Back home

Legal

Privacy Policy

Effective: July 20, 2026 · Last updated: July 20, 2026 · Governed by Canadian federal and provincial privacy law

At a glance

  • Heill AI is operated from Canada and complies with PIPEDA and applicable provincial privacy laws.
  • We collect only what is needed to deliver your coaching, nutrition, menstrual-cycle insights, and health features.
  • We never sell your personal information or health data, and we do not run advertising.
  • You can access, correct, export, or delete your data at any time by emailing [email protected].

1. Who we are (Data Controller)

Heill AI ("Heill", "we", "us", "our") operates the Heill AI mobile and web application ("the Service"). For the purposes of the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), British Columbia's Personal Information Protection Act (BC PIPA), Alberta's Personal Information Protection Act (AB PIPA), and Ontario's Personal Health Information Protection Act (PHIPA) where applicable, Heill AI is the organization responsible for the personal information described in this policy.

Our designated Privacy Officer (and, for Quebec residents, the person in charge of the protection of personal information under Law 25) can be reached at [email protected].

2. Scope and consent

This policy applies to all personal information we collect through the Heill AI app, website, customer support channels, and connected device integrations (such as Apple HealthKit and Google Health Connect). By creating an account or using the Service, you provide your express, informed consent to the collection, use, and disclosure of your personal information as described here. Where the law requires it (for example, for sensitive health data under Quebec Law 25 and PHIPA), we obtain a separate, granular consent before processing.

You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent for core data (such as your account or health profile) will mean we can no longer provide the Service to you.

3. Personal information we collect

We limit collection to what is necessary for the purposes identified below.

  • Account data: email address, display name, password hash, authentication provider identifiers (e.g. Google sign-in), and account preferences.
  • Health and fitness data (sensitive personal information): age, sex, height, weight, body composition, fitness goals, available equipment, workouts and sets logged, meals and water intake, sleep entries, hydration, steps, exercise sessions, menstrual-cycle dates and symptoms, and other measurements you record or sync.
  • Images you submit: body scans, face scans, meal and barcode snaps, and form-check videos used by the AI features you invoke.
  • Device and connected-source data: data you authorize us to read from Apple HealthKit, Google Health Connect, or similar sources (steps, sleep, workouts, heart rate).
  • Technical data: device type, OS version, app version, language, IP address, crash logs, and basic usage analytics needed to operate the Service.
  • Communications: messages you send to our support team or coach features.

Age requirements. The Service is intended for users aged 16 and older. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has created an account or submitted health, body, face, or form-check data, contact [email protected] and we will delete the information promptly.

4. Purposes for which we use your information

We use personal information only for the following identified purposes:

  • Creating and securing your account and authenticating you.
  • Generating personalized workout programs, diet plans, and AI coaching responses.
  • Analyzing snapped meals, scanned barcodes, body/face scans, and form-check videos.
  • Cross-referencing food and skincare items against your skin sensitivity and diet plan to flag good/bad matches.
  • Syncing and displaying activity, sleep, and workout data from Apple HealthKit and Google Health Connect.
  • Tracking, predicting, and visualizing menstrual-cycle dates and symptoms to support training and nutrition planning.
  • Communicating with you about the Service, updates, and security notices.
  • Detecting fraud, abuse, and protecting the integrity of the Service.
  • Meeting our legal, regulatory, and accounting obligations in Canada.

We will not use your personal information for any new purpose without first obtaining your consent, as required by PIPEDA Principle 4.2 and equivalent provincial rules.

5. Automated decision-making and AI processing

Heill AI utilizes automated artificial intelligence models to process user requests, text chats, and media uploads. These features analyze physical markers (such as face-scan and body-scan photos), process meal entries, and dynamically generate workout illustrations. These processes are entirely informational, run via secure automated third-party APIs, and do not replace professional medical evaluations or healthcare advice.

In accordance with Quebec Law 25 (s. 12.1) and emerging Canadian guidance, we disclose that these features involve automated processing of your personal information, including sensitive health data. The principal factors used are the data you provide (profile, scans, logs) and the resulting model outputs. You have the right to request human review of any significant decision and to submit observations by contacting [email protected].

Photos and prompts you submit are processed by our AI providers under contractual obligations of confidentiality and are not used to train third-party foundation models.

6. Disclosure to third parties and service providers

We share personal information strictly to the extent required to execute your app features with the following core infrastructure sub-processors:

  • Cloud and database hosting: Secured server environments utilized to maintain your encrypted account records.
  • AI Text & Vision Providers: Your text prompts and body/face scans are securely transmitted via encrypted gateways to Google LLC (Gemini API architecture) to compute progress history, fitness plans, and chat outputs.
  • AI Image Generation Providers: Prompt criteria for exercise guides are securely transmitted to OpenAI, L.L.C. (GPT Image models) solely to generate illustrative workout graphics within the application interface.
  • Authentication providers (such as Google) when you choose to sign in with them.
  • Analytics and crash-reporting tools used to maintain reliability (configured to minimize personal data).
  • Legal and regulatory authorities when compelled by valid Canadian legal process.

Each service provider is bound by a written agreement requiring them to provide a comparable level of protection to that required under PIPEDA, BC PIPA, AB PIPA, and Quebec Law 25, and to use the information only for the purposes we authorize. We do not sell, rent, or trade your personal information.

7. Storage location and cross-border transfers

Personal information may be stored on servers located in Canada and the United States, and may be processed by service providers located outside Canada (including in the United States and the European Union). When personal information is transferred outside of Canada or Quebec, it becomes subject to the laws of the jurisdiction in which it is held, and may be accessible to foreign courts, law enforcement, and national security authorities.

Before any transfer of personal information outside Quebec, we conduct a privacy impact assessment as required by section 17 of Quebec Law 25 and apply contractual and technical safeguards to ensure adequate protection. You may contact [email protected] to obtain more information about these transfers.

8. Safeguards

We protect personal information with security measures appropriate to its sensitivity, consistent with PIPEDA Principle 4.7 and equivalent provincial requirements. These include: encryption in transit (TLS) and at rest, row-level database security so only you can read your records, principle-of-least-privilege access controls, multi-factor authentication for administrative access, vendor security review, and continuous monitoring.

Despite our safeguards, no system can be guaranteed 100% secure. In the event of a confidentiality incident or breach that poses a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada (and, where applicable, the Commission d'accès à l'information du Québec) as required by law.

9. Retention and deletion

We keep your personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by law. Account and health data are retained for the lifetime of your account.

Photos, videos and scan media specifically:

  • Form-check videos (uploaded to the AI form-check feature) are processed in-memory to generate your feedback and bounding-box analysis, and the source video file is automatically deleted from our storage within 24 hours. Only the structured text feedback and rep metrics are kept in your training history.
  • Face-scan photos are used to compute your skin-health biometrics and are retained for 30 days so you can compare against your most recent scan, then automatically deleted. The numeric biometric results (scores, vectors, history) remain in your account so you can track progress over time.
  • Body-scan photos are retained for 90 days to allow before/after comparisons, then automatically deleted. The derived measurements (body-fat estimate, posture markers, composition history) remain in your account.
  • Meal and barcode snaps are retained for 30 days for re-analysis and dispute resolution, then automatically deleted; the parsed nutrition entry stays in your food log.

You can delete any individual scan, video or photo at any time from the relevant screen in the app, which removes it from our storage immediately (with a short backup-rotation tail of up to 7 days).

Account deletion timeline. When you delete your account from Settings → Account, we begin erasure immediately. Your profile and active records are removed from the live database within minutes. All remaining personal information, including any retained scan media, is erased or irreversibly anonymized from primary systems within 7 days, and purged from encrypted backups within 30 days as those backups rotate out — at which point deletion is complete and irreversible. Limited records we are legally required to retain (such as billing records under Canadian tax and consumer- protection law) are kept only for the period the law mandates and are not used for any other purpose.

10. Your privacy rights

Subject to limited legal exceptions, you have the right to:

  • Access the personal information we hold about you and know how it is used and disclosed.
  • Correct or update inaccurate or incomplete information.
  • Withdraw consent to further processing, subject to legal and contractual restrictions.
  • Delete your account and associated personal information.
  • Data portability – receive your data in a structured, commonly used technological format (Quebec Law 25, s. 27).
  • De-indexing – request that information about you be de-indexed where it causes serious injury (Quebec Law 25).
  • Object to a decision based exclusively on automated processing and request human review.
  • File a complaint with us, and ultimately with the relevant Canadian privacy regulator.

To exercise any of these rights, email [email protected]. We will respond within 30 days, as required by PIPEDA and Quebec Law 25.

11. Apple HealthKit and Google Health Connect

When you connect Apple HealthKit or Google Health Connect, Heill AI reads only the categories you authorize (such as steps, sleep, and workouts). This data is used solely to display your activity, improve your plan, and is never used for advertising, sold, or shared with data brokers, in compliance with Apple's HealthKit and Google's Health Connect policies and Canadian health-privacy law. You can revoke access at any time in your device's system settings.

12. Electronic communications (CASL)

In compliance with Canada's Anti-Spam Legislation (CASL), we send commercial electronic messages only with your consent (express or implied). Every commercial message includes our identification and an easy unsubscribe mechanism that takes effect within 10 business days. Transactional messages (security alerts, password resets, account notices) are sent without opt-in as permitted by CASL.

13. Cookies and similar technologies

The Heill AI web app uses strictly necessary cookies and local storage to keep you signed in and remember your preferences. We do not use third-party advertising or cross-site tracking cookies. Where required by law, we will present a cookie banner allowing you to manage non-essential cookies.

14. Changes to this policy

We may update this policy from time to time. If we make material changes (for example, new purposes of processing or new categories of recipients), we will notify you in-app or by email at least 30 days before the change takes effect, and obtain fresh consent where required by law.

15. Contact and complaints

For any privacy question, access request, correction, deletion request, or complaint, please contact our Privacy Officer:

Heill AI — Privacy Officer

Email: [email protected]

If you are not satisfied with our response, you have the right to file a complaint with the appropriate Canadian regulator:

  • Office of the Privacy Commissioner of Canada (OPC) – priv.gc.ca · 1-800-282-1376
  • Commission d'accès à l'information du Québec (CAI) – cai.gouv.qc.ca
  • Office of the Information and Privacy Commissioner for British Columbia – oipc.bc.ca
  • Office of the Information and Privacy Commissioner of Alberta – oipc.ab.ca
  • Information and Privacy Commissioner of Ontario (IPC) – ipc.on.ca

This policy is provided for transparency and does not constitute legal advice. It is drafted to align with PIPEDA, Quebec Law 25, BC PIPA, AB PIPA, PHIPA, and CASL as of the effective date above.