Integrated Wellness

Privacy Policy

Effective date: February 2026

The short version

Your health data belongs to you. We collect only what we need to run your optimization program, we never sell it, and you can export or permanently delete everything the portal stores about you at any time from Account & Privacy inside the portal.

What we collect

When you enroll and use the member portal, we store:

  • Profile information — name, email, age, sex, height, program and goals.
  • Progress data — weekly check-ins, weight, body composition, measurements and progress photos you choose to upload.
  • Lifestyle logs — nutrition, workouts, water, sleep and wearable-device data you import or enter.
  • Conversations — messages you exchange with the portal's AI assistant and files you share with your care team.
  • Account security data — hashed passwords, sign-in attempts and optional two-factor settings. We never store plain-text passwords.

How we use it

  • To deliver your clinician-approved plan and track your progress against it.
  • To let your care team review check-ins and adjust your protocol. No prescribed target is shown to you before a clinician approves it.
  • To personalize AI-assistant answers — grounded exclusively in your own released plan and logs.
  • To keep your account secure (fraud and abuse prevention, sign-in protection).

We do not sell your personal information, and we do not use your health data for advertising.

Who we share it with

Only the systems that operate your care, under contractual safeguards:

  • Healthie — our electronic health record, where your clinical chart lives.
  • Notion — our care team's clinical workspace for plan review and coaching notes.
  • JotForm — secure intake, activation and weekly check-in forms.
  • AI processors — assistant messages are processed by enterprise AI providers to generate responses; they are not used to train public models.
  • Infrastructure providers — encrypted hosting, database and file storage.

We may disclose information if required by law, or to protect the safety of a member or the public.

How we protect it

  • All traffic is encrypted in transit (TLS/HTTPS, HSTS enforced).
  • Access to your record requires your credentials; every API request is authorized against your own account only.
  • Optional two-factor authentication and one-time backup codes.
  • Sessions end when you close the tab unless you explicitly choose “Keep me signed in”, and the portal signs you out automatically after 30 minutes of inactivity.
  • Draft plan targets are provider-locked — they never reach your browser before clinician approval.

Your rights and controls

  • Export — download a complete JSON copy of everything the portal stores about you (Account & Privacy → Export your data).
  • Delete — permanently erase your portal account and all tracked data (Account & Privacy → Delete my account). Your separate clinical record in our care system is managed by your care team — ask them for erasure there.
  • Correct — ask your coach to correct any profile or clinical information.

Retention

We keep your portal data while your account is active. When you delete your account, portal data is erased immediately. Records our care team must keep for clinical or legal reasons are retained in the clinical record system per applicable healthcare record-keeping requirements.

Questions

Contact your coach or care team through the portal, or reach us via the contact options on our Get Started page. See also our Terms of Use.