Consumer health data notice
Consumer Health Data Privacy Policy
This separate notice describes how Relm collects, uses, and discloses consumer health data and how you can exercise rights relating to that data. It is intended to provide the disclosures required by the Washington My Health My Data Act.
1. Scope
This policy applies to consumer health data handled by Relm, operated by Batu Ganioglu. Consumer health data is personal information that identifies or can reasonably be linked to a consumer and identifies the consumer's past, present, or future physical or mental health status, including information derived or inferred from non-health information.
Relm handles consumer health data for the feature, reporting, support, and moderation purposes described below. Reading this policy, accepting the Terms, and granting Apple Health permissions are not blanket consent to every health-data use.
Cloud backup is off until you turn it on. It requires a permanent account and the separate Cloud Backup toggle under Settings → Backup; signing in does not enable it, and accounts that existed before the toggle are not switched on for you. If you previously enabled backup for the same account, signing back in can resume it. Relm treats switching that toggle on as your direction to begin cloud backup. Apple Health access depends on the categories you authorise through iOS, and social disclosure occurs only when you deliberately use a social feature. Product analytics is the exception to that pattern: it is on by default, and the five health-activity signals described in Section 2 are captured by default. Turning it off stops new capture, but already queued events can still be sent, including after the app relaunches.
2. Categories collected and purposes
| Category | Examples | Purpose | Leaves your device? |
|---|---|---|---|
| Exercise and activity | Workouts, exercises, sets, repetitions, weight, duration, routines, programs, personal records, and steps | Track training, show history and progress, calculate insights, and provide optional backup or social sharing | Saved records can enter optional Cloud Backup, social sharing or exports. Raw Apple Health step readings stay in memory and are not included in Relm Cloud Backup or the local JSON export |
| Body and fitness profile | Bodyweight and goal, sex, age in whole years, height, and activity level | Track bodyweight, calculate calorie targets, personalise fitness features, and provide optional backup | Saved records can enter optional Cloud Backup and exports; bodyweight may also be exchanged with Apple Health at your direction |
| Nutrition | Food searches, meals, calories, macronutrients, nutrition logs, and recipes | Search nutrition information, maintain your food log, calculate targets, and provide optional backup | Saved logs are included in cloud backup only if you turn Cloud Backup on; search terms are sent to USDA FoodData Central as you search and to Open Food Facts when you explicitly submit a packaged-food search, and a selected Open Food Facts product's barcode is sent to that service |
| Recovery and wellness | Manual recovery check-ins, sleep analysis, resting heart rate, heart-rate variability, and heart rate | Display recovery inputs and calculate recovery insights | Raw sleep and heart-reading caches stay in memory. Manual check-ins and saved daily recovery sub-scores can enter optional Cloud Backup and exports; the sub-scores are calculated values, not raw readings, and include capture-time and time-zone information |
| Derived or inferred health information | Recovery scores, training insights, calorie targets, and coaching suggestions | Provide requested training, nutrition, and recovery features | Saved recovery sub-scores, coaching history and profile-derived targets can enter optional Cloud Backup and exports |
| Health-related social and support content | Workout posts, captions, comments, profile information, abuse reports, and health details you voluntarily include in support messages | Publish content you choose, operate and moderate social features, and respond to support requests | Social content is stored online and disclosed according to the feature and your settings; support content is sent to our support email |
| Product-analytics signals about health activity | Five app-event types: a workout started, discarded or finished; a food entry saved; and a surface reached, including Health, Add Food, Weight, Recovery, Steps or History. Repeated reaches of the same surface are limited within an app-session window; a new app process can start another window | Understand whether people are using the app during the beta and decide what to build or fix | Yes — captured for PostHog by default, with timing, pseudonymous identifiers and fixed properties. The event properties do not contain measurements, exercise or food names, workout or meal contents, or text you enter. A discarded workout carries a fixed stage: empty, exercises only or sets logged. Relm does not attach your account identifier or enable person profiles. Queued events can still be sent after reporting is switched off, including after relaunch |
| Health-related diagnostic context | Crash stacks, exception information, operation or data-store labels, device/app and event identifiers, and technical context that can reveal a health feature or health-related information | Find and fix crashes and selected errors | Sent to Sentry while Share Usage Data is enabled, which is the default. Native exception information follows a different path from the reduced handled-error fields |
| Health-related requests and metadata | Food-search terms, exercise-video requests, request time, and network metadata that can be linked to a health or fitness feature | Return food results or videos, deliver the requested feature, prevent abuse, and secure the service | Sent to the provider needed to complete the request |
Five app-event types specifically describe health activity, and they are the five named in the table above: that a workout was started, discarded, or finished; that a food entry was saved; and that a health-related surface was reached. Their fixed properties omit measurements and entered content, but timing and identifiers can still reveal health-related activity. The other events in the privacy policy's list describe onboarding, the app being opened, screens outside the Health tab, and the paywall. Those fixed signals and their timing can also reveal use of a fitness app. There is no analytics event for a set, a recovery check-in, a bodyweight entry, or an Apple Health connection.
Product analytics is on by default and is switched off under Settings → Analytics → Share Usage Data. Switching it off stops new event capture, but already queued events can still be sent, including after the app relaunches. Relm does not attach your account identifier or enable person-profile processing. Events do carry a pseudonymous analytics identifier and timing, so they are not anonymous. Switching reporting off changes the main analytics identifier, but also triggers a separate configuration request that can contain the new identifier, a continuing SDK device identifier and time zone. That request is outside the app-event filter. Changing the main identifier does not remove every identifier or prevent links with earlier activity. Re-enabling reporting permits new capture. The switch does not delete records already held by PostHog.
On your device, the designated files holding bodyweight and its goal, manual recovery check-ins, per-day recovery scores, the record of what Relm has written to Apple Health, and the body profile used for calorie targets are marked so that iOS excludes them from your iPhone's iCloud or computer backup. That is separate from Relm's own cloud backup, which is off unless you turn it on; when you do, all of those files except the record of what Relm has written to Apple Health are part of it. Other health-bearing records, including workouts, nutrition, personal records, coaching history, and active workouts, remain eligible for iCloud or computer device backup according to your device settings. Workout files can contain a subjective recovery rating and, in older records, a retained bodyweight value. The daily step-goal preference and saved streak information are also outside these excluded files.
3. Sources of consumer health data
- You: information you enter, import, post, search for, or include in a support or privacy request.
- Apple Health: only the categories you separately authorise through iOS: bodyweight, steps, workouts, sleep analysis, resting heart rate, heart-rate variability, and heart rate.
- Food databases: USDA FoodData Central and Open Food Facts supply food, product and nutrient information that you can select for your records.
- Other people: profiles, posts, comments, interactions and reports can contain information about you.
- Your use of Relm: training history, interactions, and feature requests generated when you use the app.
- Relm's on-device calculations: scores, targets, insights, and coaching output derived from the information above.
Bodyweight import and Health exports are manual. Once Health is connected, steps and recovery can refresh when the app opens, returns to the foreground or observes a relevant Health change while running. Some recovery queries cover a recent 30-day period; that is a query window, not a retention deadline. Relm does not use background Health delivery. Completing the permission sheet does not tell Relm that every requested read category was allowed.
4. Consumer health data disclosed and recipients
The following list identifies the categories of consumer health data disclosed and the processors or third parties that may receive them.
| Recipient | Consumer health data disclosed | Why |
|---|---|---|
| Supabase | Backup categories, uploaded only if you turn Cloud Backup on; social content; account identifiers and the installation identifier linked to that information; relevant security and service metadata | Provides database, storage, authentication and backend functions, including daily database recovery backups with a seven-day window. The supplemental GitHub (Microsoft) snapshot workflow was disabled on 8 September 2026. Previously created encrypted artifacts retain their original expiration of up to 48 hours after creation; downloaded or restored copies do not expire with those artifacts |
| PostHog | The health-activity events, fixed properties, timing and pseudonymous analytics identifiers described in Section 2. Configuration requests can also carry a continuing SDK device identifier and time zone. Relm does not attach an account identifier or enable person profiles | Provides product analytics. New capture stops when you switch reporting off; queued events can still be sent after withdrawal or relaunch. Relm disables app session replay and automatic screen/tap capture. Event delivery requests no IP-to-location enrichment, but the receiving infrastructure still sees connection information |
| Sentry | Handled errors are reduced to type, domain, code and fixed operation/store labels, with diagnostic context. Native reports can include stacks, threads, software/device/operating-system context, event and correlation identifiers, and a pseudonymous device/app identifier. Native exceptions can include their reason and associated information. These can reveal health-related or identifying information. Clearing the user field and breadcrumbs does not remove every identifier or all such context | Provides crash and error diagnostics, enabled by default. A saved crash report can be sent early on the next enabled launch. Switching reporting off initiates cancellation of pending transmission, cached-report removal and closure; failed cache cleanup blocks restarting Sentry. These actions do not delete received reports or ensure a new device/app identifier |
| Apple | Bodyweight and workout records, including associated walking/running, cycling, swimming and rowing distance samples, that you direct Relm to write to Apple Health; information involved in HealthKit requests and eligible iCloud device backups | Provides Apple Health and the device permission controls you choose to use |
| United States Department of Agriculture, FoodData Central | Food-search terms, selected food identifiers and ordinary network metadata | Returns food and nutrition search results you request |
| Open Food Facts | Food-search terms, the barcode of a product you select or scan, and ordinary network metadata | Returns food and nutrition search results and product details you request |
| Google / YouTube | Exercise-video request, IP address, playback and webview information | Plays an exercise demonstration only after you tap play |
| Resend and the mailbox provider receiving moderation email | Moderation report identifiers, target identifiers, timestamps, and fixed reason categories. The message omits stored snapshots and original content; identifiers can link to health-related social content | Delivers moderation alerts so Relm can review reports |
| Recipients you choose | Health and fitness records in a JSON or workout CSV export you choose to send; workout CSV can include recovery ratings and associated bodyweight | Provides the export and sharing action you request; recipient copies are outside the in-app deletion process |
| Anyone with a profile-photo link | Your uploaded profile photo, which can itself reveal health information | Profile photos use public URLs even when your profile is private |
| Other Relm users | Workout posts, profile information, captions, comments, replies, likes, follows, and related social activity | Provides the social features you deliberately use, subject to feature visibility and profile settings |
| Cloudflare, and the mailbox provider that receives forwarded support mail | Health details you choose to include in support or privacy messages and related message metadata | Hosts getrelm.app, routes support mail, and delivers and stores the communications needed to respond to you |
New social profiles are public. A private profile restricts your workout posts and follower/following lists to you and approved followers, but remains searchable and does not hide your comments or interactions on other people's visible posts. Profile-photo URLs remain public. Other people can save copies of what they see.
Relm does not use geofences around health care facilities to identify, track, collect data from, or send messages or advertisements to consumers.
Independent services you contact directly through an app feature, including USDA FoodData Central, Open Food Facts, and YouTube, process the request under their own notices and terms.
5. Your consumer health data rights
Subject to applicable law, you may ask whether Relm is collecting, sharing, or selling your consumer health data; access that data; obtain a list of third parties and affiliates to whom it was shared or sold; withdraw consent to collection or sharing; and delete the data. See Section 4 for the recipients described by this notice.
- Access and portability: export supported saved local records as JSON from Settings. This export does not include account metadata, social/moderation records, vendor telemetry, email, raw Health caches, preferences or the active workout. Email Relm to make a broader consumer health data access request.
- Delete: account deletion removes the active account and associated cloud records before clearing the local stores included in that process. A failed attempt can already have revoked Apple access or removed the profile image. If server deletion fails, local stores are not wiped; if local cleanup fails after server success, some files can remain and backup is blocked until cleanup is resolved. A new guest identity can be created after successful cleanup. Installation identifiers, some preferences and onboarding state survive. Reports you submitted are deleted with your account; reports about your content can retain text or workout-summary snapshots and identifiers. Deletion does not automatically remove separate signup, support-mail, analytics, diagnostic, provider-log, recipient-export, device-backup or Apple Health records. Contact Relm to make a broader deletion request.
- Withdraw Apple Health access: change permissions in the Health app or iOS privacy settings. Once connected, steps and recovery can refresh while you use or return to the app. Withdrawing permission stops access to affected categories; it does not erase records already imported or calculated in Relm, or copies already exported or backed up.
- Withdraw backup collection: switch off Cloud Backup under Settings → Backup, or leave it off — it is off by default. Turning it off or signing out prevents new uploads from that device, but an upload request already sent may finish. Existing cloud records remain, and another device with backup enabled can continue uploading. Use account deletion or request removal of existing records.
- Withdraw product-analytics collection: switch off Settings → Analytics → Share Usage Data. This stops new app-event capture and changes the main analytics identifier. Queued events can still be transmitted, including after relaunch, and the switch-off configuration request can carry a continuing SDK device identifier. These limits are described in Section 2. The switch does not delete events already received by PostHog. Contact Relm for requests involving analytics records, including earlier beta records; pseudonymous data is not anonymous merely because it lacks an account identifier.
- Withdraw crash and error diagnostics: the same switch initiates cancellation of pending Sentry transmission, removal of cached reports and closure of reporting. Failed cache cleanup blocks restarting Sentry. These actions do not delete reports already received by Sentry or ensure that future reports use a different device/app identifier. Contact Relm for a request involving those records.
- Submit any other request: email support@getrelm.app. The subject “Consumer Health Data Request” can help route your message but is not required.
Consumer-health rights can require authentication and include an appeal of a refusal. Contact Relm about a refusal using the same privacy address. You can also contact the Washington State Attorney General atatg.wa.gov/file-complaint.
Consumer-health deletion rights can extend to recipients and archived/backup systems. The in-app account-deletion process does not establish deletion from those separate copies; use the contact above for a broader request. Disabling the GitHub backup workflow did not erase existing downloaded archives, extracted files or restored databases, and those copies have no established general automatic expiry. Restoring an older backup can reintroduce deleted records; automatic deletion reconciliation is not currently implemented.
Saved local health records remain until removed through the relevant controls or local cleanup; some coaching history is pruned when new verdicts are saved. Reports about deleted targets have no established general expiry. Relm has not yet established a general retention schedule or broader removal procedure for separate signup, support and email records. Provider telemetry, logs and recovery copies have separate lifetimes. The General Privacy Policy describes those retention and deletion limits.
Batu Ganioglu, doing business as Relm