subjective.PERSONAL. HEALTH.Build my free planBuild my free plan

Your information. Your choices.

Consumer Health Data Privacy Policy

Effective September 19, 2026 · Last updated September 27, 2026 · Version 2026-09-19-health-v1

This separate notice explains how Subjective Health handles your consumer health data: what we collect, why, who receives it, and how you can access, delete, or stop future collection of it.

Health information we collect

Subjective Health is operated by Centurion Movement, LLC. Consumer health data is information linked or reasonably linkable to you that identifies your physical or mental health status. We collect the information you choose to use in wellness features, including saved information from your shared Subjective and Centurion account.

Food and energy: food descriptions, meal records, nutrition estimates, calorie and protein targets, estimated full-day energy output, and daily or weekly completion and review records.

Body and goals: weight, body measurements, goals, starting-program answers including medication-use choices, preferences, and targets you accept. Personal check-ins and notes can include appetite, energy, mood, sleep, symptoms, side effects, or medication and dose if you choose to enter them. AI messages or images you submit can also contain health information.

Connected Apple Health information: with the permissions you choose in the iPhone app, the current sync bridge can upload weight, daily steps, active energy, and resting energy, with dates, sources, and sync status. Sleep is not uploaded by this bridge. Earlier records from other connected account features may contain additional information you previously chose to save.

Derived information: summaries, trends, comparisons, and AI-generated food estimates based on your entries. These are part of your health information even when calculated rather than directly entered.

Optional health-service usage information: with a separate choice, selected screen and feature names, button actions, guide progress, broad screen-size categories, approved campaign/source codes, approximate time and scroll depth, and success or general failure of an action. These records include times and random identifiers and can reveal that you use a health-related service. Signed-in usage is associated with your account. They exclude your guide answers, typed content, saved health values, photos, and raw page addresses or referring links; they are not anonymous.

For public guides and tools, optional analytics records which resource page you visit and whether you click to build a free plan. It does not record calculator activity, readings, results, or completed worksheet contents. Public-browser usage is kept separate from account usage.

Related account and service information: account identifiers, contact details, support messages, and technical request or error details when they are linked to health records or reveal use of a health-related feature. These can be health information even though they are not meal or weight entries.

Back to top

Where it comes from

You provide information through account setup, starting-plan questions, saved records, AI requests, check-ins, reviews, support messages, and any earlier intake forms. Your existing shared-account records can also appear when you sign in.

Apple Health supplies only information permitted by your device settings. Our service calculates summaries and estimates from the records you provide. You can revoke Apple Health access in your iPhone’s Health settings; revoking access stops future permitted reads but does not itself delete information already saved to your account.

When you enable optional analytics, selected actions in your browser supply the usage records. We do not join website analytics from before sign-in to your signed-in account history.

Your browser or device and our hosting and diagnostic services supply technical request and error details when you use a feature or encounter a problem.

Back to top

Why we use it

We use health information to provide the personal tracking you request: save your starting program, record meals and weight, display your chosen targets, estimate food nutrition when requested, calculate daily and weekly summaries, show your notes and connected observations, and let you review or export your record.

We also process necessary information to answer your support or privacy request, keep the service safe and working, and comply with applicable law. The current service does not provide prescribing, diagnosis, treatment decisions, or a clinician portal.

With separate permission, optional usage records help us understand which pages help people get started, which features people use or return to, and where steps fail or cause confusion. These records include session identifiers and times for calculating visit and completion patterns. A further choice lets our team use the built-in step-by-step activity view. The separate PostHog choice described below also permits session and activity-sequence analysis there. This is product improvement, not a necessary part of saving or displaying your health record.

We do not use consumer health data for advertising, audience building, affiliate targeting, or the sale of unrelated products. We do not sell consumer health data. We do not use geofencing to identify people at health-care facilities or target health-related advertising.

Back to top

Your choices and permission

You choose which records to enter and which optional features to use. The web companion asks for your affirmative choice before opening or saving health records with your account. The free starting guide uses your answers in your browser before account entry; saving them to your account requires the account permission step. Connected services also process information necessary to provide the features you request. Agreeing to service terms is not permission for unrelated health-data uses.

Optional AI food estimation sends the food description you submit to OpenAI through our server. Review the returned estimate before saving it. Manual food entry is available if you do not want to send a description for AI estimation. Apple Health requires its own device permission.

Optional analytics has its own choice, separate from permission for account health records. Letting our team use the built-in step-by-step activity view and sending a limited usage copy to PostHog have additional choices. PostHog analysis can include visits and activity sequences, independently of the built-in timeline choice. PostHog is offered only after we verify the provider setup. Declining these options does not prevent use of the service. A timeline records selected action names, not a screen video, page contents, input contents, images, or network contents.

Open Optional analytics to change these choices, download the associated usage records, or turn collection off and delete those records. Website choices before sign-in and signed-in choices are separate. For earlier website usage, use the same browser before its 30-day cookie expires or you clear it; the cookie lets us locate and manage those records without a new account. We may be unable to locate them once it is gone. You can also contact us for assistance.

Before collecting, using, or sharing an additional category of consumer health data or using it for an additional purpose not disclosed here, we will disclose the change and obtain your affirmative consent. Sharing that requires consent will have a choice separate from consent to collect; accepting this notice alone does not provide that consent.

You can withdraw health-data permission in the web companion under You → Your data & account, or use Your data & account on the permission screen before accepting. You can also contact dev@centurionmovement.com for withdrawal, including for earlier records or connected services. See the rights section below for what withdrawal changes.

Back to top

Who processes or receives it

Infrastructure providers: Vercel processes web requests that carry the health information you submit or retrieve. Amazon Web Services provides the shared backend, storage, and authentication for the health-record categories described above, including saved entries, connected observations, summaries, and associated account information. This processing delivers the features you request.

Optional product-analysis providers: Vercel processes optional usage requests and AWS stores the associated usage records. If you enable the separate PostHog choice when it is available, PostHog receives a limited copy of selected usage events for product analysis, including visits and activity sequences, with a random identifier instead of your account email. These events can reveal health-service use. We do not send saved health values or typed content for this purpose. The separate choice governs this transfer.

AI processing providers: OpenAI receives the input needed for requested AI features. Food estimation uses the food description; other connected AI features may use submitted messages, images, and relevant record context. Provider processing and retention can apply. We do not promise that these requests have zero retention.

Operational service providers: diagnostic services, including Sentry where enabled, process technical request and error details for troubleshooting; these details can identify use of a health-related feature. Our email services process the contact information and health details you include in a support or privacy request. These disclosures support troubleshooting or your request, not advertising.

No clinician, employer, health plan, advertiser, or affiliate receives access to your personal account through the current companion. If you choose to download or share a record, the recipient receives the copy you provide. We may disclose information when required by a valid legal obligation, subject to applicable law.

You may request the identities and contact details of third parties and affiliates with whom your consumer health data has been shared, as provided by applicable law. We do not provide health data to advertising networks or data brokers. The current website and companion do not enable third-party trackers to collect your health data over time across websites or services.

Back to top

Access, deletion, and withdrawal

We offer the account controls and request channels described here to all users. You can ask whether we collect, share, or sell your health information, access it, request correction or deletion, obtain information about recipients, and withdraw consent for future collection or sharing. Email dev@centurionmovement.com or use the mailing address below. We will authenticate your request without asking for your password. You do not need to create an account to make a request. Contact us if you need an accessible format or help using a request method.

You can download your companion record and request shared-account deletion from You → Your data & account. Account deletion also affects the associated Centurion account. The companion download does not include every historical Centurion feature; contact us for a broader request. Earlier intake submissions may need a separate request because they are stored outside your app account.

Optional usage records expire from access and reports after 30 days; an hourly cleanup removes expired records from the active event store. Turning off optional analytics deletes its active usage records and stops new collection for that choice. We retain limited permission and deletion records to honor and document the request. Account deletion covers account-linked usage records, and withdrawing health-data permission also turns off account analytics. Neither action automatically locates separate website usage from before sign-in; use that browser’s Optional analytics control or contact us for help.

If you enabled PostHog, turning that option off or deleting the associated analytics requests deletion of the provider copies. We also request removal of older provider copies as the associated usage identifiers expire. Provider deletion may take longer than deletion from our active records, and we follow up until it is resolved. We do not describe an accepted deletion request as confirmed erasure. The applicable deletion deadlines and backup safeguards below still apply.

Deletion requests cover applicable active records and backup copies. We notify processors, contractors, affiliates, and other recipients of a deletion request where required, and follow up on their handling of it. Deletion from backups may take longer than deletion from active systems; where Washington law applies, the permitted backup delay cannot exceed six months after authenticating the request. Any legal retention exception must be limited to its permitted purpose. Account deletion does not retrieve copies that you have already downloaded or shared yourself.

We respond without undue delay and within 45 days of receiving a request. Where legally permitted, a complex request may take one additional 45-day period; we will explain the extension within the initial period. If we deny a request, reply to appeal. We will provide the appeal decision and reasons within 45 days of receiving the appeal. Requests are ordinarily free; any legally permitted fee or refusal for excessive requests will be explained. A shorter applicable legal deadline takes precedence.

Withdrawal stops future processing that relied on your consent as soon as practicable. The web control pauses new health-data service requests and scheduled processing for your shared account. A request already running may finish, and information already transmitted to a provider cannot be recalled by that control. Your saved records remain unless you also request deletion. Privacy requests, export, deletion, and necessary account administration remain available without granting health-data permission again.

If an appeal is denied, Washington users may contact the Washington Attorney General. Other users may contact their state regulator; additional state request information appears in our Privacy Policy. We do not retaliate for exercising these rights. Choosing not to provide information can make a feature unavailable where that information is necessary to deliver it.

Back to top

Changes and contact

We update this notice when health-data practices change and provide notice of material changes in the app or by email. A change to this page is not retroactive consent. New categories or purposes require the disclosure and affirmative permission described above.

Questions, requests, or appeals: dev@centurionmovement.com. General website and account practices are described in our Privacy Policy.

Centurion Movement, LLC, 421 West 3rd Street Apartment 1215, Austin, TX 78701. Email: dev@centurionmovement.com.

Back to top