Your health data belongs to you. We collect it to help you improve your fitness, not to exploit it. This policy explains exactly what we collect, why we collect it, who we share it with, and how you control it.
1. Who We Are
ObtAIn Fitness ("ObtAIn," "we," "us," or "our") is a health and wellness technology company headquartered in Canada. We operate the website obtain.tech and the ObtAIn Fitness mobile application.
Data Controller: ObtAIn Fitness Inc.
Contact: privacy@obtain.tech
Address: [Your Canadian Business Address]
2. What Data We Collect
We only collect data that is necessary to provide our services. We categorize this into:
2.1 Account Information
- Name, email address, date of birth, gender
- Account credentials (encrypted password)
- Profile photo (optional)
2.2 Health & Biometric Data
This is our most sensitive data category. It includes data from your ObtAIn ring, scale, and any connected devices:
- Heart rate, heart rate variability (HRV), resting heart rate
- Sleep stages, sleep score, sleep duration
- Body weight, body composition (body fat %, muscle mass, bone mass, water %)
- Blood oxygen (SpO2), skin temperature trends
- Activity data: steps, calories burned, workout type and duration
- ECG readings (if supported by your device and explicitly enabled)
- Glucose trends (if supported by your device and explicitly enabled)
Special Category Data: Under GDPR and PIPEDA, health and biometric data are classified as "special category" or "sensitive personal information." We apply enhanced security and consent requirements to this data.
2.3 Lifestyle & Goal Data
- Fitness goals (weight loss, muscle gain, athletic performance, general wellness)
- Dietary preferences, allergies, supplement intake
- Smoking status, alcohol consumption (if voluntarily provided)
- Self-reported mood, energy levels, stress scores
2.4 Device & Technical Data
- Device model, operating system, app version
- IP address, crash logs, performance data
- Bluetooth connection logs with your ring/scale
2.5 Payment Information
We do not store credit card numbers. All payment processing is handled by Stripe or PayPal. We retain transaction records, subscription status, and billing history.
3. How We Use Your Data
| Purpose | Legal Basis | Data Used |
| Provide personalized coaching and insights | Contract (service delivery) | Health, lifestyle, goal data |
| Calculate your Game Ready Score / fitness metrics | Contract | Biometric, activity data |
| Send daily AI coach briefings and notifications | Consent | Health data, preferences |
| Process payments and manage subscriptions | Contract | Account, payment records |
| Improve our AI models and algorithms | Legitimate interest (anonymized) | Aggregated, de-identified data |
| Fraud prevention and security | Legitimate interest | Technical, account data |
| Legal compliance and dispute resolution | Legal obligation | All categories as required |
4. Insurance Partnership Data Sharing
This section applies specifically to our partnerships with insurance providers. We treat this as a separate, higher-tier consent from general data use.
We will never share your health data with an insurance company without your explicit, separate opt-in. General app usage does not constitute insurance data sharing consent.
4.1 What We Share (Only With Your Consent)
If you opt into an insurance partnership, we may share:
- Verified biometric averages (resting heart rate, HRV trends, sleep scores)
- Activity consistency metrics (workout frequency, step averages)
- Lifestyle audit results (smoking status, verified vs. self-reported)
- Annual health snapshot summaries
- We do NOT share: Raw ECG traces, minute-by-minute heart rate, body weight, specific sleep times, or location data
4.2 How Insurance Partners Use It
- To offer discounted premiums or wellness incentives
- To verify self-reported health information (fraud reduction)
- To generate anonymized risk pool analytics
4.3 Your Control
- You can opt in or out of any insurance partnership at any time in Settings → Data Sharing → Insurance Partners
- Withdrawing consent stops future sharing but does not retroactively delete data already received by the insurer (subject to their retention policies)
- Each insurance partner requires separate consent — we do not use blanket opt-ins
5. Hotel Partnership Data Sharing
If you use ObtAIn Fitness at a partner hotel:
- The hotel receives only aggregated, anonymized sleep scores (e.g., "Guest average sleep score: 87%")
- Individual guest data is never shared with hotel staff
- Your personal data remains under your account only
6. Data Retention
| Data Type | Retention Period | Reason |
| Account information | Until account deletion + 30 days | Service provision, legal holds |
| Health/biometric data | Until account deletion + 90 days | Historical trend analysis, legal compliance |
| Payment records | 7 years | Tax and accounting obligations |
| Consent logs | 3 years | Regulatory compliance (ROSCA, PIPEDA) |
| Anonymized analytics | Indefinitely | Cannot identify individuals |
7. Your Rights
Depending on your location, you have the following rights:
Access
Request a copy of all data we hold about you. We provide this within 30 days in machine-readable format.
Correction
Update inaccurate information through the app, or contact us to correct errors in our records.
Deletion
Request full account deletion. We erase personal data within 90 days, except where legally required to retain.
Portability
Export your health data in standard formats (CSV, JSON, Apple Health, Google Fit).
Restriction
Temporarily pause data processing while you dispute accuracy or object to use.
Objection
Object to processing based on legitimate interests, including AI training on non-anonymized data.
7.1 How to Exercise Your Rights
Email privacy@obtain.tech with your request. We verify your identity before processing. We do not charge fees for the first request per year.
8. Data Security
We implement the following safeguards:
- Encryption at rest: AES-256 for all stored health data
- Encryption in transit: TLS 1.3 for all data transmission
- Access controls: Role-based access; only authorized personnel can view health data
- Audit logs: All access to health data is logged and reviewed
- Anonymization: Data used for AI training is de-identified before processing
- Self-hosted AI: Where possible, AI processing occurs on our own infrastructure to minimize third-party data exposure
9. International Data Transfers
We are based in Canada. Your data is primarily stored on Canadian and US servers (AWS ca-central-1 and us-east-1). If we transfer data internationally, we use:
- Standard Contractual Clauses (SCCs) for EU data
- Adequacy decisions where recognized by regulators
- Data localization for health data where required by law
10. Cookies & Tracking
We use:
- Essential cookies: Required for login, security, and core functionality (no consent required)
- Analytics cookies: Google Analytics, Mixpanel — help us understand app usage (consent required)
- Marketing cookies: Pixel tags for ad attribution (consent required)
You can manage cookie preferences in Settings → Privacy → Cookie Preferences.
11. Children's Privacy
ObtAIn Fitness is not intended for users under 16. We do not knowingly collect data from children under 16. If we discover such data, we delete it immediately. Parental consent is required for users 16–18.
12. Changes to This Policy
We may update this policy as our services evolve. Material changes (especially to data sharing) require renewed consent. We notify users via email and in-app notification at least 30 days before material changes take effect.
13. Contact Us
For privacy questions, data requests, or complaints:
- Email: privacy@obtain.tech
- Mail: [Your Canadian Business Address]
- Data Protection Officer: [Name or "Contact privacy@obtain.tech"]
If you are in the EU, you also have the right to lodge a complaint with your local supervisory authority.