LEGAL

Privacy Policy

LAST UPDATED AUGUST 20, 2026

1. What we collect

Account data. Your email address and sign-in credentials, held in AWS Cognito. If you sign in with a social provider we receive your name and email from that provider.

Financial data. If you link a bank through Plaid, we receive read-only balances, transactions, and investment holdings for the accounts you choose. The Plaid access token is stored server-side (encrypted at rest in DynamoDB) and never reaches your browser or device. We can never move money.

Payment data. Subscriptions are processed by Stripe. Your card number never touches our servers — we store only your subscription status and Stripe customer reference.

Health data.Health figures you enter in the web app (heart rate, steps, calories, weight) are kept in your browser’s local storage on your device.

Camera. The optional camera pass-through renders entirely on your device. The video is never recorded, stored, analyzed, or uploaded — it is attached directly to the video element behind the HUD and nothing more.

Usage data. We use Amazon CloudWatch RUM for page-view and performance analytics, which sets cookies in your browser.

2. How we use it

To show you your own statistics, operate your subscription, keep the Service reliable and secure, and respond when you contact us. We do not sell your personal data, and we do not use your financial data for advertising.

3. Who we share it with

Only the processors the Service is built on: AWS (hosting, sign-in, storage, analytics), Plaid (bank connections), and Stripe (payments), each under their own privacy terms. We disclose data beyond that only if the law requires it.

4. Retention

Account and subscription records are kept while your account exists. Plaid access tokens are deleted immediately when you unlink a bank. Locally stored health figures and settings stay on your device until you clear them or delete your account.

5. Delete your data

You can delete your data at any time. Unlinking a bank in the app deletes the stored access token right away. To delete your account and everything tied to it, send a request through the support page from the email on your account, and we will delete your account records, subscription linkage, and any stored tokens within 30 days.

6. Cookies

The site uses cookies for analytics (CloudWatch RUM) and your browser’s local storage for sign-in tokens and your HUD settings. Blocking cookies keeps the marketing site fully usable; local storage is required for staying signed in.

7. Children

The Service is not directed at children and may not be used by anyone under 18. We do not knowingly collect data from children.

8. Changes

We’ll update this page as the Service evolves; material changes get a new “last updated” date. Questions? The support page reaches a human.