Healthefi Privacy Policy

Last updated: 29 April 2025

Welcome to Healthefi ("we", "our", "us"). We value your privacy and are committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, how we use it, and the choices you have regarding your information. By using the Healthefi mobile or web application (collectively, the "App") you agree to the practices described in this Policy.

1. Information We Collect

CategoryExamplesPurpose
Account InformationName, email address, password, company affiliation, number of employees, profile photo• Create & secure your account
• Authenticate you on sign‑in
Health & Activity DataWorkout completions (e.g., 90‑second sessions), calories burned, streaks, weight entries, goals, streak statistics• Track progress
• Award HEC tokens & participation badges
• Populate personal & company dashboards
Company DataCompany name, subscription tier, active employees count, challenge settings• Provide Employer dashboards
• Administer company challenges
Transaction DataSubscription price tier, payment status (via Stripe), purchase history• Process payments
• Provide invoices
• Prevent fraud
Device & Usage DataDevice type, operating system, crash logs, in‑app actions, referral source, IP address• Improve performance
• Debug issues
• Analytics
Cookies & Similar Tech (Web only)Session cookies, analytics tags• Maintain session state
• Measure traffic

We do not request precise location data or sensitive personal identifiers (e.g., Social Security numbers).

2. How We Use Your Information

  • Deliver Core Functionality – to create workouts, track activity, award tokens, and display dashboards.
  • Analytics & Improvement – to understand how features are used and prioritise development.
  • Personalisation – to suggest challenges and content relevant to your goals.
  • Security & Fraud Prevention – to detect and prevent malicious activity.
  • Legal Compliance – to satisfy tax, accounting, and regulatory obligations.

Legal bases under GDPR: Contractual necessity, Legitimate interests, and Consent (for optional marketing).

3. Sharing & Disclosure

RecipientReason
Service Providers (e.g., AWS, Stripe, analytics vendors)Cloud hosting, payment processing, analytics, customer support
Employers / Company AdminsAggregate, de‑identified statistics about employee participation and rewards (never raw health metrics)
Legal / Regulatory BodiesWhen required by law, court order, or to protect rights and safety
Business TransfersIn connection with a merger, acquisition, or asset sale (you will be notified)

We never sell your personal information.

4. Data Retention

We retain personal data for as long as you have an active account, or as needed to:

  • fulfil the purposes outlined in this Policy;
  • comply with legal obligations;
  • resolve disputes and enforce agreements.

Aggregated, de‑identified data may be retained indefinitely.

5. Your Rights & Choices

Depending on your locale, you may have rights to:

  • Access, correct, or delete personal data;
  • Object to or restrict processing;
  • Port data to another service;
  • Withdraw consent at any time.

To exercise these rights, use the in‑app Delete Account option or email us at privacy@healthefi.com.

6. Children's Privacy

Healthefi is not directed to children under 13. We do not knowingly collect data from children. If you believe a child has provided us information, contact us for deletion.

7. Security

We implement industry‑standard safeguards including encryption in transit (HTTPS), encryption at rest, access controls, and regular security audits. No method is 100% secure, but we strive to protect your data.

8. Third‑Party Links & SDKs

The App may contain links or integrations (e.g., Apple HealthKit, Google Fit). Their collection and use of data is governed by their own policies.

9. Changes to This Policy

We may update this Policy from time to time. Material changes will be announced via in‑app notice or email. Continued use after changes indicates acceptance.

10. Contact Us

For questions about this Privacy Policy or to exercise your rights, please contact:

Email: privacy@healthefi.com

Address: Healthefi Inc., 123 Wellness Street, San Francisco, CA 94103, USA