Consumer Health Data Privacy Policy
Effective: September 9, 2026 · Aiclysm
This policy is published separately from our Privacy Policy because the law of several US states requires it to stand on its own. It describes how we handle consumer health data as that term is defined by the Washington My Health My Data Act (RCW 19.373), and it applies to residents of Washington, Nevada (SB 370) and Connecticut. If you are in the European Economic Area, the United Kingdom or elsewhere, our Privacy Policy is the document that governs, and it grants you the same access, deletion and withdrawal rights described below.
Aiclysm is the trade name of a sole trader registered in the Czech Republic. Contact for anything in this policy: support@aiclysm.com
Where your data lives. Our servers are in the European Union, and that is where your consumer health data is stored and processed. One copy leaves it: an encrypted off-site backup held in a private repository at GitHub, in the United States, so that losing the server does not mean losing your data. Those archives are AES-256 encrypted before they leave our server, GitHub cannot read them, and they are used for nothing but rebuilding the service.
1. What we collect, and why
Everything below is collected for one purpose: to compute and show you a daily reading of your own body inside MyBodyAI, and to keep your account working. We do not use it to build advertising profiles, we do not use it to infer anything about your health for anyone other than you, and we do not use it to train models sold to third parties.
| Category of consumer health data | What it is | How it is used |
|---|---|---|
| Cardiac | Resting and maximum heart rate, heart rate variability, ECG-based atrial fibrillation detections reported by your device | Recovery, autonomic and cardiovascular indexes; biological age |
| Sleep | Sleep stages, duration, sleep score, sleep debt | Sleep quality and circadian indexes; daily status |
| Physical activity | Steps, active minutes, workouts, training load, calories, distance | Training load and performance indexes; energy map of the day |
| Respiratory | Respiratory rate, blood oxygen saturation (SpO2) | Respiratory quality index; early-change signal |
| Body measurements | Weight, body fat, muscle mass, BMI, body temperature and skin temperature deviation | Body composition part of biological age; early-change signal |
| Cardiovascular measurements | Blood pressure, VO2max, vascular age and the pulse-wave velocity it is derived from, reported by your device | Cardiovascular indexes and biological age |
| Stress and recovery | Stress score, Body Battery, resilience and recovery scores reported by your device | Stress load index; daily status |
| Data you enter yourself | Daily check-in on how you feel, notes | Shown back to you; used as context for the daily status |
| Derived health indicators | Twelve health indexes, biological age across eight areas, daily status, data-confidence score | The product itself |
| Approximate location | Coarse location, city level | Weather context in coaching only. Not stored as a location history, not used to infer where you go |
We do not collect precise location, contact lists, photos, biometric identifiers used for identification (such as face or fingerprint templates; the optional app lock is handled by your phone and never reaches us), genetic data, reproductive or sexual health data, gender-affirming care data, or any information about health care services you seek or receive.
2. Where it comes from
- From you directly: registration, your daily check-ins, and files you choose to upload, such as a Garmin data export.
- From wearable and health platforms you connect, through their official APIs using OAuth. You start every one of these connections yourself, you can disconnect at any time, and we never see or store your login credentials for those platforms.
- From your phone, through Health Connect on Android, in the categories you grant and only those. Our app reads what other apps have already written there and writes nothing back.
- From our Garmin watch app, if you install it: your daily average stress and Body Battery curve. Nothing else leaves the watch.
- Computed by us from the above.
3. What we share, and with whom
We share no consumer health data with any third party for that third party's own purposes. There is no advertising network, no data broker, no analytics partner receiving your health data.
The only parties that come into contact with it are service providers acting on our instructions under a written data processing agreement:
| Category of recipient | What they receive | Why |
|---|---|---|
| Hosting provider (European Union) | Stores the server on which your data sits. Contractually barred from accessing it. | Running the service |
| Stripe (payment processing) | No health data. Payment details and subscription status only. | Taking payment, if you subscribe |
| Google Ireland Ltd. (optional sign-in) | No health data. Your email address, name and account identifier, only if you choose to sign in with Google. | Signing you in |
| Push delivery (Google FCM on Android, browser push services on the web) | A device token, and the short text of the notification, which can name a health state such as low recovery. Notifications stay off until you turn them on, and turning them off removes the token. | Delivering notifications you asked for |
| E-mail delivery (Forpsi, Czech Republic) | Your e-mail address and the body of the message. The weekly summary carries your own scores, which are derived health indicators. These e-mails can be switched off in Settings. | Sending you account e-mails and the weekly summary |
| GitHub (encrypted off-site backups, United States) | An encrypted copy of the database backups, which includes health data. AES-256 encrypted before it leaves our server; GitHub cannot read it. | Rebuilding the service if the server is lost |
| Sentry (error monitoring, EU) | No health data. Technical error reports: stack traces, browser type, the URL. | Finding and fixing faults |
| Telegram (error alerts) | No health measurements. A server error line, which can contain the e-mail address of an account, sent to a private channel only the operator can read. | Noticing an outage within minutes |
| Open-Meteo (Germany) | No health data. Coordinates rounded to roughly 1 km, and any place name you type into the search. | Weather behind the coaching advice |
| BigDataCloud (Australia) | No health data. Coordinates rounded to roughly 1 km, with no identifier. Outside the EEA, so the transfer relies on Standard Contractual Clauses, and it happens only if you set a location. | Turning coordinates into a place name |
Our own Open Wearables middleware, which holds the connections to the wearable platforms, runs on the same European server and is covered by the hosting row above. The wearable platforms themselves are a source rather than a recipient: data flows from them to us, on connections you start, and section 2 describes them.
Affiliates: we have none. Aiclysm is a sole trader with no parent, subsidiary or affiliated company.
If we are ever legally compelled to disclose data, or if the business is ever transferred, we will tell you before it takes effect wherever the law allows us to.
4. We do not sell your health data
We have never sold consumer health data and we do not intend to. Under the My Health My Data Act a sale requires a separate, signed valid authorization from you, distinct from consent. We have never asked anyone for such an authorization and we do not have one on file for any user. If that ever changes, we would have to ask you explicitly, and you would be free to say no without losing access to anything you pay for.
5. No geofencing
We operate no geofence of any kind, and specifically none around health care facilities. We do not use location to identify or track anyone approaching, entering or leaving such a place. The only location we use is coarse, city-level, and only to put weather into the coaching text.
6. Your rights, and how to use them
You have the right to:
- Confirm and access the consumer health data we hold about you, including a list of all third parties with whom we have shared it.
- Withdraw your consent to our collection and sharing of it.
- Have it deleted, from the live system and from our backups, on the timetable set out below.
The fastest way is inside the product. Deleting your account from the account deletion page removes your health data and also disconnects the platforms you had linked. Disconnecting a single integration in Settings withdraws consent for that source alone and stops any further collection from it.
Or write to us at support@aiclysm.com from the email address on your account. We answer within 45 days. If a request is genuinely complex we may take one further 45 days, and we will tell you why before the first period runs out. There is no charge.
Deletion and backups. When you delete, your data is removed from the live system immediately, and from the backup archives held on our server within 30 days, as those archives age out. The encrypted off-site copy at GitHub keeps earlier archives in its version history, so an archive taken before your deletion can survive there for longer; it is AES-256 encrypted, GitHub cannot read it, and it is used for nothing but rebuilding the service after the loss of the server. We do not restore deleted accounts from backups.
If we say no. You can appeal any refusal by replying to our answer, or by writing to support@aiclysm.com with "Appeal" in the subject. A person, not an automated process, will review it and answer you within 45 days with the reasons. If we refuse again, you may complain to the Washington State Attorney General.
7. How long we keep it
Health data is kept until you delete your account or disconnect the integration that supplies it. The full retention table, covering every other category, is in section 8 of our Privacy Policy.
8. Not a medical service
MyBodyAI produces wellness information. It is not a medical device, it does not diagnose, treat or prevent any disease, and it is not a substitute for professional medical advice. Nothing it shows you should be used to make a medical decision on your own.
9. Changes
If we change this policy in a way that affects how we handle consumer health data, we will post the new version here with a new effective date and, where the change is material, ask for your consent again inside the app before showing you any health content.
10. Contact
Aiclysm · Prague, Czech Republic · support@aiclysm.com