Consumer Health Data Privacy Policy
This is a separate document, as required by the Washington My Health My Data Act (RCW 19.373). It describes specifically how SAYA handles consumer health data. Our general App Privacy Policy covers everything else and applies in addition to this document.
It is written for residents of Washington State, and we apply the same commitments to residents of Nevada (SB 370) and any other US state with comparable consumer health data rules.
Effective: September 2026
Who we are
Lukas Bröll Bodmanstr. 23 87439 Kempten Germany
Email: l.broell@freenet.de
SAYA is operated from Germany. We apply the EU General Data Protection Regulation — one of the strictest privacy standards in the world — to every user, and the commitments below in addition for US residents.
1. What consumer health data we collect
From your Garmin wearable, and only after you connect it and give consent:
- Heart rate throughout the day, and resting heart rate
- Heart rate variability (HRV)
- Sleep data: sleep stages, duration, sleep score
- Stress levels
- Workouts and activities: type, duration, intensity, calories, and the heart rate recorded during them
- Steps and movement data
From you directly:
- Date of birth and gender
- Maximum heart rate, if you know it
- Meal log: timing, size, composition
- Evening habits: wind-down activities, screen time, caffeine, alcohol
- Sleep environment details
Computed by us from the above:
- Recovery, Evening and Readiness scores
- Sleep profile, chronotype, recommended personal timings
- Training load and recommended wind-down time
- Statistical relationships between your habits and your recovery
We do not collect precise location data, and we do not infer health conditions or diagnoses.
2. How we collect it
Garmin data reaches us only through the connection you authorize, in two deliberate steps: you authorize Garmin to transmit the data, and you separately give consent inside the SAYA app before that connection is made. Your own entries reach us only when you type them into the app.
We do not buy consumer health data from anyone, and we do not obtain it from data brokers, advertising networks or other third parties.
3. Why we use it
Solely to provide the service you signed up for:
- Computing your personal recovery, sleep and readiness scores
- Building your sleep profile and identifying your chronotype
- Showing your history and trends
- Finding statistical relationships between your habits and your recovery
- Operating, securing and supporting your account
We do not use consumer health data for advertising, profiling for marketing, or any purpose you have not consented to.
4. Who we share it with
We do not sell your consumer health data. We have never sold it and we do not intend to. Under the My Health My Data Act, "sale" means exchanging data for anything of value — we do not do this in any form.
We share consumer health data with no one except the service providers ("processors") strictly necessary to run the app, each bound by contract to process it only on our instructions:
| Provider | What they receive | Where |
|---|---|---|
| Google Ireland Ltd. (Firebase) | Storage and processing of your account and health data | Frankfurt, Germany (europe-west3) |
Firebase Crashlytics (crash diagnostics) and Resend (the inactivity warning email) are described in the App Privacy Policy. Neither receives consumer health data: crash reports contain no health data and are not linked to your user ID, and Resend receives only your email address.
We do not share consumer health data with affiliates — we have none. We would disclose data to a public authority only if legally compelled, and would tell you unless prohibited by law.
Any future sharing that would constitute a sale would require your separate, written authorization, in the specific form the My Health My Data Act prescribes. We are not seeking such authorization and have no plans to.
5. Where it is stored
Your consumer health data is stored in Google Cloud Firestore in the region europe-west3, Frankfurt, Germany — inside the European Union, under GDPR protection.
Even with EU storage, access by Google's US entities for support or maintenance cannot be entirely excluded. Safeguards are in place for that case: Google LLC's certification under the EU-US Data Privacy Framework and the EU Standard Contractual Clauses in the Google Cloud Data Processing Addendum.
6. Your rights
As a Washington resident (and we extend these to all US users), you have the right to:
- Know and access what consumer health data we have collected about you, and with whom we have shared it.
- Withdraw consent to our collection and sharing of it, at any time.
- Delete your consumer health data.
- Not be discriminated against for exercising any of these rights. The app works exactly the same either way.
How to exercise them
| What you want | How |
|---|---|
| A copy of your data | In the app: Settings → Export my data. You get a complete machine-readable JSON file immediately. |
| Delete only the Garmin health data | In the app: Settings → Disconnect Garmin, then choose "Delete it too". |
| Delete everything | In the app: Settings → Delete account. |
| Withdraw consent | Disconnect Garmin, or delete your account. Both take effect immediately. |
| Anything else, or you cannot use the app | Email l.broell@freenet.de |
We respond to emailed requests within 45 days, and will tell you if we need a one-time extension of a further 45 days.
Deletion means deletion. When you delete your account, we erase your data from our active systems and instruct our processor to do the same, including from backups as they cycle out. We do not retain a copy.
If we say no
If we decline a request, we will tell you why. You may appeal by replying to that message or writing to l.broell@freenet.de with "Appeal" in the subject line; we will respond within 45 days. If your appeal is denied, you may contact the Washington State Attorney General at www.atg.wa.gov/file-complaint.
7. How long we keep it
We keep your consumer health data for as long as your account exists — the history is what makes personal baselines and correlations possible.
If you do not use SAYA for 24 months, we delete your account and all of its data automatically. We email you 30 days beforehand; opening the app once is enough to keep it.
8. Security
All data is transmitted encrypted (TLS). Access is protected by authentication and server-side rules so that only your own account can reach your data.
9. Not a medical service
SAYA is a wellness product, not a medical device, and we are not a healthcare provider. The app does not diagnose and is no substitute for professional medical advice. Because we are not a covered entity or business associate, HIPAA does not apply — the protections described here apply instead.
10. Changes to this policy
If we materially change how we handle consumer health data, we will update this document, change the effective date above, and notify you in the app. Where the law requires it, we will ask for your consent again before the change takes effect.