Privacy Policy

SF Inner Circle — Websites and Mobile Applications

Last Updated: July 25, 2026

This Privacy Policy explains how Syatt Fitness LLC (“Syatt Fitness,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes information when you use our websites and services, including the SF Inner Circle membership site and our mobile applications (collectively, the “Services”).

Important: We maintain a separate Washington Consumer Health Data Privacy Notice at a separate link for Washington residents and any consumer who wants information specific to consumer health data. That Notice is not part of this Privacy Policy and should be read separately.

Definitions

For purposes of this Policy:

● “Personal Information” means information that identifies, relates to, or could reasonably be linked, directly or indirectly, to an individual or household.

● “Sensitive Personal Information” means categories of personal information treated as sensitive under applicable law, including account credentials and certain health-related information.

● “Consumer Health Data” has the meaning given under Washington’s My Health My Data Act, Nevada’s consumer health data law, and similar state laws.

● “Services” means our websites, mobile applications, and related offerings described in this Policy.

● “Processing” means any operation performed on Personal Information, including collection, use, storage, disclosure, and deletion.

● “Sale” and “Share” have the meanings given under applicable law.

Websites / Apps Covered

● https://www.sfinnercircle.com (membership site)

● https://app.sfinnercircle.com (app login / web app)

● https://www.syattfitness.com (main site)

● Our iOS and Android mobile applications (including the Apple App Store version)

1. Who We Are and How to Contact Us

Company: Syatt Fitness LLC

Address: 2695 McGarity Ln, Ste 500, MB 101, Lucas, TX 75002, USA

Privacy Contact: jordan@syattfitness.com

EU Representative (GDPR Article 27): Prighter Group with its local partners

UK Representative (UK GDPR Article 27): Prighter Group with its local partners

Prighter Trust Center (GDPR/UK GDPR requests): https://app.prighter.com/portal/15213878451

If you are located in the EEA, UK, or Switzerland, you may use the Trust Center above or email jordan@syattfitness.com for privacy-related requests.

2. What This Policy Covers

This Policy applies to information we process when you create or manage an account, subscribe, log in, use app features (workouts, nutrition tracking, progress tracking, photos, and related features), connect third-party health integrations (Apple Health or Google Health Connect, where available), or contact us for support.

This Policy does not apply to third-party websites, services, or platforms you may access via links in the Services (including payment processors), which are governed by their own policies.

Optional Community Group (Facebook): We may offer members the option to join a private Facebook group moderated by Syatt Fitness staff. The Facebook group is separate from and not integrated with the Services. If you choose to join or participate, information you post and information associated with your Facebook profile will also be processed by Meta under its own terms and privacy policy, and may be viewed and processed by us for community administration, moderation, and support.

3. Information We Collect

A. Information You Provide to Us

Account and subscription information (required for account creation/subscription management):

● First and last name

● Email address

● Country/region

● Username and password

● Billing address (street address, town/city, state, zip/postal code)

Payment and transaction information:

● Subscription status and transaction details (e.g., plan type, renewal status, invoices, and receipts)

● Payment card data is processed by our payment processor(s) (e.g., Stripe, including Apple Pay and Google Pay where offered). Depending on your payment method, we may not receive or store your full payment card number. We may receive limited payment-related details (for example, card brand, last four digits, tokenized identifiers, billing address, and transaction confirmations) from the processor.

Onboarding and preference information:

● Training frequency preference (e.g., 3x/week or 4x/week)

● Equipment availability (e.g., dumbbells only or gym equipment)

● Weight goal (fat loss, maintain, gain)

● Current weight and goal weight

● Tracking preferences (calorie tracking vs. “3 plates, 2 snacks”)

● Recommended intake outputs displayed to you based on your inputs

Content and health/fitness tracking data you choose to store (optional unless noted):

● Workout program selections and completion history

● Exercise notes

● Weights used per exercise (required to proceed within some workouts)

● Reps completed per exercise (required to proceed within some workouts)

● Body weight

● Body measurements (e.g., arms, thighs, chest, waist, hips)

● Nutrition logs (e.g., calories, protein, fiber)

● “3 plates, 2 snacks” tracking entries, including optional notes and photos

● Water intake tracking

● Steps tracking and related entries (including consistency calendar entries)

● Sleep-related notes (if you choose to enter them)

● Progress photos

Perinatal program data (if and when enabled, and only if you choose to provide it):

● Pregnancy status (yes/no)

● Weeks pregnant (number)

● Contraindications screening responses (yes/no) and/or confirmation regarding listed contraindications

● Weight (if requested for program tailoring)

B. Information We Collect Automatically

When you use the Services, we (and our service providers) may automatically collect:

● Device and app information (device type, operating system version, app version, language, time zone)

● Log and usage data (IP address, timestamps, pages/screens viewed, actions taken)

● Approximate location inferred from IP address (for example, country or region)

● Diagnostic data (crash reports, error logs, and performance data); in some cases, diagnostic records may be associated with your account identifier so we can investigate issues you report.

C. Information From Connected Services and Third Parties

Apple Health and Google Health Connect (steps only):

If you connect Apple Health and/or Google Health Connect, we access your step count data only with your permission and process it to provide features such as displaying steps and supporting consistency tracking. You can revoke access in your device settings at any time.

HealthKit Data: We do not use data obtained from Apple HealthKit for advertising, marketing, or data mining, and we do not use it for any purpose other than providing the health and fitness features you request within the app.

Food and nutrition database:

If you use barcode scanning or food search features, we may send your query (such as a barcode or food search term) to our nutrition database provider to return results to you.

Referrals and affiliates:

If you arrive via an affiliate or referral link, our affiliate tools may collect referral information (for example, referral identifiers) and related website interaction data.

4. How We Use Information

We use information to:

1. Provide the Services (account creation, login, subscriptions, delivering workouts, nutrition and fitness tracking, progress graphs, and user-selected features).

2. Personalize your experience (for example, recommending programs based on equipment, training frequency, and goals). Program recommendations may be generated algorithmically from your inputs; these recommendations do not produce legal or similarly significant effects, and you may choose any program regardless of the recommendation. These recommendations are for fitness and wellness purposes and are not medical advice.

3. Process subscriptions and transactions (including billing and customer service related to subscriptions).

4. Provide customer support and respond to requests (including troubleshooting and account-related inquiries).

5. Communicate with you (transactional messages, service updates, support responses, and, where you opt in or where permitted, marketing communications). You may opt out of marketing communications as described in this Policy.

6. Maintain safety and security (fraud prevention, authentication, access control, and threat monitoring).

7. Debug, improve, and develop the Services (analytics, crash and error monitoring, performance tuning, feature improvements, and internal research and development).

8. For other purposes that are consistent with and reasonably related to the purposes described above, where permitted by applicable law. If we intend to use information for a materially different purpose, we will provide additional notice and, where required, obtain your consent.

5. How We Disclose Information

We do not sell your personal information, and we do not share personal information for cross-context behavioral advertising. We disclose information only as described below.

A. Service Providers / Processors

We disclose information to vendors that perform services for us, such as:

● Hosting, infrastructure, databases, and backups: Amazon Web Services (AWS)

● Payment processing: Stripe (including Apple Pay and Google Pay where enabled)

● Account, subscription, and order management: WordPress & WooCommerce

● Email communications: Mailchimp (customer communications/marketing) and AWS (transactional email delivery, where used)

● Website/app security: Wordfence

● Analytics (website usage/performance): Google Analytics

● Cookie consent management for www.sfinnercircle.com: CookieYes

● Affiliate/referral tracking: AffiliateWP

● User-uploaded image storage/delivery: bunny.net

● Error monitoring/crash reporting: Sentry

● Food and nutrition lookup: Nutritionix

● Development, maintenance, and customer support: CATS ARE NOT PEAS LTD (UK)

● Push notification delivery: Apple/Google notification services (as applicable)

In addition, our mobile app includes certain SDKs and libraries (for example, Flutter Local Notifications, Dio, CachedNetworkImage, webview_flutter, URL Launcher, Image Picker, Mobile Scanner, Health SDK, Shared Preferences, Package Info Plus, Timezone, and Audio

Session). Where these SDKs or libraries transmit information to third parties, such processing is subject to the disclosures in this Policy and the applicable provider’s terms.

Where required by applicable law, we engage service providers under contracts that limit their processing of personal information on our behalf.

Google Analytics configuration: Based on our current configuration, Google Signals, Google Ads integration, remarketing, and audience features are disabled.

B. Professional Advisors

We may disclose information to our professional advisors (such as lawyers, accountants, auditors, and insurers) where reasonably necessary for us to obtain advice, manage risk, or protect our legal interests.

C. Legal, Safety, and Business Transfers

● To comply with law, legal process, or government requests;

● To protect the rights, safety, and security of Syatt Fitness, our users, and others;

● In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets (including related due diligence), subject to applicable legal requirements.

D. With Your Direction or Consent

We may disclose information when you direct us to do so or give consent (for example, by enabling a connected integration).

E. Aggregated or De-identified Information

We may disclose aggregated or de-identified information that cannot reasonably be used to identify you, where permitted by applicable law.

6. Cookies and Similar Technologies

Our websites use cookies, SDKs, and similar technologies. For information specific to cookies and similar technologies currently used on www.sfinnercircle.com, please see our separate Cookie Notice. If we materially expand cookie-based features or deploy a cookie banner or preference center on other Syatt websites, we will update that Notice or publish a separate cookie notice for those properties.

Where required by applicable law, and on websites where we present a cookie banner or preference center, non-essential cookies (such as analytics cookies) are not set unless you provide consent. On www.sfinnercircle.com, we use CookieYes as our cookie consent management platform.

Some browsers offer a “Do Not Track” signal. Because there is no common industry standard for Do Not Track, our websites do not currently respond to those signals. Where required by applicable law and where technically supported by the relevant site configuration, we may

process valid browser-based opt-out preference signals, such as Global Privacy Control, in accordance with applicable law.

7. Health and Fitness Data; Sensitive Data

Some information you choose to provide or store in the Services (for example, weight, measurements, nutrition logs, step data, pregnancy status/weeks pregnant, and progress photos) may be considered sensitive or health-related data under certain laws. We process this information to provide the features you request, such as tracking, progress visualization, and program tailoring.

Where required by law, we obtain your consent before collecting or using certain sensitive data. You may withdraw your consent at any time by disabling the relevant feature (for example, disconnecting Apple Health or Google Health Connect) and/or requesting deletion. If you withdraw consent for a particular feature, you may no longer be able to use that feature, but you may continue to use other parts of the Services that do not require the relevant data.

Depending on the feature, you may be able to delete individual entries (such as logs, notes, or photos) within the app, and you may also request account deletion as described in this Policy.

Apple HealthKit Data: We do not use data obtained from Apple HealthKit for advertising, marketing, or data mining. HealthKit data is not sold or shared for advertising purposes.

Perinatal and reproductive data is used only to provide the features you request and is not used for advertising or cross-context behavioral advertising.

Important Notice Regarding HIPAA: Syatt Fitness is not a healthcare provider or health plan, and the Services are not intended to provide medical advice or to function as a medical device. In general, the Services are not operated as a HIPAA-covered entity or business associate, and information you enter in the app is not treated as protected health information under HIPAA. The Services are intended for general fitness and wellness purposes only. Always consult your healthcare provider for medical advice.

8. Your Choices and Controls

● Account information: You may update certain account information through your account settings (where available).

● Email communications: You can unsubscribe from marketing emails via the “unsubscribe” link or by contacting us. Transactional/service emails may still be sent.

● Push notifications: You can enable or disable notifications through your device settings.

● Connected health integrations: You can revoke access to Apple Health or Google Health Connect at any time in your device settings.

● Cookies and analytics (websites): Where we use analytics cookies on our websites, you can manage your preferences through the cookie banner/preference center (where presented) and through your browser settings. Google also offers a browser add-on to opt out of certain Google Analytics tracking in supported browsers.

● Data deletion: You can request account deletion through the account deletion feature in the app (Settings > Delete Account) or by emailing jordan@syattfitness.com. We may need to verify your identity before processing the request. See Sections 12 and 13 (as applicable) for additional rights details.

9. International Data Transfers

We are based in the United States and may process and store information in the United States and other countries where we or our service providers operate.

Where required under applicable law, we rely on appropriate safeguards for cross-border transfers. These safeguards may include: (a) Standard Contractual Clauses approved by the European Commission and/or the UK International Data Transfer Agreement (or UK Addendum), as applicable; (b) the EU-U.S. Data Privacy Framework and, for UK or Swiss data, the relevant UK or Swiss extensions or successor mechanisms, where a recipient is a certified participant; and/or (c) other lawful transfer mechanisms recognized under applicable law. Where appropriate, we may implement additional measures designed to protect personal information in connection with cross-border transfers.

10. Data Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, to meet legal, accounting, and tax obligations, to resolve disputes, and to enforce our agreements. Data Category

Retention Period

Account information

Duration of account; deleted within 30 days after a verified deletion request is processed

Transaction and billing records

7 years from the transaction date (tax, accounting, and legal compliance)

Health and fitness tracking data

Duration of account; deleted upon account deletion, subject to backup retention

Support communications

3 years from resolution

Server logs

90 days

Backups and archives

Up to 90 days after deletion in the ordinary course

Perinatal or pregnancy screening data (if used)

Retained only while actively using the relevant feature/program, or until deletion is requested or the account is deleted

Certain information may be retained longer where required by law or reasonably necessary to protect the security or integrity of the Services.

11. Security

We implement administrative, technical, and physical safeguards designed to protect personal information. These safeguards may include, for example, encryption in transit, access controls, and monitoring. However, no system is 100% secure and we cannot guarantee absolute security.

Data breaches and incident response. We maintain incident response procedures designed to address suspected or confirmed security incidents. If we become aware of a data breach that triggers a notification obligation under applicable law, we will notify affected individuals and, where required, regulators, within the timeframes required by law.

California notice example. California law generally requires notice to affected California residents within 30 calendar days of discovery or notification of a data breach (subject to certain permitted delays), and requires submission of a sample notice to the California Attorney General within 15 calendar days of notifying affected consumers when more than 500 California residents are affected.

FTC Health Breach Notification Rule. Because the Services may combine health-related information you enter with information from connected services (such as Apple Health or Google Health Connect), the Services may fall within the scope of the FTC’s Health Breach Notification Rule. To the extent the Rule applies, we will comply with applicable federal breach-notification requirements for certain breaches involving individually identifiable health information, which may require notice to affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.

12. U.S. State Privacy Rights

Depending on where you live, you may have rights under applicable U.S. state privacy laws, including the right to:

● Access or confirm processing;

● Correct inaccurate data;

● Delete;

● Obtain a copy or portability;

● Opt out of certain processing (for example, targeted advertising, sale, sharing, or certain profiling, where applicable).

How to exercise rights. Please email jordan@syattfitness.com with your request. Where available, you may also use in-app settings or tools to submit certain requests. We may need to

verify your identity before fulfilling your request. We will respond to verified requests within the timeframes required by applicable law.

Appeals. If we deny your request, you may appeal by replying to our response and requesting an appeal. We will respond to an appeal within the timeframe required by applicable law. If your appeal is denied, you may have the right to contact your state Attorney General or another state regulator.

Authorized agents. You may designate an authorized agent to submit requests on your behalf. Authorized agents may be required to provide written authorization signed by you and may be required to verify their own identity. We may contact you directly to confirm the request.

California Residents (CCPA/CPRA)

California residents may request information about the personal information we collected about them during the 12 months preceding their request. Categories we may collect include:

● Identifiers (for example, name, email, username, IP address)

● Contact information (for example, billing address and email address)

● Commercial information (for example, subscription status and transaction history)

● Internet or network activity (for example, log data and usage data)

● User content (for example, photos, notes, and tracking entries)

● Sensitive Personal Information (for example, account credentials and health-related information you choose to provide)

We use this information for the purposes described in Section 4 and disclose it to service providers described in Section 5.

No sale or share. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. If our practices change in the future, we will provide appropriate opt-out mechanisms, including a “Do Not Sell or Share My Personal Information” link where required by law.

Sensitive Personal Information. We collect certain categories of sensitive personal information, including account login credentials and health-related information you choose to provide. We use this information only as necessary to provide the Services you request, to authenticate your account, and to support the health and fitness features you enable. We do not use or disclose sensitive personal information for purposes beyond those reasonably necessary to provide the Services, and we do not use sensitive personal information for advertising or profiling unrelated to providing the Services.

Right to limit use of sensitive personal information. Because we use sensitive personal information only for permitted purposes, we do not provide a separate “Limit the Use of My Sensitive Personal Information” link. If you want to limit our processing, you can choose not to

provide certain data, delete or edit entries where available, disable integrations, or request deletion.

Texas Residents (Texas Data Privacy and Security Act)

Texas consumers have the rights described above, including rights to confirm processing, access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling, where applicable.

No sale of sensitive data. We do not sell sensitive data (including health data and other sensitive categories) as defined under Texas law. We process sensitive data only with consent where required by applicable law.

Texas consumers may also lodge complaints with the Texas Attorney General. To exercise rights with us first, email jordan@syattfitness.com.

Maryland Residents (Maryland Online Data Privacy Act)

No sale of sensitive data. We do not sell sensitive data of Maryland consumers.

Sensitive data minimization. We process sensitive data only as strictly necessary to provide or maintain the specific product or service you request, to the extent required by Maryland law.

Nevada Residents

Nevada law provides two frameworks relevant to our Services.

● Nevada’s online privacy law (NRS 603A.340): You may opt out of the sale of certain covered information. We do not sell personal information as defined under that law.

● Nevada’s consumer health data law (NRS 603A.400-.550): To the extent we collect consumer health data covered by Nevada law, you may have rights to confirm, access, delete, and withdraw consent with respect to that data. We do not sell consumer health data.

To exercise Nevada rights, email jordan@syattfitness.com.

Washington Residents

Washington residents and any consumer seeking information specific to consumer health data should review our separate Washington Consumer Health Data Privacy Notice.

Other U.S. States with Comprehensive Privacy Laws

Residents of Colorado, Virginia, Connecticut, Utah, Oregon, Delaware, Iowa, Montana, New Hampshire, New Jersey, Tennessee, Minnesota, Indiana, Kentucky, Rhode Island, and other states with applicable privacy laws may exercise the rights described above, subject to applicable law.

13. EEA, UK, Switzerland, and International Users (GDPR / UK GDPR / Swiss law)

If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, the following additional provisions apply to our processing of your personal data.

Controller: Syatt Fitness LLC, 2695 McGarity Ln, Ste 500, MB 101, Lucas, TX 75002, USA.

EU Representative (GDPR Article 27): Prighter Group with its local partners

UK Representative (UK GDPR Article 27): Prighter Group with its local partners

Prighter Trust Center: https://app.prighter.com/portal/15213878451

You may submit GDPR/UK GDPR requests through the Trust Center above or by emailing jordan@syattfitness.com.

Legal Bases for Processing (summary): Processing Purpose

Legal Basis

Provide the Services (account, subscriptions, features)

Performance of a contract

Process payments

Performance of a contract

Send transactional communications

Performance of a contract

Marketing communications

Consent, where required

Health and fitness data processing

Explicit consent for special category data, where applicable

Security and fraud prevention

Legitimate interests

Analytics and service improvement

Legitimate interests and/or consent, depending on context and the technology used

Legal compliance

Legal obligation

———

 

SYATT FITNESS LLC

Cookie Notice

Applies to: www.sfinnercircle.com

Last Updated: July 25, 2026

This Cookie Notice explains how Syatt Fitness LLC (“Syatt Fitness,” “we,” “us,” or “our”) uses cookies and similar technologies on www.sfinnercircle.com (the “Site”). This Notice should be read together with our Privacy Policy.

This Notice is focused on the Site identified above. It does not by itself describe cookies or similar technologies that may be used on other Syatt websites unless and until this Notice is updated to cover them or a separate cookie notice is published for those properties. Mobile app SDKs, device permissions, and other app-based tracking or diagnostic technologies are described in our Privacy Policy and in any in-app disclosures or device permission prompts, as applicable.

1. What Are Cookies and Similar Technologies?

Cookies are small text files placed on your browser or device when you visit a website. Similar technologies may include pixels, tags, local storage, and similar tools that help websites function, enhance security, remember preferences, and measure site performance.

2. Categories of Cookies and Similar Technologies We Use

We may use the following categories of cookies and similar technologies on the Site:

● Strictly necessary cookies: Required for the Site to function (for example, authentication, session management, security, and checkout-related fraud prevention).

● Functional cookies: Help remember choices and preferences, where enabled.

● Analytics cookies: Help us understand how the Site is used and improve performance.

● Affiliate or referral cookies: Help attribute referrals and administer affiliate programs, where enabled.

We do not currently use advertising or cross-context behavioral advertising cookies on the Site. If that changes, we will update this Notice and provide any rights or consent mechanisms required by applicable law.

3. Service Providers and Technologies That May Set Cookies on the Site

Depending on the page you visit, whether you log in or check out, and the preferences you choose, cookies or similar technologies on the Site may be set by us and by certain service providers, such as: Provider / Tool

Purpose / Function

CookieYes

Cookie banner and preference center; recording cookie choices

WordPress / WooCommerce

Site functionality, account/session management, and subscription or checkout flows

Wordfence

Security, firewalling, and bot/threat monitoring

Google Analytics

Site usage and performance analytics

AffiliateWP

Affiliate and referral attribution

Stripe

Payment and fraud-prevention technologies associated with checkout flows

Mailchimp (where used)

Interactions related to marketing emails and linked content

The exact names, lifespans, and combinations of cookies may vary depending on the Site page, your interaction with the Site, your consent choices, and updates made by the relevant providers. The most current list of cookies and similar technologies presented through the Site is available through the CookieYes preference center when it is shown on the Site.

4. Your Choices and How to Manage Cookies

We use CookieYes to provide the cookie banner and preference center on www.sfinnercircle.com.

For users in the EEA/UK (and in other jurisdictions where prior consent is required), non-essential cookies, including analytics cookies, are blocked until you provide consent.

You can manage cookies and similar technologies by:

● Using the cookie banner or preference center on the Site to accept or reject non-essential cookies and to change your choices later;

● Changing your browser settings to block or delete cookies (please note that blocking strictly necessary cookies may affect Site functionality).

5. Analytics

We use Google Analytics to understand how users interact with the Site and to improve performance.

Based on our current configuration, Google Signals, Google Ads integration, remarketing, and audience features are disabled. Google Analytics is used for analytics and service improvement only, not for cross-context behavioral advertising.

If you decline analytics cookies through the cookie banner or preference center (where presented), analytics cookies should not be set on the Site in jurisdictions where prior consent is required. Google also offers a browser add-on to opt out of certain Google Analytics tracking in supported browsers.

6. Do Not Track and Global Privacy Control

Some browsers offer a “Do Not Track” signal. Because there is no common industry standard for Do Not Track, the Site does not currently respond to those signals.

Some browsers or privacy tools may also send browser-based opt-out preference signals, such as Global Privacy Control. Where required by applicable law and where technically supported by the Site configuration, we may process valid opt-out preference signals in accordance with applicable law.

7. California and Other U.S. State Privacy Disclosures

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. Rights and additional state-specific disclosures are described in our Privacy Policy.

Where applicable, cookie or tracker-related requests may also be submitted using the methods described in our Privacy Policy.

8. International Data Transfers

Some providers whose technologies are used on the Site may process data outside your country of residence, including in the United States. Where required by applicable law, we use appropriate safeguards for such transfers as described in our Privacy Policy.

9. Changes to This Cookie Notice

We may update this Cookie Notice from time to time. We will update the “Last Updated” date and, where required by law, provide additional notice.

10. Contact Us

If you have questions about this Cookie Notice, contact us at jordan@syattfitness.com.

Mailing Address: Syatt Fitness LLC, 2695 McGarity Ln, Ste 500, MB 101, Lucas, TX 75002, USA

CookieYes Privacy Policy: https://www.cookieyes.com/privacy-policy/

EEA/UK users may also use the Prighter Trust Center for privacy-related requests: https://app.prighter.com/portal/15213878451

 


SYATT FITNESS LLC

Washington Consumer Health Data Privacy Notice

Last Updated: July 25, 2026

Posted pursuant to Washington’s My Health My Data Act. This Notice is separate and distinct from our general Privacy Policy and addresses only Consumer Health Data as required by Washington law.

Syatt Fitness LLC (“Syatt Fitness,” “we,” “us,” or “our”) provides this Consumer Health Data Privacy Notice to Washington residents and any other consumer using the SF Inner Circle services (the “Services”). This Notice describes how we collect, use, share, and protect Consumer Health Data as defined under Washington’s My Health My Data Act and similar state laws.

1. Categories of Consumer Health Data We Collect

We collect the following categories of Consumer Health Data, to the extent you choose to provide them or enable the related features: Category

Examples

Fitness and exercise information

Workouts completed, weights used, reps, exercise notes

Bodily measurements

Body weight and measurements of arms, thighs, chest, waist, and hips

Nutrition and dietary information

Calorie, protein, and fiber tracking; “3 plates, 2 snacks” entries; meal notes and photos

Step and activity information

Step count from Apple Health or Google Health Connect, where enabled

Sleep-related information

Sleep notes, if you choose to enter them

Images that may reveal health information

Progress photos

Water intake information

Water tracking entries

Reproductive or perinatal information

Pregnancy status, weeks pregnant, and contraindications screening responses, if you choose to use the perinatal program

Location information that may indicate attempts to acquire health services

Approximate location inferred from IP address, to the extent it may constitute Consumer Health Data under applicable law

Inferences drawn from the above

Program recommendations generated from your inputs

advertising, marketing, data mining, or profile-building outside the features you request.

3. Categories of Sources from Which We Collect Consumer Health Data

● You — when you enter data in the Services or upload photos or notes;

● Connected services you enable — Apple Health (iOS) or Google Health Connect (Android), where you grant access for step count data.

4. Categories of Consumer Health Data We Share

We do not sell Consumer Health Data. We may share Consumer Health Data with service providers or processors only as reasonably necessary to provide and secure the Services, under written contracts that restrict processing to those purposes.

We do not share Consumer Health Data with affiliates (Syatt Fitness LLC does not currently have corporate affiliates).

The categories of service providers/processors with whom we may share Consumer Health Data include: Category

Purpose

Example Vendor

Cloud hosting, database, and backup providers

Store data

Amazon Web Services (AWS)

Image storage and delivery providers

Store and deliver photos you upload

bunny.net

Development, maintenance, and support providers

Troubleshoot and support the Services

CATS ARE NOT PEAS LTD

Nutrition database providers

Return search or barcode results you request

Nutritionix

Error monitoring providers

Diagnose application errors

Sentry

Connected health integration providers

Step count integration

Apple (HealthKit); Google (Health Connect)

5. Your Consumer Health Data Rights

Subject to applicable law, you may have the right to:

● Confirm whether we collect, use, or share your Consumer Health Data;

● Access your Consumer Health Data;

● Delete your Consumer Health Data (including data stored in archived or backup systems, where required by law);

● Withdraw consent relating to the collection or sharing of Consumer Health Data.

How to exercise your rights. Email jordan@syattfitness.com with the subject line “Consumer Health Data Request” and describe your request. We may need to verify your identity before fulfilling your request. We will respond within 45 days of receipt, with a possible 45-day extension where reasonably necessary (with notice to you).

Withdrawing consent. You may withdraw consent by disabling the relevant feature in-app (for example, disconnecting Apple Health or Google Health Connect), deleting entries in-app where available, requesting account deletion through Settings > Delete Account, or emailing jordan@syattfitness.com.

Appeals. If we deny your request, you may appeal by replying to our response. We will respond to an appeal within 45 days of receipt. If we deny the appeal, you may contact the Washington Attorney General, including through the consumer complaint resources available at atg.wa.gov/consumer-issues.

6. Authorization and Consent Timing

We obtain your authorization before collecting Consumer Health Data. Consent disclosures within the app appear before any health data collection begins. You are asked to provide consent at the point of data collection — for example, before entering weight data for the first time, before connecting Apple Health, or before enrolling in the perinatal program.

If we ever intended to sell Consumer Health Data (which we do not currently do), we would first obtain separate written authorization meeting Washington’s applicable requirements. As of the date of this Notice, no such authorization is in use because we do not sell Consumer Health Data.

7. Geofencing Prohibition

Consistent with Washington law, we do not use geofencing technology within 2,000 feet of any entity providing in-person health care services to identify or track consumers seeking health care services, collect Consumer Health Data from consumers, or send notifications, messages, or advertisements related to Consumer Health Data or health care services.

We do not knowingly permit service providers to use geofencing for those purposes on our behalf in connection with the Services.

8. Data Security and Retention

We maintain administrative, technical, and physical safeguards designed to protect Consumer Health Data. These safeguards may include, for example, encryption in transit, access controls, and security monitoring.

We retain Consumer Health Data only as long as reasonably necessary to provide the features you request or as required by law. In general, Consumer Health Data is retained while your account remains active, except that perinatal or pregnancy-related data is retained only while you are actively using the relevant feature or program. Upon a verified deletion request, we will delete Consumer Health Data within 30 days, subject to backup retention of up to 90 days in the ordinary course.

9. Law Enforcement Requests and Reproductive Data

We review requests for Consumer Health Data carefully and may require valid legal process before disclosing data where permitted by law. Given the sensitivity of reproductive and pregnancy-related data, we apply heightened review to requests involving that data and may contest overbroad requests where legally permissible.

10. Children’s Data

The Services are intended for users 18 years of age or older. If we learn that we have collected Consumer Health Data from a child under 13, we will delete it promptly.

11. Contact Us

Privacy Contact: jordan@syattfitness.com

Mailing Address: Syatt Fitness LLC, 2695 McGarity Ln, Ste 500, MB 101, Lucas, TX 75002, USA

12. Changes to This Notice

We may update this Notice from time to time. We will update the “Last Updated” date and, where changes are material, provide notice through the Services and/or by email where required by law.


GDPR Certification: Art 27 representation by Prighter


powered by
Prighter

 

 


UK-GDPR Certification: Art 27 representation by Prighter


powered by
Prighter