Privacy
Privacy Policy
Placeholder: attorney review required. Consumer-health-data laws apply even though HIPAA does not. This draft lists what the final policy must cover.
Data we collect
- Account info (name, email).
- Payment info, processed by Stripe (we do not store card numbers).
- Workout completion and viewing activity.
- Optional health-adjacent data you enter (weight, diet, mobility notes).
- Patchy AI conversations, which are logged for safety and improvement.
Sub-processors
We share data only as needed with: Stripe (payments), Mux (video), Resend (email), Twilio (SMS, when enabled), and Google Gemini (Patchy AI, when enabled).
Consumer health data
HIPAA does not apply to Fit Patch, but state laws do, including the Washington My Health My Data Act, California CMIA, and others. We treat health-adjacent data with comparable care voluntarily and never claim to be “HIPAA compliant.” Health-log data is stored separately with stricter access controls and can be deleted independently of your account.
Your rights
- Access, export, correct, and delete your data.
- Opt in before any consumer-health-data sharing; we do not sell health data.
- Delete health data separately from full account deletion.
Children
Fit Patch is for adults 18+. We do not knowingly collect data from minors.