Consumer Health Data Privacy Policy
Effective: 2 September 2026 · Version: 2026-09-02
This policy explains how Octane handles consumer health data. It is separate from our general Privacy Policy and covers only this category of information.
1. Categories of consumer health data we collect, and why
We collect this only after you give consent for the specific purpose, and only what you enter or choose to connect.
| Category | What it is | Why we collect it | How we use it |
|---|---|---|---|
| Protocol records | Supplements, medications, hormones, peptides and GLP-1 medications you tell us you take; the dose and schedule you enter; the date you started or stopped; the brand; who prescribed it, if you tell us; the reason you are taking it, if you tell us | To show you your own record and work out how consistently you have taken something | Displayed back to you; used to compute adherence |
| Dose events | Each dose you record as taken or skipped, the time, and the injection site if you record one | To keep a history and compute adherence | Displayed back to you; adherence; the site-rotation history we show you |
| Reported effects | Symptoms or outcomes you choose to record, with a severity you set | So you can see patterns in your own reports | Displayed back to you; timing summaries |
| Nutrition and body data | Food and water you log; weight, body composition, activity, sleep and heart-rate data you choose to sync from Apple Health | To calculate nutrition targets and show how measurements changed over time | Targets; charts; the descriptive comparisons in the app |
| Workout records | Workouts from a fitness account you choose to connect, such as Garmin: the time, duration, distance, pace, heart rate, and the activity file your watch recorded — which can include cadence, ground contact time, running power and the second-by-second heart-rate and pace trace | To show what you actually did, judge how a session went, and set fuelling and recovery around it | Displayed back to you; training load; the fuelling and recovery figures the app computes |
We do not collect location data of any kind for health purposes, and we do not operate a geofence around any health facility. The activity file a connected watch records may contain the GPS trace of a workout; Octane does not derive location, visits or places from it. If you opt in to route outlines on share cards (off by default), the shape of a run — with its first and last 300 metres removed and no coordinates, scale or compass reference — appears only on cards you choose to publish. See the Privacy Policy for the full description.
2. Where the data comes from
- You, when you enter it in the app.
- Apple Health, only for categories you explicitly authorise on your device. Medication data from Apple Health is read-only — we can import it and cannot write to it.
- A fitness account you connect yourself, such as Garmin. You start this in Settings → Connected devices and approve it on that provider's own page; we never see or hold your password for it. Nothing is imported before you approve it, and disconnecting stops further imports immediately.
- We do not buy, licence or otherwise obtain consumer health data about you from any third party, and we do not infer it from your activity elsewhere.
3. Categories of consumer health data we share, and with whom
We do not sell consumer health data. We do not share it with advertisers, advertising networks, data brokers, or analytics providers, and Octane contains no third-party tracking SDK.
Data is disclosed only to service providers that operate the product on our behalf, under contract, and only for that purpose:
| Recipient category | Specific provider | What reaches them | When |
|---|---|---|---|
| AI providers | Anthropic (Claude); Google (Gemini) | The compounds you are currently taking, the dose and schedule you entered, how long you have been taking them, the reason you gave, and effects you reported — as context for nutrition advice | Only if you separately opt in to AI processing. Withdraw it and this stops on the next request. |
| Hosting and database | DigitalOcean (application and database hosting) | All stored data, at rest on our infrastructure | Always, as the place the product runs |
| Content delivery / TLS | Cloudflare | Encrypted traffic in transit | Always |
| Email delivery | Our SMTP provider | Coaching emails you have enabled, which may reference compounds if you opted into AI processing | Only if you enable those emails |
| Device connections | Stridee | The account identifier for the fitness provider you connect, so it can fetch your workouts on our behalf. Your workout data passes through Stridee from that provider to us. We send them no nutrition, protocol or body data. | Only if you connect a device, and only until you disconnect |
| Subscription management | Apple (App Store billing) | Subscription status and purchase records only — no health data | Always, for billing |
| Error monitoring | Sentry | Technical error and crash diagnostics (app version, device model, stack traces) — no health data; reports are scrubbed before sending | Always, to keep the product working |
| Training-plan sources | Intervals.icu; Runna | Nothing. We read your planned workouts from them; we send them no data about you | Only if you connect one |
4. Your rights, and how to use them
All of these are in the app under Settings → Protocol & health data, and take effect immediately.
| Right | What it does | How |
|---|---|---|
| Withdraw consent | Stops future collection, or future AI processing, or both | Settings → withdraw. Withdrawing collection consent also withdraws AI processing. |
| Delete | Permanently removes every protocol, dose and reported effect | Settings → delete. This is a hard delete, not an archive. Existing sessions are signed out so no device keeps a live copy. |
| Access / obtain a copy | A machine-readable export of everything we hold in these categories, including your consent history | Settings → export |
| Know who received it | The list in §3; if you want confirmation for your own account specifically, contact us | Contact below |
We will authenticate a request made outside the app before acting on it.
5. How we protect it
- Access is limited to what is necessary to run the product. Health data is not browsable by staff for support purposes.
- The admin profile switcher cannot see protocol data. Octane lets an administrator view another household member's food and training records read-only; medications, doses and reported effects are deliberately excluded from that view.
- Encrypted in transit (TLS).
- Health values never appear in application logs, error messages or metrics — counts and error codes only.
- Consent records are retained after withdrawal as the record that consent was given and later withdrawn. They contain no health data.
6. Changes
If we change the categories we collect, the purposes, or who receives the data, we will publish an updated version and ask for your consent again. We do not carry an old consent forward onto new terms.
7. Contact
To ask a question about this policy, or to exercise any right in section 4:
- In the app: Settings → Protocol & health data. Withdrawal, export and deletion all take effect immediately, without needing to contact us.
- By email: privacy@careyos.com
We will respond within 45 days, and will tell you if we need longer.