Consumer Health Data Privacy Policy — Biomatic
Biomatic by Actogram Ltd

Biomatic Consumer Health Data Privacy Policy

Effective 28 September 2026

1. Introduction and scope

This Consumer Health Data Privacy Policy supplements the Biomatic Privacy Policy. It applies to:

  • residents of the State of Washington, and any person whose consumer health data is collected in Washington (Washington My Health My Data Act, RCW ch. 19.373);
  • residents of the State of Nevada, and any person whose consumer health data is collected in Nevada (Nevada SB 370, NRS ch. 603A);
  • residents of Connecticut (Connecticut Data Privacy Act, as amended, in respect of consumer health data);
  • residents of any other US state whose law gives specific rights over consumer health data.

Where this Policy and the main Privacy Policy differ, this Policy governs consumer health data.

Who we are. Actogram Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, is the regulated entity, controller and sole decision-maker over the purposes and means of processing your consumer health data. We have no affiliates, and therefore no affiliates with whom consumer health data is shared.

Age. Biomatic is for people aged 18 or over. We do not knowingly collect consumer health data from anyone under 18. If we learn that we have, we delete the account and its data.

2. What consumer health data means

"Consumer health data" is personal information that is linked or reasonably linkable to you and that identifies your past, present or future physical or mental health status. It includes information you give us, information we collect from your device with your consent, and information we derive or infer from it. This Policy covers only personal information that qualifies as consumer health data; everything else is covered by the main Privacy Policy.

3. Categories of consumer health data we collect, and why

We collect only what is listed here. With your explicit consent, we collect:

Category What exactly Consent Purpose
Activity data Step counts with timestamps — minute by minute; the last 6 months at first sign-in, then new data as it appears; plus live step counts App Features (required) Calculating your metrics — the core function of the App
Sleep data Sleep stages (in bed, asleep, awake, and REM / core / deep where available) with start and end times Additional Data (optional) Measuring your night-rest window instead of estimating it from gaps in movement
Heart data Heart-rate samples with timestamps; daily resting heart rate Additional Data (optional) Helping the algorithm tell activity from rest and sleep
Workout data Workout type, start and end time, duration, distance, energy burned, and the workout route (GPS coordinates) where your device recorded one Additional Data (optional) Distance and intensity for the hour-by-hour shape of your day
Source device information Which device recorded each reading (for example iPhone or Apple Watch) both Knowing how reliable a reading is
Derived health data Your chronotype, rhythmotype, the hour-by-hour shape of your day, pace, average pace, performance, points, tokens, consistency score, best week and night-rest window follows the consent for the input data What the App shows you
Health information in feedback Any health information you choose to type into the feedback widget or into an e-mail to us your act of sending it Answering you and improving the App

Location. The only location data that reaches our server is the route recorded by Apple Health during a workout, and only if you turn Additional Data on and your device recorded a route. Biomatic does not ask for access to your device's location and does not collect it. We do not build a location history, and we do not use geofencing (see section 6).

Crash reports and usage statistics. We use AppMetrica, an app-analytics service, for crash reports and — only if you switch "Help improve the app" on — usage statistics (which screens you open, navigation, settings changed). AppMetrica receives no consumer health data: no step counts, heart-rate values, sleep records, workouts, locations, metrics, points or tokens, and nothing that links the data to your Biomatic account. These data are covered by the main Privacy Policy, not by this Policy.

What we do not collect. We do not collect reproductive or sexual health data, biometric identifiers, genetic data, medical conditions, medications, diagnoses, treatment or prescription information, bodily functions beyond those listed above, information about health care services you seek or receive, or precise location indicating that you sought health care.

New categories and new purposes. We will not collect, use or share any category of consumer health data, or use it for any purpose, that is not disclosed in this Policy without first disclosing the new category or purpose to you and obtaining your affirmative consent.

4. Categories of sources from which we collect consumer health data

  • The Apple Health app (HealthKit) on your iPhone, which aggregates readings from your iPhone, Apple Watch and other apps or devices you have connected to Apple Health. Biomatic only reads from Apple Health; it never writes to it.
  • Your iPhone's motion sensors (Motion & Fitness), for live step counts.
  • Our own calculations on our server, which derive the metrics listed in section 3 from the data above.
  • You, when you include health information in feedback or in a message to support.

5. Purposes, and how consent works

We collect and use consumer health data to:

  • calculate and show you your metrics;
  • send you the notifications you have switched on;
  • keep the service working and secure, including diagnosing errors;
  • improve and validate our calculation method, using de-identified copies only — with no Apple identifier, account code or device identifiers — and only if you turn on the separate, optional "Help improve our method" consent, which is off by default and has no effect on how the App works. This is internal use only in this release. We will not publish results or give data to outside researchers without asking you separately first;
  • respond to your requests and comply with the law.

Consent. We process consumer health data on your explicit, opt-in consent, given in the App before any data leaves your device. Consent is asked separately for collection and for each purpose, and the request tells you the categories collected, the purposes, the categories of recipients, and how to withdraw. Consent is never bundled with acceptance of the Terms of Use, and it is never a condition of anything other than the feature it enables. There are three separate consumer-health-data switches:

  • App Features — steps. Required for the App to calculate anything.
  • Additional Data — sleep, heart rate, resting heart rate, workouts. Optional; the App works without it, with less precise metrics.
  • Help improve our method — de-identified copies of your data used to improve and validate our calculation method. Optional, off by default, and has no effect on how the App works.

A fourth switch, Help improve the app, controls usage statistics; it involves no consumer health data (see section 3).

You can withdraw any of them at any time in Settings → Manage Consent. Withdrawal is as easy as giving consent and does not affect processing that already happened.

We do not use consumer health data for advertising, targeted marketing, cross-context behavioural advertising, or profiling that produces legal or similarly significant effects. Your metrics describe your own activity pattern and have no consequence beyond what you see in the App.

6. How and with whom we share consumer health data

We do not sell consumer health data. We have not sold it in the past and will not sell it in future without first obtaining your separate, signed authorization that meets the requirements of the applicable state law. We do not share consumer health data with any third party as that term is used in these laws, and we do not disclose it to data brokers or advertising platforms.

We do not use geofencing. We do not build, and will not build, a virtual boundary around any facility that provides health care services, including mental health, reproductive or sexual health facilities, and we do not use location to identify or track anyone in relation to such a facility.

Consumer health data is disclosed only to the following recipients, who act on our instructions under contract and never for their own purposes:

Category of recipient Who Categories disclosed Why
Hosting provider (processor) DigitalOcean, LLC — data centre in Frankfurt, Germany All categories in section 3, encrypted in transit and at rest Storing and processing your data on our behalf under a binding data processing agreement
Backup storage (processor) An external storage provider, named on request A weekly archive of the database, encrypted before it leaves our server; the provider never receives the keys and cannot read it Keeping a copy we can restore from after a failure; deleted after 30 days
Push-notification service (processor) Apple Inc. — Apple Push Notification service Notification text, which may contain a derived metric Delivering the notifications you switched on
Sign-in provider Apple Inc. — Sign in with Apple None. Apple receives no health data Creating your account
Outside researchers None in this release — If we later want to share de-identified data with research partners, we will ask for your separate, specific consent first
Law enforcement, courts, regulators Only on valid legal process Only what the process requires Legal compliance
A successor entity Only in a merger, acquisition or sale of assets All categories in section 3 Under obligations no less protective than this Policy, with prior notice to you

Access to consumer health data inside our company and at our processors is restricted to people who need it for these purposes and who are under a duty of confidentiality.

Where your data is held. Our server is in Frankfurt, Germany. If you use Biomatic in the United States, your consumer health data is transferred to and stored in Germany, and is protected there by United Kingdom and European Union data protection law in addition to the rights in this Policy.

7. Your rights

Wherever you live, and in addition to the rights in the main Privacy Policy, you have the right to:

  • Confirm and access — learn whether we are collecting, sharing or selling your consumer health data; receive a copy of it; and receive a list of all third parties and affiliates with whom we have shared or sold it, together with an active e-mail address or other means of contacting them. Today that list is: none.
  • Withdraw consent — withdraw your consent to our collection and sharing of your consumer health data. Withdrawing App Features stops collection of step data and the App can no longer calculate your metrics. Withdrawing Additional Data stops collection of sleep, heart-rate and workout data only. Withdrawing Help improve our method stops new de-identified copies from being made.
  • Delete — have your consumer health data deleted (see below).
  • Correct — ask us to correct consumer health data that is inaccurate, taking into account its nature and our purposes.
  • Obtain a portable copy — receive your consumer health data in a structured, commonly used, machine-readable format (we provide JSON).
  • Non-discrimination — we will not deny you the App or any feature, charge you a different price, or give you a different quality of service because you exercised a right. The only effects are the functional ones described above: without step data there is nothing to calculate.

Deletion, in detail. On a verified deletion request we delete your consumer health data from our records and from all parts of our network, including archived and backup systems, within 30 days, and we notify every processor and contractor that holds it to do the same, on the same terms. If a backup is restored for technical reasons after that, the data is deleted again promptly and is not returned to production use. De-identified copies, made only if you turned on "Help improve our method", are kept: when you delete your account the link between the copies and you is destroyed, so they can no longer be singled out or restored to you and cannot be deleted individually. We publicly commit not to attempt to re-identify de-identified data, we require the same of anyone who ever receives it, and we hold it only in de-identified form.

8. How to exercise your rights

How to ask. Use the switches in Settings → Manage Consent, or delete your account in Settings → Data & Privacy → Delete my account. For anything else, e-mail services@actogram.ai with "Consumer health data request" in the subject line, telling us which state you are a resident of and which right you are exercising.

Verification. The surest route is the App itself, where you are already signed in. If you write to us by e-mail, we will ask for details only you can see in the App, because we store no e-mail address or name for your account. If we cannot identify your account from what you can tell us, we will say so. We will not ask you to create an account in order to make a request.

Authorized agents. You may use an authorized agent. We will ask for written proof of the agent's authority and may still verify your identity directly.

Timing. We respond without undue delay and in any case within 45 days of receiving a verifiable request, or of verifying your identity if that is later. We may extend once by a further 45 days where reasonably necessary because of the complexity or number of requests, and will tell you within the first 45 days if we do. Requests are free, up to twice in any 12-month period. We may charge a reasonable fee for, or decline, requests that are manifestly unfounded, excessive or repetitive; if we decline we will tell you why.

Appeal. If we refuse to act on your request, we will tell you why and how to appeal. To appeal, reply to our decision or e-mail services@actogram.ai with "Appeal" in the subject line. We will respond in writing, with our reasons, within 45 days (within 60 days if you are a Connecticut resident, as that state's law provides).

Complaint to your Attorney General. If your appeal is denied, you may submit a complaint:

  • Washington — Office of the Attorney General, complaint form at https://www.atg.wa.gov/file-complaint
  • Nevada — Office of the Attorney General, Bureau of Consumer Protection, complaint form at https://ag.nv.gov/Complaints/CSU_Complaints___FAQ/
  • Connecticut — Office of the Attorney General, complaint form at https://portal.ct.gov/ag/common/complaint-form-landing-page
  • Any other state — your state Attorney General's consumer protection office. Write to us and we will point you to it.

You do not have to appeal to us before contacting your Attorney General.

9. State summary

Washington (MHMDA) Nevada (SB 370) Connecticut (CTDPA)
Separate policy required Yes, with a link on our homepage Yes No — covered here and in the Privacy Policy
Opt-in consent for health data Yes Yes Yes (sensitive data)
Sale Only with signed authorization; we do not sell Only with authorization; we do not sell Only with consent; we do not sell
Geofencing health facilities Prohibited; we do not Prohibited; we do not Prohibited; we do not
Response to a request 45 days + 45 45 days + 45; deletion within 30 days 45 days + 45
Appeal decision 45 days — 60 days
Enforcement Attorney General, and individuals under the Consumer Protection Act Attorney General only Attorney General only

10. Changes to this Policy

We may update this Policy. A new version takes effect with the app release in which it appears, and the App shows a notice on first launch after the update. Where a change adds a category of consumer health data or a new purpose, we will tell you and ask for your consent before collecting or using it. Non-material changes update the effective date only. Versions are numbered and dated; previous versions are available on request.

11. Contact

Actogram Ltd · 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom services@actogram.ai · +44 7473 968854