiding it.

If you are a Washington, Nevada, or Connecticut resident, additional protections apply to your health data — see our Consumer Health Data Privacy Policy.

1. Who we are

Metriq Body (“Metriq Body,” “we,” “us”) operates https://metriqbody.com, a fitness and nutrition coaching application. You can reach us about anything in this policy at omar@homeheroiq.com.

We are not a healthcare provider, health plan, or healthcare clearinghouse, and we are not a HIPAA covered entity. The information you give us is not protected health information under HIPAA. It is still treated as sensitive and protected under the state consumer health data laws described in this policy.

2. What we collect

Information you give us directly:

  • Assessment inputs — sex, age, height, weight, estimated body fat, goal and target weight, training experience and availability, equipment, dietary pattern and food exclusions, sleep and stress self-reports, injury areas you ask us to train around, and whether you are taking a physician-prescribed GLP-1 medication.
  • Account information — your email address and a securely hashed password. We never store your password in readable form.
  • Your logs — calories and protein you record, sets, weights and reps you log, completed sessions, weekly check-ins (weight, energy, strength trend), and the streak and score derived from them.

Information from devices you connect:

  • Wearable data — if and only if you connect a device (for example Oura or WHOOP), we read sleep duration and score, readiness or recovery score, heart-rate variability, resting heart rate, respiratory rate, steps, active energy, strain, and workout duration. Access is read-only. We never write to your device and we do not access anything outside these categories.

Information collected automatically:

  • Local storage — your protocol and logs are kept in your browser so the app works before you create an account and continues to work offline.
  • Session cookie — a single signed, HTTP-only cookie that keeps you logged in. We do not use advertising cookies or third-party trackers.
  • Server logs — our host records standard request data, including IP address, for security and abuse prevention.
  • Aggregate analytics — we use Vercel Web Analytics to count page views and see which pages people visit. It is cookieless, does not follow you across other websites, and is never given your health data, your protocol, or your logs.
We do not collect payment card numbers. If you subscribe, Stripe collects and processes your card details directly; we receive only a customer identifier and your subscription status.

3. Why we use it

  • To compute your protocol — calorie and macronutrient targets, meal plans, training splits, and weekly adaptations. This is the core purpose and it cannot be done without your assessment inputs.
  • To show you your own history, progress, and score.
  • To make recommendations more accurate — connected wearable data replaces estimates with measurements, for example setting your calorie target from measured energy burn instead of a self-reported activity level.
  • To operate your account — sign-in, email verification, password reset.
  • To process subscriptions, when you purchase one.
  • To keep the service secure — rate limiting, abuse prevention, and debugging.
  • To contact you about your account, your results, and (if you opted in at the assessment) occasional coaching emails you can unsubscribe from at any time.

4. We do not sell your data

We do not sell your personal information or your health data. We do not share it for cross-context behavioural advertising. We do not use your health data to target ads to you, and we do not permit our service providers to use it for their own purposes.

5. Who processes your data for us

We use a small number of service providers, each contractually limited to processing data on our instructions:

ProviderPurposeLocation
VercelWebsite and application hostingUnited States
Vercel Web AnalyticsAggregate page-view and traffic analytics. Cookieless — no cross-site tracking and no health data.United States
NeonDatabase hosting (your account and logs)United States
StripePayment processing and subscription billingUnited States
ResendTransactional email (verification, password reset)United States
Oura HealthWearable data, only if you connect itFinland / United States
WHOOPWearable data, only if you connect itUnited States

We may also disclose information if legally required to, or to protect the rights and safety of our users or the public. If we are ever involved in a merger or acquisition, we will notify you before your information becomes subject to a different privacy policy.

6. How long we keep it

  • Account and protocol data: for as long as your account is open, and deleted when you delete your account.
  • Wearable data: retained while the connection is active. Disconnecting stops new data immediately; you can ask us to delete what was already collected.
  • Marketing emails captured at the assessment: retained until you unsubscribe or request deletion.
  • Billing records: retained as long as required by tax and accounting law, typically seven years.
  • Server and security logs: typically 30 days.

7. Your rights

Wherever you live, you can ask us to do the following, and we will respond within 45 days:

  • Access — get a copy of the data we hold about you.
  • Correct — fix anything inaccurate. Most of your profile is editable in the app.
  • Delete — remove your account and associated data.
  • Export — receive your data in a portable format.
  • Withdraw consent — disconnect a wearable or unsubscribe from email at any time.
  • Opt out — of sale or targeted advertising. We do neither, so there is nothing to opt out of, but the right stands.

To exercise any of these, email omar@homeheroiq.com. We will not discriminate against you for exercising them. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

8. Security

Passwords are hashed with bcrypt. Sessions use signed, HTTP-only cookies. Wearable access tokens are stored server-side and are never exposed to your browser. Our database is not reachable from the public internet, and all traffic is encrypted in transit.

No system is perfectly secure. If a breach affects your data, we will notify you and the appropriate regulators as required by law, including the FTC Health Breach Notification Rule where it applies.

9. Children

Metriq Body is for adults aged 18 and over. We do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it. If you believe a minor has provided us information, contact us and we will remove it.

10. International users

We operate in the United States and your data is processed there. If you access the service from outside the US, you are transferring data to the US, which may have different data-protection laws than your country.

11. Changes

If we make a material change to this policy, we will update the date at the top and notify account holders by email before it takes effect. Continuing to use the service after a change means you accept the updated policy.