Skip to main content

Spur Consumer Health Data Privacy Policy

Last updated: July 24, 2026

This policy supplements the Spur Privacy Policy and describes how Shotz App LLC, doing business as Spur, handles “consumer health data” under laws such as Washington’s My Health My Data Act. It applies even when that information is not protected by HIPAA. Spur is not a healthcare provider and does not provide medical or mental-health advice.

Consumer Health Data We May Collect

Depending on what you choose to enter, consumer health data may include health or wellness goals; exercise and movement routines; available energy; accessibility or physical constraints; symptoms, injuries, conditions, medications, treatment information, mental-health or crisis-related statements; and inferences that could identify your health status. Please do not enter clinical details that Spur does not need.

Sources

We collect this data directly from you through onboarding, goal setup, check-ins, settings, support messages, and other text you submit. We may derive limited inferences from those entries to select or size an action. We do not collect precise location, camera evidence, medical records, or connected financial-account data as part of current app functionality.

Why We Collect And Use It

We use consumer health data only as reasonably necessary to provide requested planning and action features, save your choices, maintain safety boundaries, respond to support or privacy requests, secure the Service, and comply with law. Safety screening may stop a normal recommendation when text indicates urgent risk or a request outside Spur’s boundaries.

Sharing

We may share consumer health data with Supabase, our hosting, authentication, database, and backend processor. If—and only if—you separately enable AI personalization, we may send limited goal, milestone, time, energy, and current-context information to OpenAI to help word a response. You may decline or later withdraw this consent; deterministic features remain available. Apple and RevenueCat receive subscription or authentication information but are not intended to receive the goals, reflections, or health-related text you enter in Spur.

We do not sell consumer health data. We do not share it for cross-context behavioral advertising. We have no affiliates with access to consumer health data. If this changes, we will update this policy and obtain consent where required.

The optional Meta Pixel used on general public marketing pages does not run on this Consumer Health Data Privacy Policy page and is not configured to receive Spur goals, reflections, app activity, or consumer health data.

Your Choices And Rights

You may:

  • Access or obtain a copy of consumer health data associated with you.
  • Correct inaccurate data, including through available goal-editing controls.
  • Delete your account and active Spur product data in the app.
  • Withdraw optional AI-sharing consent in Review; withdrawal applies to future sharing.
  • Appeal a refusal of a privacy request.

To exercise access, correction, deletion, withdrawal, or appeal rights, use the app’s Privacy center or email simon@takeactionwithspur.com with “Privacy request” in the subject. We will verify your identity and respond without undue delay, generally within 45 days. If reasonably necessary, we may extend once by up to 45 additional days and will explain the extension. Appeals will be reviewed by a person not responsible for the original decision where practicable. If an appeal is denied, Washington residents may contact the Washington State Attorney General.

Deletion And Retention

In-app account deletion removes the authentication account and active Spur product records from our primary systems. We will instruct processors to delete consumer health data where required and technically applicable. Limited legal-acceptance, security, fraud-prevention, subscription, transaction, or backup records may remain where required or permitted by law; backups are isolated from ordinary use and expire under our retention process. De-identified information may be retained only where it cannot reasonably be linked back to you.

Security

We use role-based access, row-level database controls, encrypted transport, server-only credentials for authoritative writes, data minimization, and deletion procedures designed to protect consumer health data. Access is limited to people and processors who need it for authorized purposes. No system is completely secure.

Changes And Contact

We will post material changes and obtain consent when required before collecting or sharing consumer health data for a materially different purpose.

Shotz App LLC 1040 Spring Street, Apt D Madison, WI 53715 United States Email: simon@takeactionwithspur.com