At a glance
- Heill AI Inc. is a Canadian corporation and complies with PIPEDA and applicable provincial privacy laws.
- We collect only what is needed to deliver your coaching, nutrition, menstrual-cycle insights, and health features.
- We never sell your personal information or health data, and we do not show third-party advertising inside the app.
- You can access, correct, export, or delete your data at any time by emailing [email protected].
1. Who we are (Data Controller)
Heill AI Inc. ("Heill AI", "Heill", "we", "us", "our"), a corporation incorporated in Alberta, Canada, operates the Heill AI mobile and web application ("the Service"). For the purposes of the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), British Columbia's Personal Information Protection Act (BC PIPA), Alberta's Personal Information Protection Act (AB PIPA), and Ontario's Personal Health Information Protection Act (PHIPA) where applicable, Heill AI is the organization responsible for the personal information described in this policy.
Our designated Privacy Officer (and, for Quebec residents, the person in charge of the protection of personal information under Law 25) can be reached at [email protected].
2. Scope and consent
This policy applies to all personal information we collect through the Heill AI app, website, customer support channels, and connected device integrations (such as Apple HealthKit and Google Health Connect). By creating an account or using the Service, you provide your express, informed consent to the collection, use, and disclosure of your personal information as described here. Where the law requires it (for example, for sensitive health data under Quebec Law 25 and PHIPA), we obtain a separate, granular consent before processing.
You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent for core data (such as your account or health profile) will mean we can no longer provide the Service to you.
3. Personal information we collect
We limit collection to what is necessary for the purposes identified below.
- Account data: email address, display name, password hash, authentication provider identifiers (Google Sign-In and Sign in with Apple), and account preferences.
- Health and fitness data (sensitive personal information): age, sex, height, weight, body composition, fitness goals, available equipment, workouts and sets logged, meals and water intake, sleep entries, hydration, steps, exercise sessions, menstrual-cycle dates and symptoms, and other measurements you record or sync.
- Images you submit: body scans, face scans, meal and barcode snaps, and form-check videos used by the AI features you invoke.
- Device and connected-source data: data you authorize us to read from Apple HealthKit, Google Health Connect, or similar sources (steps, sleep, workouts, heart rate).
- Location and movement data (Heill Move): when you start a run or ride, your device's GPS location, speed, elevation, and route path are recorded to track your session live and produce your route map and statistics. On iOS, if you grant "Always" location access, tracking continues while your screen is locked so your session is not interrupted; location is only collected while a session you started is active — never in the background otherwise. Route coordinates you plan with may be sent to our routing provider to compute paths, distances, and elevation.
- Technical data: device type, OS version, app version, language, IP address, crash logs, and basic usage analytics needed to operate the Service. In the native app this may include device and advertising identifiers and basic app event data (such as app installs, app opens, and purchases) collected by the Meta SDK to measure the performance of our own advertising campaigns.
- Communications: messages you send to our support team or coach features.
Sign in with Apple. If you sign in using Apple's private email relay (Hide My Email), we receive an Apple-generated relay address rather than your personal email address. We use it only to contact you about your account and the Service.
Age requirements. The Service is intended for users aged 16 and older. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has created an account or submitted health, body, face, or form-check data, contact [email protected] and we will delete the information promptly.
4. Purposes for which we use your information
We use personal information only for the following identified purposes:
- Creating and securing your account and authenticating you.
- Generating personalized workout programs, diet plans, and AI coaching responses.
- Analyzing snapped meals, scanned barcodes, body/face scans, and form-check videos.
- Cross-referencing food and skincare items against your skin sensitivity and diet plan to flag good/bad matches.
- Syncing and displaying activity, sleep, and workout data from Apple HealthKit and Google Health Connect.
- Planning run and bike routes to your distance or calorie target, tracking your live GPS position during a session, and producing route maps, pace, and elevation summaries.
- Tracking, predicting, and visualizing menstrual-cycle dates and symptoms to support training and nutrition planning.
- Communicating with you about the Service, updates, and security notices.
- Detecting fraud, abuse, and protecting the integrity of the Service.
- Measuring the performance of our own advertising campaigns via the Meta SDK, using device and advertising identifiers and basic app events only.
- Meeting our legal, regulatory, and accounting obligations in Canada.
We will not use your personal information for any new purpose without first obtaining your consent, as required by PIPEDA Principle 4.2 and equivalent provincial rules.
5. Automated decision-making and AI processing
Heill AI utilizes automated artificial intelligence models to process user requests, text chats, and media uploads. These features analyze physical markers (such as face-scan and body-scan photos), process meal entries, and dynamically generate workout illustrations. These processes are entirely informational, run via secure automated third-party APIs, and do not replace professional medical evaluations or healthcare advice.
In accordance with Quebec Law 25 (s. 12.1) and emerging Canadian guidance, we disclose that these features involve automated processing of your personal information, including sensitive health data. The principal factors used are the data you provide (profile, scans, logs) and the resulting model outputs. You have the right to request human review of any significant decision and to submit observations by contacting [email protected].
Photos and prompts you submit are processed by our AI providers under contractual obligations of confidentiality and are not used to train third-party foundation models.
6. Disclosure to third parties and service providers
We share personal information strictly to the extent required to execute your app features with the following core infrastructure sub-processors:
- Cloud and database hosting: Supabase, Inc. provides our encrypted database, authentication, and file storage infrastructure.
- Subscription management: RevenueCat, Inc. receives a pseudonymous app user identifier and your subscription status in order to manage your entitlements and restore purchases. RevenueCat does not receive your health data, scans, or logs.
- AI Text & Vision Providers: Your text prompts and body/face scans are securely transmitted via encrypted gateways to Google LLC (Gemini API architecture) to compute progress history, fitness plans, and chat outputs. When you have connected a health data source with consent, summarized activity and sleep metrics may also be included to personalize these insights; they are never sold or used for advertising.
- AI Image Generation Providers: Prompt criteria for exercise guides are securely transmitted to OpenAI, L.L.C. (GPT Image models) solely to generate illustrative workout graphics within the application interface.
- Authentication providers (Google and Apple) when you choose to sign in with them.
- Mapping and routing: Google LLC (Google Maps Platform) receives the start point and waypoints you choose when planning a Heill Move route, solely to compute the route path, distance, and elevation profile. Map tiles are served by Esri. Live GPS tracks from your sessions are stored against your account and are not sent to these providers.
- Apple Watch: the Heill Watch app receives a sign-in token from your iPhone so it can save the water, workouts, heart rate and rest days you log on your wrist directly to your account. Watch entries are stored like phone entries and are not shared with third parties.
- Analytics and crash-reporting tools used to maintain reliability (configured to minimize personal data).
- Meta Platforms, Inc. (Meta SDK / App Events): in the native app, the Meta SDK receives device and advertising identifiers and basic app events (such as app installs, app opens, registration, and subscription purchases) so we can measure and improve the performance of our own advertising campaigns on Meta platforms. The Meta SDK never receives your health data, fitness logs, body or face scans, chat messages, or any HealthKit or Health Connect data.
- Legal and regulatory authorities when compelled by valid Canadian legal process.
Each service provider is bound by a written agreement requiring them to provide a comparable level of protection to that required under PIPEDA, BC PIPA, AB PIPA, and Quebec Law 25, and to use the information only for the purposes we authorize. We do not sell, rent, or trade your personal information.
7. Storage location and cross-border transfers
Personal information may be stored on servers located in Canada and the United States, and may be processed by service providers located outside Canada (including in the United States and the European Union). When personal information is transferred outside of Canada or Quebec, it becomes subject to the laws of the jurisdiction in which it is held, and may be accessible to foreign courts, law enforcement, and national security authorities.
Before any transfer of personal information outside Quebec, we conduct a privacy impact assessment as required by section 17 of Quebec Law 25 and apply contractual and technical safeguards to ensure adequate protection. You may contact [email protected] to obtain more information about these transfers.
8. Safeguards
We protect personal information with security measures appropriate to its sensitivity, consistent with PIPEDA Principle 4.7 and equivalent provincial requirements. These include: encryption in transit (TLS) and at rest, row-level database security so only you can read your records, principle-of-least-privilege access controls, multi-factor authentication for administrative access, vendor security review, and continuous monitoring.
Despite our safeguards, no system can be guaranteed 100% secure. In the event of a confidentiality incident or breach that poses a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada (and, where applicable, the Commission d'accès à l'information du Québec) as required by law.
9. Retention and deletion
We keep your personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by law. Account and health data are retained for the lifetime of your account.
Photos, videos and scan media specifically:
- Form-check videos (uploaded to the AI form-check feature) are processed in-memory to generate your feedback and bounding-box analysis, and the source video file is automatically deleted from our storage within 24 hours. Only the structured text feedback and rep metrics are kept in your training history.
- Face-scan photos are used to compute your skin-health biometrics and are retained for 30 days so you can compare against your most recent scan, then automatically deleted. The numeric biometric results (scores, vectors, history) remain in your account so you can track progress over time.
- Body-scan photos are retained for 90 days to allow before/after comparisons, then automatically deleted. The derived measurements (body-fat estimate, posture markers, composition history) remain in your account.
- Meal and barcode snaps are retained for 30 days for re-analysis and dispute resolution, then automatically deleted; the parsed nutrition entry stays in your food log.
You can delete any individual scan, video or photo at any time from the relevant screen in the app, which removes it from our storage immediately (with a short backup-rotation tail of up to 7 days).
Account deletion timeline. When you delete your account from Settings → Privacy → Your data → Delete account, we begin erasure immediately. Your profile and active records are removed from the live database within minutes. All remaining personal information, including any retained scan media, is erased or irreversibly anonymized from primary systems within 7 days, and purged from encrypted backups within 30 days as those backups rotate out — at which point deletion is complete and irreversible. Limited records we are legally required to retain (such as billing records under Canadian tax and consumer- protection law) are kept only for the period the law mandates and are not used for any other purpose.
10. Your privacy rights
Subject to limited legal exceptions, you have the right to:
- Access the personal information we hold about you and know how it is used and disclosed.
- Correct or update inaccurate or incomplete information.
- Withdraw consent to further processing, subject to legal and contractual restrictions.
- Delete your account and associated personal information.
- Data portability – receive your data in a structured, commonly used technological format (Quebec Law 25, s. 27).
- De-indexing – request that information about you be de-indexed where it causes serious injury (Quebec Law 25).
- Object to a decision based exclusively on automated processing and request human review.
- File a complaint with us, and ultimately with the relevant Canadian privacy regulator.
To exercise any of these rights, email [email protected]. We will respond within 30 days, as required by PIPEDA and Quebec Law 25.
11. Apple HealthKit and Google Health Connect
When you connect Apple HealthKit or Google Health Connect, Heill AI reads only the categories you authorize (such as steps, sleep, and workouts), and only after you grant explicit consent through the operating system's permission prompt. This data is used to display your activity, improve your plan, and personalize your insights, and is never used for advertising, sold, or shared with data brokers or with advertising or measurement providers (including Meta Platforms, Inc.), in compliance with Apple's HealthKit and Google's Health Connect policies and Canadian health-privacy law.
With your consent, summarized health metrics (such as daily step counts and sleep durations) may be processed by our AI service providers (as described in Section 6) solely to generate personalized insights, coaching, and plan recommendations for you. These metrics are processed under contractual confidentiality obligations, are not used to train third-party foundation models, and are never sold or shared with data brokers.
You can revoke access at any time either in the app under Settings → Wearables → Manage wearables, or in your device's system settings (iOS: Settings → Health → Data Access & Devices; Android: Health Connect permissions). Revoking access stops all further reading and processing of health metrics.
12. Payments and subscription data
All purchases and subscriptions are processed by the Apple App Store. We never receive or store your credit card number, CVV, or full payment credentials. We receive only your subscription status, product identifier, purchase and renewal dates, and a pseudonymous transaction identifier, which we use to unlock premium features and provide support. Billing records that we are required to keep under Canadian tax law are retained for the period the law mandates and are not used for any other purpose.
13. Electronic communications (CASL)
In compliance with Canada's Anti-Spam Legislation (CASL), we send commercial electronic messages only with your consent (express or implied). Every commercial message includes our identification and an easy unsubscribe mechanism that takes effect within 10 business days. Transactional messages (security alerts, password resets, account notices) are sent without opt-in as permitted by CASL.
15. Changes to this policy
We may update this policy from time to time. If we make material changes (for example, new purposes of processing or new categories of recipients), we will notify you in-app or by email at least 30 days before the change takes effect, and obtain fresh consent where required by law.
16. Contact and complaints
For any privacy question, access request, correction, deletion request, or complaint, please contact our Privacy Officer:
Heill AI Inc. — Privacy Officer
Email: [email protected]
If you are not satisfied with our response, you have the right to file a complaint with the appropriate Canadian regulator:
- Office of the Privacy Commissioner of Canada (OPC) – priv.gc.ca · 1-800-282-1376
- Commission d'accès à l'information du Québec (CAI) – cai.gouv.qc.ca
- Office of the Information and Privacy Commissioner for British Columbia – oipc.bc.ca
- Office of the Information and Privacy Commissioner of Alberta – oipc.ab.ca
- Information and Privacy Commissioner of Ontario (IPC) – ipc.on.ca
This policy is provided for transparency and does not constitute legal advice. It is drafted to align with PIPEDA, Quebec Law 25, BC PIPA, AB PIPA, PHIPA, and CASL as of the effective date above.