Your privacy matters. This policy explains what data Henry collects, why we collect it, how we protect it, and what rights you have. It is written in plain English.
The short version: We collect only what we need to coach you. We never sell your data. Your health data — including data from Apple Health, Oura Ring, and WHOOP, the body-composition estimates Henry infers from your photos, and any cycle data you enter — stays in your private account. It is never used to train AI models or shared with third parties for any commercial purpose.
This policy addresses your rights under the GDPR (EU/UK), CCPA/CPRA (California), COPPA (US children's privacy), the Washington My Health My Data Act, and Apple's HealthKit Guidelines.
GDPR Art. 13(1)(a) Henry is a personal AI coaching application operated by Coach Henry LLC ("Coach Henry", "we", "us", "our"), a Minnesota limited liability company. We are the data controller for all personal data described in this policy.
For any privacy questions, requests, or complaints:
We do not have a designated Data Protection Officer (DPO) as we do not meet the thresholds that make one mandatory under Article 37 GDPR. Privacy-related inquiries are handled directly by our team at the email above.
This policy applies to all personal data collected through:
It does not apply to third-party services you connect. Please review their own privacy policies for details on how they handle your data independently.
CCPA 1798.100 The sections below summarise what we collect, the source, and why — as required by California law and GDPR transparency obligations.
With your explicit permission, Henry reads the following from Apple HealthKit. HealthKit Guidelines This data is never used for advertising, never sold, and never shared with data brokers.
You can revoke Apple Health access at any time via iOS Settings → Privacy & Security → Health → Henry.
If you choose to connect your Oura Ring, Henry requests the following data via OAuth 2.0:
Henry stores your Oura access token securely — on encrypted-at-rest infrastructure, protected by row-level access controls so no other user can read it — to retrieve data on your behalf. You can disconnect Oura at any time in Henry's Settings, which revokes access and permanently deletes your stored token. Oura Privacy Policy →
If you choose to connect your WHOOP strap, Henry requests the following data via OAuth 2.0:
Henry stores your WHOOP access and refresh tokens securely — on encrypted-at-rest infrastructure, protected by row-level access controls so no other user can read them — to retrieve data on your behalf. You can disconnect WHOOP at any time in Henry's Settings, which immediately revokes our access and permanently deletes your stored tokens. We do not write any data back to WHOOP and do not use your WHOOP data to train AI models. WHOOP Privacy Policy →
When you submit photos for a check-in assessment or log a meal by photo, those images are analysed by our AI provider to estimate body composition or food macros — see Section 9.
If you enable push notifications, we store your device push token to send you coaching nudges, check-in reminders, and workout prompts. You can disable notifications at any time in iOS Settings. We do not use notification tokens to track you or serve advertising.
If you choose to use Henry's cycle-tracking features, we collect the reproductive-health information you enter — such as period start and end dates, cycle length, and related symptoms — to tailor coaching (for example, reading a premenstrual change on the scale as water weight rather than fat, and adjusting expectations around recovery). This is among the most sensitive data we handle. It is collected only if you opt into cycle tracking, is treated as special-category and consumer health data, is never sold or shared, is never used for advertising, and is never used to train AI models. You can turn off cycle tracking and delete this data at any time in Settings.
When you submit a check-in for assessment, Henry analyses your progress photos to estimate your body composition — for example, an approximate body-fat range and how developed each muscle group appears. This is a health/biometric inference Henry derives from your images. These estimates are approximate (not a clinical measurement), are generated solely to provide your coaching, and are treated as sensitive health data: never sold, never used for advertising, never used to train AI models. See Section 9 for how photos are processed.
GDPR Art. 6 & 9 For users in the EU and UK, every piece of data we process has a specific legal basis. Health data — including data from Apple Health, Oura, and WHOOP, body-composition estimates inferred from photos, and any cycle data you enter — is classified as "special category" data under Article 9 GDPR and requires explicit consent.
| Data Type | Legal Basis | GDPR Article |
|---|---|---|
| Account data (name, email, password, goals) | Performance of contract — necessary to provide the service | Art. 6(1)(b) |
| Health data (Apple Health, Oura, WHOOP) | Explicit consent — you actively connect each integration | Art. 6(1)(a) + Art. 9(2)(a) |
| Check-in photos & body-composition estimates | Explicit consent — you choose to upload each photo and trigger the assessment | Art. 6(1)(a) + Art. 9(2)(a) |
| Reproductive / cycle data | Explicit consent — collected only if you opt into cycle tracking | Art. 6(1)(a) + Art. 9(2)(a) |
| Coaching messages | Performance of contract — the core service you signed up for | Art. 6(1)(b) |
| Technical & usage data | Legitimate interests — improving reliability and performance | Art. 6(1)(f) |
| Push notification token | Consent — you grant permission via iOS prompt | Art. 6(1)(a) |
Where we rely on legitimate interests (Art. 6(1)(f)), we have assessed that our interests do not override your fundamental rights and freedoms. You may object to such processing at any time (see Section 13).
Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Withdrawal can be done by disconnecting the relevant integration, turning off cycle tracking in Settings, or contacting us directly.
We use your data for one primary purpose: to give you better, more personalised coaching. Specifically:
Your health data is never used to train AI models. Data from Apple Health, Oura Ring, and WHOOP, your body-composition estimates, and any cycle data is used solely to generate your personal coaching responses in real time. It is never pooled, anonymised for model training, sold, or shared with any third party for commercial purposes.
GDPR Art. 22 CCPA ADMT Henry's coaching is powered by a large language model (LLM). Your health data, messages, goals, and — when you trigger an assessment or log a meal by photo — your images are sent to this model to generate personalised responses and estimates. This constitutes automated processing, including deriving body-composition estimates from your photos.
Important clarifications:
Under California's automated-decision-making technology (ADMT) regulations taking effect in 2027, businesses must provide a pre-use notice for automated decision-making used in health-related contexts. We are committed to full compliance ahead of that deadline and will update this policy accordingly.
GDPR Art. 13(1)(e) CCPA 1798.110 We do not sell your data. The following trusted service providers have access to limited data to operate the app. Each is contractually bound to process your data only as instructed by us.
Supabase — database, authentication, and file storage. Your account data, health metrics, messages, and photos are stored on Supabase infrastructure (hosted on AWS, primarily in the US). Supabase is our primary data processor. Supabase Privacy Policy → Supabase DPA →
AI model provider (currently Anthropic) — Your coaching messages and relevant health context (metrics, goals, recent activity) are sent to a third-party large language model API to generate coaching responses. In addition, when you trigger a check-in assessment your progress photos are sent to this provider to estimate your body composition, and when you log a meal by photo that image is sent to estimate its macros. Our current provider is Anthropic. Anthropic does not use API-submitted data to train their models. If we change providers, we will update this policy before doing so. Anthropic Privacy Policy →
Oura Health — if connected, Henry communicates with the Oura API to read your ring data. Henry never writes data to Oura. Oura Privacy Policy →
WHOOP — if connected, Henry communicates with the WHOOP API to read your strap data. Henry never writes data to WHOOP. WHOOP Privacy Policy →
Apple — if you enable Apple Health integration, data flows from Apple's HealthKit framework on your device to Henry. Apple governs the HealthKit permission system; Henry reads only the data types you explicitly authorise. Apple Privacy Policy →
OneSignal — push notification delivery. If you enable notifications, your device token is shared with OneSignal to deliver coaching nudges and reminders. OneSignal does not receive your health data. OneSignal Privacy Policy →
Stripe — payment processing for paid subscriptions. If you subscribe, your email address and payment details are processed by Stripe. We never see or store your full card number, and Stripe does not receive your health data, messages, or photos. Stripe Privacy Policy →
FatSecret — nutrition database lookups. When you search for or log a food, the food description or barcode you enter is sent to the FatSecret Platform API to retrieve verified nutrition information. FatSecret receives only the food query — never your name, account details, health data, or photos. FatSecret Privacy Policy →
PostHog — product analytics. We use PostHog to understand how the app is used in aggregate (for example, how many people open the app or start a subscription) so we can improve it. PostHog is configured without autocapture and without session recording, so it never receives your health data, photos, messages, name, or form inputs — only a pseudonymous user identifier and a small set of non-sensitive product events. PostHog Privacy Policy →
Sentry — crash and error diagnostics. When the app encounters an error, technical diagnostic information (such as the error message and a stack trace) is sent to Sentry so we can fix it. Sentry is configured not to attach personal information; it does not receive your health data, photos, or messages. Sentry Privacy Policy →
Aside from the processors listed above, no other third parties receive your personal or health data. We do not use advertising networks or data marketplaces, and our analytics and error-reporting providers are configured not to receive your health data, photos, messages, or name.
GDPR Ch. V Henry is operated from the United States. If you are located in the EU, UK, or another jurisdiction with data transfer restrictions, your data may be transferred to and processed in the US when you use Henry.
We rely on the following transfer mechanisms:
For more information about the safeguards in place, email support@coachhenryapp.com.
Progress photos you upload, and meal photos you log, are stored in a private, access-controlled storage bucket. When you submit a check-in for assessment, your progress photos are sent to our AI provider (currently Anthropic) to generate a physique assessment — including an estimated body-fat range and per-muscle-group development. This means Henry derives a health/biometric inference (your estimated body composition) from your photos. Likewise, if you log a meal by photo, that image is sent to the AI provider solely to estimate the food and its macros.
These estimates are approximate and generated solely to provide your coaching. Your photos and the estimates derived from them are:
You can delete individual photos from within the app at any time.
We apply industry-standard security practices to protect your data:
No system is completely immune to attack. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities as required by law (GDPR Art. 33–34) without undue delay and within 72 hours of becoming aware.
GDPR Art. 13(2)(a) We retain your data for as long as your account is active and for a short period afterwards to allow account recovery:
| Data Type | Retention Period |
|---|---|
| Account data & profile | Until account deletion + 30 days |
| Health metrics (Apple Health, Oura, WHOOP) | Until account deletion + 30 days, or until integration is disconnected |
| Reproductive / cycle data | Until cycle tracking is turned off, or account deletion + 30 days |
| Coaching chat messages | Until account deletion + 30 days |
| Nutrition & weight logs | Until account deletion + 30 days |
| Check-in photos & body-composition estimates | Until deleted by you, or account deletion + 30 days |
| OAuth tokens (Oura, WHOOP) | Deleted immediately on disconnect, or account deletion |
| Push notification tokens | Until notifications disabled or account deletion |
| Crash logs & error data | 90 days from creation |
| Aggregated, anonymised usage stats | Indefinitely (cannot identify you) |
When you delete your account, we initiate permanent deletion of all personal data within 30 days. Aggregated statistics that cannot be linked back to you may be retained for product improvement purposes.
The Henry iOS app does not use browser cookies. The website coachhenryapp.com uses only essential cookies necessary for the site to function (e.g., authentication state). We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
The app may use local device storage to cache your preferences and reduce server requests. This data stays on your device and is cleared when you uninstall the app.
Regardless of where you live, you have the right to:
GDPR Art. 15–22 If you are located in the European Economic Area (EEA), EU, or United Kingdom, you also have the right to:
We will respond to GDPR requests within one month of receipt. In complex cases, this may be extended by up to two additional months with prior notice.
CCPA/CPRA If you are a California resident, you have the following rights under the California Consumer Privacy Act (as amended by Proposition 24):
To submit a California privacy request, contact us via one of the two methods below. We will respond within 45 days. One free extension of 45 days may apply for complex requests, with notice to you. We do not charge a fee for reasonable requests.
To exercise any of your rights, use either of these two methods:
We may need to verify your identity before processing requests to protect against fraudulent submissions. We will ask you to confirm your email address at a minimum.
HealthKit Guidelines Henry makes the following firm commitments regarding health data — including data from Apple Health, Oura Ring, and WHOOP, the body-composition estimates inferred from your photos, and any cycle data you enter:
These commitments apply permanently and are not subject to change by a future policy update. If we were ever to change any of these commitments, we would seek your explicit re-consent before doing so.
WA HB 1155 If you are a Washington resident, Washington's My Health My Data Act (MHMDA) gives you additional rights over your "consumer health data." Because MHMDA requires a dedicated, separately published policy, those disclosures live in our Consumer Health Data Privacy Policy.
In short: we collect consumer health data (such as body measurements, body-composition estimates inferred from your photos, nutrition, wearable metrics, and — if you opt in — cycle data) only to provide the coaching you request. We never sell it, never share it for advertising, and never use geofencing. You can withdraw consent or delete it at any time. See the full Consumer Health Data Privacy Policy for details.
COPPA 15 U.S.C. § 6501 Henry is not directed at children. We do not knowingly collect personal information from anyone under the age of 18. Users must be at least 18 years of age to create an account and use the app.
If you are a parent or guardian and believe a minor has created a Henry account, please contact us at support@coachhenryapp.com. We will delete the account and all associated data promptly upon verified request.
We do not knowingly collect the personal information of children under 13 as defined by COPPA (Children's Online Privacy Protection Act). If we become aware that a user is under 13, the account is immediately deleted.
GDPR Art. 77 If you are located in the EU or UK and believe we have processed your data unlawfully, you have the right to lodge a complaint with your local data protection supervisory authority. You may do this without first contacting us, though we encourage you to reach out to us first so we can try to resolve the issue directly.
Examples of relevant supervisory authorities:
This policy has been written to address the requirements of the following laws and guidelines. If you have questions about how we meet any specific requirement, please contact us.
| Law / Framework | Jurisdiction | Section(s) Addressed |
|---|---|---|
| GDPR (Regulation (EU) 2016/679) | EU & UK | §§ 1, 4, 6, 8, 10, 11, 13, 17 |
| CCPA / CPRA (Cal. Civil Code § 1798.100+) | California, USA | §§ 3, 7, 13.3, 13.4 |
| COPPA (15 U.S.C. § 6501) | United States | § 16 |
| Apple HealthKit Guidelines | App Store (global) | §§ 3.2, 7, 14 |
| Washington My Health My Data Act (HB 1155) | Washington, USA | §§ 3.8, 9, 14, 15 |
| CCPA ADMT Regulations (effective Jan 2027) | California, USA | § 6 |
We review this policy at least once every 12 months to keep it accurate and current. If we make material changes, we will:
Continued use of Henry after changes take effect constitutes acceptance of the revised policy. If you do not agree with a change, you may delete your account before it takes effect.
Questions, concerns, correction requests, or deletion requests — we take them all seriously.
Include "Privacy Request" in your subject line for fastest routing. We aim to acknowledge all privacy-related emails within 5 business days.