Consumer Health Data Privacy Policy

Effective 28 August 2026 · This is Milewise’s separate, standalone Consumer Health Data Privacy Policy. It is provided under the Washington My Health My Data Act (RCW 19.373) and the Nevada Consumer Health Data Privacy Act (SB 370, NRS 603A.400 et seq.), and it applies to consumers in those two states. Sections 1 to 6 apply to both; sections 7 and 8 set out what each state adds, because the two Acts differ on deadlines and on what happens after a deletion request. Milewise applies the same practices to everyone, everywhere. General privacy information: Privacy Policy.

Who we are: Milewise is operated by Moritz Niedermann, Essenweinstr. 37, 76131 Karlsruhe, Germany (“Milewise”, “we”). Contact: contact@milewise.de, +49 170 1163838. Milewise is a sole proprietorship with no employees, and it has no affiliates: no parent, no subsidiary and no group companies. Wherever these Acts require us to name affiliates, the answer is that there are none.

1. Consumer health data we collect, and why

Milewise is a training-coaching application. To provide the service you ask for, we collect and process the following categories of consumer health data:

Purpose, and how the data is used: exclusively to provide the coaching service you asked for. That means analysing your training, computing readiness and load, building and adapting your plan, and generating coaching replies and automatic summaries. Producing those replies and summaries involves sending the relevant data to the AI providers named in section 3, which act only on our instructions.

We do not use consumer health data for advertising, marketing profiles or any form of tracking, and Milewise runs no analytics on any of its surfaces. It is not used to train AI models: our AI providers are contractually barred from doing so, and where a provider offers a retention or training setting we have set it to the most restrictive option available to us.

2. Categories of sources

Consent. For account holders we collect consumer health data only with your explicit, separate consent, asked for as its own unticked checkbox and only to the extent necessary to provide the service you requested. Since 11 August 2026 there are two such consents: one at first sign-in covering your activity and training data (workouts, routes, heart rate, training zones), and one at the moment you subscribe covering your wellness and recovery data (sleep, HRV, resting heart rate, stress, body metrics) and its use by the AI coach. Wellness data is not collected before that second consent exists. You can withdraw either consent at any time (section 6), and the app is gated on them: without the wellness consent the coach, the recovery features and every automatic analysis stop; without the training-data consent the app stops entirely.

3. What is shared, and with whom

We do not sell consumer health data, and we never have. A sale would require your separate signed authorization under both Acts; we never ask for one, because we do not sell. We do not share consumer health data with any third party for that third party’s own purposes: no advertisers, no data brokers, no analytics companies, no data-sharing for research.

To run the service, data is processed on our behalf by the service providers below. Under the Washington Act, disclosure to a processor acting on our instructions is not “sharing”; we list them anyway, together with the categories of consumer health data each one receives:

Three further recipients are not processors and are named here for completeness. MET Norway and Open-Meteo (weather) and OpenStreetMap Nominatim (turning coordinates into a place name) receive coordinates, rounded, with no name, e-mail address or account identifier. When a map is displayed, your browser, not our server, loads the map tiles from OpenFreeMap (whose map data come from OpenStreetMap), which therefore sees your IP address and the area of the map you are looking at. Until 27 August 2026 those tiles came from CARTO.

4. How we protect consumer health data (RCW 19.373.050)

Washington requires us to restrict access to consumer health data to those who need it, and to maintain administrative, technical and physical security practices that meet the reasonable standard of care in our industry, appropriate to the volume and nature of the data. What that means here:

Two limits we state plainly rather than dress up. The training database itself is not encrypted at rest. The credentials and tokens inside it are encrypted, as described above, but the database file as a whole is protected by file permissions and by the access restrictions in this section, not by an additional layer of encryption. And the operator’s administration interface has no IP allowlist in front of it: it is reached over TLS and secured by a password, a second factor (a time-based one-time code or a passkey under the WebAuthn standard), an administration session limited to twelve hours, lockouts after failed sign-in attempts and rate limiting, but not by restricting the network addresses it may be reached from.

5. Our contracts with service providers (RCW 19.373.060)

Every service provider that processes consumer health data for us does so only under a binding written contract that sets out our processing instructions and limits what that provider may do with the data. Those contracts bar the provider from using the data for its own purposes, from selling it and from using it to train models, and require it to delete or return the data. We do not route consumer health data to any provider that has not accepted such terms, and a provider may not engage a further sub-processor except on the same terms. The agreements with our AI providers are on file.

6. Your rights, and how to exercise them

Exercising any of these rights is free, and it never worsens the service you receive. To answer a request we have to be sure it is really you: for an account holder that is the sign-in itself, and for a request sent by e-mail we may need to verify the address against the one on the account. If we cannot authenticate a request, we will tell you so instead of leaving it unanswered.

7. Washington residents (My Health My Data Act, RCW 19.373)

8. Nevada residents (SB 370, NRS 603A.400 et seq.)

Nevada’s Act grants the same three rights (confirm and access, withdraw consent, delete), but it runs on different clocks, so we state Nevada’s separately rather than give you one blended number that would be wrong for one of the two states.

9. Changes to this policy

We will not collect, use or share categories of consumer health data, or use them for purposes, that this policy does not name, without updating this policy first and, where the law requires it, asking for your consent. Material changes get a new effective date at the top of this page and, for account holders, a notice in the app.

Questions about this policy: contact@milewise.de, or by post to the address at the top of this page.