Overview
Add+Life ("we", "us") is a personal health and wellness app. This policy explains what data we collect, how we use and protect it, and the controls you have. The short version: your data exists to power the features you see in the app — nothing else. We do not sell it, we do not show ads, and you can delete it at any time.
Data we collect
Account data
- Email address and display name (used to create and secure your account)
- Optional profile photo, height, weight, and birth year (used to personalize your health targets)
Health & fitness data (via the Google Health API, with your consent)
- Activity: steps, distance, calories, active minutes, floors, workouts
- Sleep: duration, sleep stages, and sleep history
- Heart & vitals: heart rate, resting heart rate, heart-rate variability (HRV), blood oxygen (SpO2), breathing rate, skin temperature variation, VO2 max
- Profile and settings from your Google Health account (e.g. units, time zone)
Whoop data (only if you connect a Whoop account)
- Recovery, strain, sleep and workout data from the Whoop API
How we use your data
Your data is used solely to provide the features visible in the app:
- Displaying your daily health dashboard and week-by-week trend charts
- Computing your Add+Life scores (sleep, activity, readiness), personalized to your age when you provide a birth year
- Generating daily coaching insights from your recent data
The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.
What we never do
- No selling or transferring your data to data brokers, advertisers, or resellers — ever, in any form
- No advertising of any kind based on your data
- No use of your data for credit, lending, insurance, or employment decisions
- No use of your health data to train generalized AI or machine-learning models
Storage & security
- All data is transmitted over encrypted connections (HTTPS/TLS)
- Your Google Health access is held as an encrypted credential (AES-256); short-lived access tokens are derived on demand and never stored
- Most health data is fetched on demand to render your dashboard rather than warehoused; a small daily cache of coaching inputs may be kept to avoid repeated processing, and your device keeps a local cache for faster loading
- Access to production systems is restricted; no Add+Life human reviews your individual health data except with your explicit consent (e.g. a support request), for security investigation, or where required by law
Service providers
We use a small number of infrastructure providers to run Add+Life, acting on our instructions: application hosting (Railway), database hosting (MongoDB), and an email delivery service for account verification messages. If AI-generated coaching is enabled, the health signals for a given day may be processed by a third-party AI provider solely to generate your personal insights; such providers act as processors and do not use your data to train their models. We do not share your data with any other third parties.
Retention & deletion
- Disconnect Google Health (Settings → Manage Devices): we revoke our access with Google and delete the stored connection and any cached health-derived data on our servers
- Delete your account (Settings): permanently deletes your account and all associated data from our systems — this is irreversible
- Logout clears cached health data from your device
- You can also revoke Add+Life's access at any time from your Google Account at myaccount.google.com/permissions, or email us to request deletion
Changes & contact
If this policy changes materially, we will update this page and note the new effective date above. Questions, requests, or concerns: djugovic@thevastgroupin.com.
← Back to Add+Life