Idunia Consumer Health Data Privacy Policy
← All policies

Consumer Health Data Privacy Policy

Version 3.0 · Effective September 18, 2026

This Consumer Health Data Privacy Policy is required by the Washington My Health My Data Act (RCW 19.373) and the consumer health data laws of Nevada (SB 370) and Connecticut. It describes the consumer health data Idunia collects, the purposes and sources, the categories of third parties and affiliates it is shared with, and how you exercise your rights. It is separate from our general Privacy Policy and our Terms.

1. Categories of consumer health data we collect

Most of this you enter yourself; the exceptions are workout data you choose to import from a connected health platform, described in the Training & body data row below and in Section 2, and what the Idunia Apple Watch app reads during a run you start on it, described in the same row:

2. Sources

We collect consumer health data directly from you, through what you enter in the app, and — only if you choose to turn it on — from your device's connected health platform (Apple Health on iOS, Health Connect on Android). That connection is optional, off by default, gated behind your explicit in-app consent, and revocable at any time in Settings → Training sync. When connected, we import workouts and the calories burned during them only. On Apple Health (iOS) that is the energy each workout itself records. On Health Connect (Android) it is the active-calorie and total-calorie records for that workout's own time window, from the same app that recorded the workout; we read the total-calorie record only when no active-calorie data exists for the workout, and we subtract a standard resting-energy allowance from it so it reflects the workout rather than the whole period. Idunia writes to Apple Health only the runs you start on the Idunia Apple Watch app, saved as workouts, and never writes food, weight, cycle, or any other data. Once connected, the import can happen automatically in the background (not only when you have the app open), so you keep receiving your training data without opening the app every time. We do not buy consumer health data and do not obtain it from data brokers or advertising networks.

3. Purposes

Solely to provide the app's features to you: calculating your targets and indicators, showing your own history back to you, and — if you use the in-app Feedback feature — reading and responding to what you send us. We do not use it for advertising, marketing, profiling, or to train models for anyone else.

4. Categories of consumer health data we share

We do not share or sell your consumer health data. We have no advertising, analytics, attribution, or tracking software in the app.

Three service providers handle your data solely on our behalf, only to run the app for you. Each is contractually prohibited from using your data for any purpose of its own. One public database, Open Food Facts, is also listed below: it receives only the number of a barcode you scan, never anything about you. Using a service provider to process or store data for you is not "sharing" or "selling" under these laws.

Your cycle/reproductive data never reaches any of these providers on its own, because it stays on your device. The one exception: if you choose to attach a photo or screenshot to the in-app Feedback feature that happens to show cycle/reproductive information, that image reaches Supabase as feedback content you deliberately chose to send, not as an automatic transfer of your cycle data (see Section 1 and Section 6).

5. Categories of third parties and specific affiliates

6. Where your data is stored and how it is protected

7. Your rights

You may at any time:

To exercise any right, use the in-app controls or email founders@maxoutput.ai. We respond as soon as we can and no later than 45 days; if we need more time we will tell you why. If we decline a request, we will explain why and how to appeal.

8. Retention

Cycle data stays on your device until you delete it or uninstall the app; we keep no server copy. Other data is retained until you delete it or close your account; we remove deleted data from active systems promptly and from backups within 90 days.

9. Changes

If we materially change what we collect or how we use it, we will ask for your consent again before the change applies to data already collected. We will not retroactively apply new uses to previously collected data without your opt-in.

Contact: founders@maxoutput.ai

Change history