| What this notice is. This Consumer Health Data Privacy Notice (the “Notice”) describes how Atelo Information Technology Ltd (doing business as “shedio”) (“shedio”, “we”, “us”, or the “Company”) collects, uses, shares, and protects “consumer health data” about individuals who are residents of U.S. states with specific consumer-health-data laws, including Washington (My Health My Data Act, RCW 19.373), Nevada (SB 370 (2023); NRS 603A.400–603A.550), and Connecticut (the consumer-health-data provisions of SB 3 amending the Connecticut Data Privacy Act), and equivalent provisions under other state or federal laws that may apply from time to time. Relationship to our main Privacy Policy. This Notice supplements — but does not replace — our main Privacy Policy available at https://shedio.life/privacy. If you are not a resident of a state with a consumer-health-data law, the main Privacy Policy governs our processing of your personal data. In the event of a direct conflict between this Notice and the Privacy Policy with respect to consumer health data of residents covered by this Notice, this Notice prevails. How to reach us. For any question about this Notice, to exercise a right described here, or to lodge a concern, contact us at support@shedio.life with the subject line “Consumer Health Data Request.” |
|---|
Contents
- Definitions
- Categories of consumer health data we collect
- Sources of consumer health data
- Purposes and uses of consumer health data
- Sharing, selling, and disclosure
- Your rights and how to exercise them
- How to appeal our decision
- Security and retention
- Geofencing around health-care facilities
- Children
- Changes to this Notice
- Contact
1. Definitions
“Consumer health data” means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer’s past, present, or future physical or mental health status. This includes, without limitation, information that identifies a consumer’s attempt to seek health services, biometric data, genetic data, bodily functions, measurements, diagnoses, treatments, medications, and conditions. The Washington My Health My Data Act (“MHMDA”) uses a broad definition in RCW 19.373.010 that includes data “derived or extrapolated” from non-health information (for example, inferences made from purchase history or device data). “Consumer” means a natural person who is a resident of a state covered by this Notice and who: (i) interacts with the Service in a personal or household context; or (ii) has had consumer health data collected about them that is linked or reasonably linkable to that individual. Consistent with the MHMDA, it does not include individuals acting in an employment context. “Process” / “Processing” means any operation or set of operations performed on consumer health data, whether or not by automated means, including collection, use, storage, disclosure, analysis, deletion, modification, or any other action. “Sale” means, for purposes of this Notice and consistent with the MHMDA, the exchange of consumer health data for monetary or other valuable consideration. “Regulated entity” is the term used by the MHMDA for an entity that (a) conducts business in Washington or (b) produces or provides products or services that are targeted to Washington consumers, and that (c) alone or jointly determines the purposes and means of the processing of consumer health data. For purposes of this Notice, we are a regulated entity with respect to Washington consumers, and we apply equivalent standards to consumers covered by other state consumer-health-data laws.
2. Categories of consumer health data we collect
We may collect the following categories of consumer health data. Not every category applies to every user — the actual scope depends on the features you choose to use and the information you choose to share with us.
| Category | Examples |
|---|---|
| Physical characteristics | Height, weight, body measurements, age, sex, biological sex at birth (if voluntarily shared), body mass index (BMI) we derive from the height and weight you provide, and any progress photograph you may choose to upload. |
| Fitness and activity | Workouts you complete, duration, intensity, perceived effort, step count, heart-rate zones, active and resting energy, training progress, missed sessions, rest-day patterns. |
| Nutrition and dietary | Dietary preferences, allergies, intolerances, the meal plan generated for you, and any food, meal, or water intake you may choose to log. |
| Health goals and status | Weight-management goals, fitness goals, motivations, self-reported energy levels, stress or sleep concerns, pre-existing conditions you choose to disclose (for example, to avoid exercises contraindicated for a specific condition). |
| AI coach conversations | What you say to the AI coach, and the responses it generates. Because these conversations often concern your body, food, and health, we treat them as consumer health data. |
| Wearable and Health App data | Data you enable us to read from Apple Health, Google Health Connect, or a connected wearable device (for example, heart rate, heart-rate variability, sleep, distance covered). |
| Inferences and derived data | Analyses we derive from the data above — for example, estimates of calories burned, predicted progress toward a goal, or suggested adjustments to your plan. Consistent with the MHMDA, inferences about your health made from non-health inputs are treated as consumer health data. |
| What we do not collect. Reproductive and sexual health. shedio does not offer cycle tracking, pregnancy or post-natal programmes, or any other reproductive or sexual health feature, and we do not collect reproductive or sexual health information. Biometric and genetic data. We do not collect biometric data or genetic data: we do not perform body scanning, face recognition, or posture or movement analysis, and we do not collect voice recordings, iris scans, fingerprint templates, or DNA-level genetic data. Mental health. We do not offer mindfulness, meditation, or mood-tracking features, and we do not ask you for information about your mental health. If you choose to tell us something about it — for example, in a conversation with the AI coach — we treat it as consumer health data and protect it accordingly. Sexual orientation. We do not ask for it. |
|---|
3. Sources of consumer health data
We receive consumer health data from three main sources:
3.1. Directly from you
When you register, go through our onboarding questionnaire, set goals, complete workouts, talk to the AI coach, chat with our support team, or respond to an in-App survey, you may provide consumer health data to us.
3.2. From third parties with your permission
We may receive consumer health data from:
- Apple Health and the Apple Motion & Fitness API, on iOS/iPadOS/watchOS/macOS devices — only with permissions you grant on the Apple-native consent screen.
- Google Health Connect on Android devices — only with permissions you grant on the Google-native consent screen.
- Connected wearable devices (for example, Apple Watch, Fitbit, Garmin, Whoop, Oura, or similar), where you have authorized the integration.
| Your device-level control. You can revoke our read/write access to Apple Health, Google Health Connect, or a connected wearable at any time, directly in your device settings or in the applicable app — no request to us is required. Revocation does not retroactively delete data we already received. To request deletion of previously received data, use the rights in Section 6. |
|---|
3.3. Automatically from your use of the Service
As you use the Service, we derive consumer health data from your activity: workout completions, streaks, plan adherence, estimated caloric expenditure, and similar inferences. This data is consumer health data to the extent it reveals information about your physical or mental health status.
4. Purposes and uses of consumer health data
We use consumer health data only for the purposes described below, and only to the extent necessary for each purpose.
- Provide the Service. Generate and personalize your workout plan, meal plan, progress insights, and other features you request.
- Service communications. Send you reminders, motivational messages, and notifications related to your plan (for example, a daily workout reminder). You can manage these in the App settings.
- Improve the Service. With your consent, analyze how features are used in aggregate and develop new features. We use de-identified or aggregated data for this where possible.
- Customer support. Respond to inquiries and troubleshoot issues you report to us.
- Security and fraud prevention. Detect and investigate fraudulent or abusive activity.
- Legal, regulatory, and defensive purposes. Comply with legal obligations, respond to lawful government requests, defend against claims, and enforce our Terms and Conditions of Use.
| What we do NOT do with your consumer health data: • We do not sell it. • We never disclose it — or any inference we draw from it — to any third-party advertising, marketing, or analytics partner, for cross-context behavioural advertising or for any other purpose, and we never use it to build a custom audience, a lookalike audience, or any other advertising segment. This is absolute: it does not depend on your consent, and you cannot opt in to it. • It is not collected through cookies, SDKs, pixels, or any other tracking technology, and it is never transmitted to an advertising or analytics partner — whether through a browser pixel, a mobile SDK, or a server-side API. • It is never used by our AI providers to train, fine-tune, or otherwise improve their own models. • We do not use it for profiling that produces legal or similarly significant effects on you. • We do not use consumer health data received from Apple Health or Google Health Connect for any purpose beyond the features you requested, consistent with Apple’s HealthKit Terms and Google’s Health Connect Terms. What we may do, if you consent to marketing: if you have given us your separate, optional consent to receive marketing, we may use your goals, your progress, and how you use the Service to decide what to send you in our own emails, in-App messages, and push notifications. That stays with us — it is never disclosed to anyone else — and you can withdraw the consent at any time without affecting your access to the Service. |
|---|
5. Sharing, selling, and disclosure
| In short: we do not share your consumer health data with third parties or affiliates, and we do not sell it. We do disclose it to service providers who process it on our behalf, under contract and only on our instructions, in order to deliver the Service you asked for. There is one narrow exception: where it is necessary to respond to fraud or other malicious or deceptive activity — described in Section 5.1.1. |
|---|
5.1. We do not share consumer health data
“Share” has a specific meaning under Washington’s My Health My Data Act (RCW 19.373.010(27)): it means disclosing consumer health data to a third party or an affiliate. It expressly does not include disclosing consumer health data to a processor — a service provider that processes the data on our behalf — where that disclosure is made in order to provide the goods or services for which the data was collected, consistent with what we told you.
We do not share your consumer health data with any third party or affiliate, except as described in Section 5.1.1. In particular:
- We do not disclose consumer health data to advertising, marketing, or analytics partners, for cross-context behavioral advertising or for any other purpose.
- We have no affiliates (see Section 5.3).
- If we ever wish to share your consumer health data with a third party for any purpose other than the one described in Section 5.1.1, we will first obtain your consent for that sharing, and that consent will be separate and distinct from the consent you gave for collection, as required by RCW 19.373.030(1)(b).
5.1.1. The one exception: responding to fraud
Where it is necessary to prevent, detect, protect against, or respond to fraud, identity theft, a security incident, or other malicious or deceptive activity, we may disclose specific consumer health data as evidence — for example, to our merchant of record or payment provider when defending a chargeback that we have determined to be fraudulent. This is permitted by RCW 19.373.100(3) and, where the GDPR applies, by Article 9(2)(f) (establishment, exercise, or defence of legal claims). We bear the burden of showing that any such disclosure qualifies, and we keep a record of the basis for each one.
This exception is narrow, and it does not apply to ordinary disputes. Where a payment dispute is an ordinary consumer dispute — for example, a claim that the Service was not provided, was not as described, or that a subscription was not cancelled — we do not disclose your consumer health data. In those cases we rely only on records of your access to and use of the Service, such as the times you signed in, the date your plan was generated and delivered to you, and when you were last active. Those records show that the Service was delivered and used; they are not health data, and we do not enrich them with health data.
We never disclose consumer health data to a payment provider for any purpose other than the one described in this Section 5.1.1.
5.2. Service providers (processors) who handle consumer health data on our behalf
We do disclose consumer health data to the following categories of processors, each of which acts only on our documented instructions, under a data processing agreement that requires appropriate security and confidentiality, and none of which may use your data for its own purposes:
| Category of processor | What they do for us |
|---|---|
| Cloud hosting and storage providers | Host the Service and securely store your data on our behalf. |
| Video delivery and transcoding providers | Encode, store, and stream workout video content to you. |
| Product monitoring and error-reporting providers | Detect and fix faults and maintain service stability. |
| AI and machine-learning providers | Generate your personalized plans and operate the AI coach, under a data processing agreement that prohibits any use for the provider’s own purposes, including the training of the provider’s own models. |
| Customer support platforms | Operate our support help desk when you contact us. |
Our payment providers do not receive consumer health data, except in the narrow fraud situation described in Section 5.1.1. In the ordinary course they receive only the information needed to take payment — such as your name, email address, billing country, and the amount — and never your health, body, fitness, or nutrition data.
Two further disclosures are required by law rather than chosen by us, and are permitted under the Act:
- Legal, safety, and regulatory disclosures — to law enforcement, courts, or regulators, only where required by law or to respond to a valid legal request, or where necessary to prevent imminent harm.
- Business transactions — if we are involved in a merger, acquisition, bankruptcy, or sale of assets, consumer health data may transfer as an asset. Any successor will be required to comply with this Notice and with the Act.
5.3. Specific affiliates
Consistent with RCW 19.373.020(1)(a)(iv), we disclose the categories of third parties and the specific affiliates with whom consumer health data is shared.
Specific affiliates: none. Atelo Information Technology Ltd is our only legal entity. We have no affiliates. Categories of third parties: none. As explained in Section 5.1, we do not share consumer health data with any third party.
5.4. “Sale” of consumer health data
We do not sell consumer health data for monetary or other valuable consideration. We do not condition the provision of any part of the Service on your consent to sell consumer health data.
5.5. No disclosure of consumer health data for advertising
We do not disclose consumer health data to third parties for the purpose of cross-context behavioral advertising, targeted advertising, profiling, or other advertising or marketing purposes. Other than as described in this Section 5, consumer health data is not collected through cookies, SDKs, pixels, or any other tracking technology, and it is never transmitted to advertising or analytics partners.
6. Your rights and how to exercise them
If you are a resident of Washington, Nevada, Connecticut, or another state that provides specific consumer-health-data rights, you have the following rights with respect to your consumer health data. These rights apply in addition to any rights described in our Privacy Policy.
6.1. Right to confirm and access
You have the right to confirm whether we are processing your consumer health data, and to receive a copy of such data. The third parties and affiliates with which we may share consumer health data are identified in Section 5 of this Notice.
6.2. Right to delete
You have the right to request that we delete your consumer health data. We will honor your request unless we are permitted or required by applicable law to retain specific data — for example, to comply with tax or accounting obligations, or to defend against legal claims (see Section 8).
6.3. Right to withdraw consent
Where we rely on your consent to collect, share, or process consumer health data, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted before the withdrawal, and it does not affect processing that is permitted on another legal basis (for example, processing necessary to perform the contract with you, or to comply with a legal obligation).
6.4. Right of non-discrimination
You have the right not to be discriminated against for exercising any of the rights in this Notice. We will not deny you the Service, charge you a different price, or provide you with a lower quality of Service because you exercised a right — unless the difference reflects the value of the Service provided.
6.5. How to submit a request
You may submit a request by email to support@shedio.life, with the subject line “Consumer Health Data Request.” You can also delete your account, and the data associated with it, directly in the shedio App (Profile → Account Settings → Delete Account). If you would like to obtain a copy of the consumer health data we hold about you, you may make such a request at any time by contacting us at support@shedio.life, and we will review and handle your request in accordance with the applicable provisions of this Notice and any conditions, limitations, or requirements that may apply under the consumer-health-data law relevant to you. For authorized agents submitting a request on your behalf, we may require proof of the agent’s written authorization (for example, a signed permission or a valid power of attorney), and we may contact you directly to confirm the request.
6.6. Verification
To protect your data, we may ask you to verify your identity before acting on a request — for example, by confirming the account email, the date the account was created, and a recent transaction. For sensitive requests we may require stronger verification.
6.7. Response timeframes
We will respond to your request within the timeframe required by the consumer health data law that applies to you, and we may extend that period where, and to the extent that, the applicable law permits — in which case we will tell you about the extension and the reason for it. Requests are processed free of charge, except that we may charge a reasonable fee (or decline) if a request is manifestly unfounded, excessive, or repetitive.
7. How to appeal our decision
If we decline your request in whole or in part, you may appeal. To appeal, email support@shedio.life with the subject line “Consumer Health Data — Appeal.” Please include your original request, our response, and a brief explanation of why you believe the decision was incorrect. We will inform you of our appeal decision and the reasoning in writing within a reasonable timeframe, and in any event within the period required by applicable state law. If the appeal is also denied, you may contact the applicable state authority:
- Washington: Attorney General of Washington, Consumer Protection Division, at https://www.atg.wa.gov/file-complaint.
- Nevada: Office of the Nevada Attorney General, Bureau of Consumer Protection, at https://ag.nv.gov/Complaints/.
- Connecticut: Office of the Connecticut Attorney General, at https://portal.ct.gov/AG.
8. Security and retention
8.1. Security
Consistent with RCW 19.373.050, we (a) restrict access to consumer health data to those of our employees, processors, and contractors for whom access is necessary to further the purposes for which the data was collected, and (b) establish, implement, and maintain administrative, technical, and physical data-security practices that, at a minimum, satisfy a reasonable standard of care within our industry to protect the confidentiality, integrity, and accessibility of consumer health data. These measures are described in Section 6 of our Privacy Policy and include, at minimum, encryption in transit and at rest, role-based access controls, multi-factor authentication for staff, continuous monitoring, incident-response planning, and periodic third-party security assessments.
8.2. Retention
We retain consumer health data only for as long as reasonably necessary to provide the Service and fulfill the purposes described in this Notice, unless a longer retention period is required or permitted by applicable law. The criteria we apply are described in Section 5 of our Privacy Policy. After account deletion or an approved erasure request, we delete or de-identify consumer health data in our production systems within 30 days, except where retention is required for tax, legal, fraud-prevention, or dispute-defence purposes. We do not carry out point-in-time deletion inside our backups: those backups are held in isolated storage, are used only to restore the Service after a failure, and are overwritten on a rotating cycle of no more than 90 days.
8.3. Breach notification
In the event of a breach of security affecting consumer health data, we will notify affected individuals and the appropriate authorities within the timeframes required by applicable law. Depending on the nature of the incident, those authorities may include state attorneys general and the U.S. Federal Trade Commission under the Health Breach Notification Rule (16 C.F.R. Part 318). For these purposes, we treat an unauthorized disclosure of consumer health data that results in unauthorized acquisition — not only an intrusion by an outside attacker — as a reportable breach.
9. Geofencing around health-care facilities
| Geofence restrictions. Washington, Nevada, and Connecticut each prohibit the use of a geofence around health-care facilities to identify or track consumers, to collect consumer health data, or to send them messages or advertisements relating to their consumer health data or to health-care services. The prohibited radius differs by state: Washington — 2,000 feet (RCW 19.373.080; “geofence” is defined in RCW 19.373.010(14) as a virtual boundary within 2,000 feet of the perimeter of a physical location), around any entity providing in-person health-care services; Nevada — 1,750 feet (NRS 603A.540), around a medical facility, a facility for the dependent or other provider of in-person health-care services or products; Connecticut — 1,750 feet (Conn. Gen. Stat. § 42-526(a)(1)(C)), around any mental-health facility or reproductive or sexual health facility — and in Connecticut this prohibition is absolute and cannot be waived by your consent. Our commitment. We do not use geofencing technology to identify or track consumers seeking health-care services, to collect consumer health data, or to send messages or advertisements relating to consumer health data or to health-care services. This commitment is about what we do not do with the technology, and it is not limited to the radii defined by state law. Where you enable location-based features such as outdoor run tracking, we use your location only While In Use and only to record your route and distance for that feature; we do not use precise geolocation for advertising, behavioral profiling, or to infer a consumer’s interaction with any health-care provider. |
|---|
10. Children
The Service is intended for users aged 18 and over, and we do not knowingly collect consumer health data from individuals under 18. If you are a parent or guardian and believe that a child under 18 has provided consumer health data to us, please contact us at the address in Section 12 and we will take reasonable steps to delete that data promptly.
11. Changes to this Notice
We may update this Notice from time to time. Consistent with RCW 19.373.020(1)(c)–(d), we will not collect, use, or share categories of consumer health data, or use consumer health data for purposes, that are not disclosed in this Notice without first disclosing the additional categories or purposes and obtaining your affirmative consent. If we make a material change, we will notify Washington consumers and consumers in other covered states — typically by a prominent notice on our website, in-App message, or email. The “Last Updated” date at the top of this Notice reflects the most recent update.
12. Contact
For any question about this Notice, to exercise a right, or to appeal a decision:
- Privacy and data-protection inquiries: support@shedio.life
- Mailing address: Atelo Information Technology Ltd (d/b/a “shedio”), 1226 North King St Num 1382, Wilmington, DE 19801, USA Controller: Atelo Information Technology Ltd (d/b/a “shedio”), a Delaware corporation. Last Updated: July 20, 2026
Changelog
This is the initial version of the shedio Consumer Health Data Privacy Notice. Future revisions will be noted here.
