Consumer Health Data Privacy Policy
Effective Date: September 24, 2026
Last updated: September 24, 2026
Applies to: Residents of Washington and Nevada. Connecticut residents should also read Section 9.
Mustro, Inc., a Delaware corporation ("Mustro," "we," "us," or "our") publishes this policy to meet the Washington My Health My Data Act (RCW chapter 19.373) and the Nevada consumer health data law (SB 370 of 2023, NRS chapter 603A). It is a separate document from our general [Privacy Policy](https://mustro.ai/legal/privacy-policy), as those statutes require, and it covers only consumer health data.
Where this policy and the general Privacy Policy both describe the same practice, they are meant to agree. If they ever conflict on consumer health data for a Washington or Nevada resident, this policy governs.
We do not sell consumer health data. We have never sold it, and selling it is not part of any current or planned business model. If that ever changes, we will obtain the separate valid authorization the law requires before any sale occurs, and we will update this policy first.
1. What Counts as Consumer Health Data Here
"Consumer health data" means personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status. Under Washington and Nevada law this is broader than the health information covered by HIPAA, and broader than the "special category" health data defined by the GDPR. Mustro is not a HIPAA covered entity or business associate, and the data described here is not protected health information under HIPAA.
Mustro only holds consumer health data if you install the Health Skill. If you have not installed it, we hold none of the categories in Section 2.
2. Categories of Consumer Health Data We Collect, and Why
| Category | Examples | Why we collect it |
|---|---|---|
| --- | --- | --- |
| Sleep data | Sleep duration, stages, timing, sleep scores | To produce your briefings and to time recommendations around your recovery |
| Recovery and readiness data | Readiness scores, heart rate variability, resting heart rate | To adjust what Mustro suggests on a given day and to shape training plans |
| Vital signs | Heart rate, respiratory rate, blood oxygen, body temperature | To surface trends and to inform training load |
| Body composition | Weight, body fat percentage, lean mass | To track progress against goals you set |
| Cardiorespiratory fitness | VO2 max and related estimates | To set and adjust training intensity |
| Stress indicators | Stress and strain measures reported by your device | To adjust the intensity of what we suggest |
| Workout and activity records | Sessions, sets, loads, distances, durations, personal records | To maintain your training history and measure progress |
| Training plans and related records | Plans we generate, revisions, prescribed sessions, benchmark results, adherence records | To build, adjust, and track the plan you asked for |
| **Health information you write yourself** | Injury and medical constraints you type into a goal spec ("bad knee, no running"), and the text of any plan you paste in to import | To build a plan that respects your limits |
| Health settings | Which categories you enabled, units, and related preferences | To honour the choices you made |
The last two rows matter most. Information you type is health information about you just as much as information a device measures, and we treat it the same way.
If you enable health calendar sharing, we use workout, training-plan session, recovery and health-linked habit information to place events in your own Google Calendar. Section 4 describes that destination. Time scheduling becomes available in stages. These disclosures apply before you enable its health-sharing features.
If you enable Strava sharing, we also use your completed workout and recovery records to create activities in your Strava account. The fields we share appear in Section 4. We keep sharing preferences and activity identifiers to operate the connection, show results, and help prevent duplicate activities.
3. Categories of Sources
Our health measurements and session content come from the three sources listed below.
- Apple HealthKit, on your device, for the categories you tick in the iOS permission sheet.
- Oura, through the access you authorise on Oura's own screen.
- You, directly, when you log a workout, set a goal, type a constraint, paste in a plan, or change a health setting.
For Strava sharing, Strava also provides your account identifier and responses about activities you ask us to send. We use these records to link your account and show sharing results. We do not import Strava activity history or health measurements.
We do not buy consumer health data, we do not obtain it from data brokers, and we do not infer it from your bank, calendar, or email data.
4. Categories of Consumer Health Data We Share, and With Whom
We do not share consumer health data with advertisers or data brokers. We share it with the service providers listed below to run the Services. If you separately enable Strava sharing, we also send the session fields listed below to Strava. Strava uses that copy for its own service under its own privacy policy.
| Category of third party | Specific parties | What they receive | Constraints |
|---|---|---|---|
| --- | --- | --- | --- |
| Cloud hosting and storage | Google Cloud Platform | All categories in Section 2, encrypted at rest | Processes only on our instructions; no independent use |
| AI inference providers | Anthropic, OpenAI | Only the health data needed for the specific request, including constraint text and plan content | Contractual zero-retention terms; prompts and outputs are not retained and are **not used to train their models** |
| Transactional email | Resend | Notification content only; no health measurements | Delivery only |
| Push notification delivery | Expo | Notification content only; no health measurements | Delivery only |
We share consumer health data with no affiliates, because Mustro has none. The full vendor list for the Services is in our Subprocessors page. Adding a subprocessor that would receive consumer health data is a material change, and Section 10 says what we do first.
Optional recipients you connect
| Recipient category | Specific party | Information sent | Purpose and controls |
|---|---|---|---|
| --- | --- | --- | --- |
| Calendar service selected by you | Google Calendar | Workout, plan-session, recovery and health-linked habit titles and times. Existing Health and Habits calendar integration may also include routine descriptions, health-linked habit notes, and identifying properties linking the event to your Mustro workout, routine or habit record. | Place scheduled, live and completed health items in your connected calendar at your direction. Time writes private events and offers a neutral-title option. Google handles the calendar copy under the terms and settings of your Google account. |
| Fitness activity service selected by you | Strava | Session name, kind, start time, duration, and description. Strength includes exercise names, sets, repetitions, weights, warmup labels, and muscle groups. Cardio includes recorded distance, average heart rate, and calories. Recovery includes its kind and recorded temperature. | Create the activities you request. Your Strava privacy settings control visibility. Strava handles the copy under its own privacy policy. |
The Strava description includes a Mustro waitlist link and your referral code if you own one. We exclude notes fields. Routine and exercise names remain in the activity.
For Google Calendar, review Google's Privacy Policy and use Google's privacy contact form for questions about its processing. A private event or neutral title still goes to Google. Neither removes the separate sharing requirement. Busy copies on other accounts can reveal that time is reserved, so the sharing choice must cover those destinations.
Strava's privacy contact is DPO@strava.com. You can also use Strava Support. Its Privacy Policy describes its processing and your choices.
We may also disclose consumer health data where the law compels it, for example in response to a valid subpoena or court order. Where we are permitted to tell you, we will.
5. Consent, and How to Withdraw It
We ask for your consent before we collect consumer health data, and separately before we share it, as Washington and Nevada require.
What you agree to, and when. Before Apple Health data, Oura data, or health information you type reaches us, we show you consent language that names the categories concerned, what we do with them, the fact that the data goes to the AI providers named in Section 4 under zero-retention terms, and how to withdraw. Only after you agree does the collection begin.
Google Calendar sharing. Before health information is written to a connected calendar, we require a separate, recorded agreement for that destination and purpose. This applies to Time and to existing scheduled, live and completed-workout calendar sync. Earlier health collection consent, a Google permission grant, and acceptance of the Terms do not replace it. We keep health calendar writes off without a current agreement, including events with neutral titles. Materially changed recipients, fields or purposes require fresh consent before sharing begins.
The agreement covers the health fields and connected destinations shown to you. You can decline health calendar sharing and use the other available features. Consent to health calendar sharing does not by itself authorize readiness-driven changes to a workout. We disclose that purpose separately before enabling it.
Strava sharing. We ask for a separate agreement before you connect Strava. You can change automatic sharing choices under that agreement. Materially changed wording requires a fresh agreement. The screen describes the fields, referral link, and automatic sharing choices. You then authorize Mustro in Strava. Each automatic session kind starts off. Manual sharing requires an activity review. If you enable automatic sharing, future eligible native sessions of those kinds are sent without another review. Your earlier consent to health collection or AI processing does not authorize Strava sharing.
What we record. For each consent we record the scope, the version of the consent text you were shown, a cryptographic digest of the exact wording that appeared on your screen, the categories you granted, where the act happened, and the date and time. We verify that digest against the published wording as we record it, so a consent of ours can never be recorded against text you were not actually shown.
Withdrawing. You can withdraw any consent at any time by emailing privacy@mustro.ai. For health collection consent, you can also use Settings → Health → Consent. Strava sharing uses the separate control below. For Google Calendar sharing, contact privacy@mustro.ai or turn off the relevant calendar integration. You can also revoke Mustro access in your Google account to stop all Google Calendar access. Withdrawal stops new collection and sharing requests covered by that consent. It does not undo processing that already lawfully happened, and it does not by itself delete what we already hold. To delete, use Section 6.
To withdraw Strava sharing consent, open You > Strava and select Disconnect Strava. This turns off automatic sharing and stops new requests from Mustro. A request already in progress may still complete. If provider revocation remains unconfirmed, remove Mustro in Strava App Settings. Use Section 6 to request deletion.
We keep the record of a withdrawn consent rather than erasing it, because that record is what shows the earlier processing was permitted. Closing your account deletes the record along with everything else.
6. Your Rights
If you are a Washington or Nevada resident, you have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data.
- Access the consumer health data we hold about you, including a list of all third parties with whom we have shared it and an active email address or other online mechanism for contacting them.
- Withdraw consent to our collection and sharing of your consumer health data.
- Delete your consumer health data.
- Appeal a refusal to act on any of the above.
How to exercise them. Email privacy@mustro.ai, or use the in-app controls: Settings → Privacy → Download My Data for access, Settings → Health → Consent for health collection withdrawal, and Settings → Account → Delete Account for deletion. For Strava sharing withdrawal, use You > Strava as described in Section 5. We may need to verify your identity first, and we will not use anything you send us for verification for any other purpose.
Timing. We respond within 45 days. If we need more time we will tell you why within that period and take no more than a further 45 days. For an authenticated Nevada request to delete consumer health data, the deletion and recipient-notification deadline is 30 days, subject to the statutory backup exception.
Deletion. When you make an authenticated request to delete consumer health data, we delete the covered data from our systems as applicable law requires. We also notify recipients of the request where the law requires, including Google Calendar and Strava when they received the covered data.
Stopping health calendar sharing stops new writes. It does not itself remove an event already held by Google. You can delete that event in Google Calendar or request deletion through privacy@mustro.ai. We will carry out our deletion and recipient-notification duties under applicable law.
The in-app controls do not automatically delete activities already sent to Strava. You can delete those activities in Strava. That option does not replace our duties when you send us a deletion request.
Encrypted backups are purged on a rolling 30-day cycle. This consumer health data commitment governs over the general Privacy Policy's 90-day backup limit. Account deletion removes the consumer health data Mustro holds under this policy. It does not automatically remove a Strava activity.
Appeals. If we decline a request, we will tell you why and how to appeal. Send an appeal to privacy@mustro.ai with "Appeal" in the subject line. We respond to appeals within 45 days. If we deny your appeal, Washington residents may contact the Washington Attorney General at www.atg.wa.gov/file-complaint, and Nevada residents may contact the Nevada Attorney General at ag.nv.gov.
7. We Do Not Sell Consumer Health Data
We do not sell consumer health data as those statutes define "sell", which covers exchanging it for anything of value, not only for money. Selling it would require your separate written authorization, distinct from the consent in Section 5 and meeting the specific content requirements of RCW 19.373.070. We do not seek that authorization, because we do not sell.
8. No Geofencing
We do not use geofences around any health care facility, and we do not use geofencing to identify or track anyone seeking health care services, to collect consumer health data, or to send anyone health-related advertising. Mustro does not run advertising at all.
9. Connecticut Residents
Connecticut law reaches consumer health data through the Connecticut Data Privacy Act as amended by Public Act 23-56, which classifies consumer health data as sensitive data. That means we must have your opt-in consent before processing it, which is what Section 5 describes, and you have the CTDPA rights of access, correction, deletion, portability, and appeal.
Connecticut does not require this separate document. We cover you here so that one page answers the question for every state that treats this data as sensitive. Exercise your rights the same way, through privacy@mustro.ai.
10. Changes to This Policy
If we materially change how we collect, use, or share consumer health data, we will update this policy, change the "Last updated" date, and obtain fresh consent before the new practice begins. We will not apply a new practice to data we already hold on the strength of a consent you gave for something else.
11. Contact
Mustro, Inc. Privacy: privacy@mustro.ai
For all other privacy questions, including data that is not consumer health data, see our Privacy Policy.