Consumer Health Data Privacy Policy

Effective Date: July 23, 2026
Last Updated: July 24, 2026

This notice supplements Iridium's Privacy Policy and explains how Autumn Creek Press, LLC ("Iridium," "we," "us," or "our") handles consumer health data. It includes disclosures and rights for residents covered by Washington's My Health My Data Act and Nevada's consumer-health privacy law.

1. Consumer Health Data We May Process

Depending on the features you choose, consumer health data can include:

  • Fitness profile and goals, experience, schedules, equipment, gyms, and workout plans or history.
  • Exercises, sets, weights, repetitions, RPE, rest, notes, personal records, training volume, fatigue, and readiness or recovery information.
  • Nutrition, calorie, macro, food, barcode, hydration, sleep, activity, body-measurement, and related entries.
  • HealthKit information you authorize Iridium to read or write.
  • Location and weather context used for a feature you request.
  • Injury, limitation, symptom, or other health-related information you enter in instructions, feedback, support requests, AI prompts, conversations, images, video, or audio.
  • Inferences or recommendations generated from the information above, including proposed workouts, recovery context, or nutrition-related output.

2. Sources

We can receive consumer health data from:

  • You, including information and media you enter or submit.
  • Your device and your use of Iridium features.
  • Apple HealthKit, WeatherKit, and other Apple services you authorize.
  • Services you deliberately connect, including External Data Sync clients or agents and nutrition-lookup providers.
  • Service providers that return results for a request, such as an AI-generated response or food-search result.

3. How We Process It

  • On your device: most profile, workout, nutrition, recovery, and HealthKit information is stored and used by the app locally.
  • Through Apple services: records can be read from or written to HealthKit; supported app records can synchronize through CloudKit/iCloud; Apple can include eligible data in device backups; and WeatherKit processes location for requested weather context.
  • On Iridium servers: optional analytics, External Data Sync, feedback, account, shared-link, security, and support features can store or transmit the applicable categories described below.
  • Through AI and lookup providers: Iridium sends a request and relevant context to routing, model, voice, food, or media providers and receives a result.
  • Through support and development workflows: authorized people and tools can review reports, correspondence, diagnostics, attachments, or AI triage to respond to a request or address a problem.

4. Why We Collect and Use It

We collect or use consumer health data to:

  • Provide and personalize the fitness, workout, nutrition, recovery, and AI features you request.
  • Synchronize or export information when you deliberately enable those features.
  • Respond to support, feedback, privacy, safety, and security requests.
  • Improve reliability and product design through optional first-party app analytics.
  • Protect the Services, comply with law, and establish or defend legal claims.

We do not sell consumer health data, use it to place health-related advertisements, or permit geofencing around health-care facilities to identify or infer a person's health services.

Iridium processes pseudonymous product analytics only when you affirmatively enable Help Improve Iridium. See the Privacy Policy for the categories, controls, and deletion-request path.

5. Consumer Health Data We Disclose and the Recipients

Depending on your choices and the feature, we can disclose the following categories of consumer health data for the listed purposes:

  • Apple: HealthKit records; supported workout, nutrition, profile, and settings records synchronized through CloudKit/iCloud; location used for WeatherKit; eligible app backup data; notification metadata; and purchase/entitlement information. Purpose: provide the Apple feature, synchronize/restore data, notify you, or unlock access. Contact: Apple Privacy Contact.
  • AIProxy, OpenRouter, downstream AI providers, and ElevenLabs: prompts, custom instructions, fitness profile, goals, workout, nutrition, recovery, HealthKit-derived, location/weather, memory, image/video, and voice context needed for the AI or voice feature. Purpose: route, authenticate, protect, and answer the request. Providers can include OpenAI or Google. Contacts: AIProxy, OpenRouter, OpenAI, Google, and ElevenLabs.
  • DigitalOcean and Neon: optional app analytics categories; supported workout, nutrition, profile, settings, and training data uploaded through External Data Sync; and feedback, account, support, or security records. Purpose: host the applicable Iridium service, database, and backups. Contacts: DigitalOcean and Neon.
  • Iridium's food-search service and Open Food Facts: a food query, barcode, and ordinary request data. Purpose: return nutrition lookup results. Contact: Open Food Facts.
  • Publitio, OpenRouter/model providers, OpenAI Codex, and GitHub: report text, workout/health context included in a report, diagnostics, chat context, and submitted screenshots or other media. For feature requests, the private title and description can also be processed to draft administrator-reviewed public copy with likely identifying details removed. Purpose: store media, triage a report, prepare public feature copy, correspond about it, or run an administrator-initiated development workflow. Contacts: Publitio, OpenAI, and GitHub.
  • Netlify, Resend, and Pushover: website request data; health-related text or context a person includes in feedback/support correspondence; and notification content or metadata. Purpose: host the website and server routes, send correspondence, and notify authorized administrators. Contacts: Netlify, Resend, and Pushover.
  • Google Analytics: if your website choice permits it, public home, blog, comparison, and screenshot route/interaction information. Exercise-library, exercise-detail, legal, account, support, shared-data, and administration pages are excluded. Purpose: consented website measurement. Contact: Google.
  • Your authorized recipient: workout, nutrition, profile, settings, training, gym, or other information exposed through a compatible External Data Sync client, agent, or shared link you authorize. Purpose: complete your chosen sharing or sync action.

Providers can use subprocessors and their contact information may change. Contact our Interim Privacy Officer for the current recipient information relevant to your request.

Iridium does not currently sell consumer health data or disclose it to a corporate affiliate.

6. Your Consumer Health Data Rights

Subject to applicable law, you may ask us to:

  • Confirm whether we collect, share, or sell your consumer health data.
  • Provide access to consumer health data and a list of all third parties and affiliates with whom we shared or sold it, together with an active contact method where required.
  • Correct inaccurate consumer health data.
  • Withdraw consent for future collection or sharing.
  • Delete consumer health data, including directing applicable processors and other recipients to delete it.

Email hello[at]iridium[dot]fit with the subject Consumer Health Data Request. Do not include health details in the first message. We will respond with secure authentication steps appropriate to the records involved. You may use an authorized agent where applicable, subject to verification of the agent's authority and your identity.

For a Washington-covered request, we respond without undue delay and no later than 45 days after receipt; authentication does not extend that deadline. Where allowed, we may extend once by up to 45 additional days and will explain why. For a Nevada-covered request, we normally respond within 45 days after authentication and may take one permitted extension with notice. Deletion from archived or backup systems will be scheduled as soon as practicable and, for a Washington-covered request, no later than six months after authentication. A narrow record may be retained when law permits or requires it.

7. Appeals

If we deny your request, you may appeal by emailing hello[at]iridium[dot]fit with the subject Privacy Appeal and a short explanation. We normally respond to an appeal within 45 days. If an appeal is denied, we will explain the decision and provide the applicable regulator or attorney-general contact where required.

8. Retention

We retain consumer health data only while it is reasonably needed for the feature or purpose described above, an active request, security, legal obligations, or a documented legal hold. Optional raw app analytics are retained for up to 24 months unless they are deleted sooner in response to a verified request. Backup copies can remain until the applicable backup cycle expires. Contact the Interim Privacy Officer for the schedule applicable to a specific record.

9. Cross-Site Collection and Do Not Track

Third-party content or service providers can receive request, device, referrer, or interaction information over time and across websites when their hosted content or services load. For example, Publitio can receive requests for exercise media, and Google Analytics can receive the limited public-page information described above only if you allow it. Iridium does not respond to browser Do Not Track signals and does not authorize these providers to use consumer health data collected through Iridium for their own targeted advertising.

10. Changes and Contact

We will post changes here and update the date above. When law requires, we will provide additional notice or obtain consent before materially expanding collection, use, or disclosure.

Interim Privacy Officer
Autumn Creek Press, LLC
1203 W. Appaloosa Ln.
Lehi, UT 84043 USA
hello[at]iridium[dot]fit
https://iridium.fit