Privacy Policy
Introduction
This section will introduce SteadyAF as the data controller, explain who this Privacy Policy applies to, and describe the scope of what this document covers. It will identify the company entity responsible for processing user data and establish the effective date and jurisdiction of the policy.
- Who we are — SteadyAF's legal entity, registered address, and contact information
- Who this policy applies to — all users of the SteadyAF platform, including Athletes, Champions, and Providers
- What this policy covers — all data collected through the app, website, and related services
- Reference to applicable law — HIPAA, CCPA, and other relevant regulations
Information We Collect
This section will enumerate all categories of data collected by SteadyAF, both actively (information you provide) and passively (information collected automatically). Each category will include specific examples of the types of data collected.
- Personal information — name, email address, date of birth, profile photo
- Health and fitness data — Stability Score assessments, exercise logs, mobility measurements
- Medication information — drug names, dosages, schedules, and side effect reports
- Device data — device type, operating system, unique device identifiers, app version
- Usage data — features accessed, session duration, interaction logs, crash reports
- Apple Health / HealthKit data — steps, heart rate, activity data (with explicit permission)
- Payment information — billing details processed through our payment processor (not stored by SteadyAF)
- Communications — support tickets, feedback forms, and Champion/Provider messages
How We Use Your Information
This section will explain the specific purposes for which SteadyAF processes user data, including the legal basis for each type of processing under applicable privacy law.
- Service delivery — providing the core platform features, including assessments, exercise plans, and the AI Navigator
- Personalization — adapting the platform to individual user progress, preferences, and health status
- Communication — sending service notifications, safety alerts, progress reports, and marketing (with consent)
- Safety monitoring — detecting anomalies in Stability Scores and triggering Guardian System alerts for Champions
- Research and improvement — using de-identified, aggregated data to improve platform efficacy (never individual health data)
- Legal compliance — fulfilling obligations under HIPAA, CCPA, and other applicable regulations
- Fraud prevention and security — detecting and preventing unauthorized access and abuse
How We Share Your Information
This section will describe all circumstances under which SteadyAF shares user data with third parties, including the conditions and controls that govern each type of sharing. SteadyAF does not sell personal data.
- With your Champions — sharing access granted explicitly by the Athlete, limited to what the Athlete has permitted
- With your Providers — clinical data shared only with the Providers an Athlete has connected through the Anchor Network
- Service providers — vendors who help operate the platform (hosting, analytics, payments) under strict data processing agreements
- Legal requirements — disclosure when required by law, court order, or to protect the rights and safety of users
- Business transfers — in the event of a merger or acquisition, how user data would be handled and users notified
- Aggregated / de-identified data — non-personal, aggregate statistics that cannot be used to identify individuals
Data Security
This section will describe the technical and organizational security measures SteadyAF uses to protect user data, including health information. It will reference our HIPAA-ready architecture and the standards we adhere to.
- Encryption in transit — all data transmitted between the app and our servers uses TLS 1.2 or higher
- Encryption at rest — all stored data, including health information, is encrypted using AES-256
- HIPAA-ready practices — technical, physical, and administrative safeguards aligned with the HIPAA Security Rule
- Access controls — role-based access so only authorized personnel can access specific data categories
- Audit logging — all access to Protected Health Information is logged and monitored
- Business Associate Agreements (BAAs) — executed with all vendors who process health data on our behalf
- Incident response — procedures for detecting, reporting, and responding to data security incidents
Your Rights & Choices
This section will enumerate the rights users have over their personal and health data, and explain how to exercise those rights. Specific rights will vary based on the user's jurisdiction (e.g., California residents have additional rights under CCPA).
- Right to access — request a copy of all personal data SteadyAF holds about you
- Right to correction — update or correct inaccurate personal or health information
- Right to deletion — request deletion of your account and associated data, subject to legal retention requirements
- Data portability — export your health data and Stability Score history in a machine-readable format
- Opt-out of marketing — unsubscribe from email communications at any time via account settings or unsubscribe links
- Withdraw consent — revoke data sharing permissions for Champions, Providers, or third-party integrations at any time
- CCPA rights — specific disclosures and opt-out rights for California residents
Data Retention
This section will explain how long SteadyAF retains different categories of user data, the criteria used to determine retention periods, and what happens to data when an account is closed.
- Active account data — retained for the duration of the subscription plus a defined grace period
- Health and fitness data — specific retention periods for Stability Score history, assessments, and exercise logs
- Payment records — retained as required by financial regulations (typically 7 years)
- Account closure — process for requesting full data deletion upon account cancellation
- Backup retention — how long data remains in encrypted backups after deletion requests
- Legal holds — circumstances under which normal retention schedules may be suspended
Children's Privacy
This section will establish that SteadyAF is not intended for use by individuals under the age of 18, and describe the steps taken to prevent the collection of data from minors.
- Age requirement — SteadyAF requires users to be 18 years of age or older to create an account
- COPPA compliance — SteadyAF does not knowingly collect data from children under 13
- Account termination — process for closing accounts discovered to belong to minors
- Parental notification — how SteadyAF handles data removal requests from parents or guardians
Changes to This Policy
This section will explain how SteadyAF communicates updates to the Privacy Policy, what constitutes a material change, and how we obtain renewed consent when required by law.
- Notification method — users will be notified of material changes via in-app notification and email
- Effective date — updated policies will display the new effective date at the top of this page
- Material changes — definition of what constitutes a material change requiring explicit user consent
- Continued use — what continued use of the platform means with regard to the updated policy
Contact Us
This section will provide contact details for submitting privacy-related requests, questions, or complaints. It will also reference how to submit data subject access requests (DSARs) and the expected response timeframe.
For all privacy-related inquiries, including data access, correction, or deletion requests:
Privacy Team: privacy@steadyaf.app