MyTrainerOSMyTrainerOS
Features Pricing Compare
Sign In Start Free Trial
Start Free Trial

Health Data Privacy Policy

Last updated: August 17, 2026

Summary of Changes — 17 August 2026

We updated this policy on 17 August 2026 to correct how it described the storage of wearable data, and to say more clearly which laws we consider ourselves bound by.

  • Corrected. An earlier version of this policy described Apple HealthKit and Google Health Connect as "on-device only". That was misleading. Reading your metrics happens on your device, but the app then sends daily summaries to our servers, where they are stored. The new section "Where Your Wearable Data Lives" explains exactly what is sent and what is not.
  • Strengthened. Because we store health data, we now state that the Washington My Health My Data Act and comparable state health-privacy laws apply to us — rather than that they may apply.
  • Unchanged, and restated deliberately. We do not sell health data, we do not use it for advertising, and it never enters marketing or sales tooling.

Introduction

This Health Data Privacy Policy supplements our General Privacy Policy and provides additional details about how MyTrainerOS collects, uses, and protects your health and fitness data. This policy is designed to comply with the Washington My Health My Data Act (MHMDA), the California Consumer Privacy Act (CCPA/CPRA), and other applicable health data privacy regulations.

Health data is among the most sensitive information we process, and we are committed to transparency and user control over this data.

We store health data on our servers. We do not treat it as merely passing through the app. That is the single most important fact in this policy, and the rest of it follows from that fact.

Where Your Wearable Data Lives

People reasonably want a direct answer to "does it leave my phone?" Here it is.

How the data reaches us

  • Apple Health (HealthKit) and Google Health Connect. The MyTrainerOS app reads your metrics on your own device, using the permissions you granted in your phone's health settings. Apple and Google do not receive anything from us in this flow — these are system services on your device, not companies we send your data to.
  • WHOOP and Oura. If you connect one of these accounts directly, you authorize that provider to release your data to us, and we fetch it from them.
  • Terra API. A legacy aggregation layer from an earlier version of the product. It is not how health sync works today and remains only for older connections.

What we store on our servers

After reading data on your device, the app syncs daily summary metrics to our database, where they are stored for as long as this policy allows:

  • Resting heart rate
  • Heart rate variability
  • Sleep duration and time in each sleep stage (deep, REM, light, awake)
  • Daily step count
  • Body composition figures — body fat percentage, lean body mass, bone mass — if you have enabled that category, which is off by default

We also record a log of each sync — when it ran, from which source, which categories it covered, and whether it failed — so that you and we can tell whether your data is current.

What we do not store

  • Raw samples. The continuous, second-by-second or minute-by-minute readings your watch, ring, or phone records are not uploaded. We take the day's summary, not the underlying stream.
  • Calorie burn. We do not display wearable calorie-burn estimates anywhere in the product, because consumer devices estimate them unreliably. This is a deliberate product decision, not an oversight.

What this means legally

Storing health data — rather than only displaying it — puts us squarely within state consumer health-privacy laws, most importantly the Washington My Health My Data Act. MHMDA has no company-size threshold and gives individuals a private right of action. We therefore treat every daily summary we hold, and every score we calculate from one, as regulated consumer health data. Scores are health data too: a readiness score derived from your sleep and heart rate variability is as protected as the sleep and heart rate variability it came from.

Definitions

For purposes of this policy:

  • "Health Data" means personal information that identifies or is reasonably linkable to a consumer and relates to physical or mental health, including but not limited to fitness metrics, nutrition intake, body measurements, wearable device data, wellness assessments, and AI-generated health insights
  • "Consumer" means any individual whose health data is collected, processed, or shared by MyTrainerOS
  • "Consent" means a clear, affirmative act signifying freely given, specific, informed, and unambiguous agreement to the collection and processing of health data

Health Data We Collect

MyTrainerOS collects the following categories of health data, each requiring separate consent:

Workout Performance Data

  • Exercise type, sets, reps, weight, RPE (Rate of Perceived Exertion), RIR (Reps in Reserve)
  • Workout duration, rest periods, tempo prescriptions
  • Training volume, frequency, and intensity metrics
  • Exercise form analysis results (when using computer vision features)
  • Program effectiveness scores and plateau detection

Nutrition & Hydration Data

  • Food intake logs (manual and AI-assisted from photo recognition)
  • Macronutrient breakdown (protein, carbohydrates, fat)
  • Caloric intake and adaptive TDEE estimates
  • Hydration tracking
  • Dietary preferences, restrictions, and allergies

Body Composition Data

  • Body weight (daily logs and EWMA trends)
  • Body measurements (waist, hips, chest, arms, etc.)
  • Progress photos (before/after comparisons)
  • AI-estimated body composition (from progress photos)
  • Body-scan results, if your gym offers scanning (for example Fit3D)

Form-Review Video

  • Exercise videos you record and submit to your coach for form review
  • Your coach's annotations, notes, and corrections on those videos

Form-review video is reviewed by your coach — a person. It is shared with your coach and your gym for coaching purposes, and with no one else.

Wearable Device Data

Stored as daily summaries on our servers — see "Where Your Wearable Data Lives" above for exactly what is and is not sent.

  • Resting heart rate and heart rate variability (HRV, both RMSSD and SDNN)
  • Sleep duration and time in each stage — deep, REM, light, and awake
  • Daily step counts
  • Body composition from a connected scale or device — body fat percentage, lean body mass, bone mass — only if you enable this category, which is off by default
  • A log of each sync: when it ran, its source, the categories covered, and any error

Note: We intentionally do not display wearable calorie burn estimates due to research demonstrating significant inaccuracy in consumer devices.

Wellness & Recovery Data

  • Wellness check-in responses (sleep quality, energy, soreness, stress, mood)
  • Readiness scores (composite of sleep, HRV, training load, mood, recovery)
  • Injury risk assessments (monotony, strain, ACWR flags)
  • Habit completion data (streaks, consistency patterns)

AI-Generated Health Insights

  • Personalized coaching recommendations
  • Workout program suggestions and periodization plans
  • Nutrition periodization and macro recommendations
  • Churn risk and engagement predictions
  • Sentiment analysis of client communications

Purposes for Processing Health Data

We process health data exclusively for the following purposes:

  • Service Delivery: Providing personalized fitness coaching, workout recommendations, and nutrition guidance
  • Trainer Collaboration: Sharing relevant health data with your assigned trainer to enable effective coaching
  • AI Coaching: Generating AI-powered workout programs, readiness assessments, and proactive health interventions (JITAI)
  • Progress Tracking: Calculating trends, plateaus, effectiveness scores, and milestone achievements
  • Safety: Detecting injury risk factors, training overload, and providing volume warnings

Purposes We Do NOT Process Health Data For

  • Advertising or marketing targeting
  • Sale to third parties
  • Insurance underwriting or risk assessment
  • Employment decisions
  • Training general-purpose AI models
  • Any purpose not disclosed in this policy

Consent Requirements

We obtain your explicit consent before collecting or processing any health data. Our consent process includes:

Granular Consent

You may consent to individual categories of health data collection independently:

  • Workout performance data
  • Nutrition and hydration data
  • Body composition data (measurements and photos)
  • Wearable device data
  • Wellness and recovery data
  • AI-generated health insights

Withdrawing Consent

You may withdraw consent for any category at any time through Settings > Privacy & Consent. Upon withdrawal:

  • We immediately stop collecting new data in that category
  • Previously collected data is retained for 30 days unless you request immediate deletion
  • Some features may become unavailable (e.g., withdrawing wearable consent disables readiness scores)
  • Your trainer will be notified that certain data is no longer available

Third-Party Sharing of Health Data

We share health data only with the following categories of recipients, and only as necessary to provide our services:

Your Trainer

Your assigned trainer can view health data you have consented to share, including workout performance, nutrition logs, body measurements, wearable data, and wellness check-ins. Trainers are bound by our Trainer Terms of Service to maintain client confidentiality.

AI Processing Partners

  • Anthropic (Claude): Processes coaching conversations and generates program recommendations. Data is sent in real-time and not retained by Anthropic for model training
  • Deepgram: Transcribes voice recordings for workout/nutrition logging. Audio is processed and immediately discarded
  • Stripe, Inc.: Processes subscription payments and trainer payouts. Handles billing data subject to PCI-DSS compliance. Financial records subject to legal retention requirements

Wearable Data Providers

When you connect a wearable device, health data flows to MyTrainerOS by one of these routes. In every case, the daily summaries described in "Where Your Wearable Data Lives" are then stored on our servers — these routes describe how the data reaches us, not where it stops.

  • Apple HealthKit — read on your device by the MyTrainerOS app. Nothing is transmitted to Apple by us. Reading is on-device; storage of the daily summary is on our servers.
  • Google Health Connect — read on your device by the MyTrainerOS app, on the same terms.
  • WHOOP and Oura — connected directly by you through OAuth authorization, revocable at any time from your MyTrainerOS settings or from the provider. The access token that permits this is stored encrypted.
  • Terra API — a legacy aggregation layer retained only for older connections. It is not how current health sync works.

An earlier version of this policy described the first two as "on-device only". We have corrected that wording because it could be read as saying we never store your wearable data, which is not accurate.

Where Health Data Never Goes

These are prohibitions we hold ourselves to, and they are as much a part of this policy as the disclosures above:

  • Never sold, rented, leased, or traded — to anyone, for any purpose, at any price.
  • Never used for advertising — not to target ads to you, not to build audiences, not to measure ad performance.
  • Never in the marketing or sales plane — health and fitness data, and anything derived from it, is not used to build marketing lists, to segment campaigns, to score or prioritise sales leads, or to decide who receives a message from a gym. A gym cannot filter its marketing audience by your adherence, your readiness, your body composition, or any other health figure.
  • Never sent to accounting software. If your gym connects QuickBooks, only financial transaction records are sent. No health data goes with them.
  • Never used to train general-purpose AI models.

No Sale of Health Data

We do not sell, rent, lease, or trade your health data to any third party for any purpose.

Data Retention & Deletion

Health data retention periods:

  • Active accounts: Health data is retained as long as your account is active and you have not withdrawn consent
  • Account deletion: All health data is permanently deleted within 30 days of account deletion, with a 72-hour cooling-off period for cancellation
  • Consent withdrawal: Data for withdrawn categories is deleted within 30 days unless you request immediate deletion
  • Anonymized data: Aggregated, de-identified health data (not linkable to any individual) may be retained for platform improvement
  • If your gym changes its subscription plan: nothing is deleted. When a gym moves to a smaller plan, records over the new limit are deactivated and retained in full, and are restored if the gym moves back up. A plan change is never a deletion event for your health data.

Right to Delete

You may request deletion of specific health data categories or all health data at any time. Deletion requests are processed within 30 days. You will receive confirmation when deletion is complete.

Data Export

You may request a complete export of your health data in a machine-readable format (JSON) at any time through Settings > Privacy & Consent.

Geofencing

MyTrainerOS does not use geofencing technology to identify, track, collect data from, or send notifications to consumers based on their proximity to health care facilities, mental health facilities, or any location that could reveal health-related information.

Location data, when collected with your explicit consent, is used solely for optional gym check-in features and is never correlated with health data categories.

Security Measures for Health Data

We implement enhanced security measures for health data, including:

  • Encryption at rest and in transit (AES-256, TLS 1.3)
  • Row-level security (RLS) policies ensuring users can only access their own health data
  • Trainer access scoped to their assigned clients only
  • Progress photos stored in isolated, access-controlled buckets with signed URLs
  • Audit logging for all health data access and modifications
  • Regular security assessments and penetration testing
  • AI processing partners bound by data processing agreements prohibiting data retention

Your Rights

You have the following rights regarding your health data:

  • Access: Request a copy of all health data we hold about you
  • Correction: Request correction of inaccurate health data
  • Deletion: Request deletion of any or all health data
  • Export: Request your health data in a portable, machine-readable format
  • Consent Management: Grant or withdraw consent for individual data categories at any time
  • Restriction: Limit the use of sensitive health data to service delivery only

To exercise these rights, visit Settings > Privacy & Consent in the app, or contact us at privacy@mytraineros.com.

Contact Us

For questions or concerns about our health data practices, please contact our Privacy Team:

  • Email: privacy@mytraineros.com
  • Subject line: "Health Data Privacy Inquiry"

We will respond to all health data inquiries within 30 days.

MyTrainerOS

Every tool your training business needs — programs, scheduling, payments, and messaging in one app, with AI that assists your coaching and never replaces it. You keep 100% of your sales revenue.

Product

  • All Features
  • Scheduling
  • AI Coaching
  • Nutrition
  • Workouts
  • Pricing
  • Compare

Resources

  • Help Center & Support
  • Docs
  • Blog
  • About
  • Contact
  • Switching from QuickCoach?

Legal

  • Privacy Policy
  • Terms of Service
  • Health Data Privacy (MHMDA)
  • Cookie Policy
  • Data Retention
  • Do Not Sell or Share My Info

Sign in by role

  • I'm a Trainer
  • I'm a Member
  • I'm an Admin Assistant

Built for the gym floor.Runs on the front desk.

© 2026 MyTrainerOS LLC. All rights reserved.