/home/u618079740/domains/agencyfbinternational.com/public_html/tjwright573/wp-content/mu-plugins Privacy Policy – tjwright573
Privacy Policy - Entropy Lifestyle

Privacy Policy

Entropy Lifestyle - Master Your Energy

Last Updated: January 6, 2026
Effective Date: January 6, 2026
Version: 1.0

At KPMS3 LLC, operating as Entropy Lifestyle ("we," "our," or "us"), we are committed to protecting your privacy and ensuring you understand how your personal information is collected, used, and safeguarded. This Privacy Policy explains our data practices for the Entropy Lifestyle mobile application (the "App") and related services (collectively, the "Service").

Our Privacy Commitment: We believe your health data belongs to you. We do not sell your personal health information. We use your data only to provide and improve our Service, and we give you control over your information.

1. Information We Collect

We collect information in several ways to provide and improve our Service:

1.1 Information You Provide Directly

Category Examples Purpose
Account Information Email address, name, password Create and manage your account
Profile Information Profile photo, timezone, preferred language Personalize your experience
Onboarding Data Wake/sleep times, work hours, wellness goals, training level, commitments Generate personalized wellness protocols
User Content Social posts, photos, comments, reactions Enable community features
Feedback Task completion status, protocol ratings, check-in responses Improve recommendations over time
Gamification Data Points earned, coins balance, badges unlocked, streak counts, level progression, challenge participation Track achievements and provide rewards
Social Connections Followers, following, club memberships, challenge participants Enable social and community features
Messages Direct messages with other users, coach communications Enable private communications
Referral Data Invite codes generated, referrals made Track referral program participation

1.2 Information from Connected Devices

With your explicit consent, we collect health and wellness data from devices and platforms you choose to connect:

Apple Health (iOS) / Health Connect (Android)

Through the Sahha SDK, we access data from your device's native health store:

  • Sleep Data: Sleep duration, sleep stages (REM, deep, light), time awake, sleep efficiency, sleep start/end times
  • Activity Data: Steps, active calories, total calories, distance, active minutes
  • Heart Data: Resting heart rate, average/max/min heart rate, heart rate variability (HRV RMSSD, SDNN)
  • Wellbeing Scores: Sleep score, activity score, wellbeing score (calculated by Sahha)

WHOOP

Via OAuth API connection:

  • Recovery score, heart rate variability (HRV), resting heart rate, sleep metrics (duration, quality, stages), strain score, respiratory rate

Oura Ring

Via OAuth API connection:

  • Readiness score, sleep analysis, activity data, heart rate data, body temperature trends

You control which devices are connected and can disconnect them at any time through your account settings. You may use only one health data source at a time.

1.3 Information from Calendar Integration

If you connect your Google Calendar, we access:

  • Event start and end times
  • Event durations
  • Free/busy status
Privacy Protection: When processing calendar data with AI services, we anonymize event information. We do not send your meeting titles, attendee names, or event descriptions to external AI systems. Only timing information (start time, duration, and a generic event classification) is used for scheduling optimization.

1.4 Information Collected Automatically

Category Examples
Device Information Device type, operating system, unique device identifiers, app version
Usage Data Features used, screens viewed, interaction timestamps, task completion rates
Log Data IP address, access times, error logs

2. Health and Wellness Data

We understand that health data is particularly sensitive. This section explains how we handle your wellness information with extra care.

2.1 Types of Health Data We Process

Data Type Source How It's Used
Recovery Metrics WHOOP, Oura, Apple Health, Health Connect Determine optimal protocol intensity
Sleep Data (duration, stages, efficiency) WHOOP, Oura, Apple Health, Health Connect Adjust wake-up protocols, assess rest quality
Heart Rate Variability (HRV) WHOOP, Oura, Apple Health, Health Connect Measure stress resilience, recovery status
Resting Heart Rate WHOOP, Oura, Apple Health, Health Connect Assess cardiovascular recovery
Activity Data (steps, calories, distance) WHOOP, Oura, Apple Health, Health Connect Balance activity recommendations
Activity/Strain WHOOP, Oura Balance activity recommendations
Wellbeing Scores Apple Health, Health Connect (via Sahha) Overall wellness assessment
Self-Reported Wellness App check-ins Refine protocol effectiveness

2.2 Our Health Data Commitments

We commit to the following health data protections:
  • No Sale of Health Data: We never sell your health information to third parties.
  • No Health-Based Advertising: We do not use your health data to target advertisements.
  • Minimal AI Exposure: When using AI services, we send only anonymized health indicators (e.g., "recovery: high" rather than exact values).
  • User Control: You can delete your health data at any time.
  • Encryption: Health data is encrypted both in transit and at rest.

2.3 Wearable Data Processing

When you connect a wearable device:

  1. You authorize our App through the wearable provider's OAuth system
  2. We receive only the data categories you approve during authorization
  3. Your wearable credentials are encrypted before storage
  4. You can revoke access at any time, which immediately stops data collection
Important: We are not a medical device and do not provide medical advice. Health metrics from wearables are estimates and should not be used for medical decisions. Always consult a healthcare professional for medical concerns.

2.4 Apple HealthKit Data (iOS Users)

If you grant access to Apple Health, we access the following HealthKit data types:

  • Sleep Analysis (sleep duration, stages, efficiency)
  • Heart Rate and Resting Heart Rate
  • Heart Rate Variability (HRV)
  • Step Count and Distance
  • Active Energy Burned
Apple HealthKit Compliance:
  • HealthKit data is used solely to provide personalized wellness protocols and display your health metrics
  • We do NOT use HealthKit data for advertising or marketing purposes
  • We do NOT sell or share HealthKit data with third parties for their advertising or marketing purposes
  • We do NOT store HealthKit data in iCloud
  • You can revoke HealthKit access at any time via iOS Settings > Health > Data Access

2.5 Google Health Connect Data (Android Users)

If you grant access to Health Connect, we access the following data types:

  • Sleep Session (duration, stages)
  • Heart Rate and Resting Heart Rate
  • Heart Rate Variability
  • Steps and Distance
  • Active Calories Burned
Health Connect Compliance:
  • Health Connect data is used solely to provide personalized wellness protocols
  • We do NOT use Health Connect data for advertising purposes
  • We do NOT sell or transfer Health Connect data to third parties for advertising
  • We do NOT serve ads based on health data
  • You can revoke access at any time via Android Settings > Health Connect > App permissions

3. How We Use Your Information

3.1 Service Delivery

  • Generate personalized daily wellness protocols based on your schedule and health data
  • Display your health metrics and trends
  • Schedule wellness activities around your calendar commitments
  • Track your progress toward wellness goals
  • Enable social features (posts, comments, reactions, follows)

3.2 Personalization

  • Adapt protocol recommendations based on your recovery status
  • Learn from your feedback to improve suggestions over time
  • Customize timing based on your circadian patterns

3.3 Communication

  • Send push notifications for scheduled protocols (if enabled)
  • Notify you of social interactions (comments, reactions, follows)
  • Communicate service updates and security alerts

3.4 Service Improvement

  • Analyze aggregate, de-identified usage patterns to improve features
  • Identify and fix technical issues
  • Develop new features based on user needs

3.5 Safety and Security

  • Protect against fraud, abuse, and unauthorized access
  • Enforce our Terms of Service
  • Comply with legal obligations

4. AI and Automated Processing

Entropy Lifestyle uses artificial intelligence to provide personalized wellness recommendations. We believe in transparency about how AI processes your data.

4.1 AI Services We Use

AI Provider Purpose Data Sent (Anonymized)
Anthropic (Claude) Protocol selection and wellness recommendations Recovery band (high/moderate/low), sleep quality band, activity level, user preferences
Google (Gemini) Schedule optimization around calendar Event times and durations (not titles), free time windows, protocol timing requirements

4.2 What We DO NOT Send to AI Services

  • Your name, email, or any personal identifiers
  • Exact health metric values (we use bands/categories instead)
  • Calendar event titles, descriptions, or attendee names
  • Raw wearable data or API responses
  • Your social posts, comments, or photos

4.3 AI Data Retention

Our AI service providers have committed to the following data handling practices:

  • Anthropic: Data is not used to train models; subject to their data retention policies
  • Google: Subject to Google Cloud's data processing terms

4.4 Opting Out of AI Processing

You can disable AI-powered features in your Privacy Settings. When disabled:

  • Protocols will be generated using rule-based algorithms instead of AI
  • No data will be sent to external AI services
  • You may receive less personalized recommendations

5. Information Sharing and Disclosure

5.1 Service Providers

We share information with third-party service providers who perform services on our behalf:

Provider Type Purpose Data Shared
Database (Supabase) Data storage and authentication All user data (encrypted)
Health Data Processing (Sahha) Process Apple Health / Health Connect data User ID, health metrics from device health stores
AI Services (Anthropic, Google) Personalized recommendations Anonymized health indicators only
Push Notifications (OneSignal) Deliver push notifications User ID, device token, notification preferences
Image Storage (Supabase Storage) Store user-uploaded photos Profile photos, post images
Analytics App performance monitoring De-identified usage data

All service providers are contractually obligated to protect your data and use it only for the purposes we specify.

5.2 Wearable Providers

When you connect wearables, data flows from:

  • WHOOP to Entropy Lifestyle (via WHOOP's API with your OAuth authorization)
  • Oura to Entropy Lifestyle (via Oura's API with your OAuth authorization)

We do not send your data back to these providers. Your relationship with wearable providers is governed by their respective privacy policies.

5.3 Social Features

If you use social features, information you share may be visible to:

  • Public posts: Any Entropy Lifestyle user
  • Private posts: Only you
  • Profile information: Other users (name, photo, follower/following counts, badges)
  • Club activity: Other club members can see your participation
  • Challenge leaderboards: Challenge participants can see your progress and rankings
  • Direct messages: Only visible to you and the recipient

Important: When you share posts with health metrics (energy score, streak days, etc.), this wellness information becomes visible to other users according to your post's visibility settings.

5.4 Legal Requirements

We may disclose information when required by law or to:

  • Comply with legal process (court orders, subpoenas)
  • Protect the safety of users or the public
  • Protect our legal rights
  • Investigate potential violations of our Terms of Service

5.5 Business Transfers

If Entropy Lifestyle is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change and your choices regarding your data.

5.6 What We Never Do

  • Sell personal data: We do not sell your personal information to third parties.
  • Share for advertising: We do not share your health data for targeted advertising purposes.
  • Data mining: We do not allow third parties to mine your data for their own purposes.

6. Data Security

We implement comprehensive security measures to protect your information:

6.1 Encryption

  • In Transit: All data transmitted between your device and our servers uses TLS 1.3 encryption
  • At Rest: Data stored in our database is encrypted using AES-256 encryption
  • OAuth Tokens: Wearable authentication tokens are encrypted before storage using industry-standard encryption

6.2 Access Controls

  • Row-level security ensures users can only access their own data
  • Administrative access requires multi-factor authentication
  • Access logs track all data queries

6.3 Infrastructure Security

  • Our database provider (Supabase) maintains SOC 2 Type II certification
  • Regular security assessments and vulnerability scanning
  • Automated threat detection and monitoring

6.4 App Security

  • Secure credential storage using iOS Keychain and Android EncryptedSharedPreferences
  • Session tokens with automatic expiration
  • No sensitive data logged in production
Your Role in Security: While we implement strong security measures, no system is 100% secure. Please protect your account by using a strong password and not sharing your credentials.

7. Data Retention

We retain your data only as long as necessary to provide our Service and fulfill the purposes described in this policy.

Data Type Retention Period
Account Information Until you delete your account
Health Metrics 2 years (or until account deletion)
Daily Plans & Protocols 90 days rolling
Social Content (posts, comments) Until deleted by you or account deletion
Direct Messages Until deleted by you or account deletion
Gamification Data (points, badges, streaks) Until account deletion
Wallet Balance & Transactions Until account deletion (transaction history retained for 7 years for legal compliance)
Challenge History Until account deletion
Usage Analytics 13 months (aggregated, de-identified)
Deleted Account Data Purged within 30 days of deletion request

We may retain certain information longer if required by law or to protect our legal interests.

8. Your Rights and Choices

8.1 Access Your Data

You can view your personal data directly in the App under Profile > Privacy Settings. You may also request a complete copy of your data by contacting us.

8.2 Export Your Data

You can request an export of your data in a machine-readable format (JSON) through the App or by contacting us.

8.3 Correct Your Data

You can update your profile information, preferences, and settings directly in the App. For corrections to other data, contact us.

8.4 Delete Your Data

You can delete your account and all associated data through Profile > Privacy Settings > Delete Account. This action is permanent and cannot be undone.

8.5 Disconnect Wearables

You can disconnect WHOOP, Oura, or other connected devices at any time through Profile > Connected Devices. This revokes our access to your wearable data.

8.6 Opt Out of AI Processing

You can disable AI-powered recommendations in Privacy Settings. The App will use rule-based protocols instead.

8.7 Control Notifications

You can manage push notifications through your device settings and in-app notification preferences.

8.8 Marketing Communications

You can opt out of marketing emails by clicking "unsubscribe" in any marketing email or through your account settings.

9. State-Specific Privacy Rights

9.1 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of "sale" or "sharing" of personal information
  • Right to Non-Discrimination: Exercise your rights without discriminatory treatment
California Notice: We do not "sell" personal information as defined under CCPA. We do not "share" personal information for cross-context behavioral advertising. Therefore, there is no need to opt out of these practices.

Categories of Information Collected (past 12 months):

  • Identifiers (email, name, device IDs)
  • Personal information (profile data)
  • Health information (from connected wearables)
  • Internet activity (usage data)
  • Inferences (wellness recommendations)

9.2 Virginia, Colorado, Connecticut, Utah Residents

Residents of these states have similar rights including access, deletion, correction, and opt-out rights. Contact us to exercise your rights.

9.3 Washington Residents (My Health My Data Act)

Washington residents have specific rights regarding consumer health data:

  • Right to know what health data is collected and shared
  • Right to withdraw consent for health data collection
  • Right to delete health data

9.4 European Residents (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, you have rights under the General Data Protection Regulation (GDPR):

  • Access, rectification, and erasure of your data
  • Data portability
  • Object to processing
  • Withdraw consent at any time
  • Lodge a complaint with your local supervisory authority

Legal Basis for Processing:

  • Contract: Processing necessary to provide the Service
  • Consent: Processing health data from wearables
  • Legitimate Interests: Analytics, security, service improvement

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including the United States. These countries may have different data protection laws.

When we transfer data internationally, we use appropriate safeguards including:

  • Standard Contractual Clauses approved by the European Commission
  • Data Processing Agreements with service providers
  • Encryption of data in transit and at rest

By using our Service, you consent to the transfer of your information to the United States and other countries.

11. Children's Privacy

Entropy Lifestyle is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children under 18.

If we learn that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible. If you believe we may have collected information from a child under 18, please contact us immediately.

12. Third-Party Services

Our Service integrates with third-party services. Your interactions with these services are governed by their own privacy policies:

We encourage you to review the privacy policies of any third-party services you connect with our App.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email (for significant changes)
  • Display an in-app notification

We encourage you to review this policy periodically. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Inquiries

Email: hello@entropylifestyle.com

Subject Line: Privacy Inquiry - [Your Topic]

Data Rights Requests

Email: hello@entropylifestyle.com

Response Time: Within 30 days (45 days for complex requests)

General Legal Inquiries

Email: hello@entropylifestyle.com

Mailing Address

KPMS3 LLC (Entropy Lifestyle)
Attn: Privacy Team
Glen Allen, Virginia
United States

Scroll to Top