Privacy Policy
How we collect, protect, and handle your health data with transparency and care.
Vitality Wellness LLC ("Company," "we," "us," or "our"), a Wyoming limited liability company, operates the POWR mobile application, website (powrhealth.com), and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use the Service.
We are committed to protecting your privacy and handling your data—particularly your sensitive health and wellness data—with the utmost care and transparency. Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described herein.
If you live in Washington, Nevada, or another state with a consumer health data law, our Consumer Health Data Privacy Policy also applies to you. It summarizes the health data we collect, why, who receives it, and how to exercise your rights.
If you do not agree with this Privacy Policy, please do not use the Service.
1. Information We Collect
We collect information in three categories: information you provide directly, information collected automatically, and information from third-party sources.
1.1 Information You Provide Directly
Account Information
When you create an account, we collect:
- Email address
- Phone number (if provided for verification)
- Name (first and last)
- Username
- Profile photo (optional)
Health and Fitness Data
When you use the Service's health and wellness features, you may provide:
- Nutrition data: Food entries, meal descriptions, calorie intake, macronutrients (carbohydrates, protein, fat), micronutrients (fiber, sugar, sodium, cholesterol, vitamins, minerals), serving sizes, brand names, meal categories, dietary preferences (vegan, vegetarian, gluten-free, etc.), food allergens, ingredient information, and food scores
- Activity and recording data: Workouts and activity sessions (including type, duration, distance, pace, sets, reps, and load), sleep records, step counts, active and resting energy, heart rate, and other workout metrics—whether logged manually, captured by the Service's recording features, imported from Apple HealthKit, or read from a wearable device or health platform you connect
- Daily planning data: Planned activities, scheduled meals, reminders, and other entries you create in the Service's daily planning surface
- Supplements and intake records: Supplements logged, dosages, timing, and associated notes
- Physical measurements: Height, weight, date of birth, biological sex, target weight, weekly weight change rate, and related body measurements
- Weight history: Weight measurements over time, associated notes
- Progress photos: Photographs you upload to track physical progress
- Goals and preferences: Nutrition goals, activity goals, and current health objectives
AI Chat Conversations
When you use the in-app AI health companion, we collect and store:
- The text messages you send to the AI companion
- The AI-generated responses returned to you
- Conversation timestamps and the context (such as recent nutrition or activity entries) that was attached to each request to help the AI answer accurately
Conversation history is persisted against your account so you can refer back to it across sessions and devices. The AI chat is text-only; the Service does not record, transmit, or store voice or other audio data for the AI companion. You can delete individual conversations or your entire chat history through the Service at any time.
Communications
- Support requests, feedback, and correspondence you send to us
- Referral codes and referral participation
1.2 Information Collected Automatically
When you use the Service, we automatically collect:
Device Information
- Device type, model, and operating system version
- Device identifier and device fingerprint
- Application version
- Platform (iOS, Android, or web)
Usage and Performance Data
- Features accessed and actions taken within the Service
- Session timestamps and duration
- Error and crash reports
- Performance metrics
Network Information
- Internet Protocol (IP) address
- General geographic location (derived from IP address, not precise GPS)
Location Data
- Precise location is collected only while you are recording a distance activity in POWR (for example a run, walk, ride, or hike), and only if you grant the iOS location permission. The route it produces is stored with that session and, where you authorize HealthKit writes, written back to HealthKit.
- POWR does not collect location outside an active recording session, and does not use location for advertising or profiling.
- Where you authorize it, POWR also reads workout GPS routes that other apps wrote to Apple HealthKit, as described under Apple HealthKit below.
- General geographic location may be derived from your IP address as noted above.
1.3 Information from Third-Party Sources
Apple HealthKit
With your explicit authorization through the iOS Health permission prompt, POWR reads from and writes to Apple HealthKit. We access only the categories you authorize. An authorization you do not grant is skipped, not requested again mid-use.
Read from HealthKit (when authorized):
- Workouts and workout events, and workout GPS routes (including activity type, duration, distance, energy burned, and swim laps and stroke counts where available)
- Heart: heart rate, resting heart rate, heart rate variability, heart rate recovery, beat-to-beat intervals, and electrocardiogram samples
- Movement and activity: step count; walking, running and cycling distance; active energy; flights climbed; exercise minutes; stand hours and stand minutes
- Running form: running power, ground contact time, vertical oscillation, stride length, and running speed
- Sleep analysis
- Body measurements: body mass (weight), body fat percentage, and lean body mass
- Breathing and temperature: respiratory rate, blood oxygen saturation, body and basal body temperature, sleeping wrist temperature, sleeping breathing disturbances, six-minute walk distance, and VO₂ max
- Water intake recorded outside POWR
- Mental wellbeing: Apple State of Mind entries and mindful minutes. POWR does not read scored clinical assessments such as PHQ-9 or GAD-7.
- Cycle: menstrual flow and cycle-related symptom categories
- Clinical records from Apple Health Records, where you have linked a healthcare provider inside Apple's Health app: laboratory results, medications, conditions, allergies, and immunizations
Some of these categories are read on your device only and are never transmitted to POWR's servers. That includes running form measurements, beat-to-beat intervals, electrocardiogram samples, and sleeping breathing disturbances, which power on-device displays and are not uploaded.
Write to HealthKit (when authorized):
- Workouts you record in POWR, together with the workout route and heart rate samples that session captured
- Nutrition from meals you log in POWR, across calories, macronutrients, vitamins, and minerals
- Water you log in POWR
- Weight you log in POWR
If you discard a workout you have just recorded, POWR deletes the corresponding HealthKit sample it created for that session. POWR does not delete HealthKit data written by any other app.
HealthKit data is read on-device through Apple's HealthKit framework. You can revoke or change POWR's HealthKit permissions at any time in iOS Settings > Privacy & Security > Health > POWR, or disconnect the integration from within the Service. Revoking access stops further reads and writes; data already imported into POWR remains in your POWR account until you delete it.
Connected Devices and Services
POWR can read your data from a wearable device or health platform you connect yourself. Connecting one is optional, is never a condition of using the Service, and always begins with you signing in at that provider and approving the request on their own screen — POWR never receives, asks for, or stores your password for any of them.
The providers POWR can connect to are WHOOP, Polar, and Wahoo.
What each provider can send. POWR requests read-only access, and requests only the categories listed below. It never requests permission to write to, modify, or delete anything in your provider account.
- WHOOP: sleep and sleep stages, recovery, heart rate variability, resting heart rate, strain, respiratory rate, blood oxygen saturation, skin temperature, and workouts
- Polar: sleep, nightly recharge, heart rate variability, resting heart rate, continuous heart rate, respiratory rate, step count, active energy, and training sessions
- Wahoo: rides and workouts only.
How and when data arrives. Once you connect a provider, POWR reads from it in the background, including while the app is closed. WHOOP notifies POWR's servers when new data is ready; for every provider, POWR also re-checks on a schedule of roughly six hours so that nothing is lost if a notification goes missing. Connecting also imports the history already in your provider account rather than only what is recorded from that moment onward, usually around the last two weeks. Disconnecting stops all of this.
What we do with it. Data from a connected provider is used for the same purposes as data you enter yourself: to display your history and trends, to calculate your wellness and readiness figures, and — only if you have turned AI features on — to inform the personalized insights described in Section 2. It is held in your account under the protections described in Section 3, and the credentials for the connection itself are encrypted at rest.
AI and your connected devices. Data from WHOOP, Polar, Wahoo, or Apple Health reaches an AI model only with your permission. Our in-app coach and POWR's other AI features, which run on Anthropic's and Google's AI services (see Section 4.2), use it only after you turn AI features on. An AI assistant you connect yourself, such as ChatGPT or Grok, can read data from Polar or Apple Health only for the categories you approved on POWR's consent screen (see Section 4.3). Data POWR receives from WHOOP or Wahoo is never sent to an AI assistant you connect, because their terms do not allow it. If you do neither, this data is not sent to any AI model.
What we never do with it. We do not sell it. We do not use it for advertising, for advertising profiles, or for any credit or insurance purpose. We do not use it to train any AI model, and we contractually require our in-app AI providers, Anthropic and Google, not to use it to train their models. We do not transfer it to any party except the service providers listed in Section 4 who process it on our behalf under contract, and an AI assistant you connect and approve yourself (Section 4.3). We share it only as far as is needed to run the Service, to answer that assistant's requests, or as the law requires. No human at POWR reads it except where you have asked for support and given permission, or where the law compels us.
What we store about the connection. To keep a connection working, POWR stores the access and refresh credentials the provider issues, encrypted at rest and never exposed through the app, together with when the access credential expires, which categories you approved, the identifier the provider uses for your account there, and when POWR last read from it. POWR never receives or stores your password for any provider.
Turning a connection off. You can disconnect any provider at any time from within the Service, and independently from your account settings at the provider. Disconnecting deletes the access credential POWR holds for that provider and stops all further reads immediately. Data already imported into POWR remains in your POWR account until you delete it, either by deleting the individual records or by deleting your account — see Your Rights & Choices and Data Retention. Deleting your POWR account removes the imported data along with everything else; it does not delete anything from the provider's own service.
Laboratory Documents and Biomarkers
POWR lets you add laboratory results in three ways: by uploading a document (a PDF or an image of a printed panel), by importing results you have linked through Apple Health Records, or by entering a single marker by hand.
Uploaded documents. To transcribe an uploaded document, POWR transmits that document to our third-party AI provider in the form you supplied it. The document is not redacted before transmission. If your laboratory report displays identifying information — for example your name, date of birth, medical record number, address, or ordering physician — that information is transmitted with the document. Uploading a document for transcription requires you to enable AI features, which are off until you turn them on.
What we retain. The patient name appearing on a report is not stored in your POWR account; there is no field for it. Biomarker values and the name of the laboratory that produced them are encrypted at rest. The local copy of the document on your device is deleted once the upload completes. Uploaded documents are stored in encrypted cloud storage and are removed when you delete your account.
What we do not do. POWR does not diagnose any condition, does not provide a clinical interpretation of a result, and does not supply its own reference ranges. Reference ranges shown in the Service are the ranges printed on your own report.
1.4 When You Connect an AI Assistant
If you connect an AI assistant to POWR (see Section 4.3), we collect:
- A connection record: which assistant you connected (ChatGPT or Grok), the categories you currently allow, when you first approved it, and when you disconnected it.
- Connection credentials: the access and refresh credentials we issue to the assistant, stored only in hashed form, with their expiry times. An access credential lasts one hour. A refresh credential lasts 30 days.
- A log of each request: the time, the tool the assistant asked for (for example, sleep or food log), whether it succeeded, and a coded account identifier rather than your name or email.
- Standard web request data: the IP address and client software of whoever sent the request. For the consent screen, that is your browser. For data requests, it is usually the assistant's servers.
We do not receive your conversation with the assistant. The assistant sends us only the request it needs answered, such as a date range or an exercise name.
2. How We Use Your Information
2.1 Providing and Operating the Service
- Creating and managing your account
- Processing, storing, and displaying your Health Data
- Calculating food scores and nutrition insights
- Enabling nutrition tracking and goal management
- Displaying your progress, trends, and historical data
- Storing and managing progress photos
- Processing subscription entitlements
- Answering requests from an AI assistant you have connected, for the categories you approved (Section 4.3)
2.2 AI-Powered Features
- Analyzing food photographs to identify foods and estimate nutritional content
- Processing text-based food descriptions for nutritional analysis
- Transcribing a laboratory document you upload — a PDF or an image of a printed panel — into biomarker values you review before anything saves
- Generating personalized health insights and recommendations
- Powering the in-app AI health companion, a text-based chat experience that lets you ask questions about your own logged nutrition, activity, and recording data
- Storing your AI chat conversations against your account so you can refer back to prior responses across sessions and devices
- Calibrating your personalized wellness scores
- Providing ingredient analysis and explanations
For each AI request, we transmit only the message or input you provide together with a minimal, request-scoped context window drawn from your data (for example, the relevant recent meals or activity entries needed to answer your question). Your full health profile is not sent. The AI chat is text-only; the Service does not capture, transmit, or store voice or other audio data for the AI companion.
Document transcription is the one exception to that context window. A laboratory document you upload is transmitted whole and unredacted, so any identifying information printed on it goes with it. See Laboratory Documents and Biomarkers in Section 1.3.
We do not use your messages, conversations, photographs, or Health Data to train third-party AI models, and we contractually require our in-app AI providers, Anthropic and Google, not to use your data for their own model training. We do not collect, use, or sell personal data to train large language models. AI assistants you connect follow their providers' own policies (Section 4.3).
Everything in this Section 2.2 describes POWR's own AI features. An AI assistant you connect yourself, such as ChatGPT or Grok, is different: its provider decides how it keeps and uses what it receives. See Section 4.3.
Data Minimization for AI: When processing your data through AI features, we employ data minimization practices. Only the specific information necessary for the AI analysis is transmitted to our AI service providers—your full health profile is not sent. A laboratory document you upload for transcription is the exception: it is transmitted in the form you supplied it, without redaction.
2.3 Personalization
- Tailoring insights and recommendations to your individual health profile
- Customizing the Service experience based on your goals and preferences
- Adapting nutrition recommendations based on your goals and preferences
2.4 Service Improvement and Analytics
- Analyzing aggregated, de-identified usage patterns to improve the Service
- Identifying and fixing technical issues, bugs, and errors
- Developing new features and functionality
2.5 Communication
- Sending transactional emails (account verification, password resets)
- Delivering important Service updates and announcements
- Responding to your support inquiries and feedback
2.6 Security and Integrity
- Authenticating users and preventing unauthorized access
- Detecting and preventing fraud, abuse, and security threats
- Enforcing rate limits and usage policies to maintain service quality
- Maintaining audit logs for security and compliance purposes
2.7 Legal Compliance
- Complying with applicable laws, regulations, and legal obligations
- Responding to lawful requests from government authorities
- Establishing, exercising, or defending legal claims
3. How We Protect Your Information
We implement comprehensive technical and organizational security measures to protect your personal information, with particular emphasis on safeguarding your sensitive Health Data.
3.1 Encryption at Rest
Sensitive Health Data is encrypted at rest using AES-256-GCM (Advanced Encryption Standard with 256-bit keys in Galois/Counter Mode), an industry-leading encryption standard. The following categories of data are encrypted in our database:
- Nutrition data (detailed macronutrient and micronutrient information)
- Food ingredients and allergen information
- Food scores and analysis data
- Activity and recording data (workouts, sleep, supplements, and related metrics)
- Daily planning entries
- Weight measurements and notes
- Nutrition and activity goals
- AI chat conversations (your messages, the AI's responses, and the request-scoped context attached to each message)
- Access and refresh credentials for any wearable device or health platform you connect
3.2 Encryption in Transit
All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security) / HTTPS protocols.
3.3 Authentication and Access Control
- Industry-standard JWT (JSON Web Token) authentication
- Role-based access controls limiting data access to authorized personnel and systems
- User-scoped data access ensuring you can only access your own data
- Multi-factor authentication support via email and phone verification
3.4 Abuse Prevention
- Multi-layered rate limiting (IP-based, user-based, and device-based) to prevent abuse
- Device trust scoring to detect and prevent suspicious activity
- Automated abuse detection and response
3.5 Audit Logging
- Comprehensive audit trails recording access to and modifications of Health Data
- Encryption failure monitoring and logging
- Separate audit logging for AI-related data processing
- Audit logs are maintained for security and compliance purposes
3.6 Infrastructure Security
- Database hosted on secure cloud infrastructure with network-level protections
- Application-level input validation and parameterized database queries to prevent injection attacks
- Cross-Origin Resource Sharing (CORS) restrictions
- Connection timeout and resource management controls
3.7 Security Limitations
Despite our robust security measures, no method of electronic storage or transmission over the Internet is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. We encourage you to use strong, unique passwords and to keep your account credentials confidential.
4. Data Sharing and Disclosure
4.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information or Health Data to third parties for their marketing or commercial purposes.
4.2 Third-Party Service Providers
We share limited data with the following categories of service providers, solely as necessary to operate the Service. We also send data to an AI assistant you choose to connect, such as ChatGPT (OpenAI) or Grok (xAI). Those companies are not our service providers; see Section 4.3.
Authentication, Storage, and Product Analytics
Firebase (Google): Processes authentication data (email, phone number, account identifiers) for user authentication and account management, provides cloud storage for user-uploaded files such as progress photos, and may receive limited product analytics data such as app interactions, device/app metadata, and diagnostics when analytics is enabled in the active app configuration.
AI Processing
Anthropic (Claude): Receives most of the inputs needed to power POWR's AI features, including food images, food descriptions, laboratory documents you upload for transcription, progress photos you send for a physique reading, the text messages you send to the AI health companion, and limited request-scoped health context (such as the relevant recent nutrition or activity entries, body measurements, and recovery, sleep, heart rate variability, resting heart rate, and strain values, including values imported from wearables you connect, needed to answer a chat message or to prepare your briefings, recaps, and guidance). The AI chat is text-only, so no voice or audio data is sent to Anthropic. We apply data minimization practices, transmitting only the specific data necessary for each AI request, and your full health profile is never sent to Anthropic. An uploaded laboratory document is the one input that is not minimized: it is transmitted whole and unredacted, including any identifying information the report prints. Your inputs and conversations are not used to train Anthropic's models or any third-party AI models.
Google AI services (Gemini, through Vertex AI): Receive the inputs for the AI features that Google runs: voice recordings of meals you log by speaking, the readings a health category page summarizes in one line (for example heart rate variability and resting heart rate, or, on the cycle page, your cycle phase with related sleep and recovery readings), and, when the AI health companion's memory is on, short excerpts of what you have told it, so it can recall relevant details later. We apply the same data minimization practices, and your full health profile is never sent to Google. Your inputs and conversations are not used to train Google's foundation models or any third-party AI models.
Subscription and Payment Management
RevenueCat: Receives subscription-related data (customer identifiers, purchase events, subscription status, platform information) for managing premium subscriptions. RevenueCat does not receive any Health Data.
Email Services
Resend: Receives email addresses and verification codes for transactional email delivery (account verification). Resend does not receive Health Data.
Website Services (powrhealth.com only)
- Vercel: Hosts our website and may process IP addresses and standard web request logs. We also use Vercel Web Analytics on the website to collect aggregated, privacy-friendly page-view metrics. Vercel Web Analytics does not use cookies or persistent identifiers and does not collect Health Data.
- Plausible Analytics: Collects aggregated, cookieless page-view and navigation metrics (such as the page visited, referrer, and approximate country derived from IP address, which Plausible does not store). Plausible does not use cookies or persistent identifiers and does not collect Health Data.
- Orynth and ScrollLaunch: Serve the product-listing badge images shown in the website footer. Loading a badge sends a standard web request (including your IP address and browser user agent) to the badge provider.
Connected Devices and Services
A provider you connect — WHOOP, Polar, or Wahoo — is a source POWR reads FROM, not a recipient POWR sends to. POWR requests read-only access and does not write your POWR data back to any of them. The only information that travels outward is the request itself: the authorization POWR holds for your account, and the date range being read. Your POWR nutrition, chat, photographs, laboratory results, and manually logged entries are never transmitted to a wearable provider. See Connected Devices and Services in Section 1.3 for what each provider can send us and how to disconnect.
4.3 AI Assistants You Connect
You can connect POWR to a third-party AI assistant. Today that means ChatGPT, run by OpenAI, and Grok, run by xAI. These companies are not our service providers. They are independent companies, and they do not process your data on our behalf.
Nothing is shared until you approve it. You start the connection from the assistant. You then sign in to POWR and approve the connection on POWR's own consent screen. There you choose which categories the assistant may read: recovery and sleep, training and workouts, food log and nutrition, body metrics, and your plan. Connecting requires Powr Pro. It is a separate choice from the AI switch for POWR's in-app features.
What the assistant can read. The assistant can only read. It cannot add, change, or delete anything in POWR. We send it data only when it makes a request, and only from the categories you approved. Each answer holds only what that request asked for. The assistant can also see which devices you have connected and whether you have Powr Pro. It never receives your cycle data, lab results, clinical records, progress photos, or your chats with the in-app coach. Data POWR receives from WHOOP or Wahoo is never sent to an AI assistant you connect, because their terms do not allow it.
What happens to your data there. Once the assistant receives your data, its provider handles it under its own terms and privacy policy, not this one. That includes how long it keeps your conversations and whether it uses them to train its models. We cannot control either. Read the OpenAI privacy policy and the xAI privacy policy, and check the data settings in each assistant. To ask OpenAI about your data, use privacy.openai.com or email dsar@openai.com.
Turning it off or narrowing it. You can disconnect an assistant at any time in the POWR app under Settings > Health connections > Connected agents. Disconnecting takes effect immediately: the assistant cannot read anything more. To narrow what an assistant may read, connect it again and uncheck the categories you no longer want to share. Your latest choice replaces the earlier one. Disconnecting does not delete data the assistant already received. To delete that, use the assistant's own controls.
Section 1.4 lists what we record about a connection. Section 6.5 says how long we keep it.
4.4 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation;
- Protect and defend the rights or property of the Company;
- Prevent or investigate possible wrongdoing in connection with the Service;
- Protect the personal safety of users of the Service or the public;
- Protect against legal liability.
4.5 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred to the acquiring entity. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
4.6 With Your Consent
We may share your information with third parties when you have given us your explicit consent to do so, including an AI assistant you connect (Section 4.3).
4.7 Aggregated and De-Identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you for research, analytics, business intelligence, or other purposes.
5. Your Rights and Choices
5.1 Access Your Data
You have the right to access the personal information we hold about you. You can view most of your data directly through the Service. For a more comprehensive data access request, contact us at legal@powrhealth.com.
5.2 Correct Your Data
You can update or correct your account information and Health Data directly through the Service at any time.
5.3 Delete Your Data
You have the right to request deletion of your personal data. You can:
- Use the in-app account deletion feature—this initiates deletion of your account and associated data from our active systems, including:
- Your account and profile information
- All Health Data (nutrition logs, activity and recording data, workouts, sleep, supplements, weight entries, food scores, and daily planning entries)
- AI chat conversations and associated history
- Progress photos and uploaded files
- Connections to wearable devices and health platforms, including the stored credentials
- Connections to AI assistants such as ChatGPT or Grok, including the connection record and its hashed credentials
- Subscription records and device information
- Associated rate limiting records
- Contact us at legal@powrhealth.com to request account and data deletion.
When account deletion is requested, we immediately begin the deletion workflow and block further access to the account. Deletion from our active systems completes after required processor cleanup steps finish. Copies in backups are deleted as those backups expire; Section 6.5 gives the periods. Audit log entries and limited operational records that do not contain your Health Data may be retained for compliance, security, or dispute-resolution purposes.
5.4 Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. Contact us at legal@powrhealth.com to request a data export. Export availability may vary by data category, and certain operational, security, billing, or backup records may be excluded or provided separately where permitted by law.
5.5 Withdraw Consent
Where we rely on your consent to process personal information, you have the right to withdraw that consent at any time. This includes:
- Disconnecting third-party health services through the Service settings;
- Disconnecting an AI assistant in the POWR app under Settings > Health connections > Connected agents, or reconnecting it with fewer categories (Section 4.3);
- Revoking permissions for health data access on your device;
- Contacting us to withdraw consent for specific processing activities.
Withdrawal of consent does not affect the lawfulness of processing conducted prior to the withdrawal.
5.6 Opt Out of Communications
You may opt out of non-essential communications by:
- Following the unsubscribe instructions in any marketing email;
- Adjusting your notification preferences in the Service settings;
- Contacting us at legal@powrhealth.com.
Note that you may not opt out of transactional communications necessary for the operation of the Service (e.g., account verification, security alerts).
5.7 Manage Device Permissions
You can control the Service's access to device features (camera, photo library, health data, notifications) through your device's operating system settings at any time.
6. Data Retention
6.1 Active Account
We retain your personal information and Health Data for as long as your account is active and as needed to provide you with the Service.
6.2 After Account Deletion
Upon account deletion:
- Access to the account is blocked while deletion is in progress;
- Personal information and Health Data are removed from our active database systems once the deletion workflow completes;
- Uploaded files (such as progress photos) are removed from cloud storage as part of the deletion workflow;
- Authentication records are removed from our authentication provider as part of the deletion workflow;
- Connections to wearable devices and health platforms are deleted together with the credentials POWR stored for them, which stops all further reads;
- Connections to AI assistants are deleted together with their hashed credentials;
- Copies in backups are deleted as those backups expire, as described in Section 6.5;
- Audit log entries and limited operational records (without Health Data content) may be retained for compliance, security, and dispute-resolution purposes.
6.3 Subscription Records
Subscription event records may be retained for financial reporting and dispute resolution purposes in accordance with applicable legal requirements.
6.4 Aggregated Data
Aggregated, de-identified data that cannot be used to identify you may be retained indefinitely for analytical and research purposes.
6.5 Retention Periods
- Your account data and Health Data: kept while your account exists, until you delete the record or your account.
- AI assistant connection records: kept while your account exists, including after you disconnect the assistant, so the record shows when access began and ended. They are deleted when you delete your account.
- AI assistant credentials: an access credential stops working after one hour, and a refresh credential after 30 days or when you disconnect, whichever comes first. Their hashed records are deleted when you delete your account.
- Server and request logs: logs written by our app servers, and the request logs our cloud host keeps, are deleted after 30 days. This includes the request log for AI assistants and the IP addresses in those logs.
- Database backups: we back up our database automatically every day. Each automatic backup, and the recovery log that goes with it, is deleted after seven days. We sometimes take an extra backup by hand, for example before maintenance. Those are deleted within six months.
- Deleted files: files removed from our cloud storage, such as progress photos and lab documents, can be recovered for seven days and are then permanently deleted.
7. Cookies and Tracking Technologies
7.1 Mobile Application
The POWR mobile application does not use browser cookies. We use stateless JWT-based authentication, meaning no session cookies or tracking cookies are stored on your device by the application. When enabled in the active app configuration, the mobile application may also send limited product analytics and diagnostics events through our mobile analytics providers.
7.2 Website (powrhealth.com)
Our website is a static site that uses minimal tracking technologies:
- Privacy-friendly analytics: The website uses Vercel Web Analytics, which collects aggregated page-view metrics without setting cookies or persistent identifiers;
- Privacy-friendly analytics: The website also uses Plausible Analytics, which collects aggregated page-view and navigation metrics without setting cookies or persistent identifiers;
- Third-party images: Footer badges are loaded from Orynth and ScrollLaunch, which receive standard web request data when the images load. Fonts are served from our own domain;
- Hosting provider: Vercel may use standard cookies for site performance and security.
7.3 Do Not Track
We do not currently respond to "Do Not Track" browser signals. If we adopt this practice in the future, we will update this Privacy Policy accordingly.
8. Children's Privacy
The Service is not intended for use by children under the age of thirteen (13). We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child under 13 has provided us with personal information, please contact us immediately at legal@powrhealth.com. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take prompt steps to delete such information from our systems.
If you are between the ages of 13 and 18, you may use the Service only with the involvement and consent of a parent or legal guardian.
9. Health Data—Special Considerations
9.1 Sensitivity of Health Data
We recognize that Health Data is among the most sensitive categories of personal information. We handle all Health Data with heightened care and security protections, including encryption at rest, access controls, and audit logging.
9.2 Health Data Is Yours
Your Health Data belongs to you. We process it solely to provide the Service to you, including answering an AI assistant you have connected, and do not use it for advertising, marketing to third parties, or any purpose unrelated to providing and improving the Service for your benefit.
9.3 Data Minimization
We practice data minimization by:
- Collecting only the Health Data necessary to provide the features you use;
- Transmitting only the minimum necessary data to third-party service providers (particularly AI services), with one exception: a laboratory document you upload for transcription is transmitted whole and unredacted;
- Encrypting sensitive Health Data fields individually rather than in bulk;
- Providing granular control over which third-party health services you connect, and over which categories an AI assistant you connect may read.
9.4 No Sale of Health Data
We will never sell your Health Data. This commitment applies regardless of any business changes, acquisitions, or other corporate events. In the event of a corporate transaction, the acquiring entity must honor this commitment or obtain your separate consent.
9.5 AI Processing of Health Data
When Health Data is processed through POWR's own AI features (including the AI health companion chat):
- Data minimization is applied—only the specific data needed for the analysis or chat response is transmitted. A laboratory document you upload for transcription is the one exception: it is transmitted whole and unredacted, including any identifying information the report prints;
- AI processing is used to generate insights, recommendations, and chat responses for your personal use;
- AI-generated outputs and your chat conversation history are returned to you and stored in your encrypted account;
- The AI chat is text-only; we do not capture, transmit, or store voice or other audio data for the AI companion;
- Your inputs and conversations with POWR's AI features are not used to train third-party AI models;
- We maintain separate audit logs for AI data processing activities;
- AI features are subject to rate limiting to prevent excessive data processing.
These points cover POWR's own AI features. An AI assistant you connect yourself, such as ChatGPT or Grok, follows its provider's terms and privacy policy once it receives your data. See Section 4.3.
9.6 HIPAA Status
POWR is a consumer wellness app. We are not a covered entity or a business associate under the Health Insurance Portability and Accountability Act (HIPAA), and we do not provide POWR on behalf of any healthcare provider or health plan. Health data in POWR, including records you import from Apple Health Records and lab reports you upload, is not protected health information (PHI) under HIPAA while we hold it. Other laws still protect it, such as state consumer health data laws, and so does this policy.
We voluntarily follow security practices modeled on HIPAA's, including:
- Encryption of sensitive Health Data at rest using AES-256-GCM;
- Comprehensive audit logging of data access and modifications;
- Access controls and authentication requirements;
- Encryption failure monitoring;
- Complete data deletion upon account removal.
9.7 State Consumer Health Data Laws
Washington's My Health My Data Act, Nevada's consumer health data law, Connecticut's Data Privacy Act, and similar laws give you specific rights over your health data. Our Consumer Health Data Privacy Policy explains how we meet them and how to exercise those rights.
10. International Data Transfers
10.1 Data Processing Location
The Service is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers maintain facilities.
10.2 Your Consent to Transfer
By using the Service, you consent to the transfer of your information to the United States and other jurisdictions that may have different data protection laws than your country of residence. We take steps to ensure that your information receives an adequate level of protection in the jurisdictions in which we process it.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
11.1 Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which your information was collected, the business or commercial purposes for collection, and the categories of third parties with whom we share your information.
11.2 Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions provided by law.
11.3 Right to Correct
You have the right to request correction of inaccurate personal information we maintain about you.
11.4 Right to Opt-Out of Sale or Sharing
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.
11.5 Right to Limit Use of Sensitive Personal Information
You have the right to limit our use of sensitive personal information (including Health Data) to purposes necessary to provide the Service.
11.6 Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights.
11.7 How to Exercise Your Rights
To exercise your California privacy rights, contact us at legal@powrhealth.com. We will verify your identity before processing your request.
12. EEA / UK Privacy Rights (GDPR)
If you are located in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR:
12.1 Legal Bases for Processing
We process your personal data on the following legal bases:
- Contract: Processing necessary to perform our contract with you (providing the Service);
- Consent: Processing based on your explicit consent (e.g., health data collection, third-party integrations);
- Legitimate Interests: Processing necessary for our legitimate interests (e.g., security, fraud prevention, service improvement), balanced against your rights and freedoms;
- Legal Obligation: Processing necessary to comply with applicable legal obligations.
12.2 Your GDPR Rights
In addition to the rights described in Section 5, you have the right to:
- Object to processing based on legitimate interests;
- Restrict processing of your personal data in certain circumstances;
- Lodge a complaint with your local data protection supervisory authority;
- Withdraw consent at any time where processing is based on consent.
12.3 Data Protection Contact
For GDPR-related inquiries, contact us at legal@powrhealth.com.
13. Third-Party Links and Services
The Service may contain links to third-party websites, applications, or services. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service. We are not responsible for the privacy practices or content of third-party services.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes:
- We will update the "Last updated" date at the top of this Privacy Policy;
- We will notify you through the Service, by email, or by other appropriate means;
- We may request your renewed consent where required by applicable law.
Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the changes. If you do not agree to the revised Privacy Policy, you should discontinue use of the Service. We will not treat your continued use as consent to collect, use, or share consumer health data for a new purpose or a new category. We will ask you first.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Vitality Wellness LLC
A Wyoming Limited Liability Company
For data protection inquiries, data access requests, or data deletion requests, please email with the subject line "Privacy Request." We will endeavor to respond within thirty (30) days.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.