Consumer Health Data Privacy Policy (Washington and Nevada)
This policy applies to Washington and Nevada consumers and supplements SyncFlow's general Privacy Policy. It describes consumer health data handled by SyncFlow under Washington's My Health My Data Act and Nevada's consumer health data privacy law.
1. Consumer health data collected and purposes
- Health and fitness measurements, record dates, units, source identifiers, and related records that you select from Fitbit for transfer into Apple Health.
- Your selected health categories, sync ranges, Apple Health permissions, and HealthKit records written by SyncFlow.
- On-device sync provenance such as category, inspected range, outcome, counts, and a fixed error code. SyncFlow does not copy health measurement values into its local Sync History database.
- Health information that you choose to write or attach to a support request.
SyncFlow handles this data only to provide the sync you request, write and manage SyncFlow-authored Apple Health records, prevent duplicate writes, display local sync provenance, troubleshoot the requested operation without transmitting health or sync detail, carry out deletion choices, and answer support that you choose to submit. The Operator's server does not store Fitbit credentials, health measurements, HealthKit records, or Sync History.
2. Sources
Consumer health data comes from you and your settings or support request, from the Fitbit account you connect, and from Apple Health on your device when you grant the relevant permissions.
3. Sharing, processors, and sale
At your direction, SyncFlow reads the selected data from Fitbit and writes it to Apple Health. The relevant categories of recipients are the connected health-data source and the device health-data store. The specific services are Fitbit, operated by Google LLC, and Apple Health / HealthKit, operated by Apple Inc. SyncFlow has no affiliates with which it shares consumer health data.
SyncFlow does not automatically send consumer health data to Analytics, advertising, Sentry, support destinations, or the SyncFlow server, and does not sell consumer health data. If you choose to include health information in a support request, the email provider or Google Forms, operated by Google LLC, that you select will receive the content you submit so that the Operator can answer it. The Operator retains that support content only as reasonably needed for the response, investigation, follow-up, legal or security duties, or a dispute, then deletes or anonymizes it. Apple and Fitbit may process data under your direct relationship with them and their own terms and privacy policies.
4. Your Washington and Nevada rights
Subject to applicable law and verification, a Washington or Nevada consumer may:
- confirm whether SyncFlow collects, shares, or sells their consumer health data and access that data;
- receive a list of the third parties and affiliates with which that data was shared;
- review consumer health data held by SyncFlow and request correction where applicable;
- withdraw consent to future collection or sharing; and
- request deletion of their consumer health data.
You can stop future collection by stopping sync, disconnecting Fitbit, or revoking Apple Health permissions. In the app, “Delete Synced Data and History” deletes local Sync History and SyncFlow-authored HealthKit records. It does not delete source records held by Fitbit, Apple transaction records, or Apple Health records written by another app. You may also use “Delete Account” for the broader SyncFlow deletion flow.
Health measurements are available for review in the connected Fitbit account and Apple Health destination; local provenance is available in Sync History. To exercise a right or request correction of consumer health data held by SyncFlow, email sync.health.app@gmail.com with the subject “Consumer Health Data Request.” Describe whether you seek confirmation, access, a third-party list, correction, withdrawal, or deletion. The Operator may request information reasonably necessary to authenticate and securely complete the request. If a request is denied, you may appeal by replying with the subject “Consumer Health Data Appeal.” The Operator will respond within the time required by applicable law. If an appeal is denied, you may contact the Washington State Attorney General or the Nevada Attorney General, as applicable.
5. Cross-site collection
SyncFlow does not permit a third party to collect consumer health data over time and across different websites or online services when you use SyncFlow. Vendors may process ordinary technical, purchase, advertising, or support information as described in the general Privacy Policy, but SyncFlow does not provide them health measurements, health categories, sync ranges or counts, run keys, or HealthKit/Fitbit record identifiers for cross-site profiling.
6. Changes and contact
SyncFlow will update this separate policy before collecting, using, or sharing additional categories of consumer health data or using existing categories for materially different purposes where the law requires notice and consent.
Operator: Yoshifumi Kanno
Email:
sync.health.app@gmail.com