Fitlyze (Beta) — Consumer Health Data Privacy Policy Version: 2.0 Effective date (last updated): July 7, 2026 Last reviewed: July 7, 2026
This Consumer Health Data Privacy Policy explains how DerMo Technologies Inc. (d/b/a Fitlyze) ("Fitlyze", "we", "us", "our") collects, uses, discloses, and protects your health and fitness data, and the choices and rights you have over it.
This is a separate document that you must accept to use Fitlyze. By accepting it at sign-up, you give your consent to the processing of your health and fitness data as described here (see Section 13). It supplements — and should be read together with — our Privacy Policy.
This policy is written to meet US consumer-health-data laws — including Washington's My Health My Data Act (MHMDA), Nevada's consumer health data law (SB 370), and Connecticut's health-data rules — and, together with our Privacy Policy, it supports your rights in the European Union/EEA, Switzerland, and Canada, where your acceptance also serves as your explicit (EU/Swiss) or express (Canada) consent to process this data.
Scope. This policy applies to consumer health data / health and fitness data as described in Section 1. It does not apply to information governed by HIPAA (we are not a HIPAA-covered entity), or to data about our own personnel. Capitalized terms not defined here have the meaning given in the applicable law.
1. Health data we collect, and how we use it
We collect the following categories of health and fitness data directly from you and as a result of your use of the Service:
| Category | Examples | Purpose / how it is used |
|---|---|---|
| Body measurements, vital signs, and health metrics | Height, weight, body-fat percentage, waist/chest/hip measurements, resting heart rate, calories burned, body-weight history | Provide tracking features; generate personalized workout and nutrition suggestions |
| Demographics used for health personalization | Sex/gender, age (from your date of birth) | Account for physiological differences; provide age-appropriate suggestions; confirm you are 18+ |
| Diet and nutrition information | Foods and meals you log, quantities, water intake, nutrition plans (calorie/macro targets), photos of food and nutrition labels | Food and nutrition tracking; generate nutrition suggestions |
| Exercise and fitness activity | Activities, workout plans, exercises (sets, reps, weights), durations | Activity tracking; generate workout suggestions |
| Health/fitness information you give the AI assistant | Chat messages, transcribed voice input, and any health, diet, or fitness details you share by text, photo, or voice | Generate the responses and suggestions you request |
| Inferences | Conclusions we draw from the data above to tailor suggestions | Personalize the Service |
We also use this data to operate, secure, and debug the Service, to prevent fraud and abuse, to communicate with you about the Service, for limited safety and quality review during the beta (by authorized people bound by confidentiality — currently our two founders (the CEO and CTO)), and to comply with law. We do not use your conversations or health data to train AI models, and our AI provider does not use our data to train its models.
2. Sources
We collect health data from you (entered in the app, in chat, or as photos or voice input) and from your interactions with the Service (for example, the logs and suggestions generated for you). We do not buy health data or obtain it from data brokers.
3. Disclosure of your health data
We do not sell your health data.
We do not share your health data with third parties or affiliates for their own use, and we have no corporate affiliates.
We disclose health data only to processors that act solely on our behalf, under contract, and may not use it for their own purposes:
- Anthropic — AI processing of the requests you submit to the assistant (text, photos, voice).
- LangSmith (LangChain, Inc.) — AI observability: traces of your AI assistant interactions (your messages, the assistant's responses, and the profile context sent with them) used for debugging and for quality and safety monitoring (hosted in the European Union; traces expire automatically after a short period).
- Tavily (AlphaAI Technologies Inc.) — web search for the AI assistant: when the assistant needs current information from the web to answer you, it sends a search query (which may reflect health or fitness details in your request) and receives search results. Queries are sent without your name, email, or account identifiers (located in the United States).
- DigitalOcean — cloud hosting, database, and private storage of your uploaded images (located in Canada).
The current details for each of these processors — including their role, location, and safeguards — are published in our Sub-processor & Service Provider List (available in the References section of the User Agreements page, both during sign-up and at any time afterward). We update that list before adding or replacing a processor that handles your health data, and we obtain fresh consent where the law requires it (see Section 10).
We may also disclose health data where required by law, to protect rights or safety, or in a corporate transaction subject to equivalent protections, as described in our Privacy Policy.
No geofencing. We do not use geofences around health-care facilities, and we do not collect precise or GPS location.
4. How we rely on consent
- We collect and process your health data only with your opt-in consent (your acceptance of this policy at sign-up), and only for the purposes described here.
- Because we disclose health data only to processors acting on our behalf — not to non-processor third parties — we do not "share" or "sell" it as those terms are defined by consumer-health-data laws, and we do not seek any separate sharing consent or sale authorization. If that ever changes, we will obtain your separate, opt-in consent first (and, for any sale, a signed valid authorization).
- If we want to collect new categories of health data, or use it for new purposes not described here, we will obtain your consent first.
- You can withdraw your consent at any time (see Section 5). Withdrawal does not affect processing that already took place.
5. Your rights
Subject to verification of your identity, you have the right to:
- Confirm and access — confirm whether we collect, share, or sell your health data, and access that data, including a list of the parties with whom we have shared it (currently, only the processors named in Section 3) and how to contact them.
- Withdraw consent — to our collection (and any sharing) of your health data.
- Delete — have your health data deleted from our systems, including archived and backup systems (subject only to the narrow exceptions the law allows); we will also direct our processors to delete it. Data removed from our active systems may persist in our encrypted backups until they roll off on an approximately 30–90 day cycle, after which it is overwritten, as described in our Privacy Policy.
- Correct — correct inaccurate health data.
- Appeal — if we decline a request, you may appeal; we will respond in writing within the legal deadline and, if we deny the appeal, give you a way to complain to your regulator.
- No discrimination — we will not discriminate or retaliate against you for exercising these rights.
How to exercise your rights. Email privacy@fitlyze.app with the subject line "Health Data Request." We verify your identity and respond within the time the law requires — generally 45 days for US requests (extendable once by 45 days with notice) and within the timeframes in our Privacy Policy for the EU/Switzerland and Canada. You can also delete your account in the app to delete your data.
6. State-specific information (United States)
Washington (My Health My Data Act). You have the rights in Section 5, including the strong right to deletion described there. We obtain your opt-in consent before collecting your consumer health data, we do not sell it, and we do not use geofencing. This Health Data Policy is also published as a separate, distinct link on our homepage, as the Act requires. If we deny a rights request and your appeal, we will provide a way to contact the Washington Attorney General (www.atg.wa.gov/file-complaint). The Act is enforceable by the Attorney General and by private lawsuit.
Nevada (SB 370). We obtain your opt-in consent before collecting your consumer health data, we do not sell it without your authorization (and we do not sell it), and you have rights to confirm, access, and delete your consumer health data. Nevada's law is enforced by the Nevada Attorney General.
Connecticut. Connecticut treats consumer health data as sensitive data requiring your opt-in consent, which your acceptance of this policy provides. You also have rights to access, correct, delete, obtain a portable copy of, and opt out of certain processing of your personal data under Connecticut law, enforced by the Connecticut Attorney General.
Other states. Where another US state treats health data as sensitive personal information, we obtain your consent for its use, use it only to provide the Service (not to infer unrelated characteristics), do not sell it, and honor the rights that state provides.
7. Security and access
We restrict access to your health data to the employees, processors, and contractors who need it to provide the services you have consented to or requested ("need-to-know"). We maintain safeguards appropriate to our size and the nature of the data, including encryption of data in transit (TLS), one-way hashing of passwords, access controls and authentication, and private storage of uploaded images served only through signed, expiring links. As a beta product, we are actively strengthening these safeguards. No method of transmission or storage is completely secure.
8. International data transfers
We host the Service in Canada (Toronto). Your health data is stored and processed primarily in Canada — which the EU and Switzerland recognize as providing adequate protection — and is processed in the United States by our AI provider (Anthropic) under Standard Contractual Clauses, with the Swiss addendum as applicable. Web-search queries generated by the AI assistant are also processed in the United States by our web-search provider (Tavily) under Standard Contractual Clauses; these queries carry no name, email, or account identifiers. Traces of your AI assistant interactions are processed in the European Union by our AI observability provider (LangSmith); its parent company is US-based, so where that US entity could access the data, Standard Contractual Clauses apply. When your data is processed in another country, it may be subject to lawful access requests by that country's courts, law enforcement, and national-security authorities. Full details are in our Privacy Policy. For Québec residents, we conduct a Privacy Impact Assessment before transferring personal data outside Québec.
9. Children
Fitlyze is only for people aged 18 and over. We do not knowingly collect health data from anyone under 18, and our sign-up flow blocks registration where the date of birth indicates the person is under 18. If we learn we have collected such data, we will delete it.
10. Changes to this policy
We may update this policy. If we make material changes, we will notify you by in-app notice or email, and we will obtain fresh consent where the law requires it. The effective date above shows when the current version took effect.
11. Contact
DerMo Technologies Inc. (d/b/a Fitlyze) 2300 Yonge Street, Suite 1600, Toronto, ON M4P 1E4, Canada privacy@fitlyze.app
12. Your acceptance and consent
By ticking the box at sign-up, you confirm you have read this Consumer Health Data Privacy Policy and you give your consent. This consent is separate from your acceptance of our other documents and is required to use Fitlyze, because the app's core features process your health and fitness data. You confirm that:
I am 18 or older, and I consent to Fitlyze collecting and processing my health and fitness data — including its processing by Anthropic in the United States, by LangSmith (LangChain, Inc.) in the European Union, and — for web-search queries generated by the assistant, sent without my name or account identifiers — by Tavily (AlphaAI Technologies Inc.) in the United States, as well as by authorized people bound by confidentiality — currently our two founders (the CEO and CTO) — as described in this Consumer Health Data Privacy Policy. I understand I can withdraw my consent at any time by emailing privacy@fitlyze.app or deleting my account.