Privacy Notice
Last Updated: September 11, 2026
1. Introduction
Welcome to EverRhythm. We are committed to protecting your privacy and handling your sensitive personal and health information with the utmost care and respect. This Privacy Notice outlines our practices concerning the collection, use, and sharing of your data. It explains your rights and how we comply with various data protection regulations, including GDPR, HIPAA, and PIPEDA.
2. Information We Collect
We collect information to provide and improve our services. This includes:
- Account Information: Name, email address, password, date of birth, and other profile details.
- Health Data: Information you log about your medical conditions, symptoms, medications, treatments, mood, and other health-related activities. This is considered Protected Health Information (PHI) under HIPAA and Special Category Data under GDPR.
- Technical Data: IP address, device type, operating system, browser type, and usage data collected through cookies and similar technologies.
- Third-Party Data: We may receive data from third-party services if you choose to integrate them with your EverRhythm account.
3. How We Use Your Information
Your data is used to:
- Provide, maintain, and personalize our services.
- Generate insights and reports about your health trends.
- Communicate with you about your account and our services.
- Anonymize and aggregate data for research purposes, only with your explicit consent.
- Ensure the security of our services and for troubleshooting.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process your personal data based on the following legal grounds:
- Consent: We rely on your explicit consent to process special categories of personal data, such as your health information. You can withdraw your consent at any time.
- Contractual Necessity: To provide the services you requested as outlined in our Terms and Conditions.
- Legitimate Interests: For purposes like security, service improvement, and analytics, provided these interests do not override your fundamental rights and freedoms.
5. HIPAA and Your Protected Health Information (PHI)
For users in the United States, we are committed to protecting your PHI in accordance with the Health Insurance Portability and Accountability Act (HIPAA). We implement physical, administrative, and technical safeguards to protect your PHI. We will not use or disclose your PHI except as permitted by you or as required by law.
6. PIPEDA Compliance (Canada)
For our Canadian users, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). We are accountable for your personal information, obtain your consent for its collection and use, and limit its use to the purposes identified.
7. Data Sharing and Third Parties
We do not sell your personal data. We may share your information with:
- Service Providers: We use third-party vendors for hosting, error tracking (Sentry), and analytics. These vendors are contractually obligated to protect your data and use it only to provide services to us.
- Research Partners: Anonymized and aggregated data may be shared with research institutions if you have provided explicit consent.
- Legal Requirements: We may disclose your information if required by law, such as in response to a subpoena or court order.
8. Data Storage and Retention
Your data is stored on secure servers. We retain your personal data for as long as your account is active or as needed to provide you with our services. We may retain anonymized data for longer periods for research and statistical purposes.
9. Your Rights
You have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure ("Right to be Forgotten"): Request the deletion of your personal data.
- Data Portability: Receive your data in a machine-readable format.
- Restrict Processing: Limit how we use your data.
- Object to Processing: Object to our processing of your data for legitimate interests.
To exercise these rights, please contact us at the address below.
10. Policy Management and Versioning
We maintain a comprehensive policy management system to ensure our privacy practices remain current and compliant with evolving regulations. All policies undergo regular review and version control to track changes and maintain transparency.
Our privacy policy management includes:
- Version Control: Each policy update is versioned and tracked with detailed change logs
- Regular Reviews: Policies are reviewed at least annually or when regulatory changes occur
- Approval Process: All policy changes undergo formal review and approval before publication
- Transparency: Users are notified of significant policy changes and provided with clear information about updates
11. Contact Us
If you have any questions about this Privacy Notice or our data practices, please contact our Data Protection Officer at:
Email: privacy@everrhythm.health
Address: 123 Wellness Ave, Health City, HC 54321