AshGrid is operated by the Operator named below (“AshGrid,” “we,” “us”). Questions: privacy@ashgrid.co.
Operator
Interim notice. A formal legal entity for AshGrid is being organized. This table, and the effective date above, will be updated when formation completes. Until then, “we”, “us”, and “the Operator” refer to AshGrid’s founder, operating as a sole proprietorship.
| Field | Value |
|---|---|
| Legal entity | AshGrid, operated by its founder as a sole proprietorship (formal entity being organized) |
| Entity type | Sole proprietorship — pre-incorporation |
| Registered address | Provided on request — write to privacy@ashgrid.co |
AshGrid is a personal wellness observation service. It is not a medical device, diagnostic tool, pharmacy, clinician, or provider of medical advice, and we are not a HIPAA covered entity or business associate. Results in AshGrid are personal observations with stated uncertainty, not clinical findings.
AshGrid is available only to adults (18+) residing in the United States.
1. Information we collect
Notice at collection. California requires this summary at or before the point of collection, so it is stated up front rather than only in the detail below. We collect the categories in §1.1–1.3 — including health data, which is sensitive personal information — for the purposes in §2. We use sensitive personal information only to provide the service you asked for and for the purposes §2 lists; we do not use it to infer characteristics about you. Retention is in §7. We do not sell or share personal information, and we do not use it for cross-context behavioral advertising. Your rights are in §8.
1.1 Information you give us
| Category | Examples |
|---|---|
| Account | Email address; authentication identifiers from Apple or Google if you use them |
| Eligibility | Your attestation that you are 18+ and a US resident; your US state; date of birth (stored encrypted); age band |
| Profile | Sex at birth, timezone, goals, display and notification preferences |
| Observations | Experiments you run, protocols, amounts, timing, check-in responses, notes, symptoms, and outcomes you record |
| Community | Posts, notes, votes, and reports you choose to submit, published under a rotating pseudonym |
| Submissions | Interventions or protocols you suggest for the catalog |
| Consent | A durable, append-only record of every consent you give or withdraw, with timestamp and version |
| Support | Anything you send us directly |
1.2 Health and fitness data from your device
We read data from Apple Health (HealthKit) or Android Health Connect only if you grant that permission, and it may include: heart rate, heart rate variability, sleep, steps, active and basal energy, walking distance, oxygen saturation, respiratory rate, body temperature, body weight, and exercise and stand minutes.
We read only the metric types relevant to the experiments you are running. We never write to HealthKit or Health Connect. You can revoke this permission at any time in your device settings, and doing so stops all further reads immediately.
1.3 Information collected automatically
Device and app version, IP address, coarse timing and diagnostic telemetry, error reports, and request logs used for security, abuse prevention, and reliability.
1.4 What we do not collect
We do not collect precise geolocation, contacts, photos, microphone, or camera data. We do not use advertising identifiers, and we do not operate advertising on AshGrid.
2. How we use information
We use information to:
- provide the service: run your experiments, compute your results, and show your history;
- compute community evidence — aggregate, reliability-adjusted observations across users, subject to a minimum-cohort floor (see §4);
- generate written interpretations of your results, including via AI processing (§6);
- send notifications you have enabled;
- review, moderate, and standardize catalog submissions and community content;
- secure the service, prevent abuse and fraud, and enforce our terms;
- improve, develop, and create new products, features, models, and research, including by analyzing de-identified data (§4);
- comply with law and respond to lawful requests.
Legal bases (where applicable): performing our contract with you; your consent for health data, wearable access, and aggregate contribution; and our legitimate interests in security, abuse prevention, and product improvement.
3. Consent, and how it works here
Consent in AshGrid is specific, layered, and independently revocable. Granting one does not grant another:
- Account and core service — required to use AshGrid.
- Device health data — optional; granted in the OS permission prompt; revocable in device settings.
- Aggregate contribution — optional; a separate, neutrally-worded choice with no pre-selected default, presented during setup as its own decision and revocable at any time in Profile.
- Public posting — optional and per-post; nothing you write is public unless you post it.
Every grant and withdrawal is written to an append-only consent record. Withdrawal takes effect going forward; it does not retroactively un-publish aggregates that were already computed and released (see §4.3).
4. De-identified and aggregate data
This section covers AshGrid’s research output and the commercial rights we hold in it.
4.1 What we create
If you turn on aggregate contribution, we transform your completed results into de-identified research records. Before this happens we strip direct identifiers and replace your account with a rotating analytical key that is not linkable back to you by recipients. From those records we compute cohort statistics and combination (“interaction”) statistics.
4.2 The minimum-cohort floor
We do not publish a community statistic unless at least 30 unique people are present in every compared group, along with statistical and practical-effect thresholds. Below that floor, the app shows that evidence is still forming rather than showing a number. We do not subdivide by dose or demographics at that floor.
4.3 Our rights in de-identified and aggregate data
You grant us a perpetual, irrevocable, worldwide, royalty-free, sublicensable license to use, reproduce, modify, publish, and create derivative works from de-identified and aggregated data derived from your contributed observations, for any lawful purpose, including research, publications, evidence products, benchmarking, model development, and commercial offerings.
Because this data is de-identified and non-linkable, it is no longer personal information, and it survives deletion of your account (§8.3). Deleting your account removes your identifiable data; it does not retract aggregate statistics that already incorporate your de-identified contribution.
4.4 What we will never do with your health data
- We do not sell your personal information or your health data.
- We do not sell, license, or transfer raw wearable data — ever, in any form.
- We do not use health data for advertising or marketing, and we do not share it with data brokers.
- We do not use your identifiable health data to train third-party AI models, and our AI providers operate under zero-retention, no-training terms (§6).
These limits also reflect binding obligations to Apple and Google as a condition of HealthKit and Health Connect access.
5. When we share information
| Recipient | What | Why |
|---|---|---|
| Supabase | Account, profile, observations (encrypted in transit and at rest) | Database and authentication hosting, United States |
| Google Cloud (Cloud Run, United States) | Application traffic | Running the API |
| Anthropic | Minimal, non-identifying content for text generation | AI features, under zero-retention and no-training terms |
| Sentry | Diagnostics and error reports, scrubbed of health content | Reliability |
| Apple / Google | Authentication identifiers only | Sign-in you chose |
We may also disclose information when required by law or valid legal process; to protect the rights, safety, or property of AshGrid, our users, or the public; and in a merger, acquisition, financing, or sale of assets, in which case your information may transfer to the successor, subject to this policy or a materially similar one.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. AI processing
Some features generate written summaries of your own results. When they do, we send the minimum necessary content to our AI provider under contractual terms requiring zero retention and no training on your data. AI-generated text is automatically re-checked against a language filter before it is stored or shown, so that output is phrased as personal observation and not as medical claim, diagnosis, or treatment advice.
AI never determines safety, calculates official statistics, or recommends restricted substances. Statistical results are computed deterministically, not by a language model.
7. Retention
California’s CPRA requires a retention period, or the criteria used to set one, for each category we collect — not a general statement. This table covers every category listed in §1.
| Category (§1) | Retention period or criteria |
|---|---|
| Account (email, sign-in identifiers) | While the account is active; deleted within 30 days of a deletion request |
| Eligibility (age, US residency, state, DOB) | While the account is active, then 12 months, because it evidences that we lawfully served an adult US resident |
| Profile (sex at birth, timezone, goals, preferences) | While the account is active; deleted with the account |
| Observations (experiments, check-ins, notes, results) | While the account is active; deleted with the account |
| Community content (posts, notes, votes, reports) | Until you delete the item, or with the account |
| Submissions (catalog suggestions) | While the account is active. A submission accepted into the catalog stays as catalog content, without your identifiers |
| Consent records | 6 years after the consent ends — these are the evidence that consent was given, so they must outlive the data they authorized |
| Support correspondence | 24 months from the last message |
| Device and diagnostic logs, IP address | 30 days, then deleted or aggregated |
| Wearable ingest cache | 2 days, then hard-deleted |
| Data export files | 3 days, then deleted |
| Content sent to AI providers | Zero retention by the provider |
| De-identified aggregates | Indefinitely — no longer personal information (§4.3) |
Where a period is longer than the account’s life, it is because the record evidences a legal obligation we must be able to demonstrate, or because it is no longer linkable to you. We do not keep personal information we no longer have a stated reason to hold.
8. Your rights and choices
8.1 Rights
Depending on your state, you may have the right to know, access, correct, delete, obtain a portable copy, opt out of sale or targeted advertising (we do neither), limit use of sensitive information, and not be discriminated against for exercising a right.
Residents of Washington and Nevada: see the separate Consumer Health Data Privacy Policy, which governs consumer health data and provides additional rights, including the right to withdraw consent and to have consumer health data deleted.
California (CCPA/CPRA). We collect the categories in §1, use them for the purposes in §2, and disclose them to the recipients in §5. We do not sell or share personal information as the CCPA/CPRA defines those terms, and we have not in the preceding 12 months. Health data is sensitive personal information; we use it only to provide the service you requested and for the purposes §2 lists, which do not include inferring characteristics about you — that already meets the standard the “limit the use of my sensitive personal information” right imposes, so there is no additional use for it to restrict. You may also designate an authorized agent to make a request on your behalf.
Comprehensive state privacy laws. If you live in a state with a comprehensive consumer privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, and others as they take effect — you have the rights listed above, and, where that state provides it, the right to appeal a denial (§8.2) and to contact your Attorney General if the appeal is refused.
Several of those laws treat health data as sensitive data requiring opt-in consent. AshGrid is built that way already: device health access is an OS-level opt-in, and aggregate contribution is a separate choice with no pre-selected default (§3).
We do not process personal data for targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects (§10), so there is no processing of that kind for those opt-out rights to act on.
8.2 Exercising them
- Access / portability — Profile → Export my data, which produces a complete structured JSON copy immediately, at no cost.
- Correction — edit in the app; observations are append-only, so corrections are recorded as new entries referencing the prior one rather than overwriting history.
- Withdraw contribution — Profile → data contribution.
- Deletion — Profile → delete account, or email privacy@ashgrid.co.
- Appeal — if we deny a request, reply to our decision and we will re-review and respond in writing.
We respond within 45 days, extendable once by 45 days where permitted, and we do not charge for these requests.
8.3 What deletion does
Deleting your account removes your identifiable data: profile, observations, check-ins, results, wearable connections, and community content authored under your pseudonyms.
It does not remove de-identified aggregate statistics that already incorporate your contribution, because those are no longer linkable to you and removing one contribution would not be possible without re-identifying it. This is disclosed here, and again at the point of deletion.
9. Security
RLS on every table so a user’s rows are unreachable by other users; encryption in transit (TLS) and at rest; sensitive identifiers such as date of birth encrypted at the column level; authentication tokens stored in the device secure enclave (Keychain / Keystore), never in general app storage; privileged keys held server-side only; append-only audit records for administrative action; and least-privilege administrative access.
Breach notification. No system is perfectly secure. If a breach affects your personal information we will notify you without unreasonable delay and, where required, within the timeframe your state’s breach-notification law sets, and we will notify regulators and any other parties the law requires. The notice will describe what happened, the categories of information involved, what we have done, and what you can do.
Data minimization. We collect what a feature needs and no more. Wearable reads are limited to the metric types your active experiments use; content sent to AI providers is reduced to the minimum necessary; and diagnostics are scrubbed of health content before they leave the service.
10. Automated processing
AshGrid computes your results deterministically — the statistics, effect estimates, reliability score, and outcome verdict are produced by fixed, versioned code, not by a language model. AI is used only to write the plain-language explanation of a result that has already been computed, and that text is re-checked against a language filter before you see it (§6).
We do not use automated processing to make decisions that produce legal or similarly significant effects about you. Nothing in AshGrid determines eligibility for credit, insurance, employment, housing, or healthcare, and no output is a diagnosis or a treatment decision.
11. Do Not Track and Global Privacy Control
We do not track you across other companies’ apps or websites, and we do not serve targeted advertising, so a cross-site opt-out signal has no tracking here to act on. We honor Global Privacy Control signals where they reach us and where law requires it.
12. Children
AshGrid is for adults 18 and over. We do not knowingly collect information from anyone under 18. If we learn we have, we will delete it. The app checks eligibility at signup rather than relying on this policy alone.
13. United States only
AshGrid is offered only in the United States and its data is processed in the United States. We do not offer the service to, or knowingly collect information from, people outside the US.
14. Changes
We will post any change here with a new “Last updated” date. For material changes to how we use health data or de-identified contributions, we will give notice in the app and — where the law requires it — obtain your consent again before the change applies to you.
15. Contact
The Operator named at the top of this document. privacy@ashgrid.co