| This Privacy Policy explains how Atelo Information Technology Ltd (doing business as “shedio”), a Delaware corporation with its principal place of business at 1226 North King St Num 1382, Wilmington, DE 19801, USA (“shedio”, “we”, “us”, or the “Company”), collects, stores, uses, shares, and protects your personal data in connection with your use of the shedio mobile applications, the shedio web app at https://shedio.app, our websites (including https://shedio.life), and all related services, features, and content (collectively, the “Service”). This Privacy Policy is an information notice. It is not a consent form, and using the Service is not treated as your consent to anything described in it. Where we need your consent — in particular, to process health and other special category data — we ask for it separately and expressly, through a consent screen in the App, and you can withdraw it at any time. The legal bases we rely on for each purpose are set out in Section 2. The Service is intended only for people aged 18 or over, or the age of majority in your jurisdiction if that is higher (see Section 7). Any translation of this Privacy Policy from the English version is provided for your convenience only. In the event of any difference in meaning between the English version available at https://shedio.life/privacy and any translation, the English version will prevail and is the sole legally binding version. |
|---|
Contents
- Categories of personal data we collect
- Purposes and legal bases for processing
- How we share your personal data
- International data transfers
- Data retention
- Security of your personal data
- Children and minors
- Your privacy rights (general)
- EEA, UK, and Switzerland (GDPR / UK GDPR)
- United States — California, Virginia, Colorado, Connecticut, Utah, and other state laws
- Washington, Nevada, and Connecticut (Consumer Health Data)
- Other countries
- Artificial intelligence and automated processing
- Cookies and similar technologies
- Changes to this Privacy Policy
- Contact
1. Categories of personal data we collect
We collect personal data from three sources:
- (i) Data you provide directly to us (for example, when registering, completing our onboarding questionnaire, setting fitness or nutrition goals, or messaging our support team).
- (ii) Data we receive from third parties (for example, when you grant access to Apple Health or Google Health Connect, or when our payment processors confirm a transaction).
- (iii) Data we collect automatically (for example, device data, IP address, and analytics events generated as you use the Service).
1.1. Data you provide directly
Identifiers and account information When you create an account, you may provide your name, email address, date of birth or age, gender, and any other profile information you choose to provide. You can sign in to shedio in two ways: (a) with a one-time code (OTP) sent to your email address; or (b) with an email address and a password, which we store only as a salted hash — we do not store plain-text passwords. shedio does not offer sign-in with Apple, Google, Facebook, or any other third-party identity provider, and we therefore do not receive any identifiers from such providers. Onboarding and personalization data During onboarding and ongoing use, you may provide:
- Physical characteristics: height, weight, body measurements, age, sex, biological sex at birth (if voluntarily shared).
- Fitness and wellness information: current fitness level, activity habits, preferred workout styles (home vs. gym, cardio vs. strength), workout history, perceived effort, heart-rate zones, estimated calories burned, and training progress.
- Nutrition and dietary information: dietary preferences, allergies, intolerances, meal preferences, and any food, meal, or water intake you may choose to log.
- Goals and motivations: your stated goals (weight management, muscle gain, improved endurance, stress reduction, sleep), motivations, barriers, and lifestyle patterns.
- Pre-existing conditions: information you choose to share about a condition or injury, for example so that we can avoid exercises that are contraindicated for you.
| Special category / sensitive data. Some of the data above may be classified as “special category data” under the EU/UK GDPR (Article 9), as “sensitive personal information” under U.S. state privacy laws (for example, CPRA), or as “consumer health data” under Washington’s My Health My Data Act and similar laws. Where the law requires, we will ask for your explicit, opt-in consent before processing such data, and we describe additional protections in Section 11. You can withdraw your consent at any time in the App settings. |
|---|
User-generated content Any content you upload to the Service (for example, a profile avatar, a progress photograph, body measurements, workout notes, or reviews) is processed as personal data. shedio does not provide user-to-user messaging, public profiles, feeds, or social sharing, so your content is not visible to other users. Please still use discretion in what you choose to share. Camera and photo-library access If you choose to set a profile avatar, or to upload a progress photograph, we ask your permission to access your device camera and/or photo library, using your device’s native permission prompt. We access the camera or photo library only at the moment you choose to add or change such an image, and only for that purpose. We do not perform food recognition, body scanning, posture or movement analysis, or any other image analysis on photos you provide, and we never use them for advertising. You can revoke this permission at any time in your device settings; doing so only prevents you from uploading a new image. AI coach conversation data If you use our coach feature, we process the messages you send and receive in that conversation, together with the profile and onboarding data used to generate responses. The coach is powered by artificial intelligence, not a human coach, and your messages are processed by our AI provider as described in Section 13. Because these conversations often concern your body, food, and health, we treat them as health-related data and process them accordingly (see Sections 2.1 and 11). Please do not share confidential information, payment details, or the personal data of other people in your conversations with the coach. Payment and commercial information When you purchase a subscription or an add-on, your payment card details, billing address, and transaction information are collected by our payment processor, by our merchant of record, or by the App Store you purchased through, as applicable. We will tell you at checkout who the seller for your purchase is. We do not store your full card number, CVV, or expiration date. We receive only a transaction confirmation and a tokenized reference, plus the information necessary for tax calculation and fraud prevention, such as country and postal code. Our payment providers do not receive your health, body, fitness, or nutrition data, except in the narrow situation described in our Consumer Health Data Privacy Notice, Section 5.1.1 (responding to fraud). Customer support and communications If you contact our support team, we collect the content of your message, your email address, any attachments, and metadata about the exchange (timestamps, channel, device). If you talk with an AI-assisted support agent, your message contents may be processed by our AI provider as described in Section 13.
1.2. Data we receive from third parties
Apple Health, Google Health Connect, and wearables
| Health App integration. With your express permission, we may read from and/or write to Apple Health (and the Apple Motion & Fitness API), Google Health Connect, and compatible wearables (such as Apple Watch, Fitbit, Garmin, Whoop, or similar devices). The specific data categories are shown to you on Apple’s or Google’s native consent screens, which we do not control. Typical read categories: step count, distance covered, workouts, active and resting energy, body mass, heart rate, sleep, and any additional categories you choose on the consent screen. Typical write categories: workouts you complete in shedio and body mass you log. Your control. You can revoke our read or write access at any time, directly in the Apple Health App or Google Health Connect settings. Revocation does not delete data we previously received — to delete that data, use the request channels in Section 8. Data minimization. We do not use Apple Health or Google Health Connect data for advertising, targeting, or sale, and we do not share data received through HealthKit with third parties except as strictly necessary to provide the Service (for example, cloud hosting of your workout history). This complies with Apple’s HealthKit Terms and Google’s Health Connect Terms. |
|---|
Payment processors and fraud-prevention providers Our payment processors (see Section 3) confirm transactions, transmit tokenized card identifiers for renewals, and may share fraud signals (for example, IP reputation, velocity, chargeback history) to help us prevent abuse. Referrals and marketing attribution If you reach us via an advertising partner, affiliate, or referral, the applicable partner may share an attribution identifier so we can evaluate campaign effectiveness. We do not use a mobile measurement partner or any other device-level attribution provider, and we do not link a web conversion to an app install using a device identifier. Where we measure the effectiveness of our own marketing, we do so using privacy-preserving, aggregated methods and, on our websites, using cookies subject to your consent (see Section 14).
1.3. Data we collect automatically
Usage and product-interaction data We log how you interact with the Service: features and screens viewed, buttons tapped, workouts started/completed, time on session, onboarding answers, subscription history, and similar events. This helps us personalize the Service, measure performance, and debug issues. Device and network data We collect standard device identifiers and network data: device model, operating system and version, language and locale, time zone, IP address, mobile carrier, mobile network type, and approximate location derived from IP. We do not collect your device’s advertising identifier (the Apple IDFA or the Android Advertising ID) — see Section 1.3.1. Approximate geolocation We may infer your approximate location (city/region) from your IP address for security, fraud prevention, language localization, and statutory compliance (for example, to determine which consumer-protection laws apply). Precise geolocation (GPS) is collected only if you expressly enable a location-dependent feature. Cookies and similar technologies on our websites When you visit our websites, we and our service providers use cookies, SDKs, pixels, local storage, and similar technologies. See Section 14 for details, and our separate Cookie Policy for the current inventory, maintained in our cookie preference tool, and for your consent choices. Crash reports and diagnostics If the App crashes, we automatically collect diagnostic data — crash stack trace, device state, app version, approximate region, anonymized user identifier — to locate and fix the bug. Crash diagnostics capture the state of the App at the moment it failed, and in some circumstances that can include information you had entered or that was displayed on screen, which may include health or body data. Our crash-reporting providers act as our processors: they are bound by a data processing agreement, may not use your data for their own purposes, and the data is deleted together with your account (see Section 5).
1.3.1. We do not track you across other companies’ apps and websites
We do not track you across apps and websites owned by other companies. In particular:
- We do not access your device’s advertising identifier (the Apple IDFA or the Android Advertising ID).
- Because we do not engage in tracking as defined by Apple, we do not show you Apple’s App Tracking Transparency (ATT) permission prompt. The absence of that prompt means we are not tracking you — not that tracking is happening without your permission.
- Where we measure the effectiveness of our own marketing, we do so using privacy-preserving, aggregated methods that do not rely on device-level identifiers, and, on our websites, using cookies and similar technologies subject to your consent (see Section 14 and our Cookie Policy).
- Our App Store privacy disclosures reflect this: no data is used to track you.
If we ever decide to introduce device-level advertising measurement, we will request your permission through the ATT prompt first and update this Privacy Policy before doing so.
2. Purposes and legal bases for processing
We process your personal data for the specific purposes described below. Where the EU/UK GDPR applies, we process personal data only where we have a valid legal basis. Where U.S. state or other national privacy laws apply, we process personal data consistent with the principles described in those laws (for example, purpose limitation and data minimization).
| Purpose | Data categories used | GDPR legal basis (EEA/UK) |
|---|---|---|
| Provide and personalize the Service — generate your workout plan, meal plan, progress insights, and other personalized content, and deliver the features you request. | Identifiers; onboarding & fitness data; nutrition data; usage data; device data; Health App data; special category data (with consent). | Performance of a contract (Art. 6(1)(b)); your explicit consent for special category data (Art. 9(2)(a)). |
| Subscription and billing — process payments, detect payment fraud, handle refunds and chargebacks, calculate taxes. | Identifiers; commercial information; device data; country/postal code; transaction history. | Performance of a contract (Art. 6(1)(b)); compliance with legal obligations (Art. 6(1)(c)). |
| Customer support and the AI coach — respond to your questions, operate the AI coach conversation, and send transactional notifications, operational updates, and renewal reminders. | Identifiers; communication content; AI coach conversation content; account status; subscription details; health-related information you choose to share in those conversations. | Performance of a contract (Art. 6(1)(b)); legitimate interests in operating and securing our support channels (Art. 6(1)(f)) — our interest is in answering you accurately and preventing abuse of the channel, and we have assessed that this does not override your rights, because we use the minimum data needed and do not use it for advertising. Your explicit consent (Art. 9(2)(a)) for any health-related data you share with the coach or with support. |
| Improve the Service and develop new features — analyze which features are used, run A/B tests, measure performance, and improve our models using de-identified or aggregated data. | De-identified or aggregated usage data; anonymized interactions; survey responses. | Legitimate interests (Art. 6(1)(f)) — our interest is in making the Service work better and more safely; we have assessed that this does not override your rights, because the data is de-identified or aggregated and cannot be used to make decisions about you individually. Consent where required (Art. 6(1)(a)). |
| Our own marketing messages — send you marketing emails, in-App messages, and push notifications about shedio. | Identifiers; email; country; age range; subscription status; app-use information. And, only if you have given us your separate consent to marketing: your goals and your progress, used solely to decide what to send you in our own messages. This information stays with us and is never disclosed to anyone else. | Consent (Art. 6(1)(a)). Where the message is personalized using your goals or progress, your explicit consent (Art. 9(2)(a)) — you may withdraw it at any time without affecting your access to the Service. Exception — Maryland. Maryland’s Online Data Privacy Act permits the processing of sensitive data only where it is strictly necessary to provide the product or service the consumer asked for, and consent does not change that. We therefore do not use health data to personalize marketing for residents of Maryland, or of any other state whose law imposes the same restriction, even if they have consented to marketing. |
| Promoting shedio on third-party platforms — measure the effectiveness of our own advertising and promote shedio on search engines, social media, and similar platforms. | Identifiers; country; age range; website activity. Health data — and any inference drawn from it — is never used for this purpose, is never disclosed to any advertising or analytics partner, is never used for cross-context behavioural advertising, and is never used to build a custom audience, a lookalike audience, or any other advertising segment. We do not use advertising identifiers. | Consent (Art. 6(1)(a)) for cookies and similar technologies; legitimate interests where permitted (Art. 6(1)(f)) — our interest is in promoting our own Service; we have assessed that this does not override your rights, because no health data is used and you can opt out at any time. |
| Security, fraud prevention, and abuse detection — protect against unauthorized access, fraudulent transactions, trial abuse, chargeback fraud, and misuse of the Service. | Identifiers; device data; IP address; login events; transaction patterns; dispute records. | Legitimate interests (Art. 6(1)(f)) — our interest is in protecting the Service, our users, and ourselves from fraud and abuse; we have assessed that this does not override your rights, because the processing is limited to security signals and is expected by users. Compliance with legal obligations (Art. 6(1)(c)). |
| Defend payment disputes and establish, exercise, or defend legal claims — maintain evidence of service delivery in response to chargebacks, refund requests, regulator inquiries, and legal claims. | All categories, with particular emphasis on commercial information, service usage data, and device data. | Legitimate interests (Art. 6(1)(f)) — our interest is in defending ourselves against unfounded claims and chargebacks; we have assessed that this does not override your rights, because the data is used only for that defence and is retained no longer than the applicable limitation period. Performance of a contract (Art. 6(1)(b)); legal obligations (Art. 6(1)(c)). Where the evidence includes health-related data, Art. 9(2)(f) — establishment, exercise, or defence of legal claims. |
| Legal, regulatory, and tax compliance — respond to lawful government requests, retain records for tax and accounting, and comply with applicable law. | Transaction records; tax-relevant data; records of consent. | Compliance with legal obligations (Art. 6(1)(c)). |
2.1. Special category and sensitive data
Some of the data we process — in particular, data about your physical health, your body, your fitness, and your nutrition — may qualify as a special category of personal data under GDPR Art. 9 or as sensitive personal information under U.S. state or other applicable privacy laws. Where required by applicable law, we process such data only on the basis of your explicit, opt-in consent, which you may withdraw at any time in the App settings. Health data and marketing. There are two different things here, and we treat them differently.
- What we never do. We never disclose your health data — or any inference we draw from it — to any advertising, marketing, or analytics partner. We never use it for cross-context behavioural advertising, and we never use it to build a custom audience, a lookalike audience, or any other advertising segment. This is absolute: it does not depend on your consent, and you cannot opt in to it.
- What we may do, if you consent to marketing. If you have given us your separate, optional consent to receive marketing, we may use information about your goals, your progress, and how you use the Service to decide what to send you in our own emails, in-App messages, and push notifications. This stays with us. You can withdraw that consent at any time, and doing so does not affect your access to the Service. See also Section 11 (Consumer Health Data) and Section 13 (AI).
What we do not collect. shedio does not offer cycle tracking, pregnancy or post-natal programmes, or any other reproductive or sexual health feature, and we do not collect reproductive or sexual health information. We do not collect biometric data or genetic data: we do not perform body scanning, face recognition, or posture or movement analysis, and we do not collect voice recordings, iris scans, fingerprint templates, or DNA-level genetic data. We do not ask for your sexual orientation. We do not offer mindfulness, meditation, or mood-tracking features, and we do not ask you for information about your mental health. If you choose to tell us something about it — for example, in a conversation with the AI coach — we treat it as health data and protect it accordingly.
What happens if you withdraw consent. If you withdraw your consent to the processing of health or other special category data, we will stop that processing and delete or de-identify the affected data in accordance with Section 5. The Service will then continue to be available to you in a limited mode that does not rely on health data — you will keep your account, your subscription, and access to content that does not require health data, but features that depend on health data (such as a personalized workout or meal plan, progress insights, and the AI coach’s personalized guidance) will no longer be available until you consent again. Withdrawing consent is free, takes effect going forward, and does not affect the lawfulness of processing carried out before you withdrew it.
3. How we share your personal data
We share personal data with the following categories of recipients:
3.1. Our corporate group
Atelo Information Technology Ltd is currently our only legal entity: we have no affiliates or subsidiaries, and we therefore do not share your personal data with any affiliate. If that changes, we will update this Privacy Policy before sharing your personal data with any affiliate, and any such affiliate would be bound by data protection commitments consistent with this Privacy Policy.
3.2. Service providers (processors)
We engage third-party service providers to process personal data on our behalf under contractual obligations, including data processing agreements where required by law. They process personal data only for the purposes we specify and only as necessary to deliver their services. Typical categories include:
| Category of provider | Purpose | Examples |
|---|---|---|
| Cloud hosting, storage, content delivery, and image/media processing | Host the Service, store personal data, encode and stream workout video, and store and process the images you upload (avatar, progress photographs). | Our current providers, by category, are set out in this table. |
| Payment processors and merchant of record | Process payments, handle refunds and chargebacks, calculate and remit tax. They do not receive health, body, fitness, or nutrition data, except where specific evidence is necessary to respond to fraud (see Section 5, “Fraud prevention and dispute defence”). | Stripe; Braintree; Paddle (merchant of record). The seller and payment provider for your purchase are identified to you at checkout. |
| Crash monitoring, observability, and error reporting | Detect, diagnose, and fix technical issues. Crash diagnostics can, in some circumstances, capture health or body data that was present in the App when it failed (see Section 1.3). These providers act as our processors under a data processing agreement and may not use your data for their own purposes. | See the category description in this row. |
| Product and marketing analytics | Measure engagement, retention, and campaign performance. They do not receive health, body, fitness, or nutrition data. | Our current providers, by category, are set out in this table. Website cookies are listed in our cookie preference tool (Cookiebot). |
| Email and messaging | Send transactional and marketing messages, renewal reminders, and push notifications. | Our current providers, by category, are set out in this table. |
| Customer support platforms | Handle support tickets, live chat, and help-center content. | Our current providers, by category, are set out in this table. |
| Fraud prevention and identity verification | Detect fraud, card-testing, trial abuse, and bot traffic. | Our current providers, by category, are set out in this table. |
| AI and machine-learning providers | Power AI-assisted features, including the AI coach and AI-generated plans (see Section 13). They act only on our instructions and may not use your data for their own purposes, including to train their own models. | Our AI provider. |
| Advertising and measurement partners (website only) | Measure the performance of our own marketing and, where you have consented, promote shedio to you on third-party platforms. Health data is never shared with these partners. | Listed in our cookie preference tool (Cookiebot). |
| Consent management platform (CMP) | Collect, store, and respect your cookie, tracking, and marketing consent preferences. | Cookiebot |
3.3. Health App integrations (Apple Health / Google Health Connect / wearables)
Data received from Apple Health, Google Health Connect, or a connected wearable device is not shared with advertising or marketing partners, is not sold under any U.S. state law, and is never sold or disclosed to data brokers or other information resellers. We use such data strictly to deliver the features you requested, store it securely with our cloud hosting provider, and allow you to export or delete it as described in Section 8.
3.4. Legal, safety, and public-interest disclosures
We may disclose personal data where we have a good-faith belief that disclosure is necessary to: (a) comply with a legal obligation, court order, or lawful government request; (b) enforce our Terms and Conditions of Use, including investigation of violations; (c) detect, prevent, or address fraud, security, or technical issues; (d) protect against harm to the rights, property, or safety of shedio, our users, or the public; or (e) respond to an emergency involving risk of death or serious bodily injury.
3.5. Business transactions
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, personal data may be transferred as part of the transaction. We will use reasonable efforts to ensure any successor entity honors this Privacy Policy or provides notice of material changes.
3.6. With your direction or consent
We may share personal data in additional ways when you direct us to — for example, if you post a review through a third-party platform, or explicitly consent to a particular third-party integration. shedio does not offer built-in social sharing, public profiles, or feeds, and we never post anything on your behalf.
3.7. What we do NOT do
- No sale of personal data for monetary compensation. We do not sell your personal data in exchange for money. Note that some U.S. state laws (for example, California’s CPRA) define “sale” or “share” broadly to include certain cross-context behavioral advertising, which may be considered a “sale” or “share” under those laws even without a monetary exchange. You may opt out of such sharing where applicable (see Section 10).
- No disclosure of health data to advertising or analytics partners. Health data — whether received from Apple Health, Google Health Connect, a wearable device, or submitted by you during onboarding — and any inference drawn from it, is never disclosed to an advertising, marketing, or analytics partner, is never used for cross-context behavioural advertising, and is never used to build an advertising audience. (Where you have consented to marketing, we may use it to personalize our own messages to you; see Section 2.1.)
- No training of third-party AI models on your data. Your personal data, and in particular your health, fitness, body-related, and AI coach conversation data, is never used by our AI providers to train, fine-tune, or otherwise improve their own models. See Section 13.
- No advertising identifiers and no cross-app tracking. We do not collect the Apple IDFA or the Android Advertising ID and we do not track you across other companies’ apps and websites. See Section 1.3.1.
- No third-party advertising inside the App. We do not display advertising from third parties within the Service.
- No knowing collection of data from children under 18. See Section 7.
4. International data transfers
shedio is based in the United States. When you use the Service, your personal data is transferred to and processed in the United States and in other countries where our service providers operate. These countries may have data-protection laws that differ from those in your country, including laws that may permit government authorities to access personal data in certain circumstances.
4.1. Transfers from the EEA, UK, and Switzerland
Where required under the EU GDPR, UK GDPR, or Swiss Federal Act on Data Protection, transfers of personal data from the EEA, UK, or Switzerland to countries that are not subject to an adequacy decision rely on appropriate safeguards, in particular:
- EU Standard Contractual Clauses (Module 2 or Module 3, as applicable) adopted by the European Commission under Article 46(2)(c) GDPR;
- UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, as applicable;
- Swiss-specific amendments to the Standard Contractual Clauses, where applicable. We supplement these safeguards with technical and organizational measures such as encryption in transit and at rest, access controls, and, where appropriate, pseudonymization. A copy of the Standard Contractual Clauses used for a specific transfer is available on request; see Section 16.
4.2. Other transfers
The Service is currently offered only in the United States (see Section 12). If we open it in another country whose law requires a specific transfer mechanism, we will put that mechanism in place, and update this Privacy Policy, before we do so.
4.3. What we rely on for these transfers
For transfers out of the EEA, the UK, or Switzerland, we do not rely on your consent: we rely on the appropriate safeguards described in Section 4.1 — principally the Standard Contractual Clauses, together with the supplementary technical and organizational measures described there. The Service is currently offered only in the United States (see Section 12). If we open the Service to another country whose law requires a particular transfer mechanism, we will put that mechanism in place, and update this Privacy Policy, before we do so. You can ask us for a copy of the safeguards that apply to a specific transfer; see Section 16.
5. Data retention
We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law. Active account data We retain your account data for the duration of your active account with us. After account deletion If you delete your account or submit an erasure request, we will delete or de-identify your personal data in our production systems within 30 days, except where we are required or permitted by law to retain specific categories for longer (see below). Backups. We do not carry out point-in-time deletion inside our backups. Our backups are held in isolated storage, are not accessed or used for any purpose other than restoring the Service after a failure, and are overwritten on a rotating cycle of no more than 90 days. If we restore from a backup during that window, we re-apply your deletion immediately. The only exception is where we are required by law to preserve a copy — for example, under a litigation hold or a regulatory order — in which case the preserved copy is isolated and used only for that purpose. Content you uploaded — including your profile avatar, workout notes, and AI coach conversations — is deleted or de-identified together with your account. Legal, tax, and accounting records Transaction and tax records are retained for the period required by the applicable tax, accounting, and anti-money-laundering laws to which we are subject. Fraud prevention and dispute defence Records that we need in order to defend a payment dispute, a chargeback, or a refund claim, or to investigate repeat abuse, are retained for the period necessary for that purpose and to meet payment-network requirements — generally, no longer than the applicable limitation period for such claims. These records are limited to what is necessary, and typically consist of: the transaction record; the device, IP address, and session identifiers captured at the time of the transaction; the version of the terms and policies you accepted, together with the time and manner of your acceptance; records of the transactional emails we sent you and confirmation that they were delivered; records of when you signed in, when your plan was generated and delivered to you, and when you were last active; and records of your cancellation and refund requests. Your right to erasure and these records If you ask us to erase your personal data, we will do so — but we may retain the records listed immediately above for as long as they remain necessary for the establishment, exercise, or defence of legal claims. This is expressly permitted by Article 17(3)(e) GDPR and by the corresponding provisions of U.S. state privacy laws. Everything else is deleted or de-identified as described in this Section 5, and we record the basis on which any record is retained. Consent records Records of your consent (for example, the version of a consent statement you accepted, the date, and the scope of what you consented to) are retained for as long as they may be needed as evidence that we obtained your consent lawfully. Aggregated or de-identified data We may retain aggregated or de-identified data indefinitely for statistical, research, and service-improvement purposes, provided that such data cannot reasonably be linked back to you.
6. Security of your personal data
We take reasonable and appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure, including:
- Encryption of personal data in transit (TLS) and at rest (industry-standard encryption at our cloud provider);
- Role-based access controls, least-privilege principles, and multi-factor authentication for our staff;
- Continuous logging, monitoring, and anomaly detection across our infrastructure;
- Periodic security testing, including penetration testing and third-party security assessments;
- A documented incident response plan aligned with the breach-notification timeframes that apply to us;
- Contractual obligations on our service providers to implement appropriate security measures. No security measures are perfect, and we cannot guarantee absolute security. You are also responsible for safeguarding your login credentials and for notifying us promptly of any unauthorized access. In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected individuals and, where required, the relevant authorities, within the timeframes required by applicable law. Depending on the nature of the breach and the data involved, those authorities may include the competent data protection supervisory authority in the EEA or the UK, U.S. state attorneys general, and the U.S. Federal Trade Commission under the Health Breach Notification Rule.
7. Children and minors
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from individuals under 18. We do not direct marketing to, or engage in targeted advertising toward, individuals known to us to be under 18. If you are under 18, do not create an account, do not provide us with any personal data, and do not use the Service. If you are a parent or guardian and believe that a child under 18 has provided personal data to us, please contact us at the address in Section 16, and we will take reasonable steps to delete that data promptly. In jurisdictions with specific age-based privacy laws — including the U.S. Children’s Online Privacy Protection Act (COPPA) for children under 13, GDPR-K (Art. 8 GDPR) for children under the applicable digital-age-of-consent in each EU Member State (between 13 and 16), and similar laws — we follow the higher of the applicable minimum ages and the 18-year threshold stated above.
8. Your privacy rights (general)
Regardless of where you live, we aim to give you control over your personal data. You may exercise the following rights at any time by contacting us at support@shedio.life or by using the privacy features available in your account settings:
- Access: request a copy of the personal data we hold about you.
- Correction: correct inaccurate or incomplete personal data.
- Deletion: request that we delete your personal data, subject to the retention exceptions in Section 5. You can also delete your account directly in the App (Profile → Account Settings → Delete Account) without contacting us.
- Download / portability: receive a copy of your data in a structured, machine-readable format.
- Withdraw consent: where we rely on your consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing before withdrawal.
- Object / opt out: object to specific processing (for example, marketing), or opt out of “sale” or “sharing” where applicable.
- Marketing preferences: unsubscribe from marketing emails using the link in each email, or adjust notification preferences in the App.
8.1. How we verify your request
To protect your data, we may ask you to verify your identity before acting on a request. Depending on the type of request, we may ask for your account email, date of registration, recent order number, or other information reasonably linkable to your account. For sensitive requests we may require stronger verification.
8.2. Authorized agents
You may designate an authorized agent to submit requests on your behalf. We may require proof of the agent’s authorization (for example, a signed permission, or evidence of a valid power of attorney) and may contact you to confirm the request.
8.3. Timing and fees
We respond to privacy requests within the timeframes required by applicable law, with extensions permitted where the law allows them (for example, where a request is particularly complex). Requests are free of charge, except in limited circumstances where a request is manifestly unfounded or excessive.
8.4. Right to lodge a complaint
You may lodge a complaint with a data protection authority in your jurisdiction. We would appreciate the chance to address your concerns first — please reach out at the address in Section 16.
9. EEA, UK, and Switzerland (GDPR / UK GDPR)
This Section 9 applies if you are resident in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland.
9.1. Controller
The controller of your personal data is Atelo Information Technology Ltd (d/b/a “shedio”), with its principal place of business at 1226 North King St Num 1382, Wilmington, DE 19801, USA. For data-protection inquiries, contact us at support@shedio.life.
9.2. Contacting us about data protection
| How to reach us. You can contact us about any data-protection matter — including the exercise of any of the rights described in Section 8 and Section 9.3 — at support@shedio.life, or by writing to us at the address in Section 16. We will handle your request in accordance with the GDPR and UK GDPR, whichever applies to you. Data Protection Officer (DPO). The requirement to appoint a Data Protection Officer under Article 37 GDPR depends on the nature and scale of the processing carried out, and we keep that assessment under review as the Service grows. Data-protection enquiries should in all cases be sent to support@shedio.life. |
|---|
9.3. Your GDPR rights
In addition to the rights in Section 8, residents of the EEA, UK, and Switzerland benefit from the following rights under the GDPR and equivalent laws:
- Right of access (Art. 15). Request a copy of the personal data we process about you, together with information about how we process it.
- Right to rectification (Art. 16).
- Right to erasure (“right to be forgotten”) (Art. 17), subject to legal exceptions such as tax-record retention.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20).
- Right to object to processing (Art. 21), including to processing based on legitimate interests and to direct marketing.
- Rights in relation to automated decision-making, including profiling (Art. 22). See Section 16 for details.
- Right to withdraw consent (Art. 7(3)) where processing is based on consent.
- Right to lodge a complaint with your local supervisory authority. A list of EU supervisory authorities is available at https://edpb.europa.eu/about-edpb/board/members_en. The UK supervisory authority is the Information Commissioner’s Office (ICO) at https://ico.org.uk.
9.4. Legal guarantee of conformity
Consumers in the EEA are entitled to the statutory legal guarantee of conformity for digital content and digital services under EU Directive 2019/770, as transposed into national law. Consumers in the UK have the equivalent statutory rights under Part 1, Chapter 3 of the Consumer Rights Act 2015. Nothing in this Privacy Policy limits those statutory rights.
10. United States — California, Virginia, Colorado, Connecticut, Utah, and other state laws
This Section 10 applies if you are resident in a U.S. state with a comprehensive consumer privacy law, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with similar laws in force from time to time (including, where applicable, Texas, Florida, Oregon, Montana, Delaware, New Hampshire, New Jersey, Iowa, Tennessee, Indiana, Minnesota, Maryland, Rhode Island, Kentucky, and Nebraska (whose law has no revenue threshold)). This Section also serves as our California Notice at Collection.
Maryland residents (Maryland Online Data Privacy Act, “MODPA”). In addition to the rights described below, for Maryland residents we limit our collection of personal data to what is reasonably necessary and proportionate to provide the Service you request, and we collect, process, and share sensitive data (including health and body-related data) only where strictly necessary to provide a product or service you have requested. This is stricter than a consent standard, and we apply it as such: we do not use your health data to personalize marketing to you if you are a Maryland resident, even if you have consented to receive marketing. We do not sell sensitive data, and we do not process the sensitive data of any consumer we know or should know is under 18 for targeted advertising or sale.
10.1. Categories collected, shared, and disclosed
The table below sets out, by the statutory categories used in the CCPA/CPRA, the personal information we collect, where it comes from, why we collect it, the categories of recipients we disclose it to, whether it is “sold” or “shared” as those terms are broadly defined under U.S. state law, and how long we keep it. The categories of recipients are described in Section 3; retention is described in Section 5.
| Statutory category | Examples of what we collect | Source | Purpose | Disclosed to (categories) | “Sold” or “shared”? | Retention |
|---|---|---|---|---|---|---|
| A. Identifiers | Name, email address, account ID, device identifiers, IP address. | You; automatic collection. | Provide the Service; account and login; support; security. | Cloud hosting; analytics; email/messaging; payment providers. | App: No. Website: Yes — identifiers may be shared with advertising partners through cookies/pixels on our marketing and onboarding website. You may opt out (see below). | Section 5. |
| B. Customer-records information (Cal. Civ. Code § 1798.80(e)) | Name, billing address, payment-card token, transaction records. | You; payment providers. | Billing; refunds; chargeback defence; tax and accounting. | Payment providers and merchant of record; cloud hosting. | No. | Section 5. |
| C. Protected classification characteristics | Age or date of birth; sex/gender. | You. | Age eligibility (18+); personalization of plans. | Cloud hosting. | No. | Section 5. |
| D. Commercial information | Subscription plan, purchase and renewal history, refund and dispute records. | You; payment providers; App Stores. | Billing; renewals; fraud and chargeback defence. | Payment providers and merchant of record; cloud hosting. | No. | Section 5. |
| E. Biometric information | Not collected. We do not perform body scanning, face recognition, or posture/movement analysis. | — | — | — | No. | — |
| F. Internet or other network activity | App and website usage events, screens viewed, features used, crash and diagnostic data. | Automatic collection. | Operate, debug, and improve the Service; measure our own marketing. | Cloud hosting; analytics. | App: No. Website: Yes — website activity may be shared with advertising partners through cookies/pixels, subject to your consent and opt-out. | Section 5. |
| G. Geolocation data | Approximate location derived from IP address; precise GPS only if you turn on run tracking, and only while the feature is in use. | Automatic collection; you. | Security and legal-compliance routing; run route tracking. | Cloud hosting. | No. Precise location is never sold or shared. | Section 5. |
| H. Audio, electronic, visual, or similar information | A profile avatar or progress photograph, if you choose to upload one. | You. | Display your avatar; let you see your own progress. | Cloud hosting; media processing. | No. | Section 5. |
| I. Professional or employment information | Not collected. | — | — | — | No. | — |
| J. Non-public education information | Not collected. | — | — | — | No. | — |
| K. Inferences | Fitness level, plan recommendations, and progress insights generated from your inputs. | Derived by us. | Personalize your plan and guidance. | Cloud hosting; AI provider. | No. Health-related inferences are never sold or shared. | Section 5. |
| L. Sensitive personal information (CPRA) | Health, body, fitness, and nutrition data; AI coach conversation content; precise geolocation (if you enable run tracking); account log-in credentials. We do not collect reproductive or sexual health information, biometric data, or genetic data. | You; Apple Health / Google Health Connect (with your permission). | Provide the personalized Service you requested. Where you have consented to marketing (and you are not a Maryland resident), also to personalize our own messages to you — see Section 2.1. | Cloud hosting; AI provider; image and media processing. | Never. We do not sell or share sensitive personal information, and we do not use it for cross-context behavioural advertising. | Section 5. |
We collected the categories above, and disclosed them to the categories of recipients listed above, in the 12 months preceding the effective date of this Privacy Policy.
10.2. “Sale” and “share” of personal information
We do not sell your personal information for money. However, some U.S. state privacy laws define “sale” and “share” broadly enough to include certain cross-context behavioral advertising carried out through cookies and pixels — even where no money changes hands.
Where this applies to us, and where it does not:
- In the App, we do not engage in cross-app tracking, we do not collect advertising identifiers, and we do not display third-party advertising. Our App-side “sale”/“share” exposure is therefore none.
- On our website (including our marketing pages and the onboarding questionnaire), we use advertising and analytics technologies provided by third-party advertising platforms. Under the broad statutory definition, that use may constitute a “sale” or a “share.” The current, authoritative list of those providers is maintained in our cookie preference tool (Cookiebot), which is also where you manage your choices.
- Health data is never sold or shared. We do not transmit health, body, fitness, or consumer health data — or any inference drawn from it — to advertising or analytics partners, whether through pixels, SDKs, server-side APIs, or otherwise. See Section 3.7 and Section 11.
Your right to opt out You have the right to opt out of such “sale” and “share” of your personal information. We provide the opt-out through our “Your Privacy Choices” link, typically available in the footer of our website, and through our consent management platform (Cookiebot). We also honor valid universal opt-out signals such as the Global Privacy Control (GPC) where required by applicable law.
Nevada residents (SB 220) Separately from the consumer health data rights described in Section 11, Nevada residents have the right under Nevada Revised Statutes Chapter 603A to direct us not to make any sale of covered information that we have collected or will collect about them. We do not currently sell covered information as defined in that statute. If you are a Nevada resident and wish to submit a verified opt-out request, email support@shedio.life with the subject line “Nevada Opt-Out Request.” Sensitive personal information We use sensitive personal information (such as health-related inputs or precise location, if you enable it) only for purposes permitted by applicable law: to provide the Service you requested and, where you have consented to marketing and your state’s law allows it, to personalize our own messages to you (see Section 2.1). We never disclose it to an advertising or analytics partner. Where applicable state law grants you the right to limit the use of sensitive personal information, you may exercise that right by contacting us at support@shedio.life.
10.3. Your rights
Depending on your state of residence, you may have some or all of the following rights:
- Right to know / access the categories and specific pieces of personal information we collect, use, disclose, and (if applicable) sell or share.
- Right to delete personal information we have collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to data portability.
- Right to opt out of “sale” or “sharing” of personal information, and of targeted advertising.
- Right to limit use of sensitive personal information.
- Right to non-discrimination for exercising your privacy rights.
- Right to appeal a denial of a privacy request (available in Virginia, Colorado, Connecticut, and certain other states). To exercise a right, please contact us at support@shedio.life. You can also delete your account directly in the App (Profile → Account Settings). If you would like to receive a copy of the personal data, you may request this at any time by writing to us at support@shedio.life, and we will review and handle your request in accordance with the applicable provisions of this Privacy Policy and any conditions, limitations, or requirements that may apply. The “Your Privacy Choices” link controls cookie and tracking preferences and opt-outs of “sale”/“sharing” — it is not a channel for access, correction, deletion, or portability requests. You may designate an authorized agent to submit a request on your behalf.
10.4. California “Shine the Light”
California residents may request, once per calendar year, a list of the third parties to which we have disclosed personal information for those third parties’ direct-marketing purposes in the prior calendar year. To submit a request, send an email to support@shedio.life with the subject line “California Shine the Light Privacy Information,” including your state of residence and email address.
10.5. Notice under California Civil Code § 1789.3
California users are entitled to the following consumer-rights notice: the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs may be contacted at 1625 North Market Blvd., Suite N-112, Sacramento, CA 95834, or at (800) 952-5210.
11. Washington, Nevada, and Connecticut (Consumer Health Data)
| This Section 11 is a supplemental Consumer Health Data Privacy Notice applicable to customers covered by Washington’s My Health My Data Act (MHMDA), Nevada’s Consumer Health Privacy Law (SB 370), Connecticut’s consumer-health-data provisions, and similar laws. It supplements — not replaces — this Privacy Policy. We publish a standalone Consumer Health Data Privacy Notice at https://shedio.life/consumer-health-data, which prevails over this Section 11 in the event of conflict. |
|---|
11.1. Categories of consumer health data
“Consumer health data” means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer’s past, present, or future physical or mental health status. We may collect consumer health data from the following sources:
- Directly from you — during onboarding and ongoing use (e.g., height, weight, BMI calculated from inputs, fitness goals, fitness level, dietary preferences, any food, meal, or water intake you choose to log, any progress photograph you choose to upload, any pre-existing condition you choose to tell us about, and what you say to the AI coach).
- From third parties — when you connect Apple Health, Google Health Connect, or a wearable device (e.g., step count, heart rate, sleep, energy expenditure).
- Automatically — derived from your use of the Service (e.g., workout completions, activity trends). We do not collect reproductive or sexual health information: shedio does not offer cycle tracking, pregnancy, or post-natal features.
11.2. Purposes and intended uses
We use consumer health data only to:
- Provide the Service you requested, including personalization of workout and meal plans;
- Send service-related notifications (for example, reminders and motivational messages related to your plan);
- With your consent, analyze use of the Service to improve features and develop new ones;
- Comply with legal obligations and defend against claims. Where you have given us your separate consent to marketing, and where your state’s law permits it, we may also use your goals and progress to personalize our own messages to you; that information is never disclosed to anyone else. We do not do this for Maryland residents (see Section 10). We do not sell consumer health data, we never disclose it to an advertising or analytics partner, and we do not use it for cross-context behavioural advertising or for behavioural profiling that is not necessary to provide the Service.
11.3. Sharing of consumer health data
We share consumer health data only with: (a) our cloud hosting providers and other service providers that process it on our behalf, on our instructions, under data processing agreements; (b) our authorized personnel on a need-to-know basis; (c) law enforcement or regulators where required by law; and (d) affiliates within our corporate group under equivalent protections. We do not share consumer health data with advertising, marketing, or analytics partners for cross-context behavioral advertising.
11.4. Your rights under consumer health data laws
- Right to confirm and access: obtain confirmation of whether we process your consumer health data, and a copy of such data.
- Right to delete: request deletion of your consumer health data.
- Right to withdraw consent: withdraw any consent you previously provided for the collection, sharing, or processing of consumer health data.
- Right to appeal: if we decline a request, you may appeal to us within a reasonable timeframe. If we deny your appeal, you may contact the Washington or Nevada Attorney General’s office (or the authority in your state). To exercise a right, contact us at support@shedio.life with the subject line “Consumer Health Data Request.”
12. Other countries
The Service is currently offered only in the United States. We do not offer it to, and do not knowingly accept sign-ups from, people located in the European Economic Area, the United Kingdom, Switzerland, Japan, Canada, or elsewhere outside the United States.
If we open the Service in another country, we will update this Privacy Policy — and put in place whatever that country’s law requires of us — before we do so, not afterwards. Sections 9 and 10 describe the rights that apply where the GDPR/UK GDPR or a U.S. state privacy law applies to you.
13. Artificial intelligence and automated processing
| The Service includes features powered by machine learning and generative AI — for example, AI-generated workout plans, AI-generated meal recommendations, and AI-assisted coaching or chat. This Section explains how we use your personal data in connection with these features. |
|---|
13.1. How our AI features work
Our AI features combine (a) data you provide in onboarding, (b) data generated as you use the App (for example, completed workouts), (c) what you say to the AI coach, and (d) aggregated non-personal knowledge about fitness, nutrition, and wellness, to generate personalized suggestions. Depending on the feature, inputs and outputs may be processed by our own machine-learning systems or by a third-party AI provider acting as our processor.
13.2. Use of your personal data by AI providers
Where we rely on third-party AI providers, they act as our processors and we enter into data processing agreements that, in particular:
- Restrict use to our instructions — the provider may not use your personal data for its own purposes.
- Prohibit training on your data — see Section 13.3.
- Require deletion once the processing purpose is fulfilled, subject to any limited retention the provider applies for security and abuse-monitoring purposes and to any retention required by law. Some AI providers retain inputs and outputs for a short period (for example, up to 30 days) so that they can detect misuse of their systems, and a small number of authorized personnel at the provider may review content flagged as potentially abusive. Where that is the case, the retention is limited in time, the data is not used for training, and the provider is contractually bound to confidentiality and security.
- Require security and confidentiality consistent with our obligations to you.
13.3. Training of AI models
Your data is not used to train third-party AI models. Your personal data — including your health, body, fitness, nutrition, and AI coach conversation data — is never used by our AI providers to train, fine-tune, or otherwise improve their own models. This is an absolute commitment and it is contractually binding on our providers; it does not depend on you opting out.
We may use de-identified or aggregated data derived from your use of the Service to improve our own systems, where that data cannot reasonably be linked back to you. If we ever wish to rely on your identifiable personal data for model training in any other way, we will ask for your express consent first, and you will be free to refuse.
13.4. Automated decision-making
Under GDPR Art. 22, UK GDPR, and similar laws, you have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects on you. Our AI features are designed to be informational and advisory — they generate suggestions for you to consider, not decisions that are binding on you. The Service does not use automated decision-making to deny access to critical features, and it does not produce legal or similarly significant effects. Where we identify any processing that would qualify as automated decision-making under Art. 22, we will inform you, provide meaningful information about the logic involved, and honor your right to obtain human intervention, to express your point of view, and to contest the decision.
13.5. Limitations of AI
AI-generated outputs may be inaccurate, incomplete, biased, outdated, or inappropriate for your personal circumstances. Generative AI systems can also produce “hallucinations” — statements that are presented confidently but are factually wrong or entirely fabricated. Please see Section 5 (AI Features and Virtual Coaching) of our Terms and Conditions of Use for further information. You should verify any AI output before relying on it, especially for decisions affecting your health, nutrition, or physical activity. AI features are not a substitute for professional medical, nutritional, or psychological advice.
13.6. AI transparency (EU AI Act)
Ahead of the transparency obligations in Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which apply from 2 August 2026, we inform you that shedio’s coaching and exercise-plan features are powered by an artificial-intelligence system: when you interact with these features, you are interacting with an AI system, not a human coach. Where AI generates content for you, we identify that content as AI-generated. shedio does not use AI for emotion recognition, nor does it use subliminal, manipulative, or deceptive techniques, nor techniques that exploit vulnerabilities related to age, disability, or economic situation. Our AI exercise-plan generator is not a high-risk AI system under the EU AI Act.
14. Cookies and similar technologies
On our websites, we and our service providers use cookies, local storage, web beacons, pixels, SDKs, and similar technologies (collectively, “tracking technologies”). These are used for the following purposes:
- Strictly necessary: enable login, session management, security, and core site functions.
- Preferences: remember your language, region, and product settings.
- Analytics: measure engagement, performance, and conversion rates.
- Advertising: measure and, with your consent, promote our own Service on third-party platforms. We do not display third-party advertising within the App or on our websites. Health data is excluded from all tracking technologies. Health, body, fitness, and consumer health data is not collected through cookies, SDKs, pixels, or any other tracking technology, and is never transmitted to advertising or analytics partners. Where required by applicable law (in the EEA, UK, and similar jurisdictions), we ask for your consent before placing non-essential tracking technologies, and you can manage your preferences at any time through our consent management platform (Cookiebot). The current inventory of the specific tracking technologies we use, their vendors, and their retention periods is maintained in our cookie preference tool and described in our Cookie Policy at https://shedio.life/cookie-policy.
| Health data is excluded from all tracking technologies. Your health, body, fitness, and nutrition data — and any inference drawn from it — is not collected through cookies, SDKs, pixels, or any other tracking technology, and it is never transmitted to advertising or analytics partners, whether through a browser pixel, a mobile SDK, or a server-side API. This applies on our websites, including our onboarding questionnaire, as well as in our apps. |
|---|
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email, in-App message, or other prominent means before the changes take effect. Non-material changes will be reflected by updating the “Last Updated” date at the top of this Policy. Because this Privacy Policy is an information notice rather than a consent form, we do not treat your continued use of the Service as consent to a revised version of it. Where a change means we need your consent — for example, to process a new category of health data, or to use your data for a new purpose — we will ask you for that consent separately and expressly before the change applies to you.
16. Contact
For any questions about this Privacy Policy or to exercise a privacy right, please contact us:
- Privacy and data-protection inquiries: support@shedio.life
- General support: support@shedio.life
- Mailing address: Atelo Information Technology Ltd (d/b/a “shedio”), 1226 North King St Num 1382, Wilmington, DE 19801, USA Controller: Atelo Information Technology Ltd (d/b/a “shedio”), a Delaware corporation. Last Updated: July 20, 2026
Changelog
This is the initial version of the shedio Privacy Policy. Future revisions will be noted here.
