Metal Strength ← Back to the app
Legal

Consumer Health Data Privacy Policy

Last updated: October 8, 2026

The short version: the health data you put into Metal Strength is used for one thing — running the training log you asked for. It is never sold, never used for advertising, and never given to anyone except the providers that store and deliver it for us and, only if you switch it on, the friends you choose. You can see it, download it, delete it and withdraw your consent at any time.

1. Who this policy is for

This Consumer Health Data Privacy Policy is written for the Washington My Health My Data Act (RCW 19.373), Nevada's consumer health data law (SB 370) and the consumer-health-data rules of the Connecticut Data Privacy Act, and for any similar law. We apply it to every user, wherever they live. It sits alongside our Privacy Policy, which covers everything else (and where, for people in the EU and UK, the same data is "data concerning health" under Article 9 of the GDPR). Metal Strength is the regulated entity; how to reach us is in section 9.

2. Consumer health data we collect

Only what you choose to enter or switch on:

What we do not collect: diagnoses, conditions, medications, reproductive or sexual health information, genetic or biometric data, or your precise location. Today's steps and calories, which the app can read from your phone's health app to show on the Home screen, stay on your phone and never reach us.

3. Why we collect it and how we use it

Never: we do not use consumer health data for advertising or marketing, we do not sell it, we do not give it to data brokers, insurers or employers, and no third party uses it to train its own AI models.

4. Where it comes from

5. Who receives it

Our processors, which handle it only on our instructions and under a contract, to store and deliver the Service:

People and places you choose, each only if you act:

Authorities, only when a valid legal order requires it; we tell you unless the law forbids it. We have no affiliates. We have never sold consumer health data and we will not.

We collect consumer health data only with your consent. You give it with a tick box at sign-up that is about this data alone — it is separate from accepting the Terms — and existing accounts were asked once before continuing. Reading weight, body fat or heart rate from your phone needs its own switch and the phone's own permission. Sharing with friends needs its own switch. You can withdraw any of these at any time: turn the switch off, delete the data, delete your account, or write to us.

7. Your rights

You can also write to [email protected] from the address on your account. We answer within 45 days (we may extend this once by 45 days when necessary, and we tell you if we do). If we decline your request, you can appeal by replying with the word "Appeal"; we answer within 45 days. If your appeal is refused, you can complain to your Attorney General — in Washington, at atg.wa.gov/file-complaint.

8. How we protect it

Your health data can only be read by your own account: database row-level security enforces this on every table, progress photos sit in a private folder reached only through short-lived signed links, and every connection is encrypted. Our provider encrypts stored data at rest. We look at an account's data only to answer a request from its owner or when the law requires it. We do not use geofencing of any kind.

9. Changes and contact

If we change this policy we update the date above, and if we ever wanted to collect, use or share consumer health data in a new way we would ask for your consent first. Questions or requests: [email protected]. The operator's details are in section 1 of the Privacy Policy.