If you live in California or another U.S. state with consumer privacy laws (such as the CCPA/CPRA or the laws of Virginia, Colorado, Connecticut, Texas or Oregon), this section supplements the rest of this notice.
Categories of information we collect: identifiers (name, email address, profile picture and sign-in method); athletic profile data; health and activity data imported with your authorization from Health Connect or Apple Health, from files you import or entered manually; session routes (location); purchase and subscription information (plan, status and store, without card details); the push notification token; technical device, error and app usage information; and, on the website, browsing data if you accept analytics cookies.
Sensitive personal information: health and activity data and session routes (precise location) are considered sensitive information. We use it only to provide the service you request and for purposes permitted by law, such as account security; we do not use it to infer characteristics about you. Even so, you can ask us to limit its use by emailing soporte [at] ponderahealth [dot] com.
We use this information for the purposes described in this notice and only share it with the service providers listed in this notice, who may not use it for their own purposes.
Sale and advertising: we do not sell your personal information or share it for advertising based on your activity across other sites or services, and we do not use health data for advertising. There is therefore nothing you need to opt out of; if you still send us an opt-out request, we will record it.
Your rights: to know what information we hold about you, to access it and obtain a copy, to correct it, to delete it, to limit the use of sensitive information and not to be discriminated against for exercising these rights.
How to exercise them: from the app or by emailing soporte [at] ponderahealth [dot] com. We will verify your identity by checking that the request comes from your account’s email address or by asking you to confirm details of it. If you act through an authorized agent, we will ask the agent for a permission signed by you and may ask you to confirm your identity directly with us.
Timelines: we will respond within 45 days of receiving the request. When reasonably necessary we may extend that period as permitted by your state’s law, and we will let you know within the initial period.
Appeals: if you live in a state that recognizes this right (such as Virginia, Colorado, Connecticut, Texas or Oregon) and we deny your request in whole or in part, you can appeal by replying to our decision with the subject “Appeal”. We will respond in writing within the period set by your state’s law and, if we uphold the decision, we will tell you how to contact your state attorney general.
Retention by category: account, profile, health and activity data, photos, conversations, notification tokens and bug reports are kept while your account exists and are deleted when you delete it; data you delete within the app is deleted at that moment. Infrastructure backups are renewed periodically, so deleted data may remain in them for a limited time. Purchase records kept by the app stores and the subscription provider are governed by their own policies.
Browser privacy signals: if your browser sends Global Privacy Control (GPC), the website treats it as declining analytics cookies. The site does not respond to Do Not Track (DNT) signals because there is no common standard for interpreting them; in any case, we do not track you across third-party sites.