Azayn Health Privacy Policy
Last updated: 8 October 2026
1. Who we are
Azayn Health (the "App") is provided by the provider named in our Legal information ("Azayn", "we", "us"). For the data described here, we are the controller under the GDPR and the business under the CCPA.
Privacy contact: privacy@azayn.com
2. What this policy covers
This policy covers the Azayn Health mobile apps (iOS and Android), the Azayn Health pages on azayn.com and health.azayn.com, and the public profile pages we serve there. It does not cover Apple, Google, Microsoft, Stripe, or any trainer you choose to connect with (see sections 6 and 7). For azayn.com generally and for Air Mouse, see the Privacy Policy.
Azayn Health is for people aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a child has an account, contact us and we will delete it.
3. The short version
- Nothing about your logbook is visible to a trainer until you connect with that trainer and the trainer accepts. Once connected, the categories switched on in Profile → Sharing become visible to them. All categories except AI workout progress are switched on by default, so check your settings when you connect. You can switch any category off, or end the connection, and access stops immediately.
- We do not sell your personal data. We do not show advertising. We use no analytics or advertising trackers in the App or on the website.
- We never use health data from Apple Health or Android Health Connect for advertising and never sell it to data brokers. We use it only to provide the features you use.
- Your workout GPS routes are visible only to you. They are never shown to trainers, in feeds or in posts.
- You can ask us to delete your account and data at any time (section 10).
4. Data we collect
4.1 Information you give us
- Account: your email address; the Apple, Google or Microsoft account identifier and email, if you sign in with them.
- Profile: display name, username, profile and banner photo, summary, links, interests, optional phone number, date of birth, gender, time zone, language.
- Health and fitness (sensitive): weight, heart rate, steps, sleep, water intake, workouts (type, duration, distance, calories, effort), height, fitness goals, daily goals, and notes you write.
- Content: posts, photos, videos, captions, comments and notes you create.
- Trainer applications: if you apply as a trainer, certifications, identity documents and professional details.
- Purchases: which plan or token bundle you bought and subscription identifiers. We do not receive or store your card number.
4.2 Information from your phone, with your permission
If you enable it, we read from Apple Health (HealthKit) or Android Health Connect: steps, sleep, heart rate, weight, active calories, hydration, workouts and, where you agree, exercise routes. You choose which categories to allow in your phone's permission prompt and can change it in your phone's Settings at any time.
If you use the in-app workout recorder, we collect location (including, if you allow it, in the background so a workout keeps recording when the screen is off) and motion and activity data (so the App can notice when a walk, run or ride begins). We use location only to draw your route and measure distance for your own workouts.
4.3 Information collected automatically
- Device label, platform, IP address, user agent, and the approximate city and country derived from the IP address. The city lookup uses a database that runs on our own servers, so your IP address is not sent to a third party for it. We use this to email you when a new device signs in.
- Session information, stored as a one-way hash, so you stay signed in. Sessions expire after 30 days.
- Notifications and activity records inside the App, to show your notification feed and history.
- Update requests to Expo's update service (EAS Update), which delivers App updates without a store release. Expo receives the technical information any such request carries, such as your IP address and the App's version.
We do not collect advertising identifiers, analytics events, crash reports, contacts, or microphone audio.
4.4 Cookies
Our website sets no cookies for tracking or analytics. During social sign-in we set one short-lived, strictly necessary security cookie (hu_oauth_binding, valid for 10 minutes) that protects the sign-in from forgery. Because we use no non-essential cookies, we show no cookie banner.
5. How and why we use data
- Create and secure your account; send sign-in codes and security alerts · Data: Account, device and IP data · Legal basis: Contract (Art. 6(1)(b)); legitimate interests in account security (Art. 6(1)(f))
- Run your logbook, goals and workout features · Data: Profile, health and fitness data · Legal basis: Contract; your explicit consent for health data (Art. 9(2)(a))
- Share your data with a trainer you choose, as you configure · Data: The categories you switch on · Legal basis: Your explicit consent, per category
- Social features: public profile, posts, follows · Data: Content, profile · Legal basis: Contract; consent for what you choose to publish
- Process payments and manage subscriptions · Data: Purchase data · Legal basis: Contract; legal obligation
- Keep the community safe: reports, automatic hiding of reported posts, staff review of reports and trainer applications · Data: Content, reports, trainer documents · Legal basis: Legitimate interests; legal obligation
- Verify trainer credentials · Data: Trainer application data · Legal basis: Legitimate interests in protecting users; contract
- Comply with the law; establish or defend legal claims · Data: As needed · Legal basis: Legal obligation; legitimate interests
- Keep the service reliable and fix bugs · Data: Server logs (up to 30 days) · Legal basis: Legitimate interests
If you do not give consent to process health data, you can still use Azayn Health's social and profile features, but not the logbook, phone sync or workout features, because they are that processing. You may withdraw consent at any time (section 9). Withdrawal does not affect processing already carried out.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
6. Who sees your data
6.1 Your trainer, and what they can and cannot see
A trainer can see your data only if all of these are true: you and the trainer have an active connection that they accepted; your plan includes sharing; your overall sharing setting is not "private"; and that specific category (for example steps, weight, sleep or heart rate) is switched on. AI workout progress is the one category that is off until you switch it on. All the others are on by default for new accounts. Turn a category off, or end the connection, and access stops immediately. Workout GPS routes are never shared.
A trainer you connect with is an independent professional, not Azayn and not our employee or agent. Once you share data with them, they decide how to handle what they see, under their own duties and professional rules. Our Trainer Terms require them to keep it confidential and use it only to advise you. This policy does not govern their independent practices.
6.2 Other users and the public
What you publish is visible according to the setting you choose for it: public, followers only, private or trainer. A public profile and public posts are visible to anyone, including people without an account and search engines. A public profile page shows only your display name, username, follower count and trainer badge, plus the optional fields you have chosen to show. Images are visible to anyone who has the link.
6.3 Our service providers (processors)
They process your data only on our instructions and under data processing agreements.
- **Hetzner Online GmbH (Helsinki, Finland)** · Purpose: Hosting our databases, file storage and servers · Data: All data described in section 4
- **Microsoft Azure (Blob Storage, EU region)** · Purpose: Encrypted backups of our database · Data: The database contents, encrypted
- **Stripe (Stripe Payments Europe, Ltd., Ireland, and affiliates)** · Purpose: Card payments and subscriptions on the web · Data: Email, purchase details, payment details you enter at Stripe
- **Apple** · Purpose: App Store purchases; Sign in with Apple; Apple Maps (iOS) · Data: Purchase receipts; Apple account identifier and email; map requests
- **Google** · Purpose: Google Play purchases; Google sign-in; Google Maps (Android); sign-in and security emails (Google Workspace) · Data: Purchase tokens; Google account identifier and email; map requests; your email address and the message
- **Microsoft** · Purpose: Sign in with Microsoft · Data: Microsoft account identifier and email
- **Microsoft Azure OpenAI Service · Purpose: Generating AI workout suggestions, only if you choose that feature and consent to it (section 6.4) · Data: Your age, gender, height, weight, fitness goals, interests, recent workouts and recent activity (steps, sleep, heart rate), and anything you type in the optional note. Not** your name, email or location.
- **Expo (EAS Update)** · Purpose: Delivering App updates · Data: Technical request information such as your IP address and App version
Our database, file storage, job scheduler and image processing run on our own infrastructure at the hosting provider above.
6.4 AI workout suggestions
If you are on the Ultra plan and tap Surprise me, we ask for your separate, explicit consent before anything is sent. With it, we send the information listed in the table above to Microsoft Azure OpenAI Service to generate a workout for that day. By default your trainer cannot see your suggestions; they are not shown on your profile or in the feed. If you switch on the separate AI workout progress category in Profile → Sharing, a trainer you are connected to can see your plan for the day and which exercises you have ticked off, never the reasoning behind the plan. When you ask for a different exercise we send only the exercise being replaced and the names of the other exercises in that session. We keep each suggestion for up to 30 days. You can turn the feature off at any time in Profile → Privacy & data, which also deletes your saved suggestions. Suggestions are general ideas, not medical advice.
6.5 Legal and safety disclosures; business transfers
We may disclose data if required by law or valid legal process, to protect someone's safety, or to establish or defend legal claims. If Azayn Health is involved in a merger, acquisition or asset sale, data may transfer to the successor, which must honour this policy. We do not sell or "share" personal information as those terms are defined in California law, and we do not use health data for targeted advertising.
6.6 Payment providers' own records
Stripe, Apple and Google keep their own transaction records under their own legal obligations. Deleting your Azayn Health account does not erase those records, and does not cancel a subscription bought through Apple or Google. You must cancel that in your App Store or Google Play subscription settings.
7. International transfers
Our servers are in Finland. If you are in the EEA or the UK, your data is stored there. Some providers (Apple, Google, Microsoft, Stripe, Expo) may process data in countries outside the European Economic Area, including the United States. Where they do, the transfer is covered by an adequacy decision (such as the EU-US Data Privacy Framework, where the provider is certified) or by standard contractual clauses. You can ask us for a copy of the safeguards at privacy@azayn.com.
8. Security
We protect data with measures including: sign-in codes and session tokens stored only as one-way hashes; encryption in transit (TLS); encrypted backups; private storage for uploaded files, served through signed, time-limited image links; rate limiting on sign-in and uploads; per-category access checks on every trainer data request; and staff-only, access-restricted moderation tools. No system is perfectly secure. If a breach affects your data, we will notify you and the authorities as the law requires.
9. Your rights and choices
In the App you can edit or delete most of what you entered; change who sees each post; turn sharing categories on or off; end a trainer connection; disconnect phone sync; block or report users; manage permissions in your phone's Settings; and withdraw your consent to AI workout suggestions, which also deletes your saved suggestions.
Depending on where you live you also have the right to access, correct, delete, port, restrict or object to the processing of your data, to withdraw consent, and to complain to a data protection authority, in particular the one responsible for your place of residence or for our place of business. To exercise a right, email privacy@azayn.com from the address on your account. We respond within 30 days. Requests for access, export and deletion are handled by us by hand.
Withdrawing consent to health-data processing: disconnect phone sync and trainers in the App and ask us to delete your account (section 10).
California residents (CCPA/CPRA): the categories we collected in the last 12 months are those in section 4. The sensitive personal information we collect is health data, precise geolocation (workout routes), account credentials and trainer identity documents, and we use it only to provide the service you asked for. We do not sell or share personal information and do not offer a financial incentive for data. You may use an authorised agent. We will not discriminate against you for exercising your rights.
Washington, Nevada and other places with consumer-health-data laws: you have the right to confirm whether we collect your consumer health data, to access it, to withdraw consent and to have it deleted. Contact us at privacy@azayn.com. We do not sell consumer health data.
10. Deleting your account: exactly what happens
To delete your account, email privacy@azayn.com from the address on your account. We confirm it is you and complete the deletion within 30 days. When we do:
- You are signed out everywhere; your profile and posts stop being visible; active trainer connections end and trainers lose access; and any Stripe subscription is cancelled.
- We permanently delete your profile, health and fitness data, workouts and routes, posts and media files, notes, programs and progress, follows and blocks, device and session records, consent records, and your uploaded documents (including trainer identity documents).
- What can remain: transaction records held by Stripe, Apple and Google; backups, which age out as described in section 11; moderation records that no longer identify you; records the law requires us to keep; and anything other people copied or saved, for example a screenshot.
- Unused purchased username-change tokens are forfeited. Subscriptions bought through Apple or Google keep billing until you cancel them in the store.
11. How long we keep data
- Sign-in codes: 10 minutes.
- Sessions: 30 days from sign-in, or until you sign out.
- Everything tied to your account: until you delete it (section 10).
- Server logs: up to 30 days.
- Backups: about 7 days of point-in-time recovery; the storage service keeps deleted backup files for a further 14 days. A deleted account is removed again if a backup is ever restored.
- Records we must keep by law (for example accounting records): as long as the law requires, currently up to eight years in Germany.
12. Children
Azayn Health is not directed to, and we do not knowingly collect data from, anyone under 18.
13. Changes
We will post changes here with a new date. For material changes we will notify you in the App and ask you to accept the update again where the law requires consent.
14. Contact
Provider details: Legal information · privacy@azayn.com. You may complain to the data protection authority responsible for your place of residence or for our place of business.