Arcqtype

Legal

Consumer Health Data Privacy Policy

Effective: Pending attorney review · Last updated July 29, 2026 (draft) · counsel-review draft

Draft — pending attorney review. This document reflects how Arcqtype is built today but has not yet received final legal sign-off. Wording may change before launch.

Policy version: consumer-health-data-privacy-policy-2026-07-09 — consent records reference this exact version.

1. Scope

Arcqtype is a student-athlete training and recruiting platform. Some data we collect or infer may be "consumer health data" under state laws because it can relate to an athlete's physical or mental health, fitness, injury status, nutrition, recovery, sleep, body metrics, or safety state.

This policy is intended to stand alone from the general privacy-policy.md. It should be linked prominently wherever Arcqtype collects personal information and especially where athletes enter or sync health, recovery, nutrition, medical, Coach, or safety data.

Launch-readiness posture, locked 2026-07-09:

  • We never sell personal data.
  • Consumer health data collection and consumer health data sharing should use separate, just-in-time opt-ins where required.
  • Arcqtype is proceeding as a 13+ general App Store app, not Kids Category.
  • Coach uses OpenAI GPT-5-mini through an OpenAI-only provider registry; provider-specific wording must match the actually deployed provider and executed vendor terms before publication.
  • High-severity crisis/RED-S/self-harm safety signals should trigger in-chat refusal/resources and automatic guardian notification where legally and operationally permitted, with transparency to the athlete. This is a locked S4 posture, not a current-code-live claim until S4 ships.

---

2. Categories of Consumer Health Data We Collect

  • Category — Examples — Source / grounding
  • Fitness and training data — Workouts, exercises, sets, reps, training plans, recovery routines, soreness, return-to-training constraints — workout_logs, workout/recovery services
  • HealthKit-derived metrics — Sleep hours/quality, resting heart rate, heart-rate variability, active calories, steps, workout minutes, body weight/body metrics — Arcqtype/Core/Services/API/HealthMetricsAPI.swift; backend health.routes.ts, recovery.routes.ts, sleep.routes.ts
  • Recovery/readiness data — Recovery score, fatigue/rest labels, soreness areas, recovery protocols — health_metrics, recovery_logs, health-metrics.service.ts, dashboard-recovery.service.ts
  • Nutrition data — Meal plans, calories/macros, pantry/grocery items, water intake, nutrition preferences — nutrition migrations/services; meal-plan.service.ts
  • Medical or injury-adjacent data — Injury notes, medical restrictions, uploaded medical/training documents, prescribed exercise fields, medical photo references where present — medical/document routes; S2 hardening pending
  • Body and development data — Height, weight, biological sex, grade, age/date of birth, parent-height fields where collected — users, athlete_profiles
  • Coach health-adjacent context — Chat messages and assembled Coach context that mention injury, nutrition, recovery, RED-S, self-harm, training limits, or medical restrictions — chat_messages; Coach context/snapshot builders
  • Safety and crisis data — Moderation flags, self-harm/eating-disorder/unsafe weight-cutting signals, emergency-symptom events, future guardian-notification events — moderation.service.ts; coach-output-safety.service.ts; S4 pending

Counsel note: this list is intentionally broad because MHMDA-style definitions can cover data that identifies or is reasonably linkable to physical or mental health status, even when Arcqtype is not a healthcare provider.

---

3. Sources of Consumer Health Data

We collect consumer health data from:

  • You: profile answers, workouts, recovery check-ins, nutrition logs, Coach messages, uploaded documents/media, and manual body metrics.
  • Your device, with permission: Apple Health/HealthKit data that you authorize Arcqtype to read.
  • Arcqtype's backend calculations: recovery/readiness scores, injury-risk estimates, training adjustments, nutrition targets, Coach memory/context, and moderation/safety classifications.
  • Parents/guardians or connected adults, where applicable: guardian consent records, verification status, safety responses, and future guardian notifications.
  • Service providers: authentication, subscription, hosting, logging, and AI/model providers may return operational metadata needed to provide the service.

---

4. Why We Collect Consumer Health Data

  • Purpose — Examples
  • Provide the service — Personalize workouts, recovery, training plans, nutrition guidance, Coach responses, and recruiting readiness context
  • Safety — Avoid contraindicated exercise suggestions, refuse unsafe weight-cutting or medical advice requests, surface crisis resources, and notify a guardian on high-severity safety signals where required/permitted
  • Account and consent management — Enforce age gates, guardian verification, external-AI consent, and privacy-rights requests
  • Product reliability and abuse prevention — Debug service failures, investigate safety events, enforce acceptable use, and protect minors
  • Legal compliance — Maintain consent, safety, billing, and audit records where required by law or platform obligations

Arcqtype should collect only what is reasonably necessary for these purposes and should delete or de-identify data according to the retention schedule once S6 is implemented.

---

5. How We Share Consumer Health Data

We share consumer health data only with service providers needed to operate Arcqtype, or where you/your guardian direct us to share it.

  • Recipient category — Current / planned recipients — Data involved — Purpose
  • Cloud database and authentication — Supabase — Account, profile, health, recovery, nutrition, chat, consent, and app data — Store and secure the service data
  • Hosting / compute / logs — Render — API traffic and logs — Run backend services
  • AI/model providers — OpenAI-only Coach runtime — Coach messages and assembled context — Generate Coach responses and utility AI outputs
  • Subscription providers — RevenueCat, Apple App Store — Subscription identifiers and purchase/entitlement state — Manage subscription access
  • Authentication providers — Apple, Google, Supabase Auth — Authentication assertions and account identifiers — Sign in and account security
  • Transactional email — Resend — Guardian consent and notification emails; message previews where applicable — Consent, account, and safety notifications
  • Observability provider — Sentry pending — Scrubbed error/crash data only if S7 ships — Detect and investigate failures

We never sell personal data. We do not sell consumer health data, personal data, or minors' data, and we do not share it with advertisers or data brokers.

---

6. Separate Consent for Collection and Sharing

For consumer health data covered by laws requiring separate consent:

  • Collection consent should be requested before Arcqtype collects or syncs health, nutrition, medical, HealthKit, or comparable sensitive data.
  • Sharing consent should be separate from collection consent and separate from general Terms acceptance before Arcqtype shares consumer health data with third-party AI/model, observability, email, or other service providers where legally required.
  • Withdrawal should be available through in-app controls or privacy request channels, and withdrawal should stop future collection/sharing where legally required.

Engineering gap: the final consent ledger and separate collect/share opt-in surfaces are S3/S6 implementation work. This policy must not be published until the product path records the necessary consent version, subject, actor, timestamp, and withdrawal state.

---

7. Your Consumer Health Data Rights

Subject to verification and applicable law, you may request to:

  • Confirm whether Arcqtype collects, shares, or sells consumer health data about you.
  • Access your consumer health data.
  • Delete your consumer health data.
  • Withdraw consent for future collection or sharing.
  • Appeal a denied privacy request where applicable.

Contact: _[counsel/product to set canonical privacy email and mailing address]_

For minors, a parent or legal guardian may have the right to review, delete, or control a child's information. Arcqtype's launch posture is 13+; counsel should finalize guardian request mechanics for 13-17 users and any accidental under-13 account path.

---

8. Retention

Current code supports account deletion and hard-deletes many private athlete-owned records, but there is not yet a complete retention schedule with concrete windows for every personal-data category. The companion draft account-deletion-data-retention.md documents current deletion mechanics and gaps.

Before publication, counsel and engineering must set and implement retention windows for:

  • HealthKit-derived metrics and body metrics.
  • Recovery/readiness, soreness, injury, and nutrition data.
  • Coach chat transcripts and Coach memory/context.
  • Medical photos/source documents and derived medical fields.
  • Safety/crisis/moderation records and guardian notifications.
  • Consent, audit, billing, and operational logs.

---

9. Data Security

Arcqtype uses HTTPS/TLS, authenticated backend routes, application-layer authorization, and Supabase/Postgres storage. Backend services currently use elevated service-role database access, so public wording must not claim that Row Level Security is the sole or primary boundary for backend operations. S1/S2/S5/S7/S8 of the launch-readiness program add further redaction, signed media URLs, JWT hardening, PII-scrubbed observability, and age-signal handling.

---

Source Map

  • General Privacy Policy draft: legal/privacy-policy.md
  • Account deletion / retention draft: legal/account-deletion-data-retention.md
  • COPPA / minors draft: legal/coppa-minors-compliance.md
  • Subprocessors: legal/third-party-subprocessors.md, reference/subprocessor-list.md
  • Program rulings: plans/2026-07-09-integrated-launch-readiness-program.md
  • Master plan: handoffs/2026-07-09-privacy-safety-launch-readiness-master-plan.md
PrivacyTermsHealth dataDeletionSubprocessorsCommunityLicensesSupport© 2026 Arcqtype, Inc.