Consumer health data notice
Consumer Health Data Privacy Policy
This separate notice describes how Relm collects, uses, and discloses consumer health data and how you can exercise rights relating to that data. It is intended to provide the disclosures required by the Washington My Health My Data Act.
1. Scope
This policy applies to consumer health data handled by Relm, operated by Batu Ganioglu. Consumer health data is personal information that identifies or can reasonably be linked to a consumer and identifies the consumer's past, present, or future physical or mental health status, including information derived or inferred from non-health information.
Relm collects consumer health data only to provide features you request, as described below. We do not sell consumer health data. We do not use it for advertising. We will obtain consent before collecting or sharing additional consumer health data for a materially different purpose when applicable law requires consent.
Relm treats your deliberate permanent-sign-in action, presented with the backup disclosure, as your direction to begin cloud backup. The current version has no separate backup toggle. Apple Health collection begins only after the per-category permission action presented by iOS, and social disclosure occurs only when you deliberately use a social feature.
2. Categories collected and purposes
| Category | Examples | Purpose | Leaves your device? |
|---|---|---|---|
| Exercise and activity | Workouts, exercises, sets, repetitions, weight, duration, routines, programs, personal records, and steps | Track training, show history and progress, calculate insights, and provide optional backup or social sharing | Automatically included in cloud backup after you sign in to a permanent account, or disclosed if you deliberately post it, export it, or use another network feature; Apple Health step data is never uploaded |
| Body and fitness profile | Bodyweight and goal, sex, age in whole years, height, and activity level | Track bodyweight, calculate calorie targets, personalise fitness features, and provide optional backup | Automatically included in cloud backup after permanent sign-in; bodyweight may also be exchanged with Apple Health at your direction |
| Nutrition | Food searches, meals, calories, macronutrients, nutrition logs, and recipes | Search nutrition information, maintain your food log, calculate targets, and provide optional backup | Saved logs are automatically included in cloud backup after permanent sign-in; search terms are sent to USDA FoodData Central as you search and to Open Food Facts when you explicitly submit a packaged-food search, and a selected Open Food Facts product's barcode is sent to that service |
| Recovery and wellness | Manual recovery check-ins, sleep analysis, resting heart rate, heart-rate variability, and heart rate | Display recovery inputs and calculate recovery insights | Manual check-ins are automatically included in cloud backup after permanent sign-in; sleep and heart-related Apple Health data are never uploaded |
| Derived or inferred health information | Recovery scores, training insights, calorie targets, and coaching suggestions | Provide requested training, nutrition, and recovery features | Recovery scores stay on-device; coaching output and profile-derived targets are automatically included in cloud backup after permanent sign-in |
| Health-related social and support content | Workout posts, captions, comments, profile information, abuse reports, and health details you voluntarily include in support messages | Publish content you choose, operate and moderate social features, and respond to support requests | Social content is stored online and disclosed according to the feature and your settings; support content is sent to our support email |
| Health-related requests and metadata | Food-search terms, exercise-video requests, request time, and network metadata that can be linked to a health or fitness feature | Return food results or videos, deliver the requested feature, prevent abuse, and secure the service | Sent to the provider needed to complete the request |
3. Sources of consumer health data
- You: information you enter, import, post, search for, or include in a support or privacy request.
- Apple Health: only the categories you separately authorise through iOS: bodyweight, steps, workouts, sleep analysis, resting heart rate, heart-rate variability, and heart rate.
- Your use of Relm: training history, interactions, and feature requests generated when you use the app.
- Relm's on-device calculations: scores, targets, insights, and coaching output derived from the information above.
4. Consumer health data disclosed and recipients
The following list identifies the categories of consumer health data disclosed and the processors or third parties that may receive them. Relm has no affiliates with which it shares consumer health data.
| Recipient | Consumer health data disclosed | Why |
|---|---|---|
| Supabase, Inc. | Backup categories uploaded automatically after permanent sign-in; social content; account identifiers and the installation identifier linked to that information; relevant security and service metadata | Processes database, storage, authentication, and backend functions on Relm's behalf |
| Apple Inc. | Bodyweight and workout records you direct Relm to write to Apple Health; information involved in HealthKit requests | Provides Apple Health and the device permission controls you choose to use |
| United States Department of Agriculture, FoodData Central | Food-search terms and ordinary network metadata | Returns food and nutrition search results you request |
| Open Food Facts | Food-search terms, the barcode of a product you select, and ordinary network metadata | Returns food and nutrition search results and product details you request |
| Google LLC / YouTube | Exercise-video request, IP address, and ordinary playback metadata | Plays an exercise demonstration only after you tap play |
| Other Relm users | Workout posts, profile information, captions, comments, replies, likes, follows, and related social activity | Provides the social features you deliberately use, subject to feature visibility and profile settings |
| Cloudflare, and the mailbox provider that receives forwarded support mail | Health details you choose to include in support or privacy messages and related message metadata | Hosts getrelm.app, routes support mail, and delivers and stores the communications needed to respond to you |
| Government authorities, regulators, courts, or other legally authorised recipients | Only consumer health data reasonably necessary for a valid legal requirement, safety matter, or legal claim | Complies with applicable law or valid legal process, protects safety and rights, or establishes, exercises, or defends legal claims |
Relm does not sell consumer health data and therefore does not provide a sale authorisation process. Relm does not use geofences around health care facilities to identify, track, collect data from, or send messages or advertisements to consumers.
When a provider processes consumer health data on Relm's behalf, Relm uses service terms or contracts intended to limit processing to Relm's instructions and the services described here, require appropriate protection, and address deletion as required by applicable law. Independent services you contact directly through an app feature, including USDA FoodData Central, Open Food Facts, and YouTube, process the request under their own notices and terms.
5. Your consumer health data rights
Subject to applicable law, you may ask whether Relm is collecting, sharing, or selling your consumer health data; access that data; obtain a list of third parties and affiliates to whom it was shared or sold; withdraw consent to collection or sharing; and delete the data. Relm does not sell consumer health data and has no affiliates with which it shares consumer health data.
- Access and portability: export a JSON copy of Relm data stored locally on that device from Settings. Because the local export does not necessarily contain account metadata, server-only records, or information held by an independent third party, email Relm for a complete consumer health data access request.
- Delete: delete your account in Settings to remove the active account, associated cloud data, and local user-data categories included in the deletion process. Account deletion does not remove the installation identifier, preferences, or onboarding state stored separately on the device; removing the app clears Relm's remaining local storage. It does not delete records previously written to Apple Health, and it creates a fresh anonymous service identity when the backend is available.
- Withdraw Apple Health access: change permissions in the Health app or iOS privacy settings.
- Withdraw backup collection: use Relm without a permanent account if you do not want backup. Signing out stops future backup activity from that device but does not delete existing cloud rows; use account deletion or request removal. The current version has no backup toggle independent from sign-in.
- Submit any other request: email support@getrelm.app with the subject “Consumer Health Data Request.”
We may ask for information reasonably necessary to authenticate your request. If we refuse a request, you may appeal by replying with the subject “Consumer Health Data Appeal.” We will provide a written decision and, if the appeal is denied, instructions for contacting the Washington State Attorney General atatg.wa.gov/file-complaint.
Unless an exception applies, a valid deletion request covers consumer health data in our network, including archived and backup systems, and we will notify processors, service providers, and other recipients that must also delete it. If immediate deletion from an archived or backup system is not technically possible, we will isolate the data from use and complete deletion within the period allowed by applicable law.
Batu Ganioglu, doing business as Relm