Our privacy promise. Your health is some of the most personal information that exists, and we treat it that way. We collect only what we need to give you care and insight. We do not sell your personal information. We do not use your identifiable health data to train generalized AI models, and your data is never used in or as the basis of any insurance or underwriting model. We protect your data with strong encryption, we share it only with the people and partners delivering your care, and we give you real control to access, export, or delete it. This policy explains, in plain language, exactly what we collect, why, and the rights you have.
1. Scope of This Policy
This Privacy Policy describes how Pymander Technologies Inc. ("Pymander," "we," "us") collects, uses, shares, and protects information when you use the Pymander Health websites, apps, text-message coaching, and services (the "Service"). Some health information you share is created or held in connection with licensed healthcare Providers and may also be protected health information under the Health Insurance Portability and Accountability Act ("HIPAA"); where that applies, the Provider's Notice of Privacy Practices and our agreements with Providers also govern how that information is handled.
2. Information We Collect
We collect the following categories of information:
- Account and identity information you provide, such as your name, email address, phone number, date of birth, and the credentials you use to sign in.
- Health information you choose to share or generate through the Service, such as your health history, intake responses, goals, symptoms, lab results ordered or uploaded through the platform, prescriptions, and the content of your consultations and coaching conversations — including coaching conversations conducted by text message.
- Wearable and connected-account data you choose to link, as described below.
- Payment information, processed by our PCI-compliant payment processors. We do not store full payment-card numbers.
- Usage and device information collected automatically, such as log files, device identifiers, app interactions, and approximate location derived from your IP address, used to operate, secure, and improve the Service.
- Communications you send us, such as support requests, survey responses, and text messages sent to your coach.
3. How We Use Your Information
We use your information to provide and personalize the Service, including to deliver longevity and wellness features, generate insights through our coaching tools, deliver coaching conversations by text message and in-app messaging, coordinate consultations with licensed Providers, fulfill prescriptions and lab orders, process payments, communicate with you, maintain safety and security, prevent fraud and abuse, and comply with legal obligations. We use information only for purposes compatible with why it was collected, and we minimize what we use wherever we can.
4. Artificial Intelligence, Our Care Team, and Your Data
Our coaching features generate insights and suggestions for you using the information relevant to your request. We want to be clear about how this works:
- Your data is used to construct your own coaching responses and insights at the time you ask for them. It is not a source for advertising.
- Our care team works alongside our AI tools. Coaching responses may be prepared, reviewed, or refined by members of the Pymander care team working with our AI systems, particularly during early access as we build and validate the Service. Every member of our care team is bound by confidentiality obligations, and access to your conversations is limited to the people involved in delivering and safeguarding your care.
- Beyond care delivery, human review of coaching interactions is limited to what is necessary for safety, quality assurance, security, legal compliance, or where you have asked for help, and is subject to the same confidentiality controls.
- We do not use your identifiable health information to train generalized, foundation, or third-party AI models. Where we work to improve our own features, we use data that has been aggregated and de-identified so it can no longer reasonably be linked to you. If we ever invite you to contribute identifiable data to a specific, named research or improvement program, we will ask for your separate, explicit consent for that program alone, and declining will never affect your care.
- AI output is educational and is not a medical diagnosis or treatment. Clinical decisions are made by licensed Providers, as described in our Terms of Service.
5. Text Message Coaching and Communications
Coaching through Pymander is delivered in part by SMS and iMessage. By enrolling in text-message coaching, you consent to receive recurring coaching, care-coordination, and account messages at the mobile number you provide. Message frequency varies with your plan and activity. Message and data rates may apply. Reply STOP at any time to stop receiving messages and HELP for help; you can also manage messaging in your account settings or by contacting us. Consent to marketing texts is never a condition of purchase, and coaching texts are part of the Service you enroll in.
Text messages are transmitted through third-party messaging delivery providers acting as our service providers under confidentiality obligations. Standard SMS is not an encrypted channel, and message security in transit depends in part on your carrier and device; we protect message content on our systems as described in Section 10. If you prefer not to discuss sensitive topics by text, you can use the app or ask to move any conversation to another channel.
6. Wearable Device Data
Pymander integrates with wearable and connected sleep devices including Apple Watch, Whoop, Oura Ring, Eight Sleep, and Garmin. Wearable data, such as heart-rate variability, sleep stages, recovery scores, activity metrics, bed temperature, and blood-oxygen levels, is synced only with your explicit consent. This data is used exclusively to support your care, power personalized health insights, and inform Provider consultations. Wearable and coaching data informs your care; it is not a real-time emergency monitoring system, and no one is watching a live feed of your data. You may disconnect any wearable integration at any time from your account settings, which stops future syncing.
7. Google User Data
When you choose to connect your Google Calendar to Pymander Health, we request access to two scopes:
https://www.googleapis.com/auth/calendar.readonly: read-only access to events on your primary calendar. We use this to give your coach context about your day so it can recommend bedtime adjustments before early meetings, modify workout intensity around travel, schedule recovery practices on light-meeting days, and avoid recommending early-morning workouts before flights.https://www.googleapis.com/auth/calendar.events: write access used only when you explicitly ask the coach to put something on your calendar (for example, "schedule a 30-minute walk at 4pm" or "put a sauna session on Thursday morning"). The coach never creates, modifies, or deletes events on its own. It does not modify or delete events created by other apps or by you.
Pymander Health's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we commit that data accessed through Google's APIs is:
- used only to provide and improve features visible to the user inside Pymander Health (the coach's context-aware recommendations and explicit user-requested calendar writes);
- never used for advertising or sold to advertisers;
- never shared with third parties except as necessary to provide or improve user-facing features (e.g. our infrastructure providers, under contractual confidentiality), or as required by law;
- never accessed by humans except where necessary for security, to comply with applicable law, when we have explicit user consent to do so, or where the data has been aggregated and anonymized so it can no longer be linked to an individual;
- never used to develop, improve, or train generalized AI / machine learning models. (Calendar data is read at request time to construct your individual coaching response, not used to retrain coach models.)
Tokens issued by Google are stored encrypted in our database and used solely to call Google's APIs on your behalf. You can revoke access at any time from Settings → Connections in the Pymander Health iOS app, or from myaccount.google.com/permissions. Revoking access immediately stops all calendar reads and writes by Pymander; existing event references in your past coaching conversations remain in your message history but no new calendar data is fetched.
8. How We Share Information
We share your information only as needed to run the Service and care for you, and never to sell it. Specifically, we may share:
- With licensed Providers involved in your care, so they can review your information and make clinical decisions.
- With healthcare partners who fulfill your care, including CLIA-certified laboratories for diagnostic testing and licensed pharmacies for prescriptions. They receive only the minimum information necessary.
- With service providers who process data on our behalf — such as secure hosting, payment processing, messaging delivery, and AI infrastructure providers that power our coaching tools — under contracts that require them to protect your data, use it only to provide services to us, and never use it to train their own models.
- For legal and safety reasons, when required by law, valid legal process, or to protect the rights, safety, and security of you, others, or Pymander.
9. We Do Not Sell Your Data
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not give advertisers or data brokers access to your health data. We do not use your protected health information to serve you ads. Your data is never used in, or as the basis of, any insurance, credit, employment, or other underwriting or eligibility model — ours or anyone else's.
10. Data Security
We use strong, industry-standard safeguards to protect your information, including encryption in transit (TLS 1.3) and at rest (AES-256), access controls that limit data to authorized personnel and your designated care team, audit logging, and regular security testing. Our handling of protected health information is designed to align with HIPAA requirements, and we enter into business-associate agreements with partners where required. No system is perfectly secure, but we work continuously to protect your data and will notify you and the appropriate authorities of a breach affecting your information as required by law.
11. Data Retention
We keep your information for as long as your account is active and as needed to provide the Service. We may retain certain information longer where required to meet legal, medical-record, tax, or regulatory obligations, to resolve disputes, or to enforce our agreements. When information is no longer needed, we delete it or de-identify it. Medical records held by Providers are retained according to the Provider's legal obligations.
12. Your Privacy Rights and Choices
You are in control of your information. Depending on where you live, you have the right to:
- Access the personal information we hold about you, and learn how we use and share it.
- Correct inaccurate information.
- Delete your personal information, subject to legal retention requirements.
- Export a portable copy of your health data in a common, machine-readable format.
- Withdraw consent or disconnect integrations at any time, and opt out of non-essential communications.
- Be free from discrimination for exercising any of these rights.
To exercise any right, use your account settings or contact us at hello@pymander.app. We will verify your request and respond within the timeframe required by law (generally within 30 to 45 days). You may use an authorized agent where the law allows, and you may appeal a decision by replying to our response.
13. Consumer Health Data
Some states, including Washington and Nevada, have laws that specifically protect "consumer health data" that is not covered by HIPAA. For residents of those states, this section, together with the rest of this policy, serves as our consumer health data privacy policy. The categories of consumer health data we collect, our purposes for collecting them, the categories of recipients, and your rights are described in Sections 2, 3, 8, and 12 of this policy. We collect and share consumer health data only with your consent or as necessary to provide the Service you request. We do not sell consumer health data, and we do not process it for advertising. You may exercise your rights to access, delete, or withdraw consent, and appeal any decision, by contacting hello@pymander.app. We do not use geofencing around healthcare facilities.
14. State Privacy Rights
Residents of California and other states with comprehensive privacy laws have the specific rights described above, including the rights to know, access, correct, delete, and to opt out of any "sale" or "sharing" of personal information. Because we do not sell or share your personal information for advertising, there is no sale to opt out of, but you may still exercise your other rights as described in Section 12. California residents may also be entitled to information about our data practices under the "Shine the Light" law.
15. Cookies, Analytics, and Similar Technologies
Essential storage. To keep you signed in and to secure the Service, we store a session token in your browser and use strictly necessary first-party cookies for account and administrative access. These are required for the Service to function and are never used for advertising.
Analytics. We measure aggregate, non-identifying usage of our public pages — such as page views, referring sites, and approximate country — using a privacy-focused, cookieless analytics tool. It sets no cookies, does not track you across other websites, and does not build an advertising profile. We do not run analytics on pages where you view your health information.
Attribution. When you join the waitlist, we record how you arrived (for example, a campaign link or referring site) so we can understand which channels reach people. This is captured in temporary first-party session storage that is cleared when you close the tab — it is not a cookie and is not shared with anyone.
No advertising trackers. We do not use third-party advertising or social-media tracking pixels, and we do not sell or share your information for advertising. Because our analytics are cookieless, no cookie-consent banner is required. You can also block storage through your browser settings, though sign-in and other essential features may not work without it.
16. Children's Privacy
The Service is intended for adults 18 and older. We do not knowingly collect personal information from children under 18. If you believe a child has provided us information, contact us and we will delete it.
17. International Users
The Service is operated in the United States and intended for U.S. residents. If you access it from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your location.
18. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or the law. If we make material changes, we will notify you by email or through a prominent notice in the Service before they take effect, and we will update the "Last updated" date above. Your continued use of the Service after changes take effect means you accept the updated policy.
19. Contact Us
If you have questions about this Privacy Policy or how we handle your data, or to exercise your rights, contact us at hello@pymander.app or write to Pymander Technologies Inc., [mailing address], United States.