Consumer Health Data Privacy Policy
Effective 28 August 2026 · This is Milewise’s separate, standalone Consumer Health Data Privacy Policy. It is provided under the Washington My Health My Data Act (RCW 19.373) and the Nevada Consumer Health Data Privacy Act (SB 370, NRS 603A.400 et seq.), and it applies to consumers in those two states. Sections 1 to 6 apply to both; sections 7 and 8 set out what each state adds, because the two Acts differ on deadlines and on what happens after a deletion request. Milewise applies the same practices to everyone, everywhere. General privacy information: Privacy Policy.
Who we are: Milewise is operated by Moritz Niedermann, Essenweinstr. 37, 76131 Karlsruhe, Germany (“Milewise”, “we”). Contact: contact@milewise.de, +49 170 1163838. Milewise is a sole proprietorship with no employees, and it has no affiliates: no parent, no subsidiary and no group companies. Wherever these Acts require us to name affiliates, the answer is that there are none.
1. Consumer health data we collect, and why
Milewise is a training-coaching application. To provide the service you ask for, we collect and process the following categories of consumer health data:
- Physiological and recovery measurements from the sports accounts you connect: heart rate and heart-rate variability (HRV), resting heart rate, sleep duration and stages, blood-oxygen readings, readiness and recovery scores (for example Polar Nightly Recharge), body weight, and subjective wellness entries (mood, soreness, fatigue, reported injuries);
- Training data: activities with pace, power, cadence, elevation, training load and, where your device recorded them, GPS traces of where you trained;
- Health information you type: what you write in the coach chat, your goals and constraints (for example an injury or a schedule limit), and your private notes on an activity;
- Information we derive from the above: readiness and training-load figures we compute, coaching notes, and, unless you turn the setting off, an estimate of your home area derived from where your activities start;
- Entries from your personal Google Calendar, and only if you connect it separately and voluntarily: calendar name, event title, date, and start and end time. We list this as a category of its own because a calendar entry can name a medical appointment, a therapy session or another treatment, and is then itself consumer health data. Every read is live, at the moment the coach needs it, so that your training plan can be built around your commitments, and we never write to your personal calendar. We keep no separate store of the entries we read from Google: they are not copied into a table of your appointments and not into our response cache. The calendar of a mobile device is a different matter, because it cannot be read that way at all, and it is a category of its own below. Where the daily morning briefing is switched on, one automated read takes place once a day, without you asking for it: it reads your calendar for that one day so the briefing can take that day’s commitments into account. Only the resulting free and busy times enter the briefing, the entries themselves are not stored, and where the briefing is switched off no automated read occurs. One small technical note does outlive the read: when a saved plan puts a session on a day your calendar leaves no room for, or so late that it runs into an early start the next morning, we record that date and the times involved, never what an entry says. What the coach did read, event titles included, becomes part of that conversation like any other thing it looked up: it stays there for as long as the conversation exists, it is included in the copy of your data we send you on request, and it is therefore in our backups. Deleting the conversation deletes it. You choose which calendars may be read, and until you make that choice every calendar on the connected Google account is read. The permission Google asks you for covers the whole account; the narrowing is done by us, on our side, from your selection. When you disconnect we revoke the authorization at Google, which stops all future reads; that revocation can fail for technical reasons, so you can also withdraw the access yourself at any time in your Google account. Disconnecting does not remove titles already present in past conversations;
- Values from Apple Health, in the Milewise app for iPhone only, optional and off until you switch it on: sleep (total sleep, time in bed, and the split into deep, REM, core and awake phases), heart-rate variability as an SDNN value, the resting heart rate and the respiratory rate, one value per night. An iPhone’s health store answers only the app on the device and never a server, so the app itself reads those values and sends them to us; the raw HealthKit samples never leave the phone. Workouts from Apple Health are not sent, and no location data of any kind. Nights from the last 120 days are accepted, at most 40 in one transmission, and a night sent again replaces the one we hold. Nothing is stored without the wellness and recovery consent described in section 2. These values are not placed before the AI coach today: they are stored and no analysis reads them yet, and we will update this policy before that changes. Switching the feature off in the app deletes every night that reached us this way, as do resetting and deleting the account;
- Entries from the calendar of your mobile device, in the Milewise app only, optional and off until you switch it on: the date, the start and end time, whether the entry lasts all day, and the event title. We list this apart from the Google Calendar above for one reason: an iPhone’s calendar answers only the app on the device, so it cannot be read at the moment the coach needs it, and the only way the coach can use it hours later is for the app to send it and for us to keep it in a table of its own. It holds the same kind of entry, so a medical appointment or a therapy session can be in it in exactly the same way. Locations, attendees, descriptions, organisers and conferencing links are not sent, exactly as with Google. The app sends the current day and, by default, the following 14 days, at most 90 days ahead and at most 400 entries in one transmission. Each transmission replaces what we hold for the days it reports, so an entry you delete on the device disappears here with the next one, and a sweep that runs once a day removes every day more than three days past. Separately from the entries, the app sends the list of the calendars on the device (each calendar’s name and the identifier the operating system gives it, at most 60, no entries) so that you can also choose in a browser which of them may be read; without a choice it is every calendar the app may access, and an empty choice is none. No entry is stored without the wellness and recovery consent described in section 2; the list of calendars is stored without it, deliberately, because the choice of which calendars to share cannot be offered from an empty list, and it carries no entries. A calendar’s name is free text written by other people in the same way an event title is, so it too can suggest something about health. Switching the feature off, in the app or in the browser, deletes the stored entries, the calendar list and your selection, and resetting or deleting the account does the same; titles already present in past conversations are not removed by it;
Purpose, and how the data is used: exclusively to provide the coaching service you asked for. That means analysing your training, computing readiness and load, building and adapting your plan, and generating coaching replies and automatic summaries. Producing those replies and summaries involves sending the relevant data to the AI providers named in section 3, which act only on our instructions.
We do not use consumer health data for advertising, marketing profiles or any form of tracking, and Milewise runs no analytics on any of its surfaces. It is not used to train AI models: our AI providers are contractually barred from doing so, and where a provider offers a retention or training setting we have set it to the most restrictive option available to us.
2. Categories of sources
- The sports accounts you connect yourself: intervals.icu, Strava and Polar (Polar AccessLink). intervals.icu is an aggregator, so data you recorded on another platform, for example a Garmin watch, can reach us through it.
- You, through what you type in the app.
- Your personal Google Calendar, if you connect it. The access is read-only (the “calendar.readonly” scope) and rests on a separate, optional consent that is kept apart from signing in with Google: the sign-in itself still asks for your identity only. We read the calendar name, event title, date, and start and end time; we do not collect the attendee list of an event: it is examined only to establish whether you yourself declined, and it does not leave Google. An event title is different, because it is free text: it is passed to us exactly as written, so where a title names another person that name reaches us with it. An event’s title is written by whoever created the event, so it may not have been written by you.
- Your iPhone, through the Milewise app, and only for whichever of the two device features you switch on: the health store (Apple Health) and the device’s own calendar. Both are read on the phone, because neither answers a server, and only the fields listed in section 1 are sent. The permissions are Apple’s own and you can withdraw them at any time in the device settings. A calendar entry’s title is free text here too: it reaches us exactly as whoever created the entry wrote it.
- Us, through the figures and notes we derive from the sources above.
Consent. For account holders we collect consumer health data only with your explicit, separate consent, asked for as its own unticked checkbox and only to the extent necessary to provide the service you requested. Since 11 August 2026 there are two such consents: one at first sign-in covering your activity and training data (workouts, routes, heart rate, training zones), and one at the moment you subscribe covering your wellness and recovery data (sleep, HRV, resting heart rate, stress, body metrics) and its use by the AI coach. Wellness data is not collected before that second consent exists. You can withdraw either consent at any time (section 6), and the app is gated on them: without the wellness consent the coach, the recovery features and every automatic analysis stop; without the training-data consent the app stops entirely.
3. What is shared, and with whom
We do not sell consumer health data, and we never have. A sale would require your separate signed authorization under both Acts; we never ask for one, because we do not sell. We do not share consumer health data with any third party for that third party’s own purposes: no advertisers, no data brokers, no analytics companies, no data-sharing for research.
To run the service, data is processed on our behalf by the service providers below. Under the Washington Act, disclosure to a processor acting on our instructions is not “sharing”; we list them anyway, together with the categories of consumer health data each one receives:
- AI providers, all EU-routed. Two receive data today: Microsoft (Azure OpenAI, EU Data Boundary) and Mistral AI (France). They receive what a coaching reply needs: your conversation, athlete profile, goals and constraints, plan, coaching notes, and the training and recovery data the coach reads for that reply (activities including GPS, sleep, HRV, recovery scores, weather), and, if you have connected your personal Google Calendar or switched on your device’s own calendar, a summary of your entries: per day the committed hours and the free time windows, together with the event titles (at most eight a day plus four all-day entries). The two calendars are merged into that one summary before it is sent, because a day has one answer. The calendar name and the precise times of individual events are not passed on, and no value taken from Apple Health is passed on at all, because nothing reads those yet. Two further providers, Amazon Web Services (Bedrock, EU regions) and Google Cloud Vertex AI on an EU-only endpoint, are configured as standbys but are not in use and receive nothing today; we will update this policy before that changes.
- Hosting and backup: Hetzner Online GmbH, Germany. Our servers and our encrypted off-site backups sit there, so every category in section 1 is stored on their infrastructure.
- E-mail: our own mail server in Germany, with Mailjet (Paris, France) as the sending relay. It normally carries no health data, with one exception: if you ask for a copy of your data (section 6), the export file itself travels through it to your verified address.
- Payments, and only if you buy a subscription: Stripe Technology Europe, Limited (Dublin, Ireland), with “Sold through Link, LLC” (United States) as the merchant of record and the seller of the subscription to you. They receive your billing details (name, e-mail address, payment method, the amount and the fact of a Milewise subscription) and no training or health data at all. Nothing is sold yet; this entry describes what will happen when subscriptions open.
- Your own intervals.icu account, while the “send workouts to your watch” toggle is on: your planned workouts only, never your measurements. intervals.icu then syncs them onward to a watch you have linked to it. That toggle is on by default from the moment you connect intervals.icu and grant the calendar write permission, which the intervals.icu consent screen names expressly. It is never turned on for you if you have already set the toggle yourself, either way, or if that permission was not granted. You can switch it off at any time, and we then remove the future workouts we had written.
Three further recipients are not processors and are named here for completeness. MET Norway and Open-Meteo (weather) and OpenStreetMap Nominatim (turning coordinates into a place name) receive coordinates, rounded, with no name, e-mail address or account identifier. When a map is displayed, your browser, not our server, loads the map tiles from OpenFreeMap (whose map data come from OpenStreetMap), which therefore sees your IP address and the area of the map you are looking at. Until 27 August 2026 those tiles came from CARTO.
4. How we protect consumer health data (RCW 19.373.050)
Washington requires us to restrict access to consumer health data to those who need it, and to maintain administrative, technical and physical security practices that meet the reasonable standard of care in our industry, appropriate to the volume and nature of the data. What that means here:
- Access is restricted by design. Milewise has no employees. The operator named above is the only person with administrative access; there are no shared accounts, and server access is by SSH key only. Service providers receive only what their specific task requires.
- Account isolation: every request is bound to an account identifier derived on the server, never supplied by the browser, so one account cannot reach another’s data.
- In transit: TLS on every public endpoint, HSTS on the app domains, and only three ports reachable from the internet: the two web ports and SSH, which accepts keys only. Everything else is denied at the host firewall, and the application itself listens on the server’s loopback interface only.
- At rest: the credentials and tokens for your connected accounts are encrypted with a key kept outside the code; backups are encrypted before they leave the server and are stored off-site in Germany.
- Minimised towards providers: AI providers receive an internal numeric identifier, never your name or e-mail address; your year of birth only; and home coordinates rounded before they enter a prompt.
- Bounded processing: text from outside the system is fenced before it reaches a model, every AI write action is logged, and every paid AI path has spending and rate limits so a compromised account cannot cause unbounded processing.
Two limits we state plainly rather than dress up. The training database itself is not encrypted at rest. The credentials and tokens inside it are encrypted, as described above, but the database file as a whole is protected by file permissions and by the access restrictions in this section, not by an additional layer of encryption. And the operator’s administration interface has no IP allowlist in front of it: it is reached over TLS and secured by a password, a second factor (a time-based one-time code or a passkey under the WebAuthn standard), an administration session limited to twelve hours, lockouts after failed sign-in attempts and rate limiting, but not by restricting the network addresses it may be reached from.
5. Our contracts with service providers (RCW 19.373.060)
Every service provider that processes consumer health data for us does so only under a binding written contract that sets out our processing instructions and limits what that provider may do with the data. Those contracts bar the provider from using the data for its own purposes, from selling it and from using it to train models, and require it to delete or return the data. We do not route consumer health data to any provider that has not accepted such terms, and a provider may not engage a further sub-processor except on the same terms. The agreements with our AI providers are on file.
6. Your rights, and how to exercise them
- Confirm and access. You may confirm whether we collect, share or sell your consumer health data and get a copy of it, together with a list of all third parties and affiliates we have shared or sold it to. Self-service, no request needed: You → Account · Data & privacy → “Email me my data” sends a zip with everything we hold about your account to your verified address. We have sold your data to nobody and shared it with nobody for their own purposes, so the list the Acts ask for is the service-provider list in section 3. In our answer to any access request we will also give you an active e-mail address or online contact form for each of those recipients.
- Withdraw consent. Same place in the app, one click, at any time. Withdrawal stops the coach and every automatic analysis until you consent again.
- Delete. You → Account · Data & privacy →
“Delete my account” deletes your account and the data held with it, at
any time, without going through us. When a deletion request is made: we delete the data
from our live records and from every part of our network; any planned workouts we had
pushed to your intervals.icu calendar are removed first; and we notify every
service provider and other recipient that has received your consumer health
data, so that they delete their copies too. In our encrypted off-site backups the data
disappears as the generations rotate out (7 daily, 4 weekly, 6 monthly), at the
latest within six months of the request, which is the outer limit Washington
allows for archived and backup systems.
One of our two active AI providers is configured for zero data retention, so it holds nothing to delete. The other screens requests automatically for abuse; in the rare case where content is flagged, it can sit in a store held inside the EU that we can neither inspect nor purge. We say so rather than promise a deletion we cannot perform. - Appeal. If we ever refuse to act on a request, you may appeal simply by replying to our answer, or by writing to contact@milewise.de with “appeal” in the subject. We answer appeals in writing and explain the reasons. Section 7 says what happens if we deny a Washington appeal.
Exercising any of these rights is free, and it never worsens the service you receive. To answer a request we have to be sure it is really you: for an account holder that is the sign-in itself, and for a request sent by e-mail we may need to verify the address against the one on the account. If we cannot authenticate a request, we will tell you so instead of leaving it unanswered.
7. Washington residents (My Health My Data Act, RCW 19.373)
- Deadline. We respond to your request without undue delay and in all cases within 45 days of receiving it. That period may be extended once by 45 additional days where reasonably necessary, given the complexity and number of your requests, and if we do that we will tell you within the first 45 days, together with the reason.
- No charge. The Act allows a free response twice a year; we do not charge at all.
- If we deny your appeal, we will provide you with an online mechanism to submit a complaint to the Washington State Attorney General, whose complaint form is at atg.wa.gov/file-complaint.
- No geofencing. We do not operate, and our software does not contain, any geofence around a health care facility, and we never use one to identify, track or send messages to anyone about consumer health data.
- No sale. We do not sell consumer health data, so we never seek the valid authorization the Act requires for a sale.
- Scope of this policy. This is a separate, standalone policy, linked from the milewise.de home page, as the Act requires. We do not collect, use or share categories of consumer health data, or use them for purposes, beyond those listed here without first disclosing it and obtaining your consent.
8. Nevada residents (SB 370, NRS 603A.400 et seq.)
Nevada’s Act grants the same three rights (confirm and access, withdraw consent, delete), but it runs on different clocks, so we state Nevada’s separately rather than give you one blended number that would be wrong for one of the two states.
- Deadline. We respond without undue delay and no later than 45 days after we authenticate your request. Where reasonably necessary because of the complexity and number of your requests, we may extend that once by up to 45 additional days; if we do, we will give you notice of the extension and the reasons for it within those first 45 days (NRS 603A.510).
- Deletion, and who else we tell. Within 30 days of authenticating a deletion request we delete the consumer health data described in it from our records and our network, and we notify each affiliate, processor, contractor or other third party with which we have shared your consumer health data of your deletion request. Each of them must then delete it within 30 days of that notification (NRS 603A.515). As stated above, Milewise has no affiliates, so in practice this is the service-provider list in section 3.
- Backups. Nevada permits deletion from archived or backup systems to be delayed where that is necessary to restore the system. Our backup generations rotate out within six months, and we apply that shorter period rather than the longer one the Act would allow.
- Consent and sale. Nevada requires affirmative consent before consumer health data is collected or shared, and a separate written authorization before it is sold. We obtain that consent (section 2) and we do not sell, so no authorization is ever sought.
- Complaints. Nevada consumers may contact the Office of the Nevada Attorney General, Bureau of Consumer Protection (ag.nv.gov), which enforces this Act.
9. Changes to this policy
We will not collect, use or share categories of consumer health data, or use them for purposes, that this policy does not name, without updating this policy first and, where the law requires it, asking for your consent. Material changes get a new effective date at the top of this page and, for account holders, a notice in the app.
Questions about this policy: contact@milewise.de, or by post to the address at the top of this page.