← Back to Pivot Wellness
Legal

Privacy Policy

Last updated: September 21, 2026

Pivot Wellness connects your health information — labs, wearables, sleep, nutrition, and medical records you choose to connect — and applies AI to read them together. That only works if you trust us with the record, so this page explains exactly what we hold, what we do with it, and what we will never do.

What we collect

  • Account information — your name, email address, and authentication details.
  • Health information you connect or enter — medical records from systems you link, wearable and phone health data you grant access to, lab results, and anything you log yourself such as meals, workouts, sleep, or mood.
  • Usage information — how you interact with the product, so we can operate and improve it.
  • Payment information — handled by our payment processor, Stripe. We do not store your full card details.

Health Connect and wearable data

Where you grant access through Health Connect on Android, Apple Health on iOS, or a connected wearable account, we read only the data types you approve — for example steps, heart rate, or sleep — and only to show them to you and to power the insights you asked for.

The types the mobile app can ask for are: activity (steps, active energy, workouts, floors climbed); heart rate, resting heart rate and heart rate variability; sleep; blood oxygen, blood pressure, blood glucose, body temperature and respiratory rate; weight, height and body fat; water intake; and mindfulness sessions. You approve each one separately, and on Android you can let the app read new data in the background so your record stays current without opening it. The app reads this data; it does not write anything back to Health Connect or Apple Health.

  • We do not sell health data, and we do not use it for advertising.
  • We do not share it with third parties for their own purposes.
  • You can revoke access at any time, in your device settings or in Pivot Wellness. We then stop receiving new data.
  • You can delete data we already hold, either specific sources or your whole account.

What the mobile app uses on your phone

The Pivot Wellness app for iPhone and Android asks for each of these only when a feature needs it. Each is a separate permission you can refuse, or withdraw later in your device settings, without losing the rest of the app.

  • Camera and photos — to photograph a meal, add a progress photo, or add a lab report, letter or scan to your record, from the camera or your photo library.
    • Meal photos are sent to Pivot Wellness so we can identify the food, and only once you have turned on photo logging. We keep what we identified with your log, not the photo.
    • Progress photos and health documents are uploaded and kept in your record, because keeping them is the point. When you add a progress photo, our AI compares it with your previous photo from the same angle and records what changed.
    • Barcodes are read on your phone; only the barcode number is sent, to look up the product.
    • Exercise form check runs entirely on your phone. The video and the body positions derived from it are never uploaded. If you choose to save a session, we receive a written summary — the exercise, the rep count and the form observations — and nothing else.
  • Microphone — so you can log a meal by saying it. Only once you have turned on voice logging, the recording is sent to Pivot Wellness and transcribed by a speech model running on hardware we own. We keep the transcript and the foods we identified with your log; we do not keep the recording.
  • Location — approximate location only, to find blood-draw sites near you when you order a lab panel, and to show local weather and air quality. If you have allowed it, the app refreshes your location when you open it, at most every few hours; it does not track you in the background. We round your position to a grid of a few kilometres before storing it, so your exact coordinates are never saved. You can type a location instead.
  • Notifications — if you allow them, your device provides a push token, which we store with a random identifier the app creates for that installation, so we can send you reminders and alerts. Notifications are delivered through Apple’s and Google’s push services (Firebase Cloud Messaging). The token is removed when you sign out.
  • Bluetooth — to connect to a Pivot Wellness wearable, and only that device. Its heart rate and motion readings are sent to your record, along with the device’s name and Bluetooth identifier so we know which band is yours.
  • Face ID, Touch ID or fingerprint — to unlock the app, if you turn that on. The check happens entirely on your phone; we never receive your biometric data.
  • Time zone — sent with each request so your days, reminders and weekly totals line up with where you are.

Photo logging and voice logging are off until you turn them on, separately from each other, and turning either off takes effect immediately. The app contains no advertising, analytics or crash-reporting software.

How we use it

To operate the Service: to show you your own record, to generate the insights and summaries the product exists to produce, to let practitioners you have explicitly granted access work with you, and to keep the platform secure and running.

AI and your data

Every AI model that reads your data runs on hardware we own. There is no third-party AI provider in the path, so your record and your questions are not sent to an outside model for processing.

We do not use your data to train anyone else’s models.

Who we share with

We do not sell, rent, or trade your health information. We share it only:

  • With practitioners you choose, at a scope you set. Paying for an engagement is not consent to share your record — granting access is a separate, explicit step, and you can withdraw it at any time.
  • With service providers who run parts of the platform, such as our payment processor, under contract and only for that purpose.
  • Where the law requires it, or to protect someone’s safety.

Security and storage

Your data is encrypted in transit and at rest, and particularly sensitive material such as the access tokens for your connected medical record systems is encrypted at the row level. Access is restricted to the people and systems that need it. See Security for the current posture in detail.

Your rights

  • Export everything, in standard formats, whenever you want.
  • Delete means delete. When you delete your account we remove your data and files and cancel any paid plan, except that a plan inside a committed term keeps billing until the term ends. A short list of records outlives it, such as the log of who accessed your health information and payment records at our processor, each named with its reason on How to delete your account, with or without signing in.
  • Disconnect any source and we stop receiving new data from it.
  • Correct your record where something we hold about you is wrong.

Regulatory status

Pivot Wellness receives your health information at your direction, as a consumer application. That generally means Pivot Wellness is not a HIPAA covered entity or business associate for this data, but is subject to the FTC Act and the FTC Health Breach Notification Rule. We apply HIPAA-grade safeguards voluntarily — encryption, access controls, data minimisation, and no sharing with advertising technology — and we will notify you and the FTC of a breach as that Rule requires.

Children

Pivot Wellness is not intended for anyone under 18, and we do not knowingly collect their data.

Changes

We may update this policy. Where a change is material we will tell you rather than quietly revise this page.

Contact

For questions about your data or this policy, contact us at privacy@pivotwellness.com.

See also our Additional Disclosures and Terms of Service.

© 2026 Pivot Wellness. All rights reserved. Not medical advice.