Here is exactly what we collect, what each partner does and does not receive, and how we make money.
Your device, your signal, the match, the purchase. We hold three of them against a key with no name on it. The fourth happens somewhere else entirely.
You authorise read access through the manufacturer's own sign-in. We never see your password, and you can withdraw it at any time from their app or ours.
Sleep, heart rate, variability and activity, stored against a random key. There is no name, no email and no phone number attached to it, because we never collected one.
The engine ranks partner catalogues against that key. Partners never see the key, the signal or anything derived from it.
You buy on the merchant's own site. That order exists in their systems and in your bank, and in neither case is it connected to anything we hold.
We could not sell your health data even if we wanted to, because we never join it to a person. That is an architecture decision rather than a policy promise, which is why we will put it in writing.
The honest version, per party, rather than a paragraph about how much we value your trust.
Nothing. Not your signal, not a score, not a segment. If you buy, they get an order like any other, with no idea why you placed it.
They already hold your data. Our connection is read-only and adds nothing to what they know about you.
Your card details and your name, which they need. They never receive anything health-related.
Encrypted storage and compute in the region you selected. They hold ciphertext, and hold no keys.
For the people who want more than a reassurance.
TLS 1.3 everywhere, AES-256 at rest, with keys managed separately from the data they protect and rotated on a schedule.
Your data sits in the region set in the footer. It is not replicated across regions for convenience.
No password to reset, no account to take over, no support agent who can look you up by name. If you lose the key we cannot recover it, which is the trade.
Access to production data is scoped, logged and reviewed. No individual has standing access to the whole store.
Delete a source, a set of matches or everything. It goes immediately, including from backups on their normal cycle, and we keep no shadow copy.
Most health apps are free because you are the product. This one is not free, on purpose.
Your annual fee is the whole of what we make from you. There is no commission on what you buy and no advertising anywhere on the product.
We do not sell, rent, license or share your health data with anyone, in any form, aggregated or otherwise. There is no version of our plan where that changes.
Our commercial customers license the recommendation engine and run it against their own customers' consented data. They never receive yours.
Export your full record from the app or with your key. Machine-readable, no request form.
A source, a set of matches, or everything. Immediate, and irreversible by design.
Revoke read access from your device's own app or from ours. The feed stops the same day.
Our data protection contact answers within five working days, and sooner if it is urgent.
The pages above are the plain-English version. These are the ones that bind us.
What we collect, why, on what legal basis, and for how long. Written for the region you have selected.
Read →What runs on the site. We do not use advertising or cross-site tracking cookies.
Read →What you get, what we owe you, and what happens if either of us stops.
Read →The architecture note, in the detail a security reviewer would want.
Read →See habits, meals and products matched to your own data.