Privacy Policy

Last updated October 8, 2026

What we collect

Your account details: name, email address and, if you sign in with Google or GitHub, the basic profile those services share (name, email, avatar).

Health and activity data you choose to bring in, either by entering it yourself or by connecting a service such as Strava, Whoop, Oura, Garmin, Withings or Dexcom. We only request read access, and only the scopes needed to show that data in Healthmaxx.

How we use it

Only to run Healthmaxx for you: to sign you in, sync and display your data, and send account emails such as address verification and password resets. We do not sell your data, use it for advertising, or share it with third parties beyond the providers that host and operate the service.

Google user data

When you sign in with Google we receive your name, email address and profile picture, and use them only to create and identify your account. Healthmaxx's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Analytics and error tracking

We run our own instance of PostHog to count page views, measure sign-ups and purchases, and record errors so we can fix them. It receives the pages you visit, these events and an anonymous or account ID. Your health data is never sent to it, and we do not record sessions.

Connected services

You can disconnect any connected service at any time from the integrations page, which revokes our access and stops further syncing. You can also revoke access from the provider's own settings.

Storage and security

Data is stored in a database on servers we operate in the European Union and is sent over encrypted connections. Access tokens for connected services are kept server-side and never exposed to the browser.

Deleting your data

You can delete your account from the settings page, which removes your data. You can also email hi@kitze.io and we will delete it for you.

Contact

Questions about this policy: hi@kitze.io.